Data management system and data management method
The data management system enables secure and controlled restoration of anonymized data by integrating anonymization and authentication processes, ensuring privacy, data integrity, and legal compliance through successful third-party authentication.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- 前川淳
- Filing Date
- 2026-02-05
- Publication Date
- 2026-05-25
AI Technical Summary
Conventional data management systems fail to simultaneously protect the privacy of third parties, maintain the integrity and usefulness of recorded data, and allow third parties to restore their data to its original state, often resulting in irreversible anonymization that loses realism and increases legal risks.
A data management system that includes a recording device for anonymizing biometric data, a management device for storing and managing anonymized data, and a data terminal, and a data management device for storing and managing anonymized data, and a data management device for controlling the anonymized data, and a data management device for managing anonymized data, and a data management device for storing and managing anonymized data, and a data terminal for controlling data restoration, which allows restoration only upon successful authentication of the data owner.
Ensures privacy protection, data sovereignty, and legal compliance by allowing restoration of anonymized data only when the third party's authentication is successful, thereby preventing unauthorized access and maintaining data integrity.
Smart Images

Figure 0007864945000001_ABST
Abstract
Description
Technical Field
[0004] , , ,
[0001] The present invention relates to a data management system including a recording device for recording biometric behavior information of a third party, a management device for managing anonymized data obtained from the recording device, and a data terminal operated by a third party, and a data management method for the data management system. More specifically, it relates to a system and method for controlling the execution of anonymized data restoration based on the success of authentication of a third party himself / herself.
Background Art
[0002] In recent years, the performance, miniaturization, and low cost of recording devices have been remarkable, and the continuous recording of voice and video by individuals is becoming common in various scenarios. For example, recordings of sports and daily life using first-person perspective devices such as action cameras represented by GoPro and smart glasses, and the shooting and public release of video content for platforms such as YouTube by individual creators. In these recordings, regardless of the intention of the recorder himself / herself, in addition to family members, friends, colleagues, etc., personal identifiable information such as voiceprints, facial features, and motion features of unspecified third parties such as passers-by is often mixed in, and from the perspective of privacy protection, some anonymization processing or information control is strongly required.
[0003] Patent Document 1 below discloses that "in order to guarantee anonymity in an interactive interview service and provide a more efficient business tool by performing voice correction in real time and correcting elements such as dialects and intonations, it is a system including a generative AI for performing voice correction, means for correcting dialects, intonations, etc. of the corresponding voice in real time, means for providing an interactive interview service that guarantees anonymity for applying the corresponding voice to an interview, and means for automatically scheduling the interview schedule using the mind of GPT."
Prior Art Documents
Patent Documents
[0004] [Patent Document 1] Japanese Patent Publication No. 2025-50864 [Overview of the project] [Problems that the invention aims to solve]
[0005] However, while conventional technologies allow for irreversible anonymization of third-party voices and images (voiceprints, facial features, motion characteristics, etc.) contained in recorded data through processes such as mosaic processing and voice conversion, this results in a loss of realism and a decrease in the value and evidentiary value of the content for the recorder. Furthermore, even if the third party themselves later wishes to review their own statements or actions, they cannot restore them to their original state and can only play back processed data that sounds unnatural, even if it is their own voice or appearance.
[0006] On the other hand, if data is recorded, stored, and published without anonymization, there is a high risk of infringing on the privacy of third parties, and the recorder faces the risk of legal liability and complaint handling. Furthermore, there is a possibility that platform operators and others may use the data for AI training and other purposes without the permission of third parties, leading to the problem of data being distributed against the will of third parties.
[0007] Thus, conventional technologies have found it difficult to simultaneously satisfy multiple requirements: protecting the privacy of third parties, maintaining the usefulness and integrity of recorded data, and allowing third parties to use their own data at a later date. Furthermore, the primary approach has been reactive, such as "deleting data if there are complaints after publication," and there has been no means to proactively protect the rights of third parties from the time of recording.
[0008] The present invention was made to solve the above problems and aims to provide a data management system and a data management method that implement technical control to allow the restoration of anonymized data relating to a third party only when the authentication of that person is successful. [Means for solving the problem]
[0009] A data management system according to one aspect of the present invention comprises a recording device and a management device. A data management system The recording device includes an acquisition unit that acquires biometric behavior information including that of a third party, and an anonymization unit that converts the portion relating to the third party from the biometric behavior information acquired by the acquisition unit into a format that does not allow for personal identification and generates anonymized data. Before the anonymization unit generates the anonymized data, the extraction unit extracts feature vectors from the biological behavior information acquired by the acquisition unit, The management device includes the anonymized data from the recording device. and the feature vector The storage unit receives and stores the data from the recorder. The aforementioned feature vector An authentication unit that performs authentication of the third party in response to either a restore permission request generated in response to an operation, or a restore request made by the third party themselves. ,before The system is characterized by comprising: an authorization status management unit that sets an authorization status that permits the restoration of the portion of the anonymized data relating to the third party stored in the storage unit when authentication by the authentication unit is successful; and a restoration unit that executes a restoration process when the authorization status set by the authorization status management unit is in a state that permits restoration.
[0010] Furthermore, the recording device or management device includes a feature extraction unit that extracts feature quantities related to the third party from the biological behavior information. The restoration unit then uses these feature quantities to perform a restoration process.
[0011] Furthermore, the anonymization function can be performed not only on the recording device, but also by a processing unit located on the management device. In this way, even if the anonymization or feature extraction processing unit is changed, the core of the present invention—restoration control through authority state management based on successful authentication—remains unchanged.
[0012] Furthermore, a data management method according to one aspect of the present invention is performed using a recording device, a management device, and a data terminal, and is characterized by comprising the steps of: acquiring biometric behavior information including a third party using the recording device; anonymizing the portion relating to the third party from the biometric behavior information to generate anonymized data; storing the anonymized data in the management device; generating a restoration permission request in response to an operation from the recorder, or generating a restoration request in response to an operation from the third party via the data terminal; performing authentication of the third party in response to either the generated restoration permission request or the restoration request; setting an authorization state that permits the restoration of the portion relating to the third party in the stored anonymized data if the authentication is successful; and restoring the portion relating to the third party from the anonymized data if the set authorization state permits restoration. [Effects of the Invention]
[0013] According to the present invention, a "permission state that allows restoration" is set only when the third party's authentication is successful, and the restoration process can only be executed based on this state. As a result, no unauthenticated person can restore the information, and a technical environment is created in which only information relating to the authenticated third party can be securely restored. The core of the present invention lies in a system architecture that integrates and manages multiple processes that are separated both temporally and subjectively—anonymization at the time of recording, granting restoration rights by the third party, and restoration execution by the recorder—through a single technical control point called the "permission state."
[0014] This architecture enables a storage structure that logically separates the "anonymized data storage area" and the "access control metadata area," and technically harmonizes and simultaneously satisfies three distinct requirements that were previously often addressed individually: (1) reliable privacy protection at the time of recording (complete anonymization), (2) the exercise of data sovereignty by third parties at a later date (selective restoration), and (3) the legal restoration of data integrity by the recorder, all within a single data management system. [Brief explanation of the drawing]
[0015] The drawings show specific embodiments of the present invention and include not only essential components of the invention but also optional and preferred embodiments. [Figure 1] A block diagram for explaining the configuration of a data management system showing this embodiment. [Figure 2] A block diagram for explaining the hardware configuration of the recording device shown in FIG. 1. [Figure 3] A block diagram for explaining the hardware configuration of the management device shown in FIG. 1. [Figure 4] A block diagram for explaining the hardware configuration of the data terminal shown in FIG. 1. [Figure 5] A flowchart for explaining the data management method of the data management system showing this embodiment. [Figure 6] A flowchart for explaining the data management method of the data management system showing this embodiment. [Figure 7] A flowchart for explaining the data management method of the data management system showing this embodiment. [Figure 8] A flowchart for explaining the data management method of the data management system showing this embodiment.
Embodiments for Carrying Out the Invention
[0016] Next, the best mode for carrying out the present invention will be described with reference to the drawings.
[0017] <Explanation of System Configuration> 〔First Embodiment〕 FIG. 1 is a block diagram for explaining the configuration of a data management system showing this embodiment. Hereinafter, as an example, a data management system will be described in which a recording device that records biometric behavior information including voices and videos of a plurality of persons via a predetermined communication medium, a data terminal operated by each of the plurality of persons, and a management device that stores and manages the biometric behavior information recorded by the recording device can communicate with each other.
[0018] In this specification, "biometric behavioral information" is a general term for information including voice, facial expressions, gestures, and dynamic physical characteristics that combine these, and the feature quantities extracted from this information may be referred to as biofeature vectors (generally, feature vectors).
[0019] In this specification, “management device” means a collection of devices or software modules including one or more processors that execute the authority control logic of the present invention. Its implementation may be a centralized server, multiple nodes constituting a distributed network, an edge computing device, or a combination thereof.
[0020] In this specification, “storage unit” and “storage area” refer to any storage medium or its logical partition capable of permanently or temporarily holding data. This includes databases, file systems, distributed storage, state on a blockchain, and secure storage areas within a device.
[0021] In this specification, “authority status” refers to any form of informational status referenced to determine whether or not the restoration of anonymized data relating to a particular third party is permitted. This includes flag values in a database, cryptographically committed values, state variables on a distributed ledger (blockchain), or a combination thereof.
[0022] In this specification, "restoration process" may include not only the process of approximately or completely reconstructing the original biometric information from anonymized data, but also the process of generating content that is appropriate for the situation and characteristic of the third party in question, based on the third party's current biometric information.
[0023] In Figure 1, the management device 1 is configured to communicate with multiple data terminals 2, 3, and 4 and a recording device 5 via a network 21. Data terminals 2, 3, and 4 are intended to be operated by other people (third parties).
[0024] <Detailed configuration of the recording device> Figure 2 is a block diagram showing the hardware configuration of the recording device 5. In Figure 2, 101 is the communication unit, which communicates bidirectionally via the network 21 using a predetermined protocol. The recording device 5 is a smartphone, smart glasses, action camera, etc., which records ambient audio and video and stores them in the external memory 107. The CPU 102 performs the following functional processing. 108 is the I / O unit, to which the input unit 52, display unit 53, microphone 54, and camera 55 are connected.
[0025] The acquisition unit 51-1 acquires biometric behavior information via the microphone 54 and camera 55. The anonymization unit 51-2 analyzes the biometric behavior information acquired by the acquisition unit 51-1, converts the parts related to detected third parties (people other than the recorder) into a format that does not allow for personal identification, and generates anonymized data. The extraction unit 51-3 extracts feature vectors that can be used to match each third party from the biometric behavior information before anonymization processing.
[0026] The recording device 5 transmits the generated anonymized data and its corresponding feature vectors to the management device 1.
[0027] Furthermore, for reasons such as processing load, function consolidation, or security policy, it is also possible to configure the system so that all or part of the functions of the anonymization unit 51-2 and the extraction unit 51-3 are executed on the CPU 1-12 of the management device 1.
[0028] In this case, the recording device 5 transmits raw biological behavior information or partially processed data to the management device 1, which then performs anonymization and feature extraction. In all configurations, the output, "anonymized data" and "feature vectors," are linked in the storage unit 1-12-1 of the management device 1 and are subject to access status management.
[0029] <Detailed configuration of the control device> Figure 3 is a block diagram showing the hardware configuration of the management device 1 shown in Figure 1. In Figure 3, 1-11 is the communication unit, which communicates bidirectionally with data terminals 2, 3, and 4 and recording device 5 via network 21. The CPU 1-12 performs various functional processing by starting the BIOS stored in ROM 1-13 and executing a program that comprehensively loads input / output devices into RAM 1-14. It performs the following functional processing:
[0030] The storage unit 1-12-1 stores the anonymized data and feature vectors received from the recording device 5 in association with each other in the external memory 1-16. When storing the data, it manages the "restore permission status," which indicates whether or not to allow restoration of the data for each third party involved, by setting it to "not allowed."
[0031] The authentication unit 1-12-2 responds to either (i) a restore permission request generated in response to an operation by the recorder, or (ii) a restore request from the third party operating data terminals 2-4, and performs authentication of the third party.
[0032] The authorization status management unit 1-12-3 updates the "restore authorization status" corresponding to the third party managed by the storage unit 1-12-1 from "not possible" to "possible" only if authentication by the authentication unit 1-12-2 is successful.
[0033] The restoration unit 1-12-4, in response to a request to execute the restoration process, refers to the "restoration permission status" managed by the permission status management unit 1-12-3, confirms that the status is "permitted," and then executes the anonymized data restoration process using the feature vector stored in the storage unit 1-12-1.
[0034] <Data terminal configuration> Figure 4 is a block diagram showing the hardware configuration of data terminals 2-4 shown in Figure 1. In Figure 4, CPU 112 functions as request unit 112-1, requesting data recovery from management device 1 in response to user operation, and providing information necessary for authentication.
[0035] <Operation Flow> The flowchart shown in Figure 5 illustrates the basic data management method based on the above configuration. Note that S21-S24 and S11 correspond to recording and initialization.
[0036] The recording device 5 acquires biometric behavior information in an environment such as a sports event, anonymizes it, extracts features as described later (S21-S24), and transmits it to the management device 1. The storage unit 1-12-1 of the management device 1 receives this and initializes the restore permission status to "not permitted" for all related third parties (S11).
[0037] [Examples of processing for data terminals 2-4] A third party operating data terminals 2-4 sends a request to the management device 1 to subsequently restore biometric behavior information (including gestures, facial expressions, voice data, video data, still image data, etc.) relating to the user that has been stored in the management device 1 (step S31). At that time, the user notifies the management device 1 of the first feature vector to be restored in order to perform an authentication process that compares the first feature vector stored in the management device 1 (corresponding to the feature vector generated from the third party's biometric behavior information acquired from the recording device 5) with the second feature vector generated from the biometric behavior information newly acquired from the restoration requestor (step S32).
[0038] Data terminals 2-4 may be configured to notify management device 1 of raw speech data generated by the third party themselves. In this case, management device 1 can analyze the raw speech data and generate feature vectors.
[0039] [Example of processing by control device 1] S31 and S32 support recovery requests and authentication. (a) The recorder wishes to restore the data and sends a restoration permission request to the third party through the system, or (b) the third party who participated in the event voluntarily operates a data terminal and sends a restoration request. In either case, the authentication unit 1-12-2 of the management device 1 performs authentication of the person (S13). Status update due to successful authentication (S14) If authentication is successful, the authority status management unit 1-12-3 updates the restoration authority status corresponding to the person to "enabled" (S14).
[0040] This is a restoration process after status confirmation, in which the restoration unit 1-12-4 confirms that the authorization status is "OK" and then executes a restoration process using a feature vector (S15).
[0041] If, in step S14, the CPU 1-12 of the management device 1 determines that authentication is not OK, it records the history of the restoration process as a log in the external memory 1-16 (step S16) and terminates this process.
[0042] In this flow, all third-party information is anonymized at the time of recording, and the restoration permission status is set to "Not Allowed". Subsequently, only if a specific third party successfully authenticates, the permission status for the information relating to that person is updated to "Allowed", and as a result, the restoration process becomes executable. If authentication is unsuccessful, the permission status remains "Not Allowed", and the restoration unit 1-12-4 does not operate.
[0043] [Example of processing by recording device 5] First, the CPU 102 of the recording device 5 assumes an environment where, for example, three people are talking simultaneously in a conference room, and records audio with the microphone 54 and acquires facial images (an example of biometric behavioral information of a third party) with the camera 55 (S21).
[0044] Then, the CPU 102 of the recording device 5 temporarily stores the image data captured by the camera 55 and the audio data collected by the microphone 54 in the external memory 107 (S22). Next, the CPU 102 of the recording device 5 performs a predetermined anonymization process on the third party's biometric behavior information at a predetermined timing (for example, when recording is finished). Furthermore, the CPU 102 of the recording device 5 extracts feature vectors from the third party's biometric behavior information (step S23).
[0045] Next, the CPU 102 of the recording device 5 transmits the anonymized data and feature vectors to the management device 1 (step S24), and terminates the process.
[0046] Figure 6 is a flowchart illustrating the data processing method of the data management system shown in this embodiment. Steps S71 to S77 correspond to steps executed by the CPUs 1-12 of the management device 1.
[0047] The CPUs 1-12 of the management device 1 receive a recovery request from any of the data terminals 2-4 operated by the third party (step S71). Next, if it is determined that the authentication status of the third party is OK (step S72), the CPUs 1-12 of the management device 1 further determine whether the third party operating the data terminals 2-4 has valid recovery authority (step S73). If the CPUs 1-12 of the management device 1 determine that the recovery authority is not valid, they maintain the stored information without reading the anonymized data from the external memory 1-16 (step S74) and proceed to step S75.
[0048] On the other hand, in step S73, if the CPU 1-12 of the management device 1 determines that the third party operating the data terminals 2-4 has valid restoration authority, it executes the restoration process using the feature metadata stored in the metadata area of the external memory 1-16 (step S75).
[0049] Next, the CPUs 1-12 of the management device 1 provide the restored data to a third party (a person requesting restoration) operating the data terminals 2-4 (step S76).
[0050] Next, the CPUs 1-12 of the management device 1 save the recovery log to an immutable area allocated on the external memory 1-16 (step S77), and then terminate this process.
[0051] [Effects of the First Embodiment] This embodiment ensures the protection of third-party privacy through complete anonymization at the time of recording, while also technically guaranteeing data sovereignty by the third party by allowing restoration only through the updating of their authorization status based on successful authentication. Furthermore, the recorder can securely store and use the anonymized data and legally restore it with the third party's consent, thus achieving both data integrity and usefulness without incurring the risk of privacy infringement.
[0052] These effects are achieved through a system architecture centered on the authorization status management unit 1-12-3, which explicitly manages authorization status, thereby structurally preventing "unauthorized restoration."
[0053] [Second Embodiment] The following details the two-factor generation process for access control, as well as examples of anonymization and feature extraction processes during recording.
[0054] As described in the first embodiment, the basis for authority status management is the "anonymized data" and "feature vectors" generated by the recording device 5 (or management device 1). In this embodiment, the functional purpose of the processing content of the anonymization unit 51-2 and the extraction unit 51-3 that generate these, and examples of technical means to achieve them, are shown.
[0055] <Processing Functional Purpose> The purpose of the anonymization unit 51-2 is to remove the possibility of personal identification from third-party portions detected from biometric behavioral information. The purpose of the extraction unit 51-3 is to extract and store features from the information before anonymization processing that can be used to identify the individual at a later date. By executing these two processes sequentially and managing their outputs separately, two essential elements for access control are generated: "publicly available anonymized data" and "a restoration key usable only during user authentication."
[0056] <Functional Processing Flow> Figure 7 is a flowchart illustrating the data processing method of the data management system shown in this embodiment. Steps S61 to S68 correspond to steps executed by the CPU 102 of the recording device 5.
[0057] The CPU 102 of the recording device 5 acquires the audio / video recorded by the recording device 5 (S61). Next, the CPU 102 of the recording device 5 individually detects the faces / voices of third parties from the acquired stream (step S62). Then, the CPU 102 of the recording device 5 performs anonymization processing on the third party portions using a method selected from the multiple methods described above (step S63).
[0058] Next, the CPU 102 of the recording device 5 extracts feature vectors from the stream before anonymization based on the method described above (step S64).
[0059] Next, the CPU 102 of the recording device 5 saves the anonymized data, which was anonymized in step S63, to the external memory 107 (step S65).
[0060] Next, the CPU 102 of the recording device 5 saves the metadata of the feature vector extracted in step S64 to the metadata storage area on the external memory 107 (step S66), and then terminates this process.
[0061] The flowchart shown in Figure 7 above illustrates a series of processing steps to achieve these functions.
[0062] To summarize the above process: (Step S61): Acquire biometric behavior information. Third-party detection (S62): Detect and separate the audio and video sections of third parties other than the recorder from the acquired information. Anonymization process (S63): Apply a process to the detected third-party portions to transform or conceal personal identification features (e.g., voiceprint, facial features) to generate anonymized data. Feature vector extraction (S64): Extract feature vectors that can be used for matching from the original information before anonymization. Separation and storage (S65, S66): Store the generated anonymized data (S65) and feature vectors (S66) in logically or physically separate areas while associating them with each other.
[0063] <Examples of technical implementation methods> The following are some examples of specific technical means to achieve the aforementioned functions. An example of third-party detection (S52) in the flowchart shown in Figure 8: Voice interval detection (VAD) and speaker separation technology, as well as face recognition / person detection technology may be used.
[0064] An example of anonymization processing (S53): For speech, voiceprint features (e.g., x-vector, speaker embeddings such as ECAPA-TDNN) are extracted, and then voice quality transformations such as pitch, timbre, and formant transformations are applied.
[0065] The video will be processed with techniques such as face blurring, face transformation (e.g., DeepPrivacy-type), head masking, and 3D morph transformation.
[0066] Examples of feature vector extraction (S54): Extracted feature vectors include speech feature vectors, facial feature vectors (e.g., embeddings using FaceNet and ArcFace), and posture / motion feature vectors.
[0067] Meaning of Separate Storage (S55, S56): This means separating the data itself (anonymized data) from the metadata (feature vectors) that control the restoration rights to that data. This separation forms the basis of the security model in the permission state management of the first embodiment, in which "unless the state is updated to 'permitted,' the elements necessary for restoration are not available."
[0068] The specific technologies, algorithms, or model names listed herein are merely examples of the many possible means for achieving the aforementioned functions. The scope of the present invention is not limited to these examples and includes any technical means by which the functional objectives of "transformation and concealment of personal identification features" and "separation and extraction of matching feature vectors" are achieved.
[0069] [Effects of the second embodiment] This embodiment clarifies how the "authority status management" that forms the core of the first embodiment can be implemented not merely as a concept or business rule, but as a concrete technical process for signal processing and data management. In particular, the processing structure of extracting and separately storing feature vectors from the information before anonymization is a unique technical feature of the present invention that is not found in conventional irreversible anonymization technologies.
[0070] This makes it possible to technically reconcile two previously incompatible requirements: reliable privacy protection at the time of recording and selective restoration based on the wishes of the third party involved.
[0071] [Third Embodiment] The following describes the various authentication methods that drive permission status updates. In the present invention, "identity authentication" by the authentication unit 1-12-2 of the management device 1 can take various forms depending on the trigger for the recovery request. A recovery request is initiated based on either (i) a recovery permission request generated in response to an operation by the recorder operating the recording device 5, or (ii) a direct recovery request from the third party operating the data terminals 2-4. Regardless of the trigger for the recovery request, the authentication unit 1-12-2 verifies that the person making the recovery request is the third party concerned with the anonymized data by any of the following technical means, or a combination thereof.
[0072] The following describes the biometric feature vector matching process performed by authentication means A in this embodiment. The person requesting restoration (the third party) uses their data terminals 2-4 input devices (microphone, camera, etc.) to transmit newly acquired biometric information samples (voice samples, facial images, etc.) to the management device 1. The authentication unit 1-12-2 extracts a second feature vector from this sample and compares it with the first feature vector extracted from the anonymized data stored in the access control metadata area. If the similarity between the two exceeds a predetermined threshold, the authentication is determined to be successful, and the access status management unit 1-12-3 is instructed to update the access status corresponding to the third party to "restoreable".
[0073] The following describes the verification process using private key signatures via authentication method B. The data recovery requester (the third party) generates a cryptographic signature for the data recovery request message (or a challenge message containing an identifier that identifies the anonymized data) using a private key stored in a secure area (for example, a private key storage area in a digital wallet application) within their data terminals 2-4, and sends it to the management device 1. The authentication unit 1-12-2 verifies this signature using a public key that has been previously registered in association with the third party. If the signature verification is successful, the request is recognized as coming from the legitimate holder of the private key, and authentication is considered successful.
[0074] The following describes the non-disclosure authentication process using knowledge-based proof (ZKP) via authentication method C. The restoration requester (the third party) generates a ZKP proof that proves they know (or possess a substantially equivalent feature vector to) the first feature vector stored in the access control metadata area. This proof proves only the fact that "the generator knows that feature vector" without disclosing the first feature vector itself or any biological sample. The authentication unit 1-12-2 verifies this ZKP proof using a pre-configured verification algorithm, and if successful, authentication is considered successful.
[0075] These authentication methods are applicable regardless of the trigger for the recovery request. For example, in a process initiated by a recovery permission request from the recorder, an authentication request is sent to the data terminal of the relevant third party, where the third party responds with an authentication response using one of the above methods. In the case of a direct request from the third party, authentication information is sent simultaneously with the request. The authentication result (success / failure) of the authentication unit 1-12-2 is output in a unified format as a status update request to the authority status management unit 1-12-3, which serves as the core control point for authority management. These authentication methods are applicable not only to centrally managed environments but also to distributed network environments.
[0076] [Effects of the third embodiment] This embodiment clearly demonstrates that "identity verification" for granting restoration authority can be achieved through a variety of technical means, such as biometric matching, private key signing, and zero-knowledge proofs. Each of these methods technically verifies that "the restoration requestor is the legitimate person" from different perspectives, such as biometric attributes, possession of private keys, and knowledge of feature vectors, and can be flexibly selected and combined according to the usage scenario and privacy preferences. Furthermore, by processing the authentication results uniformly as "requests to update the authority status," the core process of the authority management model is implemented simply and consistently while maintaining diversity in authentication methods.
[0077] [Fourth Embodiment] The following provides a detailed description of the authentication and recovery sequence, using feature vector matching as an example. In this embodiment, using the authentication means A "biometric feature vector matching" described in the third embodiment as a specific example, a series of detailed processing sequences from authentication to restoration, triggered by a request from the recorder, will be explained with reference to the flowcharts in Figures 5 and 6.
[0078] First, if the recorder viewing the data acquired and anonymized by recording device 5 wants to restore the portion of a specific third party's (for example, speaker A in the meeting) speech, they perform an operation to "request permission to restore from speaker A" through the recorder's UI (Figure 5, step S31).
[0079] [Authentication process of management device 1] Figure 8 is a flowchart illustrating the data processing method of the data management system shown in this embodiment. Steps (S61) to (S68) correspond to steps executed by the CPUs 1-12 of the management device 1.
[0080] When the management device 1 receives a data recovery request from data terminals 2-4 operated by the third party, it notifies the third party operating the data terminals 2-4 of an authentication request (step S61). At this time, the CPUs 1-12 of the management device 1 present an identity verification screen that the third party can select and wait for the third party to select an identity verification method (step S62).
[0081] Here, the third party obtains a voice sample as an authentication method and compares and matches it with the feature vectors stored in external memory 1-16 (step S63).
[0082] Furthermore, the CPUs 1-12 of the management device 1 may perform the signature process using the private keys obtained from the data terminals 2-4 (step S64), or they may perform zero-knowledge proofs (step S65).
[0083] Then, the CPUs 1-12 of the management device 1 perform a verification process to determine whether the third party operating the data terminals 2-4 matches the person requesting the restoration of the anonymized data (step S66).
[0084] Next, if the CPUs 1-12 of the management device 1 determine that user authentication has been successful (step S67), the CPUs 1-12 of the management device 1 issue restoration authority to the third party operating data terminals 2-4 (step S68), and then terminate this process.
[0085] To summarize the above process, the management device 1 notifies the data terminal registered as speaker A (for example, data terminal 2) of a request for permission to restore data (Figure 6, step S61). The request includes the identifier of the target data and information prompting the user to select an authentication method.
[0086] The third party operating data terminal 2 (speaker A) receives a notification and selects an authentication method (Figure 6, step S62). If "authentication by voice sample" is selected, a voice sample of a predetermined duration is recorded using the microphone of data terminal 2 and transmitted to management device 1 (Figure 6, step S63). The authentication unit 1-12-2 extracts a second feature vector (matching feature vector) from the received voice sample in real time.
[0087] Next, the authentication unit 1-12-2 reads the first feature vector (registered feature vector) of speaker A, which was previously extracted and stored from the anonymized data of the request, from the access control metadata area. The authentication unit 1-12-2 calculates the similarity between the first feature vector and the second feature vector. If the similarity is equal to or greater than a predetermined threshold (for example, 0.8), it determines that authentication by speaker A himself was successful (Figure 6, steps S66, S67).
[0088] Upon confirming successful authentication, the authorization status management unit 1-12-3 updates the authorization status corresponding to speaker A from "unrecoverable" to "recoverable". Along with this status update, the recovery unit 1-12-4 dynamically generates a recovery key specific to that session as needed, associates it with the authorization management metadata area, and stores it. Subsequently, the management device 1 notifies the recorder that the portion for speaker A can now be recovered (enabling the transition to step S15 in Figure 5).
[0089] When the recorder or a third party wishing to restore the data (in this example, the recorder) performs the restoration operation again, the restoration unit 1-12-4 confirms that the authorization status is "restorable," retrieves the restoration key and the first feature vector from the authorization management metadata area, and reads the corresponding anonymized data from the anonymized data storage area. The restoration unit 1-12-4 applies a restoration algorithm based on the feature vector (for example, the inverse transformation of voice conversion), performs the restoration process using the restoration key, and outputs data restored to a form close to the original voice (Figure 5, step S15). The history of this restoration process is recorded in the access log of the authorization management metadata area (Figure 5, step S16).
[0090] [Effects of the fourth embodiment] This embodiment reveals a specific process of authority delegation and restoration, starting with a request from the recorder, proceeding through biometric authentication of the third party, and ultimately resulting in selective restoration to the recorder.
[0091] By illustrating the specific technique of feature vector matching, the technical feasibility of user authentication can be demonstrated in detail, and the causal relationship of the authorization management model of the present invention, in which the update of the authorization state is driven by the event of successful authentication, and the restoration process is executed only based on that state, can be clearly presented as a concrete processing flow.
[0092] [Fifth Embodiment] The following details dynamic control of permissions (recovery key, expiration date, on-device processing). In the authorization management model of the present invention, a configuration that dynamically imposes constraints on authorizations may be adopted to prevent authorizations that have entered a "recoverable" state from being used without limit or indefinitely, and to enable more granular control. In this embodiment, three control measures will be further described: dynamic generation of recovery keys, assignment of expiration dates, and local execution of processing.
[0093] (Control strategy 1 for dynamically generating recovery keys for each session) In the third or fourth embodiment described above, when authentication is successful and the authorization status is updated to "restoreable", the restoration unit 1-12-4 of the management device 1 (or a dedicated module that works in conjunction with it) dynamically generates a restoration key that uniquely identifies the authentication session and restoration request.
[0094] This key functions as a cryptographic parameter necessary to perform the recovery process, as well as a parameter that controls the recovery algorithm. The generated recovery key is stored in the privilege management metadata area, associated with the corresponding privilege status information. This recovery key is automatically invalidated (deleted or disabled) once a single recovery process is completed, or within a very short time after generation (e.g., a few minutes). This reduces the risk of privileges being abused multiple times or over a long period of time, even if authentication is successful once.
[0095] (Control measure 2: Imposing an expiration date on the permission status itself) The authorization status management unit 1-12-3 sets an expiration date for the authorization status when updating it to "recoverable". The expiration date may be an absolute date and time (e.g., January 20, 2026, 23:59) or a relative time from the time of successful authentication (e.g., 24 hours after authentication).
[0096] The permission status management unit 1-12-3 monitors the set expiration date and automatically reverts the permission status to "non-recoverable" or "expired" once the expiration date has passed. This clearly defines the period during which recovery permission can be exercised, enabling permission design that aligns with data lifecycle management and specific usage purposes (e.g., limited access period for event records).
[0097] (Anonymization and control measures using on-device processing 3) To further enhance privacy protection, an "on-device processing" mode may be provided in which at least part of the anonymization process and restoration permission control are performed on the recording device 5 or data terminals 2-4.
[0098] For example, the CPU 102 within recording device 5 completes a series of processes from detecting third-party information, anonymizing it, and extracting feature vectors from the biometric behavior information acquired by recording device 5, and only the anonymized data is sent to management device 1. The feature vectors are stored within recording device 5, and at a later authentication, feature vector matching is performed through direct communication (pairing) between the data terminal and the recording device. In this configuration, third-party biometric characteristic information is not transmitted to an external server (management device 1) via the network, minimizing privacy risks. In this case, access status management is distributed among recording device 5 and data terminals 2-4.
[0099] [Effects of the Fifth Embodiment] This embodiment demonstrates that the authorization management model of the present invention not only divides the possibility of restoration based on the success or failure of authentication, but also dynamically imposes temporal and frequency constraints on the authorization itself granted after successful authentication, thereby achieving more precise and secure control. The guarantee of one-time use through session keys, temporal limitations through expiration dates, and enhanced privacy through on-device processing are all technical measures that elevate authorization from a static "permission" to a dynamic "controllable state." As a result, this system enables the implementation of flexible authorization policies that respond to diverse business needs and regulatory requirements.
[0100] [Sixth Embodiment] The following describes in detail an embodiment of the application of an access control model to video information (multimodal support). The system of the present invention is applicable not only to audio information but also to bio-behavioral information including video information. In this embodiment, the process when the recording device 5 is equipped with a camera 55 and acquires a video stream will be described. The acquisition unit 51-1 acquires the video stream frame by frame. The person detection function included in the anonymization unit 51-2 detects and separates the face area, body area, or entire person of a third party other than the recorder from each frame.
[0101] The anonymization unit 51-2 applies a transformation to the separated third-party area that makes it impossible to identify individuals. Examples of transformation methods include blurring, random replacement of pixel values, replacement with another face by averaging facial features (e.g., DeepPrivacy-type technology), or modification of face shape by 3D morphing. As a result, it is impossible to identify third-party individuals from the transformed image.
[0102] The extraction unit 51-3 extracts facial feature vectors using a facial recognition model (e.g., FaceNet, ArcFace), pose vectors using a pose estimation model (e.g., OpenPose), or appearance feature vectors using a person re-identification model from the video area before anonymization processing. These feature vectors, like the audio feature vectors, are stored in the access control metadata area, associated with the corresponding anonymized data.
[0103] During authentication, various authentication methods described in the third embodiment are available. For example, in the case of biometric feature vector matching, the restoration requester (the third party) transmits their current face image (selfie) from a data terminal. The authentication unit 1-12-2 extracts feature vectors from this image and compares them with the face feature vectors of the person stored in the access control metadata area. After successful authentication, when the access status is updated to "restoreable", the restoration unit 1-12-4 uses the stored face feature vectors, etc., to apply inverse transformation processing (devler processing, or regeneration of face images based on feature vectors) to the anonymized video area and restores an image that is close to the original appearance.
[0104] Furthermore, if both audio and video are acquired from a single third party in the same recording session, it is preferable for the management device 1 or recording device 5 to manage the audio feature vector and video feature vector emitted from the same person by associating them based on the timestamp, sound source direction, person's location information, etc. This allows either the audio or video features to be used during authentication, and enables the restoration of both audio and video together during recovery, unifying the unit of access control as "person".
[0105] [Effects of the 6th Embodiment] This embodiment specifically demonstrates that the access control system of the present invention is fully applicable to video information. By applying a series of technical processes—person detection, anonymization, feature extraction, matching, and restoration—to video, the core functions of access control, such as reliable anonymization at the time of recording and selective restoration based on third-party authentication, can be realized even in video recording devices such as smartphones, action cameras, and smart glasses. Furthermore, by associating audio and video features, multimodal access control becomes possible, improving the practicality and convenience of the system.
[0106] [Seventh Embodiment] The following describes in detail an embodiment of the implementation of a foundational access control system using a separated data structure. To technically support the access control of the present invention and ensure its security and auditability, the storage unit 1-12-1 of the management device 1 manages data in two logically separated areas. This separation structure provides a foundation for simultaneously achieving privacy protection and independence of access control.
[0107] (1) Anonymized data storage area This area stores the data itself in a format that does not identify individuals, generated by the anonymization unit 51-2 of the recording device 5. Specifically, this includes voice-transformed audio streams, blurred or transformed video streams, and associated metadata (timestamp, recorder ID, etc.). The data in this area alone cannot identify any third-party individual.
[0108] (2) Access Control Metadata Area This area is associated with each piece of data in the anonymized data storage area and stores information necessary for recovery and access control. Specifically, it includes the following information a) to e): a) Feature vector information: Feature vectors (voice, face, posture, etc.) for each third party extracted by the extraction unit 51-3. b) Permission status information: The current restore permission status for each third party (e.g., "Restore not possible", "Restore possible (Expiration date: YYYY-MM-DD HH:MM)"). c) Authentication requirements information: Specification of the authentication method (biometric verification, private key signature, etc.) to be applied to the third party. d) Recovery key information: The dynamically generated recovery key for each session as described in the fifth embodiment (if applicable). e) Access log information: A history (log) of all events, including restore requests, authentication attempts (success / failure), permission status changes, and restore executions.
[0109] In this embodiment, upon receiving a restoration request, the restoration unit 1-12-4 first refers to the authorization management metadata area and confirms that the authorization status information corresponding to the target third party is "restoreable" and within its validity period.
[0110] If this verification fails, the restoration process is immediately terminated. If the verification is successful, the restoration unit 1-12-4 obtains feature vector information and restoration key information (if any) from the same area, and then reads the corresponding anonymized data body from the anonymized data storage area and executes the restoration process.
[0111] This sequence of "checking permission status → obtaining features, etc. → accessing the data itself" is a mechanism that technically enforces permission-based access control. The technical benefits of this separate storage logical structure are the same whether it is implemented physically within a single server or across multiple distributed nodes.
[0112] [Effects of the 7th Embodiment] This embodiment presents a specific and robust data structure for implementing the access control of the present invention. This structure, which physically and logically separates and manages the data body (anonymized data) and access metadata, offers the following core advantages.
[0113] Firstly, even if the anonymized data storage area is leaked, personally identifiable information cannot be obtained, thus inherently guaranteeing privacy protection.
[0114] Secondly, because the ability to restore is determined by a clear flag called "authority status information" in the authorization management metadata area, the authorization control logic is clear and independent.
[0115] Thirdly, because all relevant events are saved as "access log information," a complete audit trail of the system's operation remains, enabling accountability.
[0116] [Eighth Embodiment] The following describes in detail an embodiment of the implementation of the authority delegation process through a user interface. To enable the authority management of the present invention to function among actual users, a user interface (UI) that supports the authority delegation process between the recorder and the third party is implemented on the recording device 5 and data terminals 2-4.
[0117] (User interface for recording) The display unit 53 of the recording device 5, or the application screen that interacts with the recording device 5, is provided with the following display and operation elements: • A notification stating "This record contains third-party information" will be displayed on the review screen during or after recording. • A function to select specific third-party areas (e.g., audio segments of a specific speaker, video segments of a specific person). For the selected third-party area, a confirmation message such as "Do you want to request permission from this person to restore?" will be displayed, along with a "Request Permission" button.
[0118] When the recorder selects "Request permission," the management device 1 issues a restoration permission request via a data terminal that can be identified as the relevant third party (if registered) or via a notification route directed to an unspecified third party.
[0119] (Third party UI) When a request is received from the recorder, the following displays and operational elements are presented on the screens of data terminals 2-4. • A notification stating, "Your audio / video may be being recorded." • "Recorder: [Recorder Name / ID] wants to restore the record for [Date and Time]. Do you allow this?" • A selection button for "Allow," "Deny," and "Allow Partially" (e.g., Allow audio only). • "Set an expiration date if allowed" option (e.g., select from "24 hours", "1 week", "unlimited", or enter a custom date and time). Third parties express their intentions through these UI elements. The selection result is transmitted to the management device 1 and is linked to identity verification by the authentication unit 1-12-2 (third embodiment). For example, if "Allow" is selected and identity verification is successful, the authorization status management unit 1-12-3 updates the authorization status to "Restorable" and sets the selected expiration date.
[0120] All requests, responses, and settings generated through these UI operations are recorded in detail in the "Access Log Information" area of the authorization management metadata described in the seventh embodiment, ensuring transparency regarding who delegated authority, when, and under what conditions.
[0121] [Effects of the 8th Embodiment] This embodiment specifically demonstrates how the technical system of the present invention enables actual delegation of authority between users in different positions, namely the recorder and the third party, through an intuitive and user-friendly interface. The recorder's UI provides the starting point for delegation of authority, while the third party's UI provides a forum for decision-making as the data sovereign. This series of UI flows seamlessly connects technical authority control with the social consensus-building process, significantly increasing the practicality and acceptability of the system.
[0122] [Ninth Embodiment] The following details the implementation of the preventative protective effect against AI learning risks. The system of the present invention, through its access control structure, has the secondary effect of proactively reducing the risk at the data source of recorded third-party information being used for unauthorized learning by generating AI, etc.
