Program, information processing device, and information processing method

The program and apparatus address the lack of user anonymization reflection in existing systems by implementing anonymization settings, acquisition, and provision functions, effectively ensuring user confidentiality and flexibility in data handling.

JP7867480B2Active Publication Date: 2026-05-29JCB CO LTD

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
JCB CO LTD
Filing Date
2023-12-27
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing systems fail to adequately reflect user needs for anonymization when providing user data to service providers.

Method used

A program and information processing apparatus that includes a reception function to receive anonymization settings, an acquisition function to acquire user data, an anonymization function to anonymize the data based on these settings, and a provision function to provide anonymized data to service providers.

Benefits of technology

Enables the reflection of user anonymity needs when providing data to service providers, ensuring confidentiality and flexibility in anonymization processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007867480000001
    Figure 0007867480000001
  • Figure 0007867480000002
    Figure 0007867480000002
  • Figure 0007867480000003
    Figure 0007867480000003
Patent Text Reader

Abstract

To provide a program, an information processing device and an information processing method which can reflect needs regarding concealment of a user in provision of user data to a service provider when the user uses service.SOLUTION: A program causes a computer to realize: an acceptance function for accepting concealment setting for providing user data regarding a user to one or more provision destinations including a first service provider from a user device of the user of first service provided by the first service provider; an acquisition function for acquiring the user data from the user device according to operation input of the user to the user device when the user uses the first service via the user device; a concealment function for concealing the user data on the basis of the concealment setting; and a provision function for providing the concealed user data to provision destination devices of each of the one or more provision destinations.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a program, an information processing apparatus, and an information processing method.

Background Art

[0002] Conventionally, a technique for providing data related to a user who uses a service (hereinafter referred to as "user data") to an operator who provides this service is known. Patent Document 1 discloses a server device that receives a request for defining user data (first customer data) from an operator device of an operator who provides a payment service. When a user (customer) uses the payment service, this server device acquires user data from the user's terminal device based on the defined user data requested, and provides the acquired user data to the operator device.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] By the way, when providing user data, there are needs regarding user anonymization, such as wanting to anonymize some or all of the user data. However, the device described in Patent Document 1 has a problem that it cannot reflect such user needs.

[0005] Therefore, an object of the present invention is to provide a program, an information processing apparatus, and an information processing method that can reflect the needs regarding user anonymization when providing user data to a service provider when a user uses a service.

Means for Solving the Problems

[0006] A program according to one aspect of the present invention enables a computer to implement: a reception function that receives anonymization settings from a user device of a user of a first service provided by a first service provider, for providing user data about the user to one or more recipients, including the first service provider; an acquisition function that acquires user data from the user device in response to the user's operation input to the user device when the user uses the first service via the user device; an anonymization function that anonymizes the user data based on the anonymization settings; and a provision function that provides the anonymized user data to the recipient device of one or more recipients.

[0007] An information processing device according to one aspect of the present invention includes: a receiving unit that receives anonymization settings from a user device of a user of a first service provided by a first service provider for providing user data about the user to one or more service providers, including the first service provider; an acquisition unit that acquires user data from the user device in response to the user's operation input to the user device when the user uses the first service via the user device; an anonymization unit that anonymizes the user data based on the anonymization settings; and a providing unit that provides the anonymized user data to the service provider devices of one or more service providers.

[0008] An information processing method according to one aspect of the present invention involves a computer receiving an anonymization setting from a user device of a user of a first service provided by a first service provider, for providing user data about the user to one or more service providers, including the first service provider; when the user uses the first service via the user device, the computer acquires user data from the user device in response to the user's operation input to the user device, and anonymizes the user data based on the anonymization setting; The anonymized user data is provided to the service provider equipment of one or more service providers. [Effects of the Invention]

[0009] According to the present invention, when providing user data to service providers when users utilize a service, the need for user anonymity can be reflected. [Brief explanation of the drawing]

[0010] [Figure 1] This figure illustrates an example of the system configuration of the data mediation system according to this embodiment. [Figure 2] This diagram illustrates the overview of the data mediation system according to this embodiment. [Figure 3] This diagram illustrates the overview of the data mediation system according to this embodiment. [Figure 4] This figure shows an example of the functional configuration of the server device according to this embodiment. [Figure 5] This figure shows an example of the operation of the data mediation system according to this embodiment. [Figure 6] This figure shows an example of the hardware configuration of the server device according to this embodiment. [Modes for carrying out the invention]

[0011] A preferred embodiment of the present invention (hereinafter referred to as "this embodiment") will be described with reference to the attached drawings. In each drawing, components denoted by the same reference numerals have the same or similar configuration.

[0012] In the present invention, "part," "means," "apparatus," or "system" does not merely mean physical means, but also includes cases where the functions of such "part," "means," "apparatus," or "system" are realized by software. Furthermore, even if the functions of one "part," "means," "apparatus," or "system" are realized by a combination of two or more physical means, devices, or software modules, the functions of two or more "parts," "means," "apparatus," or "systems" may be realized by a single physical means, device, or software module.

[0013] <1. System Configuration> Referring to Figure 1, an example of the system configuration of the data intermediary system 1 according to this embodiment will be described. The data intermediary system 1 is a system that acts as an intermediary between a service provider (also called the "service provider") and a user who uses this service. Through this intermediation, when a user uses the service, the data intermediary system 1 provides the service provider with user data (also called "user data") in an anonymized form that conforms to the user's wishes. In addition, the data intermediary system 1 may provide user data to a recipient other than the service provider, for example.

