Information management system, information management method, and information management program
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2026-01-06
- Publication Date
- 2026-04-07
AI Technical Summary
Current decentralized identifier (DID) and verifiable certificate mechanisms, such as those using blockchain, fail to effectively control the disclosure of personal information as they are not fully decentralized, allowing unauthorized access and lack user control over who can view their information.
An information management system that receives personal information from users, registers it in an external distributed file system, and allows users to designate and control disclosure permissions, ensuring that only authorized parties can access specific information, without relying on a centralized ID issuer.
Enables users to manage and control the disclosure of their personal information on a distributed system, ensuring privacy by allowing selective sharing and maintaining user autonomy over their data.
Abstract
Description
Information management system, information management method, and information management program
[0001] The present disclosure relates to an information management system, an information management method, and an information management program.
[0002] Web 3 (Web 3.0) has been proposed as an advanced next-generation Internet system. One of the features of Web 3 is that it allows users to manage their own personal information. On the current Internet, a few large corporations are monopolizing the collection of not only basic personal information such as address and age, but also all kinds of information such as personal preferences and behavioral history, which can be problematic from the perspective of privacy.
[0003] Currently, a decentralized identifier (DID) is being developed as a mechanism that allows users to manage their own personal information. A decentralized identifier is an ID that individuals can own and manage themselves in a distributed system, without relying on a centralized ID issuer.
[0004] Verifiable credentials (VCs) are information that can be assigned to individuals and that individuals can own and manage on their own in a distributed system without relying on a centralized ID issuer. Examples of verifiable credentials include employee ID cards, membership cards, graduation certificates, admission passes, and tickets issued on a blockchain.
[0005] Japanese Patent Publication No. 2003-271782 Japanese Patent Publication No. 2023-43870
[0006] However, the decentralized identifiers and verifiable certificates mentioned above are not sufficient mechanisms for allowing users to manage their personal information themselves. Since verifiable certificates are issued on the blockchain, they can be viewed by anyone. This makes it difficult for users to restrict who can disclose each piece of information.
[0007] For example, Patent Documents 1 and 2 disclose technologies for allowing a user to restrict who can disclose each piece of information. However, the technology described in Patent Document 1 is a technology that relies on a centralized ID issuer. Meanwhile, the technology described in Patent Document 2 uses a network that employs centralized distributed ledger technology.
[0008] The present disclosure has been made in consideration of the above problems, and one exemplary purpose thereof is to provide a technology for controlling the disclosure of personal information in a distributed system without relying on a centralized ID issuer.
[0009] An information management system according to an exemplary aspect of the present disclosure comprises a personal information accepting means for accepting personal information of a user, a registration means for registering the personal information in an external distributed file system, disclosure destination designation information for designating a destination to which the personal information will be disclosed from the user, and a disclosure permission accepting means for accepting permission to disclose at least a portion of the personal information to the destination designated by the disclosure destination designation information, an acquisition means for acquiring at least a portion of the personal information from the external distributed file system, and a disclosure means for disclosing at least a portion of the personal information to the destination designated by the disclosure destination designation information.
[0010] An information management method according to an exemplary aspect of the present disclosure is an information management method executed by an information management system, and includes a personal information acceptance process that accepts personal information of a user, a registration process that registers the personal information in an external distributed file system, disclosure destination designation information that designates a disclosure destination of the personal information from the user, and a disclosure permission acceptance process that accepts permission to disclose at least a portion of the personal information to the disclosure destination designated by the disclosure destination designation information, an acquisition process that acquires at least a portion of the personal information from the external distributed file system, and a disclosure process that discloses at least a portion of the personal information to the disclosure destination designated by the disclosure destination designation information.
[0011] An information management program relating to an exemplary aspect of the present disclosure causes one or more computers provided in an information management system to execute a personal information acceptance process that accepts a user's personal information, a registration process that registers the personal information in an external distributed file system, disclosure destination designation information that designates a disclosure destination of the personal information from the user and permission to disclose at least a portion of the personal information to the disclosure destination designated by the disclosure destination designation information, an acquisition process that acquires at least a portion of the personal information from the external distributed file system, and a disclosure process that discloses at least a portion of the personal information to the disclosure destination designated by the disclosure destination designation information.
[0012] According to one exemplary aspect of the present disclosure, an exemplary effect is provided in that a technology can be provided that allows individuals to control the disclosure of personal information on a distributed system without relying on a centralized ID issuer.
[0013] FIG. 1 is a block diagram showing an example of a configuration of an information management system according to the present disclosure. FIG. 2 is a flow diagram showing an example of the flow of an information management method according to the present disclosure. FIG. 3 is a block diagram showing an example of the configuration of an information management system and related devices according to the present disclosure. FIG. 4 is a sequence diagram showing an example of the flow of an information management method according to the present disclosure. FIG. 5 is a diagram showing an example of personal information according to the present disclosure. FIG. 6 is a diagram showing an example of personal information registration information according to the present disclosure. FIG. 7 is a diagram showing an example of disclosure destination related information according to the present disclosure. FIG. 8 is a diagram showing an example of disclosure destination designation information according to the present disclosure. FIG. 9 is a diagram showing an example of a screen for selecting disclosure permission according to the present disclosure. FIG. 10 is a diagram showing an example of disclosure history information according to the present disclosure. FIG. 11 is a block diagram showing the configuration of a computer constituting an information management system according to the present disclosure.
