Program, information processing device, and information processing method

JP7911712B2Active Publication Date: 2026-08-27JCB CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024066194
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-04-16
Publication Date
2026-08-27
Estimated Expiration
2044-04-16

AI Technical Summary

Benefits of technology

【0009】 本発明によれば、サービスを利用者が利用する際の利用者データの提供にあたって、利用者の個人情報を保護しつつ、提供先での利活用をふまえたデータの提供を実現できる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007911712000001
    Figure 0007911712000001
  • Figure 0007911712000002
    Figure 0007911712000002
  • Figure 0007911712000003
    Figure 0007911712000003
Patent Text Reader

Abstract

To realize provision of data that takes into account an intended use at a recipient while protecting user's personal information, when providing user data of a user using a service to a recipient.SOLUTION: A program causes a computer to realize: a reception function for accepting, from a user device of a user of a first service provided by a first service provider, a separation setting for separating user data into first data containing user's personal information and second data not containing the personal information and providing the separated user data to one or more recipients, including the first service provider; an acquisition function for acquiring the user data from the user device in response to user input on the user device when the user uses the first service via the user device; a separation function for separating the user data into the first data and the second data based on the separation setting; and a provision function for providing the second data separated from the user data to each of recipient devices of one or more recipients.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a program, an information processing apparatus, and an information processing method.

Background Art

[0002] Conventionally, there is known a technique of providing data regarding a user who uses a service (hereinafter referred to as "user data") to a destination including an operator who provides this service after anonymously processing the data for protecting the personal information of the user. Patent Document 1 discloses a cooperation server that acquires anonymized customer data obtained by anonymously processing customer data managed by each of a plurality of operator servers that manage customer data. This cooperation server combines the anonymized customer data obtained from the plurality of operator servers and provides it to at least one of the operator servers and other external devices. [[ID=We]]

Prior Art Documents

Patent Documents

[0003] <Here]]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the apparatus described in Patent Document 1 above, although personal information can be protected by anonymously processing the user data to be provided, since the data to be provided is uniformly anonymously processed, there is room for improvement in the data provision aspect from the viewpoint of data utilization.

[0005] Therefore, the present invention realizes data provision that takes into account utilization at the destination while protecting the personal information of the user when providing user data when the user uses the service.

Means for Solving the Problems

[0006] It should be noted that there are some inaccuracies in the original text you provided, such as "

先行技術文献

Prior Art Documents

特許文献

Patent Documents

[0007] An information processing device according to one aspect of the present invention includes: a receiving unit that receives a setting for separating user data relating to a user into first data including the user's personal information and second data not including personal information, from a user device of a user of a first service provided by a first service provider to one or more recipients, including the first service provider; an acquisition unit that acquires user data from a user device in response to the user's operation input to the user device when the user uses the first service via the user device; a separation unit that separates the user data into first data and second data based on the setting; and a provisioning unit that provides the second data separated from the user data to the recipient device of one or more recipients.

[0008] An information processing method according to one aspect of the present invention involves a computer receiving a sorting setting from a user's device of a user of a first service provided by a first service provider, to provide user data to one or more recipients, including the first service provider, by dividing the user data into first data including the user's personal information and second data not including personal information. When a user uses the first service via the user device, the computer acquires user data from the user device in response to the user's operation input to the user device, sorts the user data into first data and second data based on the sorting setting, and provides the second data separated from the user data to the recipient device of each of the one or more recipients. [Effects of the Invention]

[0009] According to the present invention, when providing user data to users when they use a service, it is possible to provide data while protecting the user's personal information and taking into account how the data will be used by the recipient. [Brief explanation of the drawing]

[0010] [Figure 1] This figure illustrates an example of the system configuration of the data mediation system according to this embodiment. [Figure 2] This diagram illustrates the overview of the data mediation system according to this embodiment. [Figure 3] This diagram illustrates the overview of the data mediation system according to this embodiment. [Figure 4] This figure shows an example of the functional configuration of the server device according to this embodiment. [Figure 5] This figure shows an example of the operation of the data mediation system according to this embodiment. [Figure 6] This figure shows an example of the hardware configuration of the server device according to this embodiment. [Modes for carrying out the invention]

[0011] A preferred embodiment of the present invention (hereinafter referred to as "this embodiment") will be described with reference to the attached drawings. In each drawing, components denoted by the same reference numerals have the same or similar configuration.

[0012] In the present invention, "part," "means," "apparatus," or "system" does not merely mean physical means, but also includes cases where the functions of such "part," "means," "apparatus," or "system" are realized by software. Furthermore, even if the functions of one "part," "means," "apparatus," or "system" are realized by a combination of two or more physical means, devices, or software modules, the functions of two or more "parts," "means," "apparatus," or "systems" may be realized by a single physical means, device, or software module.

[0013] <1. System Configuration> Referring to Figure 1, an example of the system configuration of the data intermediary system 1 according to this embodiment will be explained. The data intermediary system 1 is a system that acts as an intermediary between a service provider (also referred to as the "service provider") and a user who uses this service. Through this intermediation, when a user uses the service, the data intermediary system 1 separates data about the user (also referred to as the "user data") into data containing the user's personal information (also referred to as the "first data") and data that does not contain personal information (also referred to as the "second data") and provides it to the service provider in a manner that conforms to the user's wishes. In addition, the data intermediary system 1 may, for example, provide the user data to a recipient other than the service provider.

[0014] The personal information included in the first data may be, for example, information that can identify and distinguish the individual user. Also, the second data may include, for example, information indicating the user's instruction to the service provider device 300a of the first service by the user's operation input (also referred to as "instruction information") and anonymized information other than this instruction information. The anonymized information may be, for example, information that cannot identify and distinguish the individual user. In other words, the anonymized information may be information that does not correspond to the personal information of the user. Also, the anonymized information may be, for example, information that does not constitute pseudonymous information.

[0015] The first data may include, for example, pseudonymous information (including pseudonymized information), and / or information related to the user's transactions and settlements (for example, purchase and settlement history, authentication history, information related to characters such as avatars held by the user, information related to assets held by the user such as NFTs, cryptocurrency assets, in-game currency, information related to game media such as items held by the user, etc.).