[0014] This embodiment describes an example in which a business operator (also called the "intermediary") that acts as an intermediary between users and service providers operates and manages the data intermediary system 1. For example, the intermediary manages user data provided by users when using the service and / or provides a user interface on behalf of the service provider.

[0015] An intermediary, for example, receives user data entered by users when using a service on behalf of the service provider, anonymizes the received user data, and then forwards it to the service provider. This restricts the service provider's access to the user data. This anonymization may include, for example, anonymizing the user data and / or encrypting the user data.

[0016] The intermediary may, for example, encrypt user data before providing it to the service provider. Furthermore, the intermediary may provide the service provider with information to decrypt this encrypted user data (also called "decryption information") if certain conditions are met, such as a predetermined period of time. The intermediary may cease providing the decryption information to the service provider if the predetermined conditions are no longer met.

[0017] As shown in FIG. 1, the data mediation system 1 includes, for example, a server device 100, a user's user device 200, and a service provider's operator device 300. The server device 100, the user device 200, and the operator device 300 are connected to each other via a network N so as to be communicable with each other.

[0018] [Server device] The server device 100 is an information processing device capable of communicating with the user device 200 and the operator device 300. By executing a predetermined program (also referred to as a "server program"), the server device 100 acquires user data from the user device 200, anonymizes the acquired user data according to the user's settings, and provides the anonymized user data to the operator device 300. In the present embodiment, it is assumed that the server device 100 is operated and managed by an intermediary.

[0019] [User device] The user device 200 is an information processing device used by the user, and is, for example, a terminal device such as a smartphone or a laptop. By executing a predetermined program (also referred to as a "user program"), the user device 200 transmits user data and the like to the server device 100, displays various screens of the data mediation system 1 to the user, and accepts operation inputs from the user with respect to the displayed screens. The user program may be, for example, an application program dedicated to the data mediation system 1 installed in the user device 200, or may be a web browser that the terminal device standardly includes.

[0020] [Operator device] The service provider device 300 is an information processing device used by a service provider. The service provider provides various services to users. The service provider device 300 may, for example, be one of the devices that constitute a system (also called a "service system") for a service provider to provide services to users. The service provider device of the first service provider that provides the first service will be referred to as "first service provider device 300a," and the service provider device of the second service provider that provides a second service different from the first service will be referred to as "second service provider device 300b." The first service provider and the second service provider are examples of recipients. The service provider device 300 is also an example of a recipient device.

[0021] User data may include, for example, information for verification processes such as registration, authentication, and authorization provided to service providers, various operation and input information when using the service, and various information about the device used by the user (e.g., OS, location information, keyboard settings, device-specific information, cookies, and / or other data that can be used for tracking).

[0022] User data may include, for example, user identification information to identify the user, payment method information or payment account information for the payment method used by the user, and service information or service account information for the service used by the user. In addition, if the user is an individual, user data may include, for example, the user's attributes (user's personal data), such as name, telephone number, address, email address, personal identification number (My Number), gender, and / or date of birth.

[0023] User data may include, for example, user personal data, such as usage history information showing each user's usage of multiple services. Specifically, the usage history information may include browsing history information for each of the multiple service sites, operation history information for the user device 200 when accessing the sites (including instruction information described later), and / or site login history information. This history information may also be information contained in the user device 200's cookies. User data may also include, for example, the user's location information (specifically, the location information of the user device 200).

[0024] Payment method information is information relating to a payment method. This information may include, for example, type information indicating the type of payment method (e.g., credit card payment, debit card payment, electronic money payment, etc.), payment method identification information for identifying the payment method (e.g., ID, card number, or account number, etc.), payment service provider information regarding the payment service provider, user identification information for the payment method, and security information for the security of the payment method. Furthermore, payment method information may also include, for example, at least a portion of the payment account information for the corresponding payment method.

[0025] Payment account information refers to information about a user's account (hereinafter also referred to as "payment account") used to utilize a payment method. Payment account information may include, for example, payment account identification information (e.g., ID or card number, etc.) to identify the user's payment account, and payment method information for the corresponding payment method. Payment account information may also include, for example, authentication information (e.g., payment account password, etc.) in user authentication of the payment account.

[0026] User data may include, for example, authentication information (a form of verification information) for authenticating a user. Authentication information is information that is an element of a predetermined authentication method and is used to authenticate a user in that predetermined authentication method. Authentication information may include, for example, information about possessions, biometric information, and stored information.

[0027] Possession information may include, for example, card information relating to an IC card or magnetic card that is a possession of the user, information that can be read from a terminal or card with an NFC tag embedded, information that can be read from an Individual Number Card (My Number Card), driver's license, passport, Basic Resident Register Card (with the user's photo), etc., and / or device information relating to a device that is a possession of the user (for example, user device 200) (specifically, device identification information, etc.).

[0028] Biometric information may include, for example, information relating to the user's physical characteristics such as facial features, fingerprints, palm prints, voiceprints, veins, and / or iris.

