Information processing system, information processing method, and program

JPWO2025192061A1Pending Publication Date: 2025-09-18
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2026506726
Authority / Receiving Office
JP · JP
Patent Type
Applications
Priority Date
2024-03-14
Filing Date
2025-01-27
Publication Date
2025-09-18

AI Technical Summary

Technical Problem

Existing technologies fail to appropriately conceal sensitive information, leading to potential breaches of privacy and security.

Method used

An information processing system with an acquisition unit, concealment unit, and output unit that acquires user attributes and file content, applies concealment based on these attributes, and outputs the concealed file.

Benefits of technology

Effectively keeps sensitive information secure by tailoring concealment methods to user attributes, ensuring appropriate information disclosure and privacy protection.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

Provided is an information processing system having: an acquisition unit that acquires a file and information indicating a user attribute; a concealment unit that conceals a content section included in the file, on the basis of the user attribute and the type of information in said content section; and an output unit that outputs the file in which the content section has been concealed by the concealment unit.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing system, information processing method, and program

[0001] The present disclosure relates to an information processing system, an information processing method, and a program.

[0002] Patent Document 1 discloses a technique for syntactically analyzing document data and replacing each piece of personal information extracted with data different from the personal information.

[0003] Japanese Patent Application Laid-Open No. 2006-221560

[0004] However, with the technology described in Patent Document 1, for example, there are cases where information cannot be appropriately concealed.

[0005] In view of the above-mentioned problems, an object of the present disclosure is to provide a technology that can appropriately conceal information.

[0006] In a first aspect of the present disclosure, an information processing system is provided that has an acquisition unit that acquires information indicating a user's attributes and a file, a concealment unit that conceals the content portion based on the user's attributes and the type of information of the content portion contained in the file, and an output unit that outputs the file in which the content portion has been concealed by the concealment unit.

[0007] In addition, a second aspect of the present disclosure provides an information processing method in which an information processing system acquires information indicating a user's attributes and a file, conceals the content portion based on the user's attributes and the type of information of the content portion included in the file, and outputs the file in which the content portion has been concealed.

[0008] In addition, a third aspect of the present disclosure provides a program for causing a computer to execute a process of acquiring information indicating a user's attributes and a file, concealing the content portion based on the user's attributes and the type of information of the content portion contained in the file, and outputting the file with the content portion concealed.

[0009] According to one aspect, information can be appropriately kept secret.

[0010] FIG. 1 is a diagram showing an example of the configuration of an information processing system according to an embodiment. FIG. 2 is a diagram showing an example of the configuration of a communication system according to an embodiment. FIG. 3 is a diagram showing an example of the hardware configuration of an information processing system according to an embodiment. FIG. 4 is a flowchart showing an example of processing when a label is assigned in the information processing system according to an embodiment. FIG. 5 is a diagram showing an example of processing when information is kept confidential in the information processing system according to an embodiment. FIG. 6 is a diagram showing an example of information recorded in a user DB according to an embodiment. FIG. 7 is a diagram showing an example of information recorded in a confidentiality setting DB according to an embodiment. FIG. 8 is a diagram showing an example of a display screen according to an embodiment.

[0011] The principles of the present disclosure will be described with reference to some exemplary embodiments. It should be understood that these embodiments are set forth for illustrative purposes only, to aid those skilled in the art in understanding and practicing the present disclosure, without implying any limitation on the scope of the disclosure. The disclosure described herein may be implemented in various ways other than those described below.

[0012] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.

[0013] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. Note that each drawing is merely an example for describing one or more embodiments. Each drawing is not related to only one particular embodiment, but may also be related to one or more other embodiments. As will be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, an embodiment not explicitly shown or described. Not all features or steps shown in any one drawing are necessarily required to describe an exemplary embodiment, and some features or steps may be omitted. The order of steps described in any drawing may be changed as appropriate.

[0014] (First Embodiment) <Configuration> The configuration of an information processing system 10 according to the embodiment will be described with reference to Fig. 1. Fig. 1 is a diagram showing an example of the configuration of the information processing system 10 according to the embodiment. The information processing system 10 has an acquisition unit 11, a concealment unit 12, and an output unit 13. Each of these units may be realized by cooperation between one or more programs installed in the information processing system 10 and hardware such as a processor and memory of the information processing system 10.

[0015] The acquisition unit 11 acquires information indicating user attributes and a file. The concealment unit 12 conceals the content portion based on the user attributes and the type of information of the content portion included in the file. The output unit 13 outputs the file whose content portion has been concealed by the concealment unit 12. This allows information to be appropriately concealed from the user.

[0016] (Embodiment 2) Next, the configuration of a communication system 1 according to an embodiment will be described with reference to FIG. 2. <System Configuration> FIG. 2 is a diagram showing an example of the configuration of a communication system 1 according to an embodiment. In the example of FIG. 2, the communication system 1 has an information processing system 10, a user terminal 20A, and a user terminal 20B. Hereinafter, when there is no need to distinguish between the user terminal 20A and the user terminal 20B, they will also be simply referred to as "user terminal 20." In the example of FIG. 2, the information processing system 10 and the user terminal 20 are connected so as to be able to communicate via a network N. Note that the number of information processing systems 10 and user terminals 20 is not limited to the example of FIG. 2.

[0017] Examples of the network N include the Internet, a mobile communication system, a wireless local area network (LAN), a LAN, a bus, etc. Examples of the mobile communication system include a fifth generation mobile communication system (5G), a sixth generation mobile communication system (6G, Beyond 5G), a fourth generation mobile communication system (4G), a third generation mobile communication system (3G), etc.

[0018] The information processing system 10 may be, for example, a device such as a server, a cloud server, a personal computer, or a smartphone. The information processing system 10 outputs (transmits) to the user terminal 20, for example, a file whose content portion is hidden.

[0019] The user terminal 20 is, for example, a terminal used by a user, such as a personal computer, a tablet, or a smartphone. The user terminal 20 displays a display screen based on information received from the information processing system 10, for example.

[0020] <Hardware Configuration> Fig. 3 is a diagram showing an example of the hardware configuration of the information processing system 10 according to the embodiment. In the example of Fig. 3, the information processing system 10 (computer 100) includes a processor 101, a memory 102, and a communication interface 103. These components may be connected via a bus or the like. The memory 102 stores at least a portion of a program 104. The communication interface 103 includes an interface required for communication with other network elements.

[0021] When the program 104 is executed by the processor 101, memory 102, and other components in cooperation with each other, the computer 100 performs at least some of the processing of the embodiments of the present disclosure. The memory 102 may be of any type. As a non-limiting example, the memory 102 may be a non-transitory computer-readable storage medium. The memory 102 may also be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. Although only one memory 102 is shown in the computer 100, several physically different memory modules may be present in the computer 100. The processor 101 may be of any type. The processor 101 may include one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and, as a non-limiting example, a processor based on a multi-core processor architecture. The computer 100 may have multiple processors, such as application-specific integrated circuit chips that are time-slaved to a clock that synchronizes the main processor.

[0022] Embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software that may be executed by a controller, microprocessor, or other computing device.

[0023] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as instructions included in program modules, that execute on a target real or virtual processor or device to perform the processes or methods of the present disclosure. Program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or divided among program modules as desired in various embodiments. The machine-executable instructions of the program modules may be executed in local or distributed devices. In a distributed device, the program modules may be located in both local and remote storage media.

[0024] The program code for executing the methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus. When the program code is executed by the processor or controller, the functions / acts in the flowcharts and / or implementing block diagrams are performed. The program code may be executed entirely on the machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine, or entirely on a remote machine or server.

[0025] The program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored on a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable media or tangible storage media include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, CD-ROM, digital versatile disc (DVD), Blu-ray disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable media or communication media include electrical, optical, acoustic, or other forms of propagated signals.

[0026] <Processing> <<Processing When Labeling>> Next, an example of processing when labeling by the information processing system 10 according to the embodiment will be described with reference to Fig. 4 and Fig. 5. Fig. 4 is a flowchart showing an example of processing when labeling by the information processing system 10 according to the embodiment. Fig. 5 is a diagram showing an example of processing for assigning labels to each content portion included in a file according to the embodiment. Note that the processing in Fig. 4 may be executed, for example, when a file is newly registered (recorded, saved) in a specific file server or the like from the user terminal 20, or periodically.

[0027] In step S101, the acquisition unit 11 acquires a file. Here, the acquisition unit 11 may acquire, for example, a file such as a document, audio, or image (still image or video) that has been newly registered in a specific file server or the like from the user terminal 20.

[0028] Next, the anonymization unit 12 determines (estimates, infers) the type of information for each content portion included in the file (step S102). Here, the anonymization unit 12 may estimate the type of information for each content portion, such as proper nouns, words, sentences, and images such as photographs, included in the document file, using, for example, AI (Artificial Intelligence) that performs natural language processing (NLP, Neuro Linguistic Programming). Alternatively, the anonymization unit 12 may estimate the type of information for each content portion, such as images such as photographs, included in the document file, using, for example, AI that performs image recognition.

[0029] The types of information may include, for example, personal information of the injured person, personal information of the person who engaged in the problematic behavior, place names, station names, serious accident situations, minor accident situations, incident situations (for example, near misses, which are events that come just short of leading directly to an accident), instructions from management, trade secrets, etc.

[0030] For example, if the acquired file is an audio file or a video file with audio, the anonymization unit 12 may convert (transcribe) the audio data into text data using AI, etc. Then, the anonymization unit 12 may estimate the type of information for each content portion, such as a proper noun, word, or sentence, included in the text data.

[0031] Next, the anonymization unit 12 assigns (records) information (labels) indicating the determined information type to each content portion included in the file (step S103). Here, the anonymization unit 12 may, for example, add the determined labels as metadata for each content portion included in the file and record the metadata in the file. In this case, the anonymization unit 12 may, for example, use a description format such as XML (Extensible Markup Language) to record each piece of metadata in association with each content portion.

[0032] In the example of Fig. 5, a label 501 such as "Station Name" is assigned to the station name portion included in the text data 500 of the document file. A label 502 of "Personal Information of Person Who Became Problematic" is assigned to the driver's name portion. A label 503 of "Personal Information of Injured Person" and a label 504 of "Personal Information of Person Who Became Problematic" are assigned to the name portion of the passenger who collided with the train. A label 505 of "Serious Accident Circumstances" is assigned to a text portion 511 that explains the circumstances of the accident.

[0033] Note that the concealment unit 12 may assign a label to each content portion based on the operation of an operator (administrator, etc.) instead of or in addition to the information processing system 10 automatically assigning a label to each content portion.

[0034] <<Processing When Information is Confidential>> Next, an example of processing when information is confidential in the information processing system 10 according to the embodiment will be described with reference to Figs. 6 to 9. Fig. 6 is a flowchart showing an example of processing when information is confidential in the information processing system 10 according to the embodiment. Fig. 7 is a diagram showing an example of information recorded in a user DB (database) 701 according to the embodiment. Fig. 8 is a diagram showing an example of information recorded in a confidentiality setting DB 801 according to the embodiment. Fig. 9 is a diagram showing an example of a display screen according to the embodiment. Note that the processing in Fig. 6 may be executed, for example, when a file is viewed on the user terminal 20 in response to a user operation (for example, an operation to access a specific file).

[0035] In step S201, the acquisition unit 11 acquires information indicating user attributes and a file. Here, the acquisition unit 11 may acquire the user attributes from the user DB 701 when authenticating the user of the user terminal 20 using an ID and a password, for example.

[0036] In the example of FIG. 7 , the user DB 701 stores passwords and user attributes in association with user IDs. The user attributes may include, for example, the department to which the user belongs, the user's rank, and information about the work the user is responsible for. The user attributes may include three or more different attributes. The information in the user DB 701 may be stored in a storage device inside the information processing system 10, or may be stored in a storage device external to the information processing system 10. The information in the user DB 701 may be registered in advance by, for example, an operator or the like.

[0037] Next, the anonymization unit 12 determines whether to anonymize each content portion included in the file based on the user attributes, the type of information in each content portion, etc. (step S202). Here, the anonymization unit 12 may determine whether to anonymize each content portion based on, for example, the anonymization setting DB 801. In this case, the anonymization unit 12 may determine whether to anonymize a content portion based on, for example, the user attributes, the type of information in the content portion, and at least one of the type of file content and access status. Note that the anonymization unit 12 may estimate the type of file content using, for example, AI that performs natural language processing.

[0038] In the example of FIG. 8, the confidentiality setting DB 801 stores the type of information to be confidential in association with a combination of user attributes, file content type, and access status.

[0039] The type of file content may include, for example, the type of event that the file content targets. In this case, for example, in the case of a document file recording the results of an investigation into a railway accident, the anonymization unit 12 may disclose details of the cause of the accident to a user whose user attribute is a driver, while concealing information about the victim and the perpetrator. This allows, for example, the driver to use this information as a reference for preventing similar accidents from occurring again. Furthermore, for example, the anonymization unit 12 may conceal details of the cause of the accident from a user whose user attribute is a station employee, while disclosing an outline of the cause of the accident and information about the victim. This allows, for example, the station employee to respond to inquiries from related parties of the victim based on the content of the file.

[0040] The type of file content may also include, for example, the time of the event that the file content covers. In this case, for example, in the case of a document file that records the results of an investigation into a railway accident that has been going on for a predetermined period of time (for example, 50 years) or for which the statute of limitations has expired, the concealment unit 12 may disclose information about the victim and conceal information about the suspect. This can reduce, for example, damage to the reputation of a suspect who has not been found guilty.

[0041] The type of file content may also include, for example, whether or not a person related to the event that the file content is a target of is still alive. In this case, the anonymization unit 12 may anonymize information about a suspect if the suspect has already passed away. Note that the anonymization unit 12 may determine whether or not a person related to the event is still alive by, for example, referring to an external database or the like.

[0042] The type of file content may also include, for example, a type corresponding to at least one of the verdict regarding the event that the file content covers and the results of an investigation regarding the event. In this case, the concealment unit 12 may disclose information about the victim and conceal information about the suspect, for example, when a court verdict is reached or when an investigation result indicates that the suspect's behavior was not problematic. This can reduce, for example, damage to the reputation of a suspect whose guilt has not been determined. The concealment unit 12 may also disclose information about the suspect, for example, when a court verdict is reached or when an investigation result indicates that the suspect's behavior was problematic. The concealment unit 12 may, for example, obtain the results of a verdict or investigation related to the event by referring to an external database, etc.

[0043] The type of file content may also include, for example, a type according to whether the file content is publicly available. In this case, the anonymization unit 12 may not anonymize information that has already been made public. The anonymization unit 12 may, for example, search an external database or information on the Internet to determine whether information such as information on the suspect, information on the victim, and information about the accident is publicly available.

[0044] The access status may include, for example, at least one of the time period and the location where the user accessed the file. In this case, the concealment unit 12 may conceal the outline of the cause of the accident if a station employee accesses the file during the day, and disclose the outline of the cause of the accident if the station employee accesses the file at night. This allows the necessary information to be disclosed to the station employee, for example, in an operation in which only station personnel respond to inquiries from relatives of the victim during the day and station personnel on duty respond to inquiries from relatives of the victim at night.

[0045] The information in the confidential setting DB 801 may be recorded in a storage device inside the information processing system 10, or may be recorded in a storage device outside the information processing system 10. The information in the confidential setting DB 801 may be registered in advance by, for example, an operator or the like.

[0046] Furthermore, the anonymization unit 12 may use data of a file in which each content portion has been set to be confidential for a user with a specific attribute by an operator or the like as training data to perform machine learning to determine the type of information to be confidential for the specific user attribute or the like. Then, the anonymization unit 12 may record setting information in the anonymization setting DB 801 based on the learning result. Thereby, for example, when a file in which anonymization has been set according to the user attribute or the like exists, the setting information can be automatically recorded in the anonymization setting DB 801 using the file.

[0047] Next, the anonymization unit 12 generates a file in which each content portion determined to be anonymized is anonymized (step S203). Here, for example, if the content portion is text data, the anonymization unit 12 may replace the text data with a blacked-out display object or obscured characters (e.g., a circle). Furthermore, the anonymization unit 12 may replace the text data with information indicating the type of information in the content portion. This allows, for example, the user to understand why the content portion to be anonymized has been anonymized. Furthermore, compared to when the content portion is anonymized, the user can more easily understand the context of the text.

[0048] Furthermore, for example, if the content portion is audio data, the concealment unit 12 may replace the audio data with a specific sound (for example, a beep), etc. Furthermore, for example, if the content portion is image data, the concealment unit 12 may replace the image data with a blacked-out display object or apply mosaic processing to the image data.

[0049] Next, the output unit 13 outputs the file in which each content portion has been concealed by the concealment unit 12 (step S204).

[0050] 9, a portion of each content portion of the text data of the document file shown in Fig. 5 is replaced with information (label name) indicating the type of information in the content portion, and is displayed on a display screen 901 of the user terminal 20. In the example of Fig. 9, information types "station name" and "serious accident situation" are disclosed to users with specific attributes, while information "personal information of injured person" and "personal information of person who committed problematic behavior" are kept secret by being replaced with label names 911 and 912.

[0051] <Modifications> The information processing system 10 may be a device contained in a single housing, but the information processing system 10 of the present disclosure is not limited to this. Each unit of the information processing system 10 may be realized by cloud computing configured with one or more computers, for example. Furthermore, the information processing system 10 and the user terminal 20 may be the same device. Such information processing systems 10 are also included as examples of the "information processing system" of the present disclosure.