[0016] In this embodiment, an example will be described in which a business operator (also referred to as an "intermediary operator") that mediates between the user and the service provider operates and manages the data mediation system 1. The intermediary operator, for example, manages the user data provided by the user when using the service and / or provides a user IF on behalf of the service provider.

[0017] The intermediary operator, for example, receives the user data input by the user when using the service on behalf of the service provider, divides the received user data into first data and second data, and then mediates between the service provider. Thereby, the intermediary operator restricts the acquisition of the service provider's user data.

[0018] The division of the user data may consider, for example, the following patterns (1) to (3). <0ooOOOO89>(1) When the user data is composed of only the first data: Divide the entire user data as the first data (2) When the user data is composed of only the second data: Divide the entire user data as the second data (3) When the user data is composed of the first data and the second data: Divide it into user data, the first data, and the second data.

[0019] The intermediary may, for example, provide the service provider with the second data separated from the user data. Furthermore, the intermediary may encrypt the first data separated from the user data and then provide it to the service provider. Additionally, when a predetermined condition such as a predetermined period (also referred to as a "decryption condition") is satisfied, the intermediary may provide the service provider with information (also referred to as "decryption information") for decrypting this encrypted first data. The intermediary may terminate the provision of the decryption information to the service provider when the decryption condition is no longer satisfied. The decryption condition may include, for example, for each service provider, having consent information indicating consent to the provision and use of personal information from the user, and / or having obtained an ISMS certification (ISO27001) or a P mark, etc.

[0020] As shown in FIG. 1, the data mediation system 1 includes, for example, a server device 100, a user's user device 200, and a service provider's business device 300. Also, the server device 100, the user device 200, and the business device 300 are connected to each other via a network N so as to be communicable.

[0021] [Server Device] The server device 100 is an information processing device capable of communicating with the user device 200 and the business device 300. By executing a predetermined program (also referred to as a "server program"), the server device 100 acquires user data from the user device 200, separates the data according to the user's settings for the acquired user data, and provides the separated data to the business device 300. In this embodiment, it is assumed that the server device 100 is operated and managed by the intermediary, but the gist is not limited to this.

[0022] [User Device] The user device 200 is an information processing device used by the user, such as a smartphone or laptop computer. The user device 200 transmits user data to the server device 100, displays various screens of the data mediation system 1 to the user, and accepts user input for the displayed screens by executing a predetermined program (also called the "user program"). The user program may be, for example, an application program specifically for the data mediation system 1 installed on the user device 200, or it may be a web browser that is standard on the terminal device.

[0023] [Business equipment] The service provider device 300 is an information processing device used by a service provider. The service provider provides various services to users. The service provider device 300 may, for example, be one of the devices that constitute a system (also called a "service system") for a service provider to provide services to users. The service provider device of the first service provider that provides the first service will be referred to as "first service provider device 300a," and the service provider device of the second service provider that provides a second service different from the first service will be referred to as "second service provider device 300b." The first service provider and the second service provider are examples of recipients. The service provider device 300 is also an example of a recipient device.

[0024] User data may include, for example, the user's personal information, including user identification information for identifying the user; payment method information or payment account information for the payment method used by the user; and service information or service account information for the service used by the user.

[0025] Personal information may include, for example, user identification information (ID), personal or corporate attribute information (name, trade name, company name, location or address, contact information (telephone number or email address), gender, date of birth, and / or occupation, etc.).

[0026] Payment method information is information relating to a payment method. This information may include, for example, type information indicating the type of payment method (e.g., credit card payment, debit card payment, electronic money payment, etc.), payment method identification information for identifying the payment method (e.g., ID, card number, or account number, etc.), payment service provider information regarding the payment service provider, user identification information for the payment method, and security information for the security of the payment method. Furthermore, payment method information may also include, for example, at least a portion of the payment account information for the corresponding payment method.

[0027] Payment account information refers to information about a user's account (hereinafter also referred to as "payment account") used to utilize a payment method. Payment account information may include, for example, payment account identification information (e.g., ID or card number, etc.) to identify the user's payment account, and payment method information for the corresponding payment method. Payment account information may also include, for example, authentication information (e.g., payment account password, etc.) in user authentication of the payment account.

[0028] User data may include, for example, information used for verification processes such as registration, authentication, and authorization for service providers (also referred to as "verification information"). Some or all of the verification information may be classified as personal information.

[0029] User data may include, for example, instruction information for the service provider's equipment 300 based on user input to the user's equipment 200 when the user uses the service.

[0030] Instruction information may be, for example, various operation and input information by the user to the service system (e.g., processing commands). Instruction information may also be, for example, a request to the website of the first service provided by the first service provider device 300a (also referred to as the "first service site"). Specifically, instruction information may be force information entered by the user when using the first service, such as keyboard input, voice input, mouse processing, or controller processing input.

[0031] User data may include, for example, usage history information showing each user's usage of multiple services. Specifically, usage history information may include browsing history information for each of the multiple service sites, operation history information (including instruction information) for the user device 200 when accessing the sites, and / or site login history information. This history information may also be information contained in the user device 200's cookies. User data may also include, for example, the user's location information (specifically, the location information of the user device 200).

[0032] User data may include, for example, authentication information (a form of verification information) for authenticating a user. Authentication information is information that is an element of a predetermined authentication method and is used to authenticate a user in that predetermined authentication method. Authentication information may include, for example, information about possessions, biometric information, and stored information.

[0033] Possession information may include, for example, card information relating to an IC card or magnetic card that is a possession of the user, information that can be read from a terminal or card with an NFC tag embedded, information that can be read from an Individual Number Card (My Number Card), driver's license, passport, Basic Resident Register Card (with the user's photo), etc., and / or device information relating to a device that is a possession of the user (for example, user device 200) (specifically, device identification information, etc.).

[0034] Biometric information may include, for example, information relating to the user's physical characteristics such as facial features, fingerprints, palm prints, voiceprints, veins, and / or iris.