[0029] The stored information may include, for example, user identification information, payment method numbers (e.g., card number or account number), telephone number, account name such as email address, password (including PIN code), signatures or drawings entered or selected by the subject, and answers to prescribed questions in a free-form or multiple-choice format. It may also include any other information stored by the subject that can be retrieved by the server device 100.

[0030] User data may include, for example, device information related to the user's user device 200. Alternatively, for each user, user data and device information for one or more user devices 200 for each user may be associated and registered in the storage unit 130.

[0031] User data may include, for example, instruction information indicating the user's instructions to the first service provider equipment 300 via operational input, and at least one of the user's personal data. The instruction information may be, for example, a request to the first service site of the first service provider equipment 300.

[0032] Device information may include, for example, device identification information for identifying each device (e.g., an ID assigned to each device, device-specific identification information, or other information set for each device), device type (e.g., classification of PC, smartphone, tablet, EV, drone, or service-specific communication device), product name, MAC address, IP address, and / or serial number. Device information may also include, for example, information about the OS, information recorded in the memory of each device (e.g., ID and token information for one or more applications installed on each device), and positioning method corresponding to the location information provided by each device to the data intermediary system 1 (server device 100) (e.g., classification of GPS, UWB, BLE, or NFC).

[0033] [network] Network N consists of wireless or wired networks. Examples of Network N include mobile phone networks or PHS (Personal Handy-phone System) networks, wireless LAN (Local Area Network, including communication compliant with IEEE 802.11 (so-called Wi-Fi®)), 3G (3rd Generation), LTE (Long Term Evolution), 4G (4th Generation), 5G (5th Generation), WiMAX®, infrared communication, visible light communication, Bluetooth®, wired LAN, telephone lines, power line communication, power line networks, and networks compliant with IEEE 1394, etc.

[0034] <2. Overview> An example of data mediation system 1 will be explained with reference to Figures 2-3.

[0035] <2-2. Data Intermediation> Figure 2 shows an example of how user data is mediated by the data mediation system 1. In this example, the first service provided by the first service provider is described as a web service, but the intention is not to limit the first service to a web service. The first service can be any service that involves the exchange of user data between the user device 200 and the service provider device 300 via the network.

[0036] As shown in Figure 2, for example, the server device 100 may relay communication between the user device 200 and the first service provider device 300a that occurs when a user uses the first service. During this relay, the server device 100 will conceal user data based on settings specific to each user and each service. In this example, we will describe an example of re-accessing the website of the first service (hereinafter also referred to as the "first service site") from the user device 200.

[0037] (1) The user device 200 sends a request to the first service provider device 300a as an HTTP request to log in to the first service site provided by the service provider and display the top screen (including a request for user authentication to the first service). The server device 100 receives this display request in order to anonymize the user data contained in this display request and pass it to the first service provider device 300a. This display request includes, for example, information about the first service site's cookie (1st Party Cookie). This cookie information may include, for example, website browsing history information, input data to the first service site (for example, the contents of the shopping cart in the e-commerce cart function), account information for logging in to the first service site, etc.

[0038] For example, when the server device 100 relays the above display request to the first business device 300a, it may anonymize (process anonymize) the information of the cookie as follows. • Website browsing history information: Encrypted using an encryption key • Information entered on the first service site: Specific information that constitutes the user's personal information will be anonymized (e.g., deleted or replaced).

[0039] The server device 100 may, for example, perform user authentication processing on behalf of the first service provider device 300a based on the above account information. If user authentication is successful, the server device 100 may generate an authentication token. This authentication token may indicate that the authenticity of the user has been confirmed by the authentication processing on the server device 100.

[0040] In response to the display request sent from the user device 200, the server device 100 sends the anonymized information and the generated authentication token (a cookie with some information replaced is also called a "processed cookie") to the first business device 300a in place of some of the information in the cookie sent from the user device 200.

[0041] (2) The first service provider device 300a sends display information, including an HTML file and images, for displaying the top screen of the first service site (also called the "top page"), to the user device 200 as an HTTP response corresponding to the HTTP request (processed cookie) sent above. The server device 100 receives this transmitted display information and sends it to the user device 200. If there is no need to process the display information, the server device 100 may not relay it in this way, and it may be sent directly from the first service provider device 300a to the user device 200. The user device 200 receives the display information and displays the top screen of the first service site based on this received display information.

[0042] (3) The user device 200 sends the user input information for each input form on the displayed top screen to the first business device 300a as an HTTP request (POST method). The input information includes, for example, the user's ID (id), name (name), address (Address), DM sending permission flag (DM_Flag), and information about the destination screen in the request body (HTTP body part). The server device 100 receives the HTTP request in order to anonymize the user data contained in this HTTP request and pass it to the business device 300.

[0043] For example, when the server device 100 relays the above HTTP request to the first service provider device 300a, it may anonymize a portion of the information contained in the request body as follows. • User ID: Unprocessed • Name: Anonymized (e.g., replaced with "XX XX") • Address: Anonymized (e.g., shortened to city / ward level) • DM sending permission flag: No editing • Destination screen information: Unprocessed

[0044] The server device 100 sends the input information, partially anonymized, to the first business device 300a in place of the input information of the above request sent from the user device 200.