[0123] The biometric behavioral information acquired by the recording device 5 is immediately anonymized by the recording device 5 or the management device 1. Therefore, the data stored in the anonymized data storage area of the management device 1 is already in a format that makes it impossible to identify individuals. Even if this anonymized data is collected by a platform operator or the like and used as training data for an AI model, only anonymized patterns that are not linked to individuals will be learned.
[0124] The key point here is that, in principle, raw feature vectors linked to individuals (stored in the access control metadata area) cannot be combined with anonymized data and restored as "personally identifiable data" unless authenticated by a third party. In other words, any data that leaks outside this system and can be used for AI learning is always limited to anonymized forms. For this reason, this system also functions as a technical foundation to enhance compliance with the "data minimization principle" and "purpose limitation principle" required by data protection regulations such as GDPR.
[0125] [Effects of the 9th Embodiment] According to this embodiment, it becomes clear that the system of the present invention, in addition to its direct objectives of protecting privacy and establishing data sovereignty, also provides a preventative protective effect against the risks of unauthorized data learning by generative AI and other modern challenges. Essential anonymization at the time of recording and strict authentication requirements for restoration fundamentally narrow the channels through which personally identifiable raw data can be distributed and used outside the system. This demonstrates that the present invention has value not merely as an access control technology, but as a foundational technology for sustainable privacy protection in a data-driven society.
[0126] The present invention can also be realized by supplying a program that implements one or more of the functions of each of the embodiments described above to a system or device via a network or storage medium, and by a process in which one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (for example, an ASIC (Application-Specific Integrated Circuit)) that implements one or more functions.
[0127] The above embodiments and combinations thereof provide a novel data management system and method that simultaneously achieves "reliable protection of third-party privacy at the time of recording" and "selective restoration of data based on the will of the third party," which were difficult to achieve simultaneously with conventional technologies. At its core lies in exclusively conditioning the restoration of anonymized data on the successful authentication of the third party concerned, and explicitly managing and transitioning the "authority state" based on the authentication result.
[0128] As one configuration of a data management system that realizes the core technological concept described above, a system comprising a recording device and a management device is disclosed. The recording device comprises an acquisition unit that acquires biometric behavioral information (voice, video, movements, etc.) including third parties, and an anonymization unit that converts the portion of the acquired biometric behavioral information relating to the third party into a format that does not allow for personal identification.
[0129] The management device includes a storage unit that receives and stores the anonymized data from the recording device; an authentication unit that performs authentication of the third party in response to either a restoration permission request generated in response to an operation by the recorder or a restoration request made by the third party themselves; an authorization status management unit that, when authentication by the authentication unit is successful, sets an authorization status that permits the restoration of the portion of the anonymized data related to the third party stored in the storage unit; and a restoration unit that performs a restoration process when the authorization status set by the authorization status management unit permits restoration.
[0130] Based on this basic configuration, a form for achieving selective restoration is disclosed. In this form, the restoration unit restores only the portion relating to a third party whose authorization status permits restoration, and does not restore the portion relating to other third parties within the same anonymized data.
[0131] Furthermore, a form of utilizing features is disclosed. In this form, the recording device or management device includes a feature extraction unit that extracts features related to a third party from biological behavior information, and the restoration unit performs restoration using these extracted features.
[0132] The authentication unit that performs identity verification is disclosed to be implementable by a variety of technical means. Specifically, these include methods such as matching based on biometric information (voiceprint, face, etc.), verification of private key signatures, and verification of zero-knowledge proof (ZKP) proofs.
[0133] A configuration that enables dynamic control of permission states is also disclosed. In this configuration, the permission state management unit can assign an expiration date to the permission states that are set to be allowed to be restored.
[0134] Furthermore, a configuration is disclosed that includes a separate storage structure that forms the basis for ensuring privacy protection and independence of access control. In this configuration, the management device includes a first storage area for storing the anonymized data itself, and a second storage area for storing metadata such as feature quantities and access status information separately from the anonymized data.
[0135] Furthermore, the series of processes performed by the above system configuration can also be defined as a data management method. This method includes the steps of: acquiring biometric behavior information including a third party using a recording device; anonymizing the portion relating to the third party from the biometric behavior information to generate anonymized data; storing the anonymized data in a management device; generating a restoration permission request in response to an operation from the recorder, or generating a restoration request in response to an operation from the third party via a data terminal; performing authentication of the third party in response to either the generated restoration permission request or the restoration request; setting an authorization state that permits the restoration of the portion relating to the third party in the stored anonymized data if the authentication is successful; and restoring the portion relating to the third party from the anonymized data if the set authorization state permits restoration.
[0136] In connection with this basic process, a method for achieving selective restoration is disclosed. In this method, the restoration step restores only the portion relating to a third party whose authorization status permits restoration, and does not restore other portions relating to third parties included in the anonymized data.
[0137] Furthermore, a method for achieving feature-based reconstruction is disclosed. This method further includes a step of extracting features related to a third party from biological behavior information, and the reconstruction step is performed using these extracted features. This feature extraction step may be performed on a recording device or on a management device.
[0138] The system and method realized by the present invention provide the following effects in data recording and usage scenarios involving three parties: the recorder, the third party, and the platform operator: protection of essential privacy at the time of recording, establishment of data sovereignty of the third party, legal restoration of data integrity for the recorder, technical separation and selective restoration of rights, and proactive compliance with future AI ethics and regulations.
[0139] The disclosure relating to the present invention described above can be summarized to at least the following:
[0140] (1) A data management system comprising a recording device and a management device, wherein the recording device includes an acquisition unit that acquires biometric behavior information including that of a third party, and an anonymization unit that converts the portion relating to the third party from the biometric behavior information acquired by the acquisition unit into a format that does not allow for personal identification and generates anonymized data. Before the anonymization unit generates the anonymized data, the extraction unit extracts feature vectors from the biological behavior information acquired by the acquisition unit, The management device includes the anonymized data from the recording device. and the feature vector The storage unit receives and stores the data from the recorder. The aforementioned feature vector An authentication unit that performs authentication of the third party in response to either a restore permission request generated in response to an operation, or a restore request made by the third party themselves. ,before The system is characterized by comprising: an authorization status management unit that sets an authorization status that permits the restoration of the portion of the anonymized data relating to the third party stored in the storage unit when authentication by the authentication unit is successful; and a restoration unit that executes a restoration process when the authorization status set by the authorization status management unit is in a state that permits restoration.
[0141] (2) The restoration unit restores only the portion relating to the third party whose authorization status permits restoration, and does not restore any other portions of the anonymized data relating to the third party.
[0142] (3) The recording device or the management device is characterized by comprising a feature extraction unit that extracts feature quantities relating to the third party from the biological behavior information.
[0143] (4) The restoration unit is characterized by using the features extracted by the feature extraction unit to restore the portion relating to the third party from the anonymized data.
[0144] (5) The authentication unit is characterized by performing verification based on the biometric information of the third party.
[0145] (6) The authentication unit is characterized by performing verification of the private key signature by the third party.