[0035] The stored information may include, for example, user identification information, payment method numbers (e.g., card number or account number), telephone number, account name such as email address, password (including PIN code), signature or drawing entered or selected by the user, free-form or multiple-choice answers to prescribed questions, or any other information stored by the user that can be retrieved by the server device 100.

[0036] User data may include, for example, device information related to the user's user device 200. Alternatively, for each user, user data and device information for one or more user devices 200 belonging to each user may be associated and registered in the storage unit 130. Device information may be categorized, for example, as personal information or anonymous information.

[0037] Device information may include, for example, device identification information to identify each device (e.g., an ID assigned to each device, device-specific identification information, or other information set for each device), device type (e.g., classification of PC, smartphone, tablet, EV, drone, or service-specific communication device), product name, MAC address, IP address, serial number, and / or other device-specific information.

[0038] Device information may include, for example, information about the OS, information recorded in the memory of each device (for example, ID and token information for one or more applications installed on each device), and a positioning method corresponding to the location information provided by each device to the data intermediary system 1 (server device 100) (for example, GPS, UWB, BLE, or NFC classification).

[0039] Device information may include, for example, peripheral device configuration information indicating the settings of peripheral devices such as keyboards made by the user, cookies stored on each device, and / or other data that can be used for tracking.

[0040] [network] Network N consists of wireless or wired networks. Examples of Network N include mobile phone networks or PHS (Personal Handy-phone System) networks, wireless LAN (Local Area Network, including communication compliant with IEEE 802.11 (so-called Wi-Fi®)), 3G (3rd Generation), LTE (Long Term Evolution), 4G (4th Generation), 5G (5th Generation), WiMAX®, infrared communication, visible light communication, Bluetooth®, wired LAN, telephone lines, power line communication, power line networks, and networks compliant with IEEE 1394, etc.

[0041] <2. Overview> An example of data mediation system 1 will be explained with reference to Figures 2-3.

[0042] <2-2. Data Intermediation> Figure 2 shows an example of how user data is mediated by the data mediation system 1. In this example, the first service provided by the first service provider is described as a web service, but the intention is not to limit the first service to a web service. The first service can be any service that involves the exchange of user data between the user device 200 and the service provider device 300 via the network.

[0043] As shown in Figure 2, for example, the server device 100 may relay the communication between the user device 200 and the first service provider device 300a that occurs when a user uses the first service. During this relay, the server device 100 separates the user data based on settings for each user and each service (separation settings described later).

[0044] The user data in the data intermediation system 1 may be separated (disconnected) by the following classifications, for example: • Separation of data containing users' personal information (also referred to as "Data 1") and data that does not contain users' personal information (also referred to as "Data 2"). • Separation of information included in the first data into user personal information, pseudonym information, and transaction / payment information. • Separation of information included in the second data set into instruction information indicating user instructions and anonymous information other than instruction information.

[0045] Anonymous information may include, for example, location information of the device used by the user (including user device 200), the type of program the user is running in the virtual space area, character information about avatars and other characters that the user can operate (e.g., coordinate axis information indicating the character's position, information about the character's modeling and animation, etc.), history information regarding the processing history of the program the user has run (e.g., the start time of processing and the time required for each process), and setting information indicating various settings such as language settings and security settings for each device and application used by the user.

[0046] The sorting of user data in the data intermediation system 1 may, for example, be done by sorting (dividing) the data according to the data items contained in the user data. Furthermore, in this sorting, for example, one data item may be divided into multiple categories. For example, a data item indicating a request to the first service site may be divided into two parts, instruction information and anonymous information.

[0047] (1) The user device 200 sends a request to the first service provider device 300a to log in to the first service provider device 300a and display the top screen, as a request to display the first service site, in order to display the top screen. The server device 100 receives this display request in order to separate the user data contained in this display request and pass it to the first service provider device 300a. This display request includes, for example, information about the first service site's cookie (1st Party Cookie). This cookie information may include, for example, website browsing history information, input data to the first service site (for example, the contents of the shopping cart in the e-commerce cart function), and confirmation information for logging in to the first service site (account information).

[0048] When the server device 100 relays the above display request to the first business device 300a, it may, for example, separate the information of the cookie as follows. • Website browsing history information: Secondary data (anonymous information) • Information entered into the first service site: Second data (instruction information) • Verification information required to log in to the first service site: First data (personal information)

[0049] The server device 100 may, for example, perform user authentication processing on behalf of the first service provider device 300a based on the separate verification information described above. If user authentication is successful, the server device 100 may generate authentication result information (for example, an authentication token) indicating the authentication result. This authentication token may indicate that the authenticity of the user has been confirmed by the authentication processing on the server device 100. Furthermore, after the authentication processing, the server device 100 may encrypt the account information and register it in the storage unit 130.

[0050] In response to the display request sent from the user device 200, the server device 100 separates some or all of the information from the cookie sent from the user device 200 into first data and second data, and sends only the second data (and authentication result information) to the first business device 300a.

[0051] (2) In response to the above-mentioned display request, the first service provider device 300a transmits display information, including an HTML file and images, for displaying the top page of the first service site, to the user device 200. The server device 100 receives this transmitted display information and transmits it to the user device 200. If there is no need to process the display information, the server device 100 may transmit it directly from the first service provider device 300a to the user device 200 without relaying it in this manner. The user device 200 receives the display information and displays the top screen of the first service site based on the received display information.

[0052] (3) The user device 200 transmits the information entered by the user for each input form on the displayed top screen to the first service provider device 300a as input information to the first service site. This input information includes, for example, the user's ID, name, address, a flag indicating whether or not to send direct mail, and information about the destination screen. The server device 100 receives this input information in order to separate the user data contained in this input information and pass it to the service provider device 300.

[0053] When the server device 100 relays the above input information to the first business device 300a, for example, it may separate (divide) the above input information as follows. In addition, the user's ID may be separated as second data (anonymous information) depending on the separation settings and the information held by the first business to which the information is provided. • User ID: Primary Data (Personal Information) • Name: First Data (Personal Information) • Address: Primary Data (Personal Information) • DM sending permission flag: Second data (instruction information) • Destination screen information: Second data (instruction information)

[0054] The server device 100 transmits to the first business device 300a the input information with the first data separated (deleted) in place of the input information for the display request transmitted from the user device 200.

[0055] <2-3. Data Intermediation> Figure 3 shows an example of the overall functional configuration of the data mediation system 1. As shown in Figure 3, the functions implemented by the data mediation system 1 may be classified and arranged as follows, for example. The classified functions cooperate with each other (including information sharing and / or function sharing; the same applies hereinafter). [Service provider equipment 300: Service provider] • Service delivery function: A function that enables the delivery of a service (for example, in the case of a web service, the functions provided by the web server (presentation layer) and the AP server (application layer)). • Data management function: A function for managing data necessary for providing services, such as user data (for example, a function provided by the DB server (database layer) in the case of a web service). [Server device 100: Intermediary] • Anonymous information processing function: A function that performs various processes on the anonymous information separated by the sorting function. • Separation function: A function that receives input information from the user device 200, separates it into first data and second data, and further separates the second data into instruction information and anonymous information, and provides it to the operator device 300. • User Interface Function: A function that receives input information from the user device 200 and provides output information (including display information) received from the operator device 300 to the user device 200. • Personal information processing function: A function that performs various processing on personal information separated by the sorting function.

[0056] In this example, it is assumed that the reception unit 111 of the server device 100 has previously received settings (also called "distribution settings") from the user device 200 for distributing user data to one or more service providers, including the first service provider, and that information indicating these received distribution settings (also called "distribution setting information") is registered in the storage unit 130. Furthermore, in this example, it is assumed that the user has already logged into the first service site, and that the screen displayed after logging into the first service site is shown.

[0057] In particular, the configuration may include settings for providing the user data of a user of the first service provided by the first service provider to one or more recipients, including the first service provider, by dividing the user data into first data and second data. In addition, the configuration may include settings for providing the second data by dividing it into instruction information and anonymous information.

[0058] (1) As shown in Figure 3, the user makes an operation input on the screen of the first service site displayed on the user device 200. The user device 200 transmits the input information (a form of user data) resulting from this operation input to the server device 100. The acquisition unit 112 of the server device 100 acquires this transmitted input information.

[0059] (2) The sorting unit 113 of the server device 100 sorts the input information into first data and second data based on the sorting setting information. The sorting unit 113 may further sort this sorted second data into instruction information and anonymous information (and other information).

[0060] (3) The data processing execution unit 115 of the server device 100 performs processing (also called "internal processing") on the anonymous information separated from the second data, either for each recipient or common to multiple recipients, based on the data processing settings. The registration unit 117 of the server device 100 may also register, for example, the anonymous information separated from the second data and / or information indicating the execution result of this internal processing (also called "internal execution result information") in the second storage unit 132. The provision unit 118 of the server device 100 may also provide the internal execution result information and / or the separated anonymous information to the second service provider's second service provider device 300b.

[0061] The internal processing may, for example, extract data items common to anonymous information from multiple users and calculate statistical values ​​(e.g., mean, median, or mode) of these extracted data items. Alternatively, the internal processing may, for example, extract specific data items that meet predetermined conditions from the anonymous information and analyze the relationship between these data items and other data items (e.g., calculate correlation coefficients between data items). Furthermore, the internal processing may, for example, analyze the changes in these values ​​over time.

[0062] The second operator device 300b may perform processing on the provided internal execution result information and / or anonymous information (also referred to as "external processing") and transmit this external execution result information (also referred to as "external execution result information") to the server device 100 in order to provide this external execution result information to the user device 200. The acquisition unit 112 of the server device 100 acquires this transmitted external execution result information, and the provision unit 118 of the server device 100 provides this acquired external execution result information to the user device 200. The internal execution result information and the external execution result information are collectively referred to as "execution result information".

[0063] External processing may, for example, classify users based on anonymous information using pre-configured categories or machine learning techniques (such as clustering). External processing may also generate and distribute information (also called "advertising information") that displays advertisements for products and / or services according to the results of this classification. For example, if the anonymous information indicates that the user is in their "30s," is "female," and has browsing history information that includes browsing history of websites related to mountain climbing, the second business device 300b may classify the user as a "female in her 30s who likes mountain climbing." Based on the results of this classification, the second business device 300b may send advertising information about products and services related to mountain climbing (especially products and services aimed at women) to the user device 200 of this classified user.

[0064] (4) The provision unit 118 of the server device 100 provides, for example, instruction information separated from the second data to the first service provider device 300a. The service provision function of the first service provider device 300a acquires this provided instruction information. The service provision function starts providing the first service to the user according to this instruction information. Specifically, the service provision function generates display information that displays the screen of the first service site according to the instruction information and transmits this generated display information to the server device 100. The acquisition unit 112 of the server device 100 acquires this transmitted display information. The provision unit 118 of the server device 100 transmits this acquired display information to the user device 200. The user device 200 receives this transmitted display information and displays the screen of the first service site to the user based on this display information.

[0065] (5) The encryption unit 116 of the server device 100 performs encryption processing on the personal information set aside as the first data. The registration unit 117 of the server device 100 may register this encrypted personal information in the first storage unit 131. The provision unit 118 of the server device 100 may also provide this encrypted personal information to the first service provider's first service provider device 300a.

[0066] Under the above configuration, the data intermediary system 1 can separate user data into first data containing personal information and second data not containing personal information, and provide the separated second data to the recipient without anonymizing it. Therefore, the second data, separated from the user's personal information, can be provided to the recipient without unnecessarily narrowing the scope of its use. Thus, the recipient can use the second data, which has been provided as data that does not identify individuals. In this way, when providing user data when users use the service, it is possible to protect the user's personal information while providing data that takes into account how it will be used by the recipient.

[0067] <3. Functional Configuration> Referring to Figure 4, the functional configuration of the server device 100 according to this embodiment will be described. As shown in Figure 4, the server device 100 includes a control unit 110, a communication unit 120, and a storage unit 130.

[0068] The control unit 110 includes a reception unit 111, an acquisition unit 112, a sorting unit 113, and a providing unit 118. The control unit 110 may also include, for example, a verification unit 114, a data processing execution unit 115, an encryption unit 116, and / or a registration unit 117.

[0069] [Reception Department] The reception unit 111 receives various settings and / or requests from the user device 200 and / or the service provider device 300. For example, as one form of reception, the reception unit 111 may receive a message indicating the information entered by the user when the user enters information on the screen of the data intermediary system 1 website (also called the "data intermediary site") displayed on the user device 200.

[0070] The reception unit 111 receives special settings from the user device 200 of a user of the first service provided by the first service provider, for one or more recipients, including the first service provider. The special settings may be, for example, settings to provide user data related to this user in separate first data and second data. The reception unit 111 may, for example, receive and accept information indicating the input special settings from the user device 200 when the user inputs the special settings on the screen of the data mediation site on the user device 200. Alternatively, the reception unit 111 may register this received special settings information in the storage unit 130.

[0071] The reception unit 111 may receive data processing settings for processing (internal and / or external processing) to be performed on anonymous information from, for example, the first service provider's equipment 300a, the equipment of each of the one or more recipients, or the operation manager's equipment (not shown) of the operation manager. The operation manager may be, for example, a person who operates and maintains the data mediation system 1 or the system administrator.

[0072] The reception unit 111 may, for example, receive a request from the first service provider's equipment 300a to provide user data (encrypted first data and / or second data) to a recipient different from the first service provider (e.g., a second service provider, etc.). The reception unit 111 may also receive, for example, a special setting and / or encryption setting from a user's equipment 200 of a user of the first service provided by the first service provider to provide user data (e.g., second data, etc.) concerning this user to one or more service providers, including the first service provider.

[0073] The allocation settings may, for example, specify how to allocate resources for each user and for each service. Furthermore, there may be allocation settings that are common to multiple service providers.

[0074] The allocation settings may also include, for example, settings for recipients, specifically settings for how to allocate services to each recipient. The allocation settings may also include, for example, settings for allocation to a second service provider.

[0075] The reception unit 111 may, for example, receive a decryption request from a service provider's equipment 300 to decrypt at least a portion of the encrypted first data. When a decryption request is received, possible configurations include (a) the encryption unit 116 of the server device 100 decrypting the data itself, or (b) the provision unit 118 providing decryption information to the requesting service provider's equipment 300 so that the service provider's equipment 300 can decrypt the data.

[0076] The reception unit 111 may, for example, receive a request from the first service provider's equipment 300a to provide second data to a different recipient (for example, a second service provider, etc.) from the first service provider.

[0077] [Acquisition Department] The acquisition unit 112 acquires various information and requests (e.g., authentication requests, display requests, processing requests for external processing, etc.) from the user device 200 and / or the service provider device 300. The acquisition unit 112 may, for example, receive messages indicating the input information when the user inputs various information to the first service site or data intermediary site displayed on the user device 200. As another example, the acquisition unit 112 may, for example, receive data files of various information from the user device 200 or the service provider device 300 in a cyclic or event-driven manner. As yet another example, the acquisition unit 112 may, for example, instruct an API implemented by an external system (not shown), such as a cloud file system, to reference various information and acquire various information as a result. The acquisition unit 112 may also acquire various information by, for example, having the user device 200 use a library of an SDK corresponding to the data intermediary system 1.

[0078] The acquisition unit 112 may, for example, acquire user data of the user (including user data included in various requests such as authentication requests and display requests) from the user device 200 in response to the user's operation input to the user device 200 when the user uses the first service via the user device 200.

[0079] The acquisition unit 112 may, for example, acquire permission information from the user device 200 indicating the user's permission to decrypt (unencrypt) the user data.

[0080] The acquisition unit 112 may, for example, acquire consent information from the user device 200 indicating the user's consent to provide at least one of the following to a recipient: (a) user data, (b) first data, (c) second data, or (d) anonymized information from the second data.

[0081] [Serving section] The sorting unit 113 divides the user's data into first data and second data based on the sorting settings received from the user. The sorting unit 113 may, for example, classify each data item of the user data to determine whether it belongs to the first data or the second data, and then, based on the result of this classification, divide (separate) each of the one or more data items of the user data into first data and second data.

[0082] One possible method of portioning by the portioning unit 113 is the following process. • If the user data includes both the first data and the second data: (a) to (c) below (a) Divide user data into first data and second data. (i) Delete or conceal the data items corresponding to the first data from the user data, leaving only the data items corresponding to the second data. (c) Delete the data items corresponding to the second data from the user data, leaving only the data items corresponding to the first data. • If the user data contains only the first data: Separate (identify) the entire user data as the first data. • If user data contains only secondary data: Separate (identify) the entire user data as secondary data.

[0083] The sorting unit 113 may, for example, divide the second data into instruction information and anonymous information based on the sorting settings.

[0084] The portioning unit 113 may, for example, store information indicating the history of the portioning process in the storage unit 130.

[0085] [Verification Section] The verification unit 114 verifies the legitimacy of a user (e.g., the user's authenticity and / or existence) when the user uses the first service and / or the data intermediary system 1, etc. The verification unit 114 verifies the legitimacy of the user, for example, based on verification information contained in the user data. Specifically, the verification of the legitimacy of the user may be user identity verification and / or user authentication. For example, if the verification unit 114 determines that it has been able to verify the legitimacy of the user on behalf of the first service provider, and / or if it has been specifically configured in the settings or encryption settings to provide an authentication token instead of verification information, it may generate an authentication token based on the verification information.

[0086] Verification information is information used to verify the legitimacy of the user, i.e., the user is the person they claim to be, when using the first service and / or data intermediary system 1, etc. Verification information may be, for example, authentication information, or it may indicate an authentication element (knowledge, possession, biometric). Furthermore, verification information may be a combination of multiple types of authentication elements for multi-factor authentication (for example, a combination of a credit card and a PIN code).

[0087] The verification unit 114 may, for example, verify the authenticity of the user by comparing (or in other words, matching) the information contained in the user data stored in the storage unit 130 with the verification information obtained from the user device 200.

[0088] [Data Processing Execution Unit] The data processing execution unit 115 performs processing on the anonymized information separated from the second data, either for each recipient or common to multiple recipients, based on the data processing settings.

[0089] [Encryption section] The encryption unit 116 performs encryption processing on the first data. The encryption processing by the encryption unit 116 may, for example, encrypt all or part of the first data using an encryption key. The encryption method used for this encryption may be, for example, a symmetric-key cryptography method, a public-key cryptography method, or a hybrid method.

[0090] The encryption unit 116 may, for example, encrypt the user verification information provided to the service provider's device 300 as personal information. The encryption unit 116 may, for example, separate the user identification information (ID) of the user in the first service from other personal information included in the verification information and encrypt only the other personal information.

[0091] The encryption settings may include, for example, whether or not to provide encrypted first data to each recipient. Furthermore, the encryption settings may also include, for example, the method of encryption and / or decryption conditions (e.g., the period during which decryption is permitted) for each recipient.

[0092] The encryption unit 116 may decrypt the encrypted first data based on the decryption request received by the reception unit 111.

[0093] [Registration Department] The registration unit 117 registers user data, etc., in the storage unit 130, etc. The registration unit 117 may also register encrypted first data in the first storage unit 131. In addition, the registration unit 117 may register anonymous information in the second storage unit 132. The first storage unit 131 and the second storage unit 132 have physically or logically different storage areas.

[0094] According to the above configuration, encrypted first data and anonymous information can be registered in different storage units. For this reason, for example, the level of information security for the first storage unit 131, which registers the encrypted first data, may be set relatively high and its availability lower, while the level of information security for the second storage unit 132 may be set relatively low. Furthermore, comparing registering encrypted first data and anonymous information in the same storage unit with registering them in different storage units, the former carries a higher security risk because there is a greater risk that the first data and anonymous information may be associated (combined) and decrypted. Therefore, this configuration can address the risk of the first data and anonymous information being associated in this way.

[0095] [Provider] The data provider unit 118 provides various data to the user device 200 and / or the service provider device 300, etc., particularly based on settings, etc. The manner in which the data provider unit 118 provides various data may be any manner. For example, the data provider unit 118 may send a data file or message (e.g., an HTTP request) containing the second data to these devices in an event-driven manner. Alternatively, as another example, the data provider unit 118 may provide the second data to the service provider device 300, etc., via a library of an API or SDK that it implements.

[0096] The provisioning unit 118 provides, for example, the second data separated from the user data to the provisioning device of each of the one or more recipients.

[0097] According to the above configuration, it is possible to provide a second set of data to the recipient while protecting the user's personal information, without uniformly anonymizing the user data. Therefore, by providing the second set of data, separated from the user's personal information, the scope of utilization of the user data can be further narrowed without being excessively restricted. Thus, when providing user data when users use the service, it is possible to provide data that takes into account how it will be used by the recipient while protecting the user's personal information.

[0098] The supply unit 118 may, for example, provide instruction information separated from the second data to the first business operator's device 300a.

[0099] Instructions from users regarding the first service site, etc., must be delivered to the first service provider's device 300a in order to appropriately utilize the first service in accordance with the user's requests. With this configuration, it is possible to deliver necessary information to the first service provider while protecting the user's personal information, so as not to disrupt the use of the first service.

[0100] The provisioning unit 118 may, for example, provide the recipient device with execution result information showing the execution result of processing (internal processing) by the data processing execution unit 115. With this configuration, only the results of processing on anonymous information can be provided to the first service provider's first service provider device 300a without providing the anonymous information itself. Therefore, the information security of the user's anonymous information can be ensured.

[0101] The providing unit 118 may, for example, provide the service provider's device 300 with decryption information to unencrypt the encrypted user data based on the decryption request and / or permission information. The providing unit 118 may, for example, provide the service provider's device 300 with a symmetric key to be paired as decryption information for user data encrypted using a symmetric key encryption scheme. The decryption information may also have an expiration date set, for example. If the expiration date of the decryption information has passed, the service provider's device 300 may be prevented from using this decryption information for decryption.

[0102] With the above configuration, the service provider's device 300 can also decrypt and use user data retrospectively with the user's permission. Therefore, the decrypted user data can be used at the recipient simply by providing decryption information, without having to provide (transmit) the decrypted user data to the service provider's device 300 again. This ensures security while enhancing convenience.

[0103] The provisioning unit 118 may, for example, provide anonymized information separated from user data to a recipient device (e.g., a second service provider device 300b) of a different recipient (e.g., a second service provider) based on the provision request and consent information from the first service provider received by the receiving unit 111. The provisioning unit 118 may also, for example, provide encrypted first data and / or separated second data based on the provision request and consent information.

[0104] According to the above configuration, the server device 100 can provide confidential user data to different recipients, such as the second service provider, in response to a request from the first service provider. Therefore, the first service provider can allow these recipients to acquire and utilize the confidential user data without having to provide the user data to them themselves.

[0105] [g section] The communication unit 120 transmits and receives various data via the network N to and from the user device 200, the operator device 300, or other external system devices.

[0106] [Storage] The storage unit 130 stores configuration information related to users or user data (for example, configuration information, information indicating data processing settings, information indicating encryption settings, etc.). The storage unit 130 may store each data using a database management system (DBMS) or using a file system. If a DBMS is used, a table may be created for each data, and each data may be managed by associating these tables.

[0107] The storage unit 130 may include, for example, a first storage unit 131 and / or a second storage unit 132. The first storage unit 131 may store encrypted first data. The second storage unit 132 may store, for example, anonymous information and / or execution result information.

[0108] The first storage unit 131 and the second storage unit 132 may have different security levels set for them. Specifically, if the security levels are set to three stages: "high," "medium," and "low," and the scope of access rights granted and the level of access rights differ depending on the stage, the first storage unit 131 may be set to a security level of "high," while the second storage unit 132 may be set to a security level of "medium." When the security level is set to "high," for example, data registered in the first storage unit 131 may be accessible only to a limited number of users, such as system administrators, and only read and update operations among CRUD (Create, Read, Update, Delete) may be permitted. On the other hand, when the security level is set to "medium," for example, data registered in the first storage unit 131 may be accessible to specific users, including users other than system administrators, and all CRUD operations except deletion may be permitted.

[0109] <4. Example of operation> Refer to Figure 5 to explain an example of the operation of the data intermediary system 1. Figure 5(a) is a flowchart showing an example of the flow of the configuration process in the data intermediary system 1. Figure 5(b) is a flowchart showing an example of the flow of the user data provision process in the data intermediary system 1. Note that the order of the processes shown below is just an example and may be changed as appropriate.

[0110] As shown in Figure 5(a), the reception unit 111 of the server device 100 receives a setting from the user device 200 of the user of the first service to provide user data to one or more recipients, including the first service provider, in the form of first data and second data (S10). The registration unit 117 of the server device 100 registers the setting information indicating the setting in the storage unit 130, associating it with the user's account information (S11).

[0111] As shown in Figure 5(b), when a user uses the first service via the user device 200, the acquisition unit 112 of the server device 100 acquires user data from the user device 200 in response to the user's operation input to the user device 200 (S20). The sorting unit 113 of the server device 100 separates the acquired user data into first data and second data based on the sorting settings described above (S21). The provision unit 118 of the server device 100 provides the second data separated from the user data to the provisioning devices of one or more recipients (S22).

[0112] <5. Hardware Configuration> Referring to Figure 6, an example of a hardware configuration when the server device 100 and / or user device 200 described above are implemented using a computer 800 will be explained. Note that the functions of each device can also be implemented by dividing them among multiple devices.

[0113] As shown in Figure 6, the computer 800 includes a processor 801, a memory 803, a storage device 805, an input I / F unit 807, a data I / F unit 809, a communication I / F unit 811, and a display device 813.

[0114] The processor 801 controls various processes in the computer 800 by executing programs (for example, server programs or user programs) stored in memory 803. For example, the various functional units of the control unit 110 of the server device 100 and / or the control unit of the user device 200 can be realized by the processor 801 executing programs temporarily stored in memory 803.

[0115] Memory 803 is a storage medium such as RAM (Random Access Memory). Memory 803 temporarily stores the program code of the program executed by the processor 801, as well as data required during program execution.

[0116] The storage device 805 is a non-volatile storage medium such as a hard disk drive (HDD) or flash memory. The storage device 805 stores the operating system and various programs necessary to implement the above configurations. In addition, the storage device 805 can also store tables for registering various data such as user data and configuration information, and a database for managing those tables. Such programs and data are loaded into memory 803 as needed and accessed by the processor 801.

[0117] The input interface unit 807 is a device for receiving input from the user. Specific examples of the input interface unit 807 include keyboards, mice, touch panels, various sensors, and wearable devices. The input interface unit 807 may be connected to the computer 800 via an interface such as USB (Universal Serial Bus).

[0118] The data interface unit 809 is a device for inputting data from outside the computer 800. Specific examples of the data interface unit 809 include drive devices for reading data stored on various storage media. The data interface unit 809 may also be located outside the computer 800. In that case, the data interface unit 809 would be connected to the computer 800 via an interface such as USB.

[0119] The communication interface unit 811 is a device for performing data communication with external devices of the computer 800 via a network N, either wired or wirelessly. The communication interface unit 811 may also be located outside the computer 800. In that case, the communication interface unit 811 is connected to the computer 800 via an interface such as USB.

[0120] The display device 813 is a device for displaying various types of information. Specific examples of the display device 813 include liquid crystal displays, organic EL (Electro-Luminescence) displays, and displays for wearable devices. The display device 813 may be located outside the computer 800. In that case, the display device 813 is connected to the computer 800, for example, via a display cable. Furthermore, if a touch panel is used as the input I / F unit 807, the display device 813 can be integrated with the input I / F unit 807.

[0121] This embodiment is illustrative for explaining the present invention and is not intended to limit the invention to this embodiment alone. Furthermore, the present invention can be modified in various ways without departing from its essence. Moreover, those skilled in the art can adopt embodiments in which each of the elements described below is replaced with equivalent ones, and such embodiments are also included within the scope of the present invention.

[0122] [Differentiation] Although the present invention has been described based on the above embodiments, the following cases are also included in the present invention.

[0123] [Example 1] At least some of the components of the server device 100 according to the above embodiment may be provided by the user device 200 and / or the operator device 300. For example, the operator device 300 may implement all or part of the functions of the verification unit 114 of the server device 100.

[0124] [Differentiation 2] In the above embodiment, an example was described in which the storage unit 130 of the server device 100 includes a first storage unit for registering encrypted personal information and a second storage unit for registering anonymous information. However, at least one of these storage units may be provided by a storage unit of an external system device (for example, a file system). [Explanation of Symbols]

[0125] 1...Data intermediary system, 100...Server device, 110...Control unit, 111...Reception unit, 112...Acquisition unit, 113...Distribution unit, 114...Verification unit, 115...Data processing execution unit, 116...Encryption unit, 117...Registration unit, 118...Provision unit, 120...Communication unit, 130...Storage unit, 200...User device, 300...Business operator device, 800...Computer, 801...Processor, 803...Memory, 805...Storage device, 807...Input I / F unit, 809...Data I / F unit, 811...Communication I / F unit, 813...Display device.

Claims

1. On the computer, A receiving function that receives a setting for separating user data from a user's device of a user of a first service provided by a first service provider, to provide the user data to one or more recipients, including the first service provider, into first data including the user's personal information and second data not including the personal information. When the user uses the first service via the user device, the acquisition function acquires user data from the user device in response to the user's operation input to the user device, A sorting function that divides the user data into first data and second data based on the sorting settings, An encryption function that performs encryption processing on the first data, A registration function that registers the encrypted first data in the first storage unit and anonymous information that does not correspond to the user's personal information contained in the second data in the second storage unit, A data processing execution function that performs processing on the anonymous information registered in the second storage unit, The system provides a provisioning function that, while holding the encrypted first data in the first storage unit, provides execution result information indicating the result of the processing performed by the data processing execution function to the provisioning device of each of the one or more provisioning devices. program.

2. On the computer, A receiving function that receives a setting for separating user data from a user's device of a user of a first service provided by a first service provider, to provide the user data to one or more recipients, including the first service provider, into first data including the user's personal information and second data not including the personal information. When the user uses the first service via the user device, the acquisition function acquires user data from the user device in response to the user's operation input to the user device, A sorting function that divides the user data into first data and second data based on the sorting settings, The system provides a provisioning function that provides the second data, separated from the user data, to the recipient device of each of the one or more recipients. The second data includes instruction information indicating the user's instructions to the first service provider's equipment of the first service based on the operation input, and anonymous information other than the instruction information. The aforementioned setting includes a setting for providing the second data separately into the instruction information and the anonymous information, The sorting function, based on the sorting settings, sorts the second data into the instruction information and the anonymous information. The aforementioned provision function provides the instruction information separated from the second data to the first operator device. program.

3. The second data includes instruction information indicating the user's instructions to the first service provider's equipment of the first service based on the operation input, and anonymous information other than the instruction information. The aforementioned setting includes a setting for providing the second data separately into the instruction information and the anonymous information, The reception function receives data processing settings for the process to be executed on the anonymous information from each of the one or more recipient devices or the operation manager device of the operation manager. The sorting function, based on the sorting settings, sorts the second data into the instruction information and the anonymous information. The computer is further provided with a data processing execution function that performs processing on the anonymized information separated from the second data, either for each recipient or common to multiple recipients, based on the data processing settings. The aforementioned provisioning function provides the recipient device with execution result information indicating the result of the processing. The program according to claim 1 or 2.

4. The aforementioned second data includes anonymous information that does not constitute the user's personal information. The reception function receives a request from the first service provider's equipment for the provision of user data to a recipient other than the first service provider, The acquisition function acquires consent information from the user device indicating the user's consent to the provision of the anonymous information to the recipient. The provision function provides the anonymous information separated from the user data to the recipient's device based on the provision request and the consent information. The program according to claim 2.

5. A receiving unit that receives a setting for separating user data from a user's device of a user of a first service provided by a first service provider, to provide the user data to one or more recipients, including the first service provider, into first data including the user's personal information and second data not including the personal information, When the user uses the first service via the user device, an acquisition unit acquires user data from the user device in response to the user's operation input to the user device, A sorting unit that sorts the user data into first data and second data based on the sorting settings, An encryption unit that performs encryption processing on the first data, A registration unit registers the encrypted first data in the first storage unit and anonymous information that does not correspond to the user's personal information contained in the second data in the second storage unit. A data processing execution unit that performs processing on the anonymous information registered in the second storage unit, The system includes a providing unit that, while holding the encrypted first data in the first storage unit, provides execution result information indicating the result of the processing performed by the data processing execution unit to each of the one or more providing devices of the providing devices. Information processing device.

6. Computers The first service provider receives a setting from the user's device of a user of the first service provided by the first service provider to provide user data to one or more recipients, including the first service provider, by separating the user data into first data including the user's personal information and second data not including the personal information. When the user uses the first service via the user device, the user data is acquired from the user device in response to the user's operation input to the user device. Based on the above sorting settings, the user data is sorted into the first data and the second data. The first data is subjected to encryption processing, The encrypted first data is registered in the first storage unit, and the anonymous information that does not correspond to the user's personal information included in the second data is registered in the second storage unit. The second memory unit performs processing on the anonymous information registered therein. While the encrypted first data is held in the first storage unit, execution result information indicating the result of the processing is provided to each of the one or more recipient devices. Information processing methods.

7. A receiving unit that receives a setting for separating user data relating to a user into first data including the user's personal information and second data not including the personal information, from the user's device of a user of a first service provided by a first service provider to one or more recipients including the first service provider, When the user uses the first service via the user device, an acquisition unit acquires user data from the user device in response to the user's operation input to the user device, A sorting unit that sorts the user data into first data and second data based on the sorting settings, The system includes a provisioning unit that provides the second data separated from the user data to the provisioning device of each of the one or more recipients, The second data includes instruction information indicating the user's instructions to the first service provider's equipment of the first service based on the operation input, and anonymous information other than the instruction information. The aforementioned setting includes a setting for providing the second data separately into the instruction information and the anonymous information, The sorting unit, based on the sorting settings, divides the second data into the instruction information and the anonymous information. The providing unit provides the instruction information separated from the second data to the first business operator device. Information processing device.

8. A computer, The system accepts a setting from the user's device of a user of the first service provided by the first service provider to provide user data to one or more recipients, including the first service provider, by separating the user data into first data including the user's personal information and second data not including the personal information. When the user uses the first service via the user device, the user data is acquired from the user device in response to the user's operation input to the user device. Based on the above sorting settings, the user data is sorted into the first data and the second data, The second data separated from the user data is provided to the recipient device of each of the one or more recipients, and the following is performed: The second data includes instruction information indicating the user's instructions to the first service provider's equipment of the first service based on the operation input, and anonymous information other than the instruction information. The aforementioned setting includes a setting for providing the second data separately into the instruction information and the anonymous information, The above separation includes separating the second data into the instruction information and the anonymous information based on the separation setting, The provision described above includes providing the instruction information separated from the second data to the first operator's device. Information processing methods.

Citation Information

Patent Citations

  • Coordination server program, business operator server program, and data coordinated system

    JP2021117679A

  • Method and system for implementing privacy notice, consent, and preference with a privacy proxy

    US20060095956A1

  • Data sanitization system for public host platform

    US20190190890A1