[0045] <2-3. Data Intermediation> Figure 3 shows an example of the overall functional configuration of the data mediation system 1. As shown in Figure 3, the functions implemented by the data mediation system 1 may be classified and arranged as follows, for example. The classified functions cooperate with each other (including information sharing and / or function sharing; the same applies hereinafter). [Service provider equipment 300: Service provider] • Verification function: A function to verify the legitimacy of the user when providing the service. • Service delivery function: A function that enables the delivery of a service (for example, in the case of a web service, the functions provided by the web server (presentation layer) and the AP server (application layer)). • Data management function: A function for managing data necessary for providing services, such as user data (for example, a function provided by the DB server (database layer) in the case of a web service). [Server device 100: Intermediary] • Verification proxy function: This function acts as a proxy for the service provider's verification function, verifying the user's legitimacy and providing the verification results to the service provider. • User Interface Function: A function that receives input information from the user device 200 and provides output information (including display information) received from the operator device 300 to the user device 200. • Confidentiality function: A function that conceals user data provided by users when using the service, according to the user's settings.

[0046] In this example, it is assumed that the user device 200 has previously received confidentiality settings for providing user data to one or more service providers, including the first service provider, and that information indicating these received confidentiality settings (also referred to as "confidentiality setting information") is registered in the storage unit 130.

[0047] (1) As shown in Figure 3, when a user uses the first service via the user device 200, the user performs an operation input (login operation input) to log in to the first service to the user device 200. The user device 200 transmits the input information from this operation input to the server device 100. This input information may include an authentication request and authentication information for user authentication in the first service. The server device 100 obtains user data (user authentication information) from the user device 200 in response to the user's login operation input to the user device 200.

[0048] (2) The verification unit 114 of the server device 100 performs user authentication by verifying the legitimacy of the user based on the above authentication information. Alternatively, the verification unit 114 may not perform user authentication and, if the settings and / or predetermined conditions of the service provider are met, send an authentication request including the above authentication information to the verification function of the service provider device 300. The service provider device 300 may perform user authentication itself by verifying the legitimacy of the user based on the authentication request sent from the server device 100.

[0049] (3) The service provision function of the service provider device 300 obtains the result of user authentication from the server device 100 or its own device's verification function. If the result of user authentication indicates successful authentication, the service provision function starts providing the first service to the user. Specifically, the service provision function generates display information to show the screen to which the user transitions after logging into the first service site (in this example, the "top screen"), and sends this generated display information to the server device 100. The acquisition unit 112 of the server device 100 acquires this transmitted display information. The provision unit 115 of the server device 100 sends this acquired display information to the user device 200. The user device 200 receives this transmitted display information and displays the top screen of the first service site to the user based on this display information.

[0050] (4) The user makes an operation input to the top screen displayed on the user device 200. The user device 200 transmits the input information (a form of user data) resulting from this operation input to the server device 100. The acquisition unit 112 of the server device 100 acquires this transmitted input information.

[0051] (5) The concealment unit 113 of the server device 100 performs the process of concealing the acquired input information based on the concealment setting information. The concealment unit 113 registers this concealed input information in the storage unit 130. The provision unit 115 of the server device 100 provides this concealed input information to the service provider devices 300 of one or more service providers (in this example, the first service provider and the second service provider).

[0052] The data concealment process performed by the data concealment unit 113 may be, for example, one of the following processes (a) to (c). (a) Encrypt all data: All data is encrypted before being provided. This means that the content of the data cannot be viewed without decryption. This ensures confidentiality. (i) Encrypting data other than data necessary for service provision (processing instructions): When it is necessary to receive processing instructions from users, such as function operations, in order to provide the service, data related to processing instructions will not be encrypted, while data not directly related to processing instructions (for example, location information and device information about the user, various history information, etc.) will be encrypted. This will ensure confidentiality. (c) By performing intermediate processing, direct data exchange between the user (data provider) and the first service provider (data user) is avoided, and all or part of the data is separately encrypted and provided: Processing instructions such as operations related to service provision are issued from the data intermediary system 1, and the model adopts not to directly provide data from the user, but to separately provide all or part of the data to the recipient. As a result, the first service provider is unable to see the user's identity or instructions.

[0053] Under the above configuration, the data intermediary system 1 can control the content of user data provided by the intermediary to the service provider based on the user's privacy settings, and can also handle a part of the user interface on behalf of the service provider. Therefore, when providing user data to the service provider when a user uses the service, the system can reflect the user's privacy needs.

[0054] Under the above configuration, the data intermediary system 1 can apply privacy settings via the cloud side, i.e., network N. Therefore, privacy settings can be applied independently of the edge side, i.e., the terminal device of the user device 200 and the installed applications and configuration files such as web browsers. Consequently, for example, if a user's browser settings on a particular device refuse to provide cookies to a certain service site, this setting is not shared with other devices or browsers, reducing the burden on the user who would otherwise need to configure it separately.

[0055] <3. Functional Configuration> Referring to Figure 4, the functional configuration of the server device 100 according to this embodiment will be described. As shown in Figure 4, the server device 100 includes a control unit 110, a communication unit 120, and a storage unit 130.

[0056] The control unit 110 includes a reception unit 111, an acquisition unit 112, a concealment unit 113, and a provision unit 115. The control unit 110 may also include, for example, a verification unit 114.

[0057] [Reception Department] The reception unit 111 receives various settings and / or requests from the user device 200 and / or the service provider device 300. For example, as one form of reception, the reception unit 111 may receive a message indicating the information entered by the user when the user enters information on the screen of the data intermediary system 1 website (also called the "data intermediary site") displayed on the user device 200.

[0058] The reception unit 111 receives confidentiality settings from the user device 200 of a user of the first service provided by the first service provider, for providing user data about this user to one or more service providers, including the first service provider. The reception unit 111 may, for example, receive and accept information indicating the entered confidentiality settings from the user device 200 when the user enters the confidentiality settings on the screen of the data mediation site on the user device 200. Alternatively, the reception unit 111 may register this received confidentiality setting information in the storage unit 130.

[0059] The data concealment settings may include, for example, whether user data can be provided from the user to each recipient, one or more data items to be provided, and the content of concealment for each data item (for example, whether or not it is subject to concealment, and if so, the degree of concealment). Furthermore, the data concealment settings may be set for each recipient registered in the data intermediary system 1, for example, to the degree of concealment, such as (a) conceal all data, (b) conceal sensitive information, or (c) conceal personal information. The data concealment settings may also be set for each recipient, for example, to include whether or not data items are concealed, the method of concealment processing, and the conditions for data disclosure (for example, the provision period and / or whether or not encryption / conversion processing is required).

[0060] Confidentiality settings may, for example, specify how to conceal information for each user and for each service. Confidentiality settings may also, for example, provide individual settings for instruction information and personal data for each user and / or service provider (service). Confidentiality settings may also specify that instruction information is not concealed, while personal data is concealed. Furthermore, confidentiality settings may specify, for example, that user personal information is concealed uniformly (specifically, anonymized or encrypted), while user usage history information is not concealed. Confidentiality settings may also include common settings for multiple service providers.

[0061] According to the above configuration, separate settings can be applied to instruction information and personal data. For example, concealing instruction information is likely to affect the provision of services, and the requirement for confidentiality is generally relatively low. On the other hand, personal data is less likely to affect the provision of services, but the requirement for confidentiality is generally relatively high. In this way, concealment settings can be flexibly applied according to the characteristics of each type of user data.

[0062] The concealment settings may also include, for example, settings for how to conceal data for each recipient. The concealment settings may also include, for example, concealment settings for a second service provider.

[0063] The reception unit 111 may, for example, receive a decryption request from the service provider's equipment 300 to decrypt at least a portion of the encrypted user data. When a decryption request is received, possible actions include (a) the server device 100 decrypting the data itself, or (b) providing decryption information so that the requesting service provider's equipment 300 can decrypt the data.

[0064] The reception unit 111 may, for example, receive a request from the first service provider's equipment 300a to provide user data to a different recipient (for example, a second service provider, etc.) from the first service provider.

[0065] The reception unit 111 may, for example, receive conditions for user verification (also called "verification conditions") from the service provider's equipment 300. The reception unit 111 may also register information indicating these received verification conditions (also called "verification condition information") in the storage unit 130.

[0066] The verification conditions may, for example, specify the method for registering user data, the method for verifying the user's identity during data registration, the method for identifying the user, and / or the method for authentication and authorization.

[0067] The method of registering user data may include, for example, the types of user data to be acquired, the user's personal data (e.g., name, email address, mobile phone number, address, date of birth, etc.), and other data necessary for providing the service.

[0068] The method of identity verification during data registration may include, for example, eKYC, public personal authentication, OTP receipt confirmation, or platform provider-dependent verification.

[0069] Methods for identifying users may include, for example, issuing an ID to identify each user, registering the user's email address, providing cookies or similar to the user device 200, or issuing an electronic certificate to authenticate the user or the user device 200.

[0070] The methods for authentication and authorization may include, for example, requiring registration and verification of an ID / password, requiring registration and verification of biometric authentication, device authentication, FIDO authentication, or a combination of these.

[0071] The reception unit 111 may, for example, accept the registration destination for all or part of the user data. This registration destination may be the data intermediary system 1 (specifically, the storage unit 130 of the server device 100, etc.) and / or the system of the first service (specifically, the storage unit of the first business operator device 300a, etc.). The reception unit 111 may register information indicating the accepted registration destination (also called "registration destination information") in the storage unit 130.

[0072] [Acquisition Department] The acquisition unit 112 acquires various information from the user device 200 and / or the operator device 300.

[0073] The acquisition unit 112 may, for example, receive messages indicating the various information entered by the user when various information is entered by the user on the first service site or data intermediary site displayed on the user device 200. Alternatively, the acquisition unit 112 may receive data files of various information from the user device 200 or the service provider device 300 in a cyclic or event-driven manner. Alternatively, the acquisition unit 112 may, for example, instruct an API implemented by an external system (not shown), such as a cloud file system, to reference various information and acquire the information as a result. The acquisition unit 112 may also acquire various information by, for example, having the user device 200 use a library of an SDK corresponding to the data intermediary system 1.

[0074] The acquisition unit 112 acquires user data from the user device 200 in response to the user's operation input to the user device 200 when the user uses the first service via the user device 200.

[0075] The acquisition unit 112 may, for example, acquire permission information from the user device 200 indicating the user's permission to decrypt the user data.

[0076] The acquisition unit 112 may, for example, acquire consent information from the user device 200 indicating the user's consent to the provision of user data to the second service provider.

[0077] The acquisition unit 112 may, for example, register the acquired user data (e.g., highly confidential information such as account information and / or authentication information) and registration destination information indicating where the user data is registered in the storage unit 130.

[0078] The acquisition unit 112 may, for example, acquire information about service providers and other recipients (also referred to as "recipient information") from the service provider equipment 300. The acquisition unit 112 may also register the acquired recipient information in the storage unit 130.

[0079] The recipient information may include, for example, the recipient's attribute information (e.g., name, company name / trade name, address, services provided, contact information, corporate website, etc.), the purpose of using the provided data (e.g., provision of services, public interest, government / legal requirements, etc.), the method of data provision (e.g., information indicating the provision method such as API integration, identification information for provision, and / or the data provision cycle (e.g., immediate, periodic batch processing, on-demand provision in response to requests, etc.)).

[0080] [Anonymization Department] The anonymization unit 113 anonymizes user data based on the user's anonymization settings. For example, the anonymization unit 113 may anonymize user data. Specifically, the anonymization unit 113 may anonymize user data by deleting items or cells, generalizing all or part of the user data by abstracting, conceptualizing, or shortening it with numbers, performing top (bottom) coding, data exchange, or adding noise (errors).

[0081] If anonymization is performed, the anonymization unit 113 may register processing history information indicating the processing history in the storage unit 130. Alternatively, the anonymization unit 113 may restore the user data to its state before anonymization based, for example, on the release request and processing history information received by the reception unit 111.

[0082] The anonymization unit 113 may, for example, encrypt all or part of the user data using an encryption key as an anonymization measure. Possible encryption methods used for encryption include, for example, symmetric-key cryptography, public-key cryptography, and hybrid methods.

[0083] The concealment unit 113 may, for example, not conceal the instruction information, but conceal at least a portion of the personal data.

[0084] With the above configuration, the anonymization unit 113 can handle instruction information and personal data separately, even without user settings. For example, anonymizing instruction information is likely to affect the provision of services, and the requirement for confidentiality is generally relatively low. On the other hand, personal data is less likely to affect the provision of services, but the requirement for confidentiality is generally relatively high. In this way, user data can be flexibly anonymized according to the characteristics of each type of data.

[0085] The anonymization unit 113 may, for example, anonymize the verification information provided to the service provider's device 300. The anonymization unit 113 may, for example, not encrypt the user identification information (ID) in the first service included in the verification information, but encrypt other personal information.

[0086] The concealment unit 113 may decrypt the user data based on the decryption request received by the reception unit 111. The concealment unit 113 may, for example, decrypt encrypted user data.

[0087] [Verification Section] The verification unit 114 verifies the legitimacy of the user (e.g., the authenticity and / or existence of the user). The verification unit 114 verifies the legitimacy of the user, for example, based on verification information contained in the user data. The verification unit 114 may also verify the legitimacy of the user, for example, based on verification conditions. Specifically, the verification of the legitimacy of the user may be user identity verification and / or user authentication. If the verification unit 114 determines, for example, that the legitimacy of the user has been verified, and / or if the privacy setting has configured to provide an authentication token instead of verification information, it may generate an authentication token based on the verification information.

[0088] Verification information is information used to verify the legitimacy of the user when using the first service, that is, to confirm that the user is indeed the person they claim to be. Verification information may be, for example, authentication information, or it may represent an authentication element (knowledge, possession, biometric). Furthermore, verification information may be a combination of multiple types of authentication elements for multi-factor authentication (for example, a combination of a credit card and a PIN code).

[0089] The verification unit 114 may, for example, verify the authenticity of the user by comparing (or in other words, matching) the information contained in the user data stored in the storage unit 130 with the verification information obtained from the user device 200.

[0090] When the service provider's device 300 performs a process to verify the legitimacy of the user when using the first service, the verification unit 114 may, for example, have the service provider's device 300 provide verification information included in the user data to the service provider's device 300 via the provision unit 115.

[0091] [Provider] The data provider unit 115 provides various data to the user device 200 and / or the service provider device 300, etc. The manner in which the data provider unit 115 provides various data may be any manner. For example, the data provider unit 115 may send data files or messages (e.g., HTTP requests, etc.) containing user data to these devices in an event-driven manner. Alternatively, as another example, the data provider unit 115 may provide user data to the service provider device 300, etc. via a library of an API or SDK that it implements.

[0092] The provisioning unit 115 provides, for example, anonymized user data to the respective recipient devices (e.g., service provider devices 300) of one or more recipients (e.g., service providers).

[0093] According to the above configuration, user data provided to the service provider can be made confidential according to the user's confidentiality settings. Therefore, when providing user data to service providers when users use the service, the user's needs regarding confidentiality can be reflected.

[0094] The providing unit 115 may, for example, provide the business operator device 300 with concealed verification information and / or verification result information showing the verification result of the verification unit 114. The verification result information may, for example, be information that directly shows the verification result, or it may be an authentication token generated according to the verification result. The verification information may include highly confidential information such as passwords and the user's biometric information, and sending the verification information as is to the receiving device poses security challenges. With this configuration, the security of highly confidential information can be improved by concealing it or by sending the verification result instead of the verification information.

[0095] The providing unit 115 may, for example, provide the operator device 300 with unconfidential instruction information and / or personal data that is at least partially confidential.

[0096] The provisioning unit 115 may, for example, provide the business operator's device 300 with decryption information to decrypt the encrypted user data based on the decryption request and permission information. If the decryption is encryption of the user data, the decryption information may be decryption information. For example, the provisioning unit 115 may provide the business operator's device 300 with a symmetric key to be paired as decryption information for user data encrypted using a symmetric key encryption scheme. The decryption information may also have an expiration date set. If the expiration date of the decryption information has passed, the business operator's device 300 may be prevented from using this decryption information to decrypt the data.

[0097] With the above configuration, the service provider's device 300 can also decrypt user data retrospectively and use it with the user's permission. Therefore, the decrypted user data can be used at the recipient simply by providing decryption information, without having to provide (transmit) the decrypted user data to the service provider's device 300 again. This ensures security while enhancing convenience.

[0098] The provisioning unit 115 may, for example, provide confidential user data to a recipient device (e.g., a second service provider device 300b) of a different recipient (e.g., a second service provider) based on the service request from the first service provider and the consent information from the user received by the receiving unit 111.

[0099] According to the above configuration, the server device 100 can provide confidential user data to different recipients, such as the second service provider, in response to a request from the first service provider. Therefore, the first service provider can allow these recipients to acquire and utilize the confidential user data without having to provide the user data to them themselves.

[0100] [g section] The communication unit 120 transmits and receives various data via the network N to and from the user device 200, the operator device 300, or other external system devices.

[0101] [Storage] The storage unit 130 stores user data and information related to the management of user data. The storage unit 130 may store each data using a database management system (DBMS) or using a file system. If a DBMS is used, a table may be created for each data, and each data may be managed by associating these tables.

[0102] <4. Example of operation> Refer to Figure 5 to explain an example of the operation of the data intermediary system 1. Figure 5(a) is a flowchart showing an example of the flow of the privacy setting process in the data intermediary system 1. Figure 5(b) is a flowchart showing an example of the flow of the user data provision process in the data intermediary system 1. Note that the order of the processes shown below is just an example and may be changed as appropriate.

[0103] As shown in Figure 5(a), the reception unit 111 of the server device 100 receives an anonymization setting from the user device 200 of the user of the first service to provide user data to one or more recipients, including the first service provider (S10). The acquisition unit 112 of the server device 100 acquires consent information from the user device 200 indicating the user's consent to provide user data to one or more service providers (S11). The reception unit 111 and the acquisition unit 112 of the server device 100 each register the anonymization setting information indicating the anonymization setting and the consent information in the storage unit 130 in association with the user's account information (S12).

[0104] As shown in Figure 5(b), when a user uses the first service via the user device 200, the acquisition unit 112 of the server device 100 acquires user data from the user device 200 in response to the user's operation input to the user device 200 (S20). The concealment unit 113 of the server device 100 refers to the storage unit 130 and conceals the user data based on the concealment settings (S21). The provision unit 115 of the server device 100 provides the concealed user data to the service provider devices 300 of one or more service providers (S22).

[0105] <5. Hardware Configuration> Referring to Figure 6, an example of a hardware configuration when the server device 100 and / or user device 200 described above are implemented using a computer 800 will be explained. Note that the functions of each device can also be implemented by dividing them among multiple devices.

[0106] As shown in Figure 6, the computer 800 includes a processor 801, a memory 803, a storage device 805, an input I / F unit 807, a data I / F unit 809, a communication I / F unit 811, and a display device 813.

[0107] The processor 801 controls various processes in the computer 800 by executing programs (for example, server programs or user programs) stored in memory 803. For example, the various functional units of the control unit 110 of the server device 100 and / or the control unit of the user device 200 can be realized by the processor 801 executing programs temporarily stored in memory 803.

[0108] Memory 803 is a storage medium such as RAM (Random Access Memory). Memory 803 temporarily stores the program code of the program executed by the processor 801, as well as data required during program execution.

[0109] The storage device 805 is a non-volatile storage medium such as a hard disk drive (HDD) or flash memory. The storage device 805 stores the operating system and various programs necessary to implement the above configurations. In addition, the storage device 805 can also store tables for registering various data such as user data, and a database (DB) for managing those tables. Such programs and data are loaded into memory 803 as needed and accessed by the processor 801.

[0110] The input interface unit 807 is a device for receiving input from the user. Specific examples of the input interface unit 807 include keyboards, mice, touch panels, various sensors, and wearable devices. The input interface unit 807 may be connected to the computer 800 via an interface such as USB (Universal Serial Bus).

[0111] The data interface unit 809 is a device for inputting data from outside the computer 800. Specific examples of the data interface unit 809 include drive devices for reading data stored on various storage media. The data interface unit 809 may also be located outside the computer 800. In that case, the data interface unit 809 would be connected to the computer 800 via an interface such as USB.

[0112] The communication interface unit 811 is a device for performing data communication with external devices of the computer 800 via a network N, either wired or wirelessly. The communication interface unit 811 may also be located outside the computer 800. In that case, the communication interface unit 811 is connected to the computer 800 via an interface such as USB.

[0113] The display device 813 is a device for displaying various types of information. Specific examples of the display device 813 include liquid crystal displays, organic EL (Electro-Luminescence) displays, and displays for wearable devices. The display device 813 may be located outside the computer 800. In that case, the display device 813 is connected to the computer 800, for example, via a display cable. Furthermore, if a touch panel is used as the input I / F unit 807, the display device 813 can be integrated with the input I / F unit 807.

[0114] This embodiment is illustrative for explaining the present invention and is not intended to limit the invention to this embodiment alone. Furthermore, the present invention can be modified in various ways without departing from its essence. Moreover, those skilled in the art can adopt embodiments in which each of the elements described below is replaced with equivalent ones, and such embodiments are also included within the scope of the present invention.

[0115] [Differentiation] Although the present invention has been described based on the above embodiments, the following cases are also included in the present invention.

[0116] [Example 1] At least some of the components of the server device 100 according to the above embodiment may be provided by the user device 200 and / or the operator device 300. For example, the operator device 300 may implement all or part of the functions of the verification unit 114 of the server device 100.

[0117] [Differentiation 2] (2) In the above embodiment, an example was described in which the operator device 300 is provided with the function for generating display information for providing the first service (for example, information for displaying each screen of the first service site), but some or all of this function may be provided by the server device 100. [Explanation of symbols]

[0118] 1...Data intermediation system, 100...Server device, 110...Control unit, 111...Reception unit, 112...Acquisition unit, 113...Anonymization unit, 114...Verification unit, 115...Provision unit, 120...Communication unit, 120...Storage unit, 200...User device, 200...Operator device, 800...Computer, 801...Processor, 803...Memory, 805...Storage device, 807...Input I / F unit, 809...Data I / F unit, 811...Communication I / F unit, 813...Display device.

Claims

1. On the computer, A reception function that receives confidentiality settings for providing user data relating to a user from the user's device of a user of the first service provided by the first service provider to one or more recipients, including the first service provider, When the user uses the first service via the user device, the system includes an acquisition function that obtains user data from the user device in response to the user's operation input to the user device, A concealment function that conceals the user data based on the aforementioned concealment settings, The function provides the confidentialized user data to the recipient device of each of the one or more recipients, If the first service provider's equipment requests the provision of the user data to a recipient other than the first service provider, The aforementioned reception function receives the aforementioned request for provision, The acquisition function acquires consent information from the user device indicating the user's consent to the provision of the user data to the different recipients. The aforementioned concealment settings include concealment settings for different recipients, The provision function provides the confidentialized user data to the different recipient devices based on the provision request and consent information. program.

2. The user data includes verification information used to confirm the legitimacy of the user when using the first service. The computer is provided with a verification function that verifies the legitimacy of the user based on the verification information. The aforementioned provision function provides the first service provider's first service provider device with anonymized verification information and / or verification result information indicating the verification result of the aforementioned verification function. The program according to claim 1.

3. The user data includes at least one of the following: instruction information indicating the user's instructions to the first service provider's device of the first service based on the operation input, and the user's personal data. The aforementioned concealment settings are configured individually for each user and / or recipient, for each of the instruction information and the personal data. The program according to claim 1 or 2.

4. The user data includes at least one of the following: instruction information indicating the user's instructions to the first service provider's device of the first service based on the operation input, and the user's personal data. The concealment function does not conceal the instruction information, but conceals at least a portion of the personal data. The aforementioned provision function provides the first operator's device with the unconfidential instruction information and / or personal data that is at least partially confidential. The program according to claim 1 or 2.

5. The reception function receives a decryption request from the first service provider's first service provider device to decrypt at least a portion of the encrypted user data. The acquisition function acquires permission information from the user device indicating the user's permission to cancel the transaction. The aforementioned provision function provides the first business operator device with decryption information to decrypt the concealed user data based on the decryption request and the permission information. The program according to claim 1 or 2.

6. A receiving unit that receives confidentiality settings from the user device of a user of the first service provided by the first service provider, for providing user data concerning the user to one or more service providers, including the first service provider, When the user uses the first service via the user device, an acquisition unit obtains user data from the user device in response to the user's operation input to the user device, A concealment unit that conceals the user data based on the aforementioned concealment settings, The system includes a provisioning unit that provides the confidentialized user data to the service provider equipment of each of the one or more service providers, If the first service provider's equipment requests the provision of the user data to a recipient other than the first service provider, The reception unit receives the request for provision, The acquisition unit acquires consent information from the user device indicating the user's consent to the provision of the user data to the different recipients. The anonymization unit performs anonymization for the different recipients, The provisioning unit provides the anonymized user data to the different recipient devices based on the provision request and the consent information. Information processing device.

7. Computers Regarding the confidentiality settings for providing user data relating to a user from the user device of a user of the first service provided by the first service provider to one or more service providers, including the first service provider: Accepting the aforementioned privacy settings, When the user uses the first service via the user device, the user data is obtained from the user device in response to the user's operation input to the user device. Based on the aforementioned concealment settings, the user data is made confidential. The anonymized user data is provided to the service provider equipment of each of the one or more service providers. In response to a request from the first service provider's equipment for the provision of user data to a recipient different from the first service provider, Upon receiving the aforementioned request for provision, From the user device, consent information indicating the user's consent to the provision of the user data to the recipient is obtained. The aforementioned confidentiality measures are applied to different recipients. Based on the aforementioned request for provision and the aforementioned consent information, the anonymized user data is provided to the recipient device of the different recipient. Information processing methods.