[0146] (7) The authentication unit is characterized by performing verification of the zero-knowledge proof (ZKP) proof by the third party.
[0147] (8) The authority status management unit is characterized by assigning an expiration date to the authority status that allows restoration that has been set.
[0148] (9) The management device is characterized by comprising a first storage area for storing the anonymized data and a second storage area for storing the feature quantities and the authority status information managed by the authority status management unit separately from the anonymized data.
[0149] (10) A data management method performed using a recording device, a management device and a data terminal, comprising the steps of: acquiring biometric behavior information including a third party using the recording device; anonymizing the portion relating to the third party from the biometric behavior information to generate anonymized data; Before generating the anonymized data, an extraction step is performed to extract feature vectors from the generated biological behavior information, The anonymized data and the feature vector The steps include saving the data to the management device and from the recorder The aforementioned feature vector Depending on the operation to return The method is characterized by including the steps of: generating an original request; performing authentication of the third party in response to either the generated restoration permission request or the restoration request; setting an authorization state that permits the restoration of the portion of the stored anonymized data relating to the third party if the authentication is successful; and restoring the portion relating to the third party from the anonymized data if the set authorization state permits restoration.
[0150] (11) The restoration step is characterized in that it restores only the portion relating to the third party whose authorization status permits restoration, and does not restore any other portions of the anonymized data relating to the third party.
[0151] (12) The method further includes a step of extracting features relating to the third party from the biological behavior information, wherein the restoration step is performed using the extracted features.
[0152] (13) The step of extracting the feature quantities is characterized in that it is performed on the recording device.
[0153] (14) The step of extracting the feature quantities is characterized in that it is performed by the management device. [Industrial applicability]
[0154] The above data management system and data management methods are particularly effective in a variety of scenarios, such as those described below.
[0155] (1) Individual creation and sharing of digital content For example, in sports and travel recordings using action cameras such as GoPro, or in street photography by vlog creators, the system can automatically protect the privacy of third parties who accidentally appear in the footage while maintaining the sense of realism in the content. Third parties who appear in the footage can later have only their own portion restored and used after identity verification.
[0156] (2) Continuous recording environment using wearable AI devices and smart glasses With the proliferation of next-generation wearable devices (such as smart glasses) that enable continuous recording from the user's perspective, this data management system can become an indispensable foundational technology in an environment where countless pieces of third-party information can be acquired in daily life. Recorders can maintain their own life logs in complete form while automatically protecting the privacy of third parties who appear in the footage. Third parties can later restore and use only the scenes in which they were involved, after identity verification.
[0157] (3) Record keeping and knowledge management in work and training This system allows for the recording of internal company meetings and online training sessions, preserving them as official records while protecting participants' privacy. Participants can later reconstruct only their own contributions for review and learning purposes.
[0158] (4) New services in the events and tourism industry This service allows for the creation of anonymized records of all attendees in commemorative photo and video services at concerts and tourist destinations. At a later date, attendees can verify their identity and purchase only the parts in which they appear, providing personalized products while protecting their privacy.
[0159] This invention is widely applicable as a foundational technology that resolves the dilemma between privacy protection and data usefulness, and technically enables the selective restoration of data by the third party themselves, in almost any situation in which a recording device may acquire information of a third party, particularly in a near-future society where continuous recording becomes commonplace. [Explanation of Symbols]
[0160] 1 Management device 2 Data terminals 3 Data terminals 4 Data terminals 5. Recording Devices
Claims
1. A data management system comprising a recording device and a management device, The recording device is An acquisition unit that acquires biometric behavioral information including that of a third party, An anonymization unit generates anonymized data by converting the portion relating to the third party from the biometric behavior information acquired by the acquisition unit into a format that does not allow for personal identification. The system includes an extraction unit that extracts feature vectors from the biological behavior information acquired by the acquisition unit before the anonymization unit generates the anonymized data, The aforementioned control device is A storage unit that receives and stores the anonymized data and the feature vector from the recording device, An authentication unit that performs authentication of the third party in response to either a restoration permission request generated by the recorder in response to an operation involving the feature vector, or a restoration request made by the third party themselves. If authentication by the authentication unit is successful, the authorization status management unit sets an authorization status that permits the restoration of the portion of the anonymized data related to the third party stored in the storage unit, When the authority status set by the authority status management unit is in a state that permits restoration, the restoration unit executes the restoration process. A data management system characterized by having the following features.
2. In the data management system according to claim 1, The data management system is characterized in that the restoration unit restores only the portion relating to the third party whose authorization status permits restoration, and does not restore any other portions of the anonymized data relating to the third party.
3. In the data management system according to claim 1, A data management system characterized by comprising a feature extraction unit that extracts features related to the third party from the biological behavior information, wherein the recording device or the management device is equipped with a feature extraction unit.
4. In the data management system described in claim 3, The data management system is characterized in that the restoration unit restores the portion relating to the third party from the anonymized data using the features extracted by the feature extraction unit.
5. In the data management system according to claim 1, The authentication unit is characterized by performing verification based on the biometric information of the third party.
6. In the data management system according to claim 1, The authentication unit is characterized by performing verification of the private key signature by the third party in question.
7. In the data management system according to claim 1, The authentication unit is characterized by performing verification of a zero-knowledge proof (ZKP) proof by the third party in question.
8. In the data management system according to claim 1, The aforementioned authorization status management unit is characterized by assigning an expiration date to the authorization status that allows restoration.
9. In the data management system described in claim 3, The management device is characterized by comprising a first storage area for storing the anonymized data and a second storage area for storing the feature quantities extracted by the feature quantity extraction unit and the authority status information managed by the authority status management unit separately from the anonymized data.
10. A data management method performed using a recording device, a management device, and a data terminal, The recording device acquires biometric behavior information including that of a third party, and generates anonymized data by anonymizing the portion of the biometric behavior information relating to the third party. Before generating the anonymized data, an extraction step is performed to extract feature vectors from the generated biological behavior information, The steps include storing the anonymized data and the feature vector in the management device, The steps include generating a restoration request from the recorder in response to an operation involving the feature vector, The steps include performing authentication of the third party in response to either the generated restore permission request or the restore request, If the authentication is successful, the steps include setting an authorization status that allows the restoration of the portion of the stored anonymized data relating to the third party, If the configured permission state allows restoration, the step is to restore the portion relating to the third party from the anonymized data. A data management method characterized by including the following.
11. In the data management method described in claim 10, The data management method is characterized in that the restoration step restores only the portion relating to the third party whose authorization status permits restoration, and does not restore any other portions of the anonymized data relating to the third party.
12. In the data management method according to claim 10 or 11, The method further includes the step of extracting features related to the third party from the aforementioned biological behavior information, A data management method characterized in that the restoration step is performed using the extracted features.
13. In the data management method described in claim 12, A data management method characterized in that the step of extracting the aforementioned features is performed on the recording device.
14. In the data management method described in claim 12, A data management method characterized in that the step of extracting the aforementioned features is performed by the management device.