Personal information management program, personal information management method, and user terminal
The personal information management program securely integrates and manages user data across multiple service providers, addressing the challenge of unified digital wallet access by reading and storing information from identification documents, thus enabling secure and compliant service usage.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
- Filing Date
- 2025-12-22
- Publication Date
- 2026-07-23
Smart Images

Figure JP2025044907_23072026_PF_FP_ABST
Abstract
Description
Personal information management program, personal information management method, and user terminal
[0001] The present disclosure relates to a personal information management program, a personal information management method, and a user terminal.
[0002] A technology called a digital wallet is known for enabling a user to safely use services and perform payments using a user terminal typified by a smartphone. In Patent Document 1, a method of starting a blockchain transaction using a wallet device including a non-temporary processor-readable medium having a memory, a display, an input interface, and a processor communicating with a biometric sensor, the method including, in the wallet device, receiving a transaction request including an address and an amount from a first computing device; capturing biometric information from the user using the biometric sensor; generating a bio-vector from the biometric information; comparing the bio-vector with a stored vector to authenticate the user; and signing the transaction request using a private key having a corresponding public key upon authentication.
[0003] Japanese Patent Application Publication No. 2022-508773
[0004] There is room for further consideration in order to realize a digital wallet that can safely use services provided by each of a plurality of service providers in a unified manner.
[0005] An object of the present disclosure is to provide a technology for realizing a digital wallet that can safely use services provided by each of a plurality of service providers in a unified manner.
[0006] One aspect of this disclosure provides a personal information management program that runs on a processor in a user terminal owned by a user, and which reads the user's basic personal information from the user's identification document, displays an input screen for the user's additional personal information, obtains the additional personal information based on the user's input operation on the input screen, transmits the user personal information, including the basic personal information and the additional personal information, to a predetermined external server, and stores the user personal information in the memory of the user terminal.
[0007] One aspect of this disclosure provides a personal information management method that is performed on a user terminal owned by a user, the method comprising: reading the user's basic personal information from the user's identification document; displaying an input screen for the user's additional personal information; acquiring the additional personal information based on the user's input operation on the input screen; transmitting the user personal information, including the basic personal information and the additional personal information, to a predetermined external server; and storing the user personal information in the memory of the user terminal.
[0008] One aspect of this disclosure provides a user terminal owned by a user, comprising a processor and memory, wherein the processor reads the user's basic personal information from the user's identification document, displays an input screen for the user's additional personal information, acquires the additional personal information based on the user's input operation on the input screen, transmits the user personal information, including the basic personal information and the additional personal information, to a predetermined external server, and stores the user personal information in the memory.
[0009] These comprehensive or specific embodiments may be implemented as systems, devices, methods, integrated circuits, computer programs, or recording media, or as any combination of systems, devices, methods, integrated circuits, computer programs, and recording media.
[0010] According to this disclosure, it is possible to realize a digital wallet that allows users to securely utilize services provided by multiple businesses in one place.
[0011]
[0012] Embodiments of the present disclosure will be described in detail below, with appropriate reference to the drawings. However, descriptions that are unnecessarily detailed may be omitted. For example, detailed descriptions of already well-known matters and redundant descriptions of substantially identical configurations may be omitted. This is to avoid the following description becoming unnecessarily verbose and to facilitate understanding for those skilled in the art. The accompanying drawings and the following description are provided to enable those skilled in the art to fully understand the present disclosure and are not intended to limit the subject matter of the claims. The functions of one configuration shown in this embodiment may be realized by two or more physical configurations, or the functions of two or more configurations may be realized by, for example, one physical configuration.
[0013] (Embodiment 1) <Hardware Configuration> Figure 1 shows an example of the hardware configuration of the DIW system 1 according to Embodiment 1. DIW is an abbreviation for Digital ID Wallet.
[0014] The DIW system 1 comprises a user terminal 10, a DIW cloud 20, a service provider server 30, and a service terminal 40. However, the DIW system 1 may omit some of these devices.