[0052] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.

[0053] Some or all of the above embodiments may be described as, but are not limited to, the following supplementary notes. Note that some or all of the elements (e.g., configurations and functions) described in each supplementary note subordinate to supplementary note 1 may also be subordinate to independent supplementary notes in other categories in a similar subordinate relationship. Some or all of the elements described in any supplementary note may be applied to various hardware, software, and recording means, systems, and methods for recording software. (Supplementary note 1) An information processing system comprising: an acquisition unit that acquires information indicating user attributes and a file; a concealment unit that conceals the content portion based on the user attributes and the type of information of the content portion included in the file; and an output unit that outputs the file in which the content portion has been concealed by the concealment unit. (Supplementary note 2) The information processing system described in supplementary note 1, in which the concealment unit conceals the content portion based on the user attributes, the type of information of the content portion, and the type of content of the file. (Supplementary Note 3) The information processing system according to Supplementary Note 2, wherein the type of content of the file includes a type corresponding to at least one of the type of event covered by the content of the file, the time of the event, and whether or not a person related to the event is still alive. (Supplementary Note 4) The information processing system according to Supplementary Note 2 or 3, wherein the type of content of the file includes a type corresponding to at least one of a verdict regarding the event covered by the content of the file and an investigation result regarding the event. (Supplementary Note 5) The information processing system according to Supplementary Note 2 or 3, wherein the type of content of the file includes a type corresponding to whether or not the content of the file is publicly available. (Supplementary Note 6) The information processing system according to Supplementary Note 1, wherein the concealment unit conceals the content portion based on the attributes of the user, the type of information of the content portion, and at least one of the time period and place at which the user accessed the file. (Supplementary Note 7) The information processing system according to Supplementary Note 1, wherein the attributes of the user include three or more different attributes.(Supplementary Note 8) The information processing system according to Supplementary Note 1, wherein the concealment unit replaces the content portion with information indicating a type of information of the content portion, and the output unit outputs the file in which the content portion has been replaced by the concealment unit to the user. (Supplementary Note 9) An information processing method, wherein the information processing system: acquires information indicating user attributes and a file, conceals the content portion based on the user attributes and the type of information of the content portion included in the file, and outputs the file in which the content portion has been concealed. (Supplementary Note 10) A program that causes a computer to execute processes of: acquires information indicating user attributes and a file, conceals the content portion based on the user attributes and the type of information of the content portion included in the file, and outputs the file in which the content portion has been concealed.

[0054] This application claims priority based on Japanese Patent Application No. 2024-040272, filed March 14, 2024, the disclosure of which is incorporated herein in its entirety by reference.

[0055] REFERENCE SIGNS LIST 1 communication system 10 information processing system 11 acquisition unit 12 concealment unit 13 output unit 20 user terminal

Claims

1. An information processing system having: an acquisition unit that acquires information indicating a user's attributes and a file; a concealment unit that conceals the content portion based on the user's attributes and the type of information of the content portion contained in the file; and an output unit that outputs the file whose content portion has been concealed by the concealment unit.

2. The information processing system according to claim 1, wherein the concealment unit conceals the content portion based on the attributes of the user, the type of information in the content portion, and the type of content of the file.

3. The information processing system of claim 2, wherein the type of content of the file includes a type corresponding to at least one of the type of event that the content of the file covers, the time of the event, and whether or not a person related to the event is still alive.

4. The information processing system according to claim 2 or 3, wherein the type of content of the file includes a type corresponding to at least one of a judgment regarding the event covered by the content of the file and an investigation result regarding the event.

5. The information processing system according to claim 2 or 3, wherein the type of content of the file includes a type according to whether the content of the file is public or not.

6. The information processing system of claim 1, wherein the concealment unit conceals the content portion based on the attributes of the user, the type of information in the content portion, and at least one of the time period and location at which the user accessed the file.

7. The information processing system according to claim 1, wherein the user attributes include three or more different attributes.

8. The information processing system of claim 1, wherein the concealment unit replaces the content portion with information indicating the type of information in the content portion, and the output unit outputs the file in which the content portion has been replaced by the concealment unit to the user.

9. An information processing method, in which an information processing system acquires information indicating a user's attributes and a file, conceals the content portion based on the user's attributes and the type of information of the content portion contained in the file, and outputs the file with the content portion concealed.

10. A program that causes a computer to execute the following process: acquire information indicating user attributes and a file; conceal the content portion based on the user attributes and the type of information of the content portion contained in the file; and output the file with the content portion concealed.