[0014] The following are examples of embodiments of the present invention. However, the present invention is not limited to the exemplary embodiments shown below, and various modifications are possible within the scope of the claims. For example, embodiments obtained by appropriately combining the technical means employed in the exemplary embodiments shown below may also be included in the scope of the present invention. Furthermore, embodiments obtained by appropriately omitting some of the technical means employed in the exemplary embodiments shown below may also be included in the scope of the present invention. Furthermore, the effects mentioned in the exemplary embodiments shown below are examples of effects expected in the exemplary embodiments, and do not define the scope of the present invention. In other words, embodiments that do not exhibit the effects mentioned in the exemplary embodiments shown below may also be included in the scope of the present invention.
[0015] [First Exemplary Embodiment] A first exemplary embodiment, which is an example of an embodiment of the present invention, will be described in detail with reference to the drawings. This exemplary embodiment is a basic form for each of the exemplary embodiments described below. Note that the scope of application of each technical means employed in this exemplary embodiment is not limited to this exemplary embodiment. That is, each technical means employed in this exemplary embodiment can also be employed in other exemplary embodiments included in the present disclosure, to the extent that no particular technical obstacles arise. Furthermore, each technical means shown in the drawings referenced to explain this exemplary embodiment can also be employed in other exemplary embodiments included in the present disclosure, to the extent that no particular technical obstacles arise.
[0016] (Configuration of Information Management System) The configuration of the information management system 1 will be described with reference to Fig. 1. Fig. 1 is a block diagram showing an example of the configuration of the information management system 1. As shown in Fig. 1, the information management system 1 includes a personal information accepting unit (personal information accepting means) 10, a registration unit (registration means) 11, a disclosure permission accepting unit (disclosure permission accepting means) 12, an acquisition unit (acquisition means) 13, and a disclosure unit (disclosure means) 14.
[0017] The information management system 1 may be configured by, for example, one or more computers. The information management system 1 may also include at least one processor.
[0018] The personal information receiving unit 10 receives personal information of a user.
[0019] In this specification, personal information refers to information about an individual, including information that indicates an individual's characteristics (such as name, address, age, preferences, and health care information) and information that indicates an individual's behavior (such as behavioral history in real life or online).
[0020] For example, the personal information accepting unit 10 may receive an identifier that identifies a user and personal information of the user from a terminal used by the user via an arbitrary network. Alternatively, the personal information accepting unit 10 may receive an identifier that identifies a user and personal information of the user from a device other than the terminal used by the user via an arbitrary network.
[0021] The registration unit 11 registers the personal information received by the personal information receiving unit 10 in an external distributed file system.
[0022] In this specification, an external distributed file system refers to a decentralized file system, such as IPFS (Inter Planetary File System).
[0023] Registering personal information in an external distributed file system means making the personal information available for retrieval from the external distributed file system, and the registration unit 11 may register personal information in an external distributed file system, for example, by sending the personal information to the external distributed file system via any network.
[0024] The disclosure permission receiving unit 12 receives (i) disclosure destination designation information from the user that designates a destination to which personal information will be disclosed, and (ii) permission to disclose at least a portion of the personal information to the destination designated by the disclosure destination designation information. Note that the "at least a portion of the personal information" may also be referred to as the subject of the disclosure permission.
[0025] The disclosure destination is not particularly limited, and may be, for example, a company or an organization. The disclosure destination designation information may be any information that can designate a disclosure destination, and may be, for example, a code (symbol) that designates a disclosure destination.
[0026] The disclosure permission receiving unit 12 may receive the disclosure destination designation information and the disclosure permission separately or together. When the disclosure destination designation information and the disclosure permission are received separately, the order in which they are received is not particularly limited.
[0027] The acquisition unit 13 acquires at least a portion of the personal information that is the subject of the disclosure permission accepted by the disclosure permission acceptance unit 12 from the external distributed file system in which the registration unit 11 has registered the personal information.
[0028] The disclosure unit 14 discloses at least a part of the personal information acquired by the acquisition unit 13 to a recipient designated by the recipient designation information.
[0029] The disclosure method is not particularly limited, and the disclosure can be performed in any method. For example, the disclosure unit 14 may transmit at least a part of the personal information acquired by the acquisition unit 13 to the disclosure destination via any network.
[0030] (Effects of the Information Management System) As described above, the information management system 1 employs a configuration in which a user's personal information is registered in an external distributed file system, and the personal information is retrieved from the external distributed file system and disclosed to a disclosure destination in accordance with disclosure permission received from the user. Therefore, the information management system 1 has the effect of enabling individuals to control the disclosure of their personal information on a distributed system without relying on a centralized ID issuer.
[0031] (Flow of Information Management Method) The flow of information management method S1 will be described with reference to Fig. 2. Fig. 2 is a flow diagram showing an example of the flow of information management method S1. As shown in Fig. 2, information management method S1 includes personal information reception processing S10, registration processing S11, disclosure permission reception processing S12, acquisition processing S13, and disclosure processing S14.
[0032] The information management method S1 is executed by the information management system 1.
[0033] In the personal information receiving process (S10), the information management system 1 receives the personal information of the user.
[0034] In the registration process (S11), the information management system 1 registers the personal information received in the personal information receiving process in an external distributed file system.
[0035] In the disclosure permission acceptance process (S12), the information management system 1 accepts (i) disclosure destination designation information from the user that specifies the recipient of personal information to be disclosed, and (ii) permission to disclose at least some of the personal information to the recipient specified by the disclosure destination designation information.
[0036] In the acquisition process (S13), the information management system 1 acquires at least a portion of the personal information that is the subject of the disclosure permission accepted in the disclosure permission acceptance process from the external distributed file system in which the personal information was registered in the registration process.
[0037] In the disclosure process (S14), the information management system 1 discloses at least a part of the personal information acquired in the acquisition process to the recipient designated by the recipient designation information.
[0038] (Effects of the Information Management Method) As described above, the information management method S1 employs a configuration in which a user's personal information is registered in an external distributed file system, and the personal information is retrieved from the external distributed file system and disclosed to a disclosure destination in accordance with disclosure permission received from the user. Therefore, the information management method S1 has the effect of enabling individuals to control the disclosure of their personal information on a distributed system without relying on a centralized ID issuer.
[0039] Second Exemplary Embodiment A second exemplary embodiment, which is an example of an embodiment of the present invention, will be described in detail with reference to the drawings. Components having the same functions as those described in the above exemplary embodiment will be denoted by the same reference numerals, and their description will be omitted as appropriate. The scope of application of each technical means employed in this exemplary embodiment is not limited to this exemplary embodiment. That is, each technical means employed in this exemplary embodiment can also be employed in other exemplary embodiments included in the present disclosure, to the extent that no particular technical hindrance occurs. Furthermore, each technical means shown in each drawing referenced to describe this exemplary embodiment can also be employed in other exemplary embodiments included in the present disclosure, to the extent that no particular technical hindrance occurs.
[0040] (Configuration of Information Management System) The configuration of the information management system 1A will be described with reference to Fig. 3. Fig. 3 is a block diagram showing an example of the configuration of the information management system 1A and related devices. In addition to the personal information accepting unit (personal information accepting means) 10, registration unit (registration means) 11, disclosure permission accepting unit (disclosure permission accepting means) 12, acquisition unit (acquisition means) 13, and disclosure unit (disclosure means) 14 provided in the information management system 1, the information management system 1A includes a disclosure destination related information accepting unit (disclosure destination related information accepting means) 15, a disclosure destination related information presenting unit (disclosure destination related information presenting means) 16, a disclosure history presenting unit (disclosure history presenting means) 17, a personal information registration information storage unit 18, a disclosure destination related information storage unit 19, and a disclosure history information storage unit 20.
[0041] The information management system 1A is also connected to a user terminal 2, a disclosure destination server 3, and a distributed file system 4 via a network NW. The user terminal 2 is a terminal used by a user. The disclosure destination server 3 is a server used by a company or organization that is a candidate for disclosure of personal information. The distributed file system 4 is a distributed file system external to the information management system 1A, such as IPFS.
[0042] (Flow of Information Management Method) FIG. 4 is a sequence diagram showing an example of the flow of an information management method.
[0043] At any timing, a personal information acceptance process (S10) is executed. In the personal information acceptance process, the personal information acceptance unit 10 of the information management system 1A accepts personal information P of the user from the user via the user terminal 2. The personal information P may include one or more items, for example, as shown in FIG. 5 .
[0044] In one embodiment, the personal information accepting unit 10 may identify the user by a decentralized identifier.
[0045] In this specification, a decentralized identifier (DID) is an identifier that can be used without relying on a centralized ID issuer. In one aspect, the decentralized identifier is an identifier registered on a blockchain (distributed ledger), and may be, for example, a public key of a cryptocurrency wallet.
[0046] Furthermore, in one embodiment, the personal information accepting unit 10 may identify a user by a decentralized identifier and a non-fungible token (NFT).
[0047] A non-fungible token is, for example, a non-fungible token that is registered on the same blockchain (distributed ledger) as a decentralized identifier and can be used to identify a user in combination with the decentralized identifier.
[0048] Additionally, in one aspect, non-fungible tokens may be used to indicate that a user has access to the information management system 1A.
[0049] In this case, the personal information accepting unit 10 may be configured to determine whether a specific non-fungible token is associated with the decentralized identifier in the personal information accepting process (S10), and not accept personal information P from the user if a specific non-fungible token is not associated with the decentralized identifier.
[0050] In the following embodiment, a configuration in which a user is identified by a decentralized identifier will be described as an example, but the identifier for identifying a user in this specification is not limited to a decentralized identifier.
[0051] Next, in a registration process (S11), the registration unit 11 of the information management system 1A registers the personal information P received in the personal information receiving process in the distributed file system 4.
[0052] In one aspect, the registration unit 11 may convert the personal information P into a format suitable for registration before registering it in the distributed file system 4. For example, the format of the personal information P to be registered in the distributed file system 4 may be a format such as encrypted JSON. Furthermore, the registration unit 11 may ensure security by dividing the personal information P into small files.
[0053] In one aspect, if the distributed file system 4 manages registered information using hash values and the information can be obtained using the hash values, the registration unit 11 may conceal the hash values so that they are not known to third parties.
[0054] In one aspect, if the personal information P accepted in the personal information acceptance process has already been registered in the distributed file system 4 , the registration unit 11 may update the personal information registered in the distributed file system 4 .
[0055] In one aspect, the registration unit 11 may obtain registration information (for example, the above-mentioned hash value) for obtaining or updating the personal information P from the distributed file system 4. Then, the registration unit 11 may record information indicating the user (decentralized identifier), information indicating the distributed file system 4 as the registration destination, and personal information registration information S including the registration information in association with the decentralized identifier in the personal information registration information storage unit 18, as shown in FIG.
[0056] Here, the registration unit 11 uses the personal information P only to register it in the distributed file system 4, and does not store it in the information management system 1A. In other words, after the registration unit 11 registers the personal information P in the distributed file system 4, or in parallel with the registration, the personal information P is deleted from the information management system 1A.
[0057] Furthermore, a disclosure destination related information receiving process (S20) is executed at an arbitrary timing. The disclosure destination related information receiving process may be executed before the personal information receiving process S10.
[0058] In the disclosure destination related information reception process, the disclosure destination related information reception unit 15 of the information management system 1A receives disclosure destination related information R related to the candidate disclosure destination from the disclosure destination server 3 of the candidate disclosure destination. The disclosure destination related information reception unit 15 stores the disclosure destination related information R in the disclosure destination related information storage unit 19.
[0059] The disclosure destination related information R includes, for example, as shown in Figure 7, the name of the candidate disclosure destination, the code of the candidate disclosure destination (disclosure destination designation information), the URL of the candidate disclosure destination, and information indicating the disclosure method for disclosing personal information to the candidate disclosure destination.
[0060] In other words, the disclosure method is an interface used to disclose personal information, and may include, for example, a protocol or ID for transmitting information.
[0061] This completes preparation for disclosure of personal information P by information management system 1A. Next, we will explain the case where disclosure destination server 3 sends a disclosure request for personal information P to the user by email, QR code, etc. (S100). The disclosure request includes disclosure destination designation information D that designates the disclosure destination, and the user accesses information management system 1A via user terminal 2 and transmits disclosure destination designation information D.
[0062] At any timing, a first disclosure permission acceptance process is executed. In the first disclosure permission acceptance process, the disclosure permission acceptance unit 12 of the information management system 1A accepts disclosure destination designation information D that designates a disclosure destination of personal information from a user identified by a decentralized identifier via the user terminal 2. The disclosure destination designation information D may be any information that designates a disclosure destination, as shown in Fig. 8, and may be, for example, a code of the disclosure destination indicated by the disclosure destination related information R.
[0063] Also, in the first disclosure permission acceptance process (S21), similar to the personal information acceptance process (S10), in one embodiment, the personal information acceptance unit 10 determines whether a specific non-fungible token (NFT, Non-Fungible Token) is associated with the decentralized identifier, and if a specific non-fungible token is not associated with the decentralized identifier, the disclosure destination designation information D may not be accepted from the user.
[0064] Next, the disclosure destination related information presentation unit 16 may present at least a portion of the disclosure destination related information R regarding the disclosure destination specified by the disclosure destination designated information D to the user who accepted the disclosure destination designated information D in the disclosure permission acceptance process in the disclosure destination related information presentation process (S22).
[0065] For example, in one aspect, the disclosure destination related information presentation unit 16 may present to the user names, URLs, etc. of candidate disclosure destinations by referring to the disclosure destination related information R stored in the disclosure destination related information storage unit 19. On the other hand, the disclosure destination related information presentation unit 16 does not need to present to the user information indicating the disclosure method.
[0066] Furthermore, in the second disclosure permission acceptance process (S23), the disclosure permission acceptance unit 12 accepts permission to disclose at least a portion of the personal information to the disclosure recipient designated by the disclosure recipient designation information D. At this time, the disclosure permission acceptance unit 12 may accept a selection of which items of the multiple items included in the personal information P are to be disclosed to the disclosure recipient.
[0067] 9 is a screen that the disclosure destination-related information presenting unit 16 and the disclosure permission accepting unit 12 display on the user terminal 2 in the disclosure destination-related information presenting process and the second disclosure permission accepting process. As shown in Fig. 9, the name and URL of the disclosure destination are displayed on the screen Q. Furthermore, the screen Q may display each item of personal information P and accept a selection of whether to permit or not permit disclosure for each item.
[0068] Note that FIG. 9 is merely an example, and the screen displayed on the user terminal 2 is not particularly limited.
[0069] Next, in an acquisition process (S13), the acquisition unit 13 of the information management system 1A acquires at least a portion of the personal information P that is the subject of the disclosure permission accepted in the second disclosure permission acceptance process from the distributed file system 4 that registered the personal information P in the registration process. The acquisition unit 13 acquires at least a portion of the personal information P that is the subject of the disclosure permission from the distributed file system 4, for example, by referring to the registration information indicated by the personal information registration information S that is stored in association with the decentralized identifier in the personal information registration information storage unit 18.
[0070] Next, in a disclosure process (S14), the disclosure unit 14 of the information management system 1A discloses at least a portion of the personal information P acquired in the acquisition process to a disclosure destination designated by the disclosure destination designation information D. In one aspect, the disclosure unit 14 may disclose at least a portion of the personal information P to the disclosure destination in a manner designated by the disclosure destination related information D related to the disclosure destination.
[0071] Here, the disclosure unit 14 uses the personal information P only to disclose it to the recipient and does not store it in the information management system. In other words, after or at the same time that the disclosure unit 14 discloses the personal information P to the recipient, the personal information P is deleted from the information management system 1A.
[0072] Then, the disclosure unit 14 associates the disclosure history information L indicating the history of the disclosures that have been performed with the decentralized identifier and records it in the disclosure history information storage unit 20. The disclosure history information L may include, for example, the date and time, the disclosure destination, the content of the disclosed personal information P, and the like for each disclosure, as shown in FIG.
[0073] Then, at any timing, a disclosure history presentation process (S24) is executed. In the disclosure history presentation process, the disclosure history presentation unit 17 of the information management system 1A may present, to a user identified by the decentralized identifier, a history of disclosure based on the disclosure permission received from the user.
[0074] In one aspect, the disclosure history presentation process may be started by a user requesting the disclosure history presentation process from the information management system 1A via the user terminal 2. In response to a request from a user identified by a decentralized identifier, the disclosure history presentation unit 17 may transmit to the user terminal 2 the disclosure history information L corresponding to the user that is stored in the disclosure history information storage unit 20.
[0075] (Effects of the Information Management System) As described above, the information management system 1A employs a configuration in which, after or in parallel with the registration unit 11 registering personal information P in the distributed file system 4, the personal information P is deleted from the information management system 1A, and after or in parallel with the disclosure unit 14 disclosing at least a portion of the personal information P to be disclosed, the at least a portion of the personal information P is deleted from the information management system 1A. Therefore, according to the information management system 1A, in addition to the effects achieved by the information management system 1, the effect is obtained in that personal information is not stored in the information management system 1A either, and individuals can more easily control the disclosure of their personal information on the distributed system.
[0076] The information management system 1A is further configured to include a disclosure destination related information receiving unit 15 that receives, from the candidate disclosure destinations, disclosure destination related information R related to the candidate disclosure destinations, and a disclosure destination related information presentation unit 16 that presents, to a user who has received the disclosure destination designation information D from the disclosure permission receiving unit 12, at least a portion of the disclosure destination related information R related to the disclosure destination designated by the disclosure destination designation information D. Therefore, in addition to the effects achieved by the information management system 1, the information management system 1A can present to the user the disclosure destination related information received from the candidate disclosure destinations, and the user can confirm the disclosure destination related information and select personal information to be disclosed to the disclosure destinations.
[0077] Furthermore, in the information management system 1A, the disclosure destination-related information R related to candidate disclosure destinations includes information specifying the method of disclosure to the candidate disclosure destinations, and the disclosure unit 14 is configured to disclose at least a portion of the personal information P to be disclosed to the disclosure destinations in the method specified by the disclosure destination-related information R related to the disclosure destinations. Therefore, in addition to the effects achieved by the information management system 1, the information management system 1A has the effect of being able to disclose personal information P to the disclosure destinations in a more appropriate method.
[0078] Furthermore, in the information management system 1A, the disclosure permission receiving unit 12 is configured to receive a selection of which items to disclose to the discloser from among multiple items included in the personal information P. Therefore, in addition to the effects of the information management system 1, the information management system 1A has the effect of allowing the user to more easily control the personal information P to be disclosed to the discloser.
[0079] Furthermore, the information management system 1A is configured to further include a disclosure history presentation unit 17 that presents, to a user identified by a decentralized identifier, a history of disclosure based on disclosure permission received from the user. Therefore, in addition to the effects of the information management system 1, the information management system 1A allows users to refer to their past disclosure history, thereby providing the effect that individuals can more easily control the disclosure of their personal information on the distributed system.
[0080] Furthermore, in the information management system 1A, the personal information accepting unit 10 and the disclosure permission accepting unit 12 are configured to determine whether a specific non-fungible token is associated with a decentralized identifier, and not accept the decentralized identifier if a specific non-fungible token is not associated with the decentralized identifier. Therefore, in addition to the effects of the information management system 1, the information management system 1A has the effect of being able to decentralize and restrict users who have access rights to the information management system 1A.
[0081] [Example of Software Implementation] Some or all of the functions of the information management systems 1, 1A (hereinafter also referred to as "the system") may be implemented by hardware such as an integrated circuit (IC chip), or by software.
[0082] In the latter case, the system is realized by, for example, one or more computers that execute instructions of a program, which is software that realizes each function. An example of such a computer (hereinafter referred to as computer C) is shown in Figure 11. Figure 11 is a block diagram showing the hardware configuration of computer C that constitutes the system.
[0083] The computer C includes at least one processor C1 and at least one memory C2. The memory C2 stores a program P for causing the computer C to function as each of the above-mentioned devices. In the computer C, the processor C1 reads and executes the program P from the memory C2, thereby realizing each function of the above-mentioned system.
[0084] The processor C1 may be, for example, a central processing unit (CPU), a graphics processing unit (GPU), a digital signal processor (DSP), a micro processing unit (MPU), a floating point number processing unit (FPU), a physics processing unit (PPU), a tensor processing unit (TPU), a quantum processor, a microcontroller, or a combination thereof. The memory C2 may be, for example, a flash memory, a hard disk drive (HDD), a solid state drive (SSD), or a combination thereof.
[0085] The computer C may further include a RAM (Random Access Memory) for expanding the program P during execution and for temporarily storing various data. The computer C may also include a communication interface for transmitting and receiving data to and from other devices. The computer C may also include an input / output interface for connecting input / output devices such as a keyboard, a mouse, a display, and a printer.
[0086] The program P can also be recorded on a non-transitory, tangible recording medium M that can be read by the computer C. Such a recording medium M can be, for example, a tape, a disk, a card, a semiconductor memory, or a programmable logic circuit. The computer C can acquire the program P via such a recording medium M. The program P can also be transmitted via a transmission medium. Such a transmission medium can be, for example, a communication network or broadcast waves. The computer C can also acquire the program P via such a transmission medium.
[0087] [Appendix 1] This disclosure includes the techniques described in the following appendices. However, the present invention is not limited to the techniques described in the following appendices, and various modifications are possible within the scope of the claims.
[0088] (Supplementary Note 1) An information management system comprising: a personal information accepting means for accepting personal information of a user; a registration means for registering the personal information in an external distributed file system; a disclosure permission accepting means for accepting, from the user, disclosure destination designation information that designates a destination to which the personal information will be disclosed and permission to disclose at least a portion of the personal information to the destination designated by the disclosure destination designation information; an acquisition means for acquiring at least a portion of the personal information from the external distributed file system; and a disclosure means for disclosing at least a portion of the personal information to the destination designated by the disclosure destination designation information.
[0089] (Appendix 2) An information management system as described in Appendix 1, wherein the personal information is deleted from the information management system after or at the same time as the registration means registers the personal information in the external distributed file system, and the at least some of the personal information is deleted from the information management system after or at the same time as the disclosure means discloses the at least some of the personal information.
[0090] (Appendix 3) The information management system described in Appendix 1 further comprises: a disclosure destination related information receiving means for receiving disclosure destination related information relating to the candidate disclosure destination from the candidate disclosure destination; and a disclosure destination related information presentation means for presenting at least a portion of the disclosure destination related information relating to the disclosure destination specified by the disclosure destination designated information to a user from whom the disclosure permission receiving means has received the disclosure destination designated information.
[0091] (Appendix 4) An information management system as described in Appendix 3, wherein the disclosure destination-related information regarding the candidate disclosure destination includes information specifying a method of disclosure to the candidate disclosure destination, and the disclosure means discloses at least some of the personal information to the candidate disclosure destination in the method specified by the disclosure destination-related information regarding the candidate disclosure destination.
[0092] (Supplementary Note 5) The information management system according to Supplementary Note 1, wherein the disclosure permission accepting means accepts a selection of which items of the personal information are to be disclosed to the disclosure recipient, from among a plurality of items included in the personal information.
[0093] (Supplementary Note 6) The information management system according to Supplementary Note 1, further comprising a disclosure history presentation means for presenting to the user a history of disclosure based on the disclosure permission received from the user.
[0094] (Appendix 7) The information management system described in Appendix 1, wherein the personal information accepting means and the disclosure permission accepting means determine whether a specific non-fungible token is associated with the decentralized identifier, and do not accept the specific non-fungible token if the specific non-fungible token is not associated with the decentralized identifier.
[0095] (Appendix 8) An information management method executed by an information management system, comprising: a personal information acceptance process that accepts personal information of a user; a registration process that registers the personal information in an external distributed file system; a disclosure permission acceptance process that accepts disclosure destination designation information that designates a disclosure destination of the personal information from the user and permission to disclose at least a portion of the personal information to the disclosure destination designated by the disclosure destination designation information; an acquisition process that acquires at least a portion of the personal information from the external distributed file system; and a disclosure process that discloses at least a portion of the personal information to the disclosure destination designated by the disclosure destination designation information.
[0096] (Appendix 9) The information management method described in Appendix 8, wherein the personal information is deleted from the information management system after or in parallel with registering the personal information in the external distributed file system in the registration process, and the at least some of the personal information is deleted from the information management system after or in parallel with disclosing the at least some of the personal information in the disclosure process.
[0097] (Appendix 10) The information management method described in Appendix 8 further includes a disclosure destination related information acceptance process that accepts disclosure destination related information related to the candidate disclosure destination from the candidate disclosure destination, and a disclosure destination related information presentation process that presents at least a portion of the disclosure destination related information related to the disclosure destination specified by the disclosure destination designated information to a user who has accepted the disclosure destination designated information in the disclosure permission acceptance process.
[0098] (Appendix 11) An information management method as described in Appendix 10, wherein the disclosure destination-related information regarding the candidate disclosure destination includes information specifying a method of disclosure to the candidate disclosure destination, and in the disclosure process, at least some of the personal information is disclosed to the candidate disclosure destination in the method specified by the disclosure destination-related information regarding the candidate disclosure destination.
[0099] (Supplementary Note 12) The information management method according to Supplementary Note 8, wherein the disclosure permission acceptance process accepts a selection of which items of a plurality of items included in the personal information are to be disclosed to the disclosure recipient.
[0100] (Supplementary Note 13) The information management method according to Supplementary Note 8, further comprising a disclosure history presentation process of presenting to the user a history of disclosure based on the disclosure permission received from the user.
[0101] (Appendix 14) An information management method as described in Appendix 8, wherein in the personal information acceptance process and the disclosure permission acceptance process, it is determined whether a specific non-fungible token is associated with the decentralized identifier, and if the specific non-fungible token is not associated with the decentralized identifier, the information management method does not accept the information.
[0102] (Appendix 15) An information management program that causes one or more computers provided in an information management system to execute: a personal information acceptance process that accepts a user's personal information; a registration process that registers the personal information in an external distributed file system; a disclosure permission acceptance process that accepts, from the user, disclosure destination designation information that designates a destination to which the personal information will be disclosed and permission to disclose at least some of the personal information to the destination designated by the disclosure destination designation information; an acquisition process that acquires at least some of the personal information from the external distributed file system; and a disclosure process that discloses at least some of the personal information to the destination designated by the disclosure destination designation information.
[0103] (Appendix 16) The information management program described in Appendix 15, which causes the one or more computers to erase the personal information from the information management system after or in parallel with registering the personal information in the external distributed file system in the registration process, and erase at least some of the personal information from the information management system after or in parallel with disclosing at least some of the personal information in the disclosure process.
[0104] (Appendix 17) The information management program described in Appendix 15 further causes the one or more computers to execute a disclosure destination related information acceptance process that accepts disclosure destination related information related to the candidate disclosure destination from the candidate disclosure destination, and a disclosure destination related information presentation process that presents at least a portion of the disclosure destination related information related to the disclosure destination specified by the disclosure destination designated information to a user who has accepted the disclosure destination designated information in the disclosure permission acceptance process.
[0105] (Appendix 18) The disclosure destination-related information regarding the candidate disclosure destination includes information specifying a method of disclosure to the candidate disclosure destination, and the information management program described in Appendix 17 causes the one or more computers to disclose at least some of the personal information to the candidate disclosure destination in the disclosure process using the method specified by the disclosure destination-related information regarding the candidate disclosure destination.
[0106] (Appendix 19) The information management program described in Appendix 15, which causes the one or more computers to accept a selection of which items of multiple items contained in the personal information to disclose to the disclosure recipient in the disclosure permission acceptance process.
[0107] (Supplementary Note 20) The information management program according to Supplementary Note 15, further causing the one or more computers to execute a disclosure history presentation process that presents to the user a history of disclosure based on the disclosure permission received from the user.
[0108] (Appendix 21) The information management program described in Appendix 15, which causes the one or more computers to identify the user by a decentralized identifier or a combination of a decentralized identifier and a non-fungible token in the personal information acceptance process and the disclosure permission acceptance process.
[0109] [Appendix 2] This disclosure includes the techniques described in the following appendices. However, the present invention is not limited to the techniques described in the following appendices, and various modifications are possible within the scope of the claims.
[0110] (Supplementary Note 1) An information management system comprising at least one processor, the at least one processor executing: a personal information acceptance process for accepting personal information of a user; a registration process for registering the personal information in an external distributed file system; a disclosure permission acceptance process for accepting, from the user, disclosure destination designation information for designating a destination to which the personal information will be disclosed and permission to disclose at least a portion of the personal information to the destination designated by the disclosure destination designation information; an acquisition process for acquiring at least a portion of the personal information from the external distributed file system; and a disclosure process for disclosing at least a portion of the personal information to the destination designated by the disclosure destination designation information.
[0111] The information management system may further include a memory, and the memory may store a program for causing the at least one processor to execute each of the processes.
[0112] (Appendix 2) An information management system as described in Appendix 1, wherein the personal information is deleted from the information management system after or in parallel with registering the personal information in the external distributed file system in the registration process, and the at least some of the personal information is deleted from the information management system after or in parallel with disclosing the at least some of the personal information in the disclosure process.
[0113] (Appendix 3) The information management system described in Appendix 1, wherein the at least one processor further executes a disclosure destination related information acceptance process that accepts disclosure destination related information related to the candidate disclosure destination from the candidate disclosure destination, and a disclosure destination related information presentation process that presents at least a portion of the disclosure destination related information related to the disclosure destination specified by the disclosure destination designation information to a user from whom the disclosure permission acceptance means has accepted the disclosure destination designation information.
[0114] (Appendix 4) An information management system as described in Appendix 3, wherein the disclosure destination-related information regarding the candidate disclosure destination includes information specifying a method of disclosure to the candidate disclosure destination, and wherein the at least one processor, in the disclosure process, discloses at least some of the personal information to the candidate disclosure destination in the method specified by the disclosure destination-related information regarding the candidate disclosure destination.
[0115] (Supplementary Note 5) The information management system according to Supplementary Note 1, wherein the at least one processor accepts a selection of which items of the personal information to disclose to the disclosure recipient in the disclosure permission acceptance process.
[0116] (Supplementary Note 6) The information management system according to Supplementary Note 1, wherein the at least one processor further executes a disclosure history presentation process that presents to the user a history of disclosure based on the disclosure permission received from the user.
[0117] (Appendix 7) The information management system described in Appendix 1, wherein the at least one processor identifies the user by a decentralized identifier or a combination of a decentralized identifier and a non-fungible token in the personal information acceptance means and the disclosure permission acceptance process.
[0118] 1, 1A... Information management system 2... User terminal 3... Disclosure destination server 4... Distributed file system 10... Personal information reception unit 11... Registration unit 12... Disclosure permission reception unit 13... Acquisition unit 14... Disclosure unit 15... Disclosure destination related information reception unit 16... Disclosure destination related information presentation unit 17... Disclosure history presentation unit 18... Personal information registration information storage unit 19... Disclosure destination related information storage unit 20... Disclosure history information storage unit P... Personal information S... Personal information registration information R... Disclosure destination related information D... Disclosure destination designation information Q... Screen L... Disclosure history information
Claims
1. A means of receiving personal information from users, A registration means for registering the aforementioned personal information in an external distributed file system, Disclosure destination designation information that specifies the recipient to whom the aforementioned personal information is to be disclosed, and a means for receiving permission to disclose at least a portion of the aforementioned personal information to the recipient designated by the disclosure destination designation information, An acquisition means for acquiring at least some of the personal information from the external distributed file system, An information management system comprising a disclosure means for disclosing at least a portion of the aforementioned personal information to a recipient designated by the recipient designation information.
2. After the registration means registers the personal information in the external distributed file system, or in parallel with the registration, the personal information is deleted from the information management system. The information management system according to claim 1, wherein after the disclosure means discloses or in parallel with the disclosure of at least some of the personal information, at least some of the personal information is deleted from the information management system.
3. A means for receiving information related to a disclosing recipient from the aforementioned candidate disclosing recipient, The information management system according to claim 1, further comprising: a means for presenting disclosure destination-related information to a user who has received the disclosure destination-designated information; and a means for presenting at least a portion of the disclosure destination-related information relating to the disclosure destination designated by the disclosure destination-designated information.
4. The aforementioned recipient-related information relating to the candidate recipient includes information specifying the method of disclosure to the candidate recipient, The information management system according to claim 3, wherein the disclosure means discloses at least a portion of the personal information to the recipient in a manner specified by the recipient-related information relating to the recipient.
5. The information management system according to claim 1, wherein the disclosure permission acceptance means accepts the selection of which of the multiple items included in the personal information to disclose to the recipient.
6. The information management system according to claim 1, further comprising a means for presenting to the user a history of disclosures based on the disclosure permission received from the user.
7. The information management system according to claim 1, wherein the personal information receiving means and the disclosure permission receiving means identify the user by a decentralized identifier, or a combination of a decentralized identifier and a non-fungible token.
8. An information management method performed by an information management system, The personal information acceptance process that receives users' personal information, A registration process for registering the aforementioned personal information in an external distributed file system, Disclosure destination designation information specifying the recipient of the personal information from the user, and a disclosure permission acceptance process that accepts permission to disclose at least a portion of the personal information to the recipient designated by the disclosure destination designation information, An acquisition process for acquiring at least some of the personal information from the external distributed file system, An information management method including a disclosure process that discloses at least a portion of the aforementioned personal information to a recipient designated by the recipient designation information.
9. In the registration process described above, after or concurrently with the registration of the personal information to the external distributed file system, the personal information is deleted from the information management system. The information management method according to claim 8, wherein, after disclosing or in parallel with disclosing at least some of the personal information in the disclosure process, the at least some of the personal information is deleted from the information management system.
10. A recipient-related information reception process that receives recipient-related information concerning the recipient candidate from the aforementioned recipient candidate, The information management method according to claim 8, further comprising: a disclosure destination-related information presentation process, in which, to a user who has received the disclosure destination designation information in the disclosure permission acceptance process, presents at least a portion of the disclosure destination-related information relating to the disclosure destination designated by the disclosure destination designation information to the user who has received the disclosure destination designation information in the disclosure destination designation process.
11. The aforementioned recipient-related information relating to the candidate recipient includes information specifying the method of disclosure to the candidate recipient, The information management method according to claim 10, wherein in the disclosure process, at least a portion of the personal information is disclosed to the recipient in a manner specified by the recipient-related information relating to the recipient.
12. The information management method according to claim 8, wherein in the disclosure permission acceptance process, the method accepts the selection of which of the multiple items included in the personal information to disclose to the recipient.
13. The information management method according to claim 8, further comprising a disclosure history presentation process that presents to the user a history of disclosures based on the disclosure permission received from the user.
14. The information management method according to claim 8, wherein in the personal information acceptance process and the disclosure permission acceptance process, the user is identified by a decentralized identifier, or a combination of a decentralized identifier and a non-fungible token.
15. One or more computers in the information management system, The personal information acceptance process that receives users' personal information, A registration process for registering the aforementioned personal information in an external distributed file system, Disclosure destination designation information specifying the recipient of the personal information from the user, and a disclosure permission acceptance process that accepts permission to disclose at least a portion of the personal information to the recipient designated by the disclosure destination designation information, An acquisition process for acquiring at least some of the personal information from the external distributed file system, An information management program that performs a disclosure process, which involves disclosing at least a portion of the aforementioned personal information to the recipient specified by the designated recipient information.
16. To the aforementioned one or more computers, In the registration process, after registering the personal information in the external distributed file system, or concurrently with the registration, the personal information is deleted from the information management system. The information management program according to claim 15, wherein, after disclosing or in parallel with disclosing at least some of the personal information in the disclosure process, the at least some of the personal information is deleted from the information management system.
17. To the aforementioned one or more computers, A recipient-related information reception process that receives recipient-related information concerning the recipient candidate from the aforementioned recipient candidate, The information management program according to claim 15, further comprising: causing a user who has received the disclosure destination designation information in the disclosure permission acceptance process to perform a disclosure destination related information presentation process, which presents at least a portion of the disclosure destination related information relating to the disclosure destination designated by the disclosure destination designation information to the user who has received the disclosure destination designation information in the disclosure destination acceptance process;
18. The aforementioned recipient-related information relating to the candidate recipient includes information specifying the method of disclosure to the candidate recipient, To the aforementioned one or more computers, The information management program according to claim 17, wherein in the disclosure process, the program causes the recipient to disclose at least a portion of the personal information in a manner specified by the recipient-related information relating to the recipient.
19. To the aforementioned one or more computers, The information management program according to claim 15, which, in the disclosure permission acceptance process, allows the user to select which of the multiple items included in the personal information to disclose to the recipient.
20. To the aforementioned one or more computers, The information management program according to claim 15, further causing the user to perform a disclosure history presentation process that presents the user with a history of disclosures based on the disclosure permission received from the user.