[0015] User terminal 10 is a device used by the user, such as a smartphone, tablet, or notebook PC.
[0016] The user terminal 10 includes, as hardware, a processor 11, memory 12, storage 13, a camera 14, an input device 15, a display device 16, and a communication device 17.
[0017] The processor 11 works in cooperation with the memory 12 to execute a computer program (e.g., DIW application 50) to realize the functions of the user terminal 10 of this disclosure. The processor 11 may be read as a Central Processing Unit (CPU), controller, arithmetic circuit, or control circuit, etc. The processor 11 may also include a Graphics Processing Unit (GPU) and / or a Neural Network Processing Unit (NPU).
[0018] The memory 12 is composed of a volatile storage medium and / or a non-volatile storage medium, and stores computer programs and data, etc.
[0019] The storage 13 is composed of a non-volatile storage medium and stores computer programs and data. Examples of the storage 13 include flash memory, Solid State Drive (SSD), or Hard Disk Drive (HDD).
[0020] The camera 14 is equipped with an image sensor, such as a Complementary Metal Oxide Semiconductor (CMOS) image sensor or a Charge Coupled Device (CCD) image sensor, and generates captured images.
[0021] The input device 15 is a device that receives input from the user, and is, for example, a touch panel, touchpad, keyboard, mouse, and / or microphone.
[0022] The display device 16 is a device that displays a screen, and is composed of, for example, a liquid crystal display or an organic EL display.
[0023] The communication device 17 is a device that controls wired communication and / or wireless communication. The communication device 17 supports, for example, Ethernet®, Wi-Fi®, cellular communication (e.g., LTE, 4G, 5G), Bluetooth® Classic, Bluetooth Low Energy (BLE), and / or Near Field Communication (NFC).
[0024] The DIW Cloud 20 provides a cloud service for managing DIW. The DIW Cloud 20 may consist of one or more server devices. The server devices comprising the DIW Cloud 20 include a processor 21, memory 22, storage 23, and communication device 24.
[0025] The processor 21 works in cooperation with the memory 22 to execute a computer program, thereby realizing the functions of the DIW cloud 20 of this disclosure. The processor 21 may be read as a CPU, controller, arithmetic circuit, or control circuit, etc. The processor 21 may also include a GPU and / or NPU.
[0026] The memory 22 is composed of a volatile storage medium and / or a non-volatile storage medium, and stores computer programs and data, etc.
[0027] The storage 23 is composed of a non-volatile storage medium and stores computer programs and data. Examples of the storage 23 include flash memory, SSD, or HDD.
[0028] The communication device 24 is a device that controls wired communication and / or wireless communication. The communication device 24 supports, for example, Ethernet, Wi-Fi, cellular communication (e.g., LTE, 4G, 5G), Bluetooth Classic, and / or Bluetooth Low Energy (BLE).
[0029] The service provider server 30 is a server managed by the service provider. The service provider server 30 is equipped with the same hardware (e.g., processor and memory, etc.) as the server device of the DIW Cloud 20 described above.
[0030] The service terminal 40 is a terminal used when providing services, and is installed and managed by, for example, a service provider. Specific examples of the service terminal 40 will be described later.
[0031] The service terminal 40 includes, as hardware, a processor 41, memory 42, a camera 43, an input device 44, a display device 45, and a communication device 46. However, the service terminal 40 may not include some of these devices.
[0032] The processor 41 works in cooperation with the memory 42 to execute a computer program, thereby realizing the functions of the service terminal 40 of this disclosure. The processor 41 may be read as a CPU, controller, arithmetic circuit, or control circuit, etc. The processor 41 may also include a GPU and / or NPU.
[0033] The memory 42 is composed of a volatile storage medium and / or a non-volatile storage medium, and stores computer programs and data, etc.
[0034] The camera 43 is equipped with an image sensor, such as a CMOS image sensor or a CCD image sensor, and generates captured images.
[0035] The input device 44 is a device that receives input from the user, and is, for example, a touch panel, touchpad, keyboard, mouse, and / or microphone.
[0036] The display device 45 is a device that displays a screen, and is composed of, for example, a liquid crystal display or an organic EL display.
[0037] The communication device 46 is a device that controls wired communication and / or wireless communication. The communication device 46 supports, for example, Ethernet, Wi-Fi, cellular communication (e.g., LTE, 4G, 5G), Bluetooth Classic, and / or Bluetooth Low Energy (BLE). The communication device 46 may also support Near Field Communication (NFC).
[0038] The user terminal 10, the DIW cloud 20, the service provider server 30, and the service terminal 40 may send and receive information from each other via a predetermined communication network 5. However, the service terminal 40 may not be connected to the communication network 5. Examples of the communication network 5 include wired LAN, wireless LAN, the internet, or a cellular network (mobile communication network).
[0039] The user terminal 10 may establish wireless communication (e.g., short-range wireless communication) with the service terminal 40, for example, using BLE or NFC.
[0040] <Functional Configuration> Figure 2 is a diagram showing an example of the functional configuration of the DIW system 1 according to Embodiment 1.
[0041] <Functions of the User Terminal> Users can install and run the DIW application 50 and the service application 70 on the user terminal 10. The service application 70 controls and manages the provision of personal information to services provided by each business operator. The service application 70 may differ for each service (or each business operator). In other words, multiple service applications 70 may be installed on the user terminal 10. The DIW application 50 provides functions for securely using services provided by multiple business operators in a consolidated manner. Next, the functions of the DIW application 50 will be explained.
[0042] The DIW application 50 has the following functions: a service master list acquisition unit 51, a user personal information acquisition unit 52, an available service extraction unit 53, a service usage condition output unit 54, a collaboration consent acquisition unit 55, a face matching unit 56, a request reception unit 57, a provided information extraction unit 58, a log output unit 59, and a data management unit 60.
[0043] The service master list acquisition unit 51 acquires the service master list 100A from the DIW Cloud 20 and stores it in the data management unit 60 as the service master list 100B. The service master lists 100A and 100B are lists of services provided by each service provider. The service master lists 100A and 100B register the services of service providers whose integration has been approved by the operator of the DIW Cloud 20.
[0044] The user personal information acquisition unit 52 acquires personal information from the user's identity certificate and securely manages the personal information in cooperation with the DIW cloud 20. Hereinafter, the personal information acquired from the user's identity certificate is referred to as basic personal information. Further, the user personal information acquisition unit 52 acquires and manages additional personal information from the user for information that is insufficient in the personal information acquired from the identity certificate (for example, the kana of the name, etc.). Hereinafter, the additional personal information acquired from the user is referred to as additional personal information. Further, the user personal information acquisition unit 52 manages, as specific personal information, part of the basic personal information or additional personal information (for example, information extracted only from the city, ward, and village of the address), or information specified based on the basic personal information or additional personal information (for example, the age calculated based on the date of birth). Hereinafter, the basic personal information, the additional personal information, and the specific personal information may be collectively referred to as personal information. Also, each item included in the personal information may be referred to as personal attribute information.
[0045] This embodiment will explain the case where the identity certificate is a My Number card. However, the identity certificate may be any document that can acquire personal information, such as a driver's license, a residence card, or a passport.
[0046] The available service extraction unit 53 extracts the services available to the user from the service master list 100B and generates an available service ID list 120.
[0047] The service usage condition output unit 54 refers to the service master list 100B and displays the conditions for the user to use the service on a screen (for example, the display device 16 of the user terminal 10).
[0048] The cooperation consent acquisition unit 55 acquires consent from the user as to whether the services provided by the business operator may be linked with the DIW app 50. The cooperation consent acquisition unit 55 acquires a user ID for service, which is a dedicated user ID for the service that has consented to be linked with the DIW app 50, from the DIW cloud 20 and registers it in the consented service ID list 130.
[0049] The face matching unit 56 compares the face image information captured by the camera 14 with the face image information recorded in the user's personal information record 110 to determine whether they belong to the same person. This face image information is obtained from an identification document. This matching may be implemented using known face matching technology.
[0050] The request receiving unit 57 receives requests for personal information from the service application 70 or service terminal 40 when the service is used.
[0051] The information extraction unit 58 extracts personal attribute information provided at the time of consent to linkage or service use and outputs it to the service application 70 or service terminal 40.
[0052] The log output unit 59 identifies the services to which personal information was provided during the initial connection or when using the service, and sends the identified information as a log to the DIW Cloud 20. The DIW Cloud 20 receives the log and stores it as a personal information provision log 220. This allows the DIW Cloud 20 to manage which personal attribute information of which user was provided to which service or business operator as a personal information provision log 220.
[0053] The data management unit 60 manages the data used by the DIW application 50. The data management unit 60 may manage the service master list 100B, user personal information records 110, available service ID list 120, and consented service ID list 130. These lists and records will now be described.
[0054] <Service Master List> Figure 3 shows an example of the configuration of service master lists 100A and 100B according to Embodiment 1.
[0055] Service master lists 100A and 100B are lists of services provided by businesses that have already linked with DIW Cloud 20. Service master list 100A may be managed by DIW Cloud 20. DIW application 50 may, if necessary, retrieve service master list 100A from DIW Cloud 20 and retain it as service master list 100B.
[0056] The service master lists 100A and 100B have the following items: service ID, service name, business ID, terms of use, personal attribute information required by the service, service usage conditions, service linkage date, and service period.
[0057] The Service ID is an ID that uniquely identifies a service. The Service Name is the name of the service corresponding to the Service ID. The Service Provider ID is an ID that uniquely identifies the service provider that provides the service corresponding to the Service ID. If one service provider provides one service, one Service ID is associated with one Service Provider ID. If one service provider provides multiple services, multiple Service IDs may be associated with one Service Provider ID.
[0058] The Terms of Service outline the rules that users must follow when using the service corresponding to the Service ID. The Terms of Service may also be a file or URL containing the Terms of Service.
[0059] The personal attribute information requested by a service indicates the personal attribute information required to use the service corresponding to the service ID. For example, if "name" and "address" are required to use a certain service, "name" and "address" will be set in the personal attribute information requested by the service.
[0060] The service usage conditions indicate the conditions that must be met to use the service corresponding to the service ID. For example, for a service provided only to residents of Adachi Ward, the service usage condition would be "the user's address is in Adachi Ward." For example, for a service provided only to those 20 years of age or older, the service usage condition would be "the user is 20 years of age or older." For example, for a service provided only to those under 20 years of age, the service usage condition would be "the user is under 20 years of age." Multiple conditions may be set for the service usage conditions.
[0061] The service integration date indicates the date on which the service provider integrated (registered) the service corresponding to the service ID with DIW Cloud 20, or the date on which the integration was updated.
[0062] The service period indicates the period during which the service corresponding to the service ID is provided. The service period may include a start date and time and an end date and time.
[0063] <User Personal Information Record> Figure 4 is a diagram showing an example of the configuration of a user personal information record 110 according to Embodiment 1.
[0064] The user personal information record 110 stores basic personal information obtained from the user's identification document, additional personal information entered by the user, and specific personal information of the user generated by the DIW application 50 based on the basic personal information and / or additional personal information, all associated with the user's user ID. The user personal information record 110 is stored in the data management unit 60 of the DIW application 50.
[0065] The user ID is an ID used to uniquely identify a user and is assigned by DIW Cloud 20.
[0066] The basic personal information obtained from the user's identification document includes name, address, date of birth, gender, and facial image information. The facial image information is an image of the user's face taken when the identification document was created or renewed. If the identification document is a My Number Card, the basic personal information can be obtained from the IC chip of the My Number Card.
[0067] Additional personal information may include information that is insufficient with basic personal information when using the service. Examples of additional personal information include, but are not limited to, the phonetic spelling of the last name, the phonetic spelling of the first name, mobile phone number, email address, and password.
[0068] Specific personal information refers to information that is frequently requested when using a service, for example, and is pre-extracted or calculated. Specific personal information includes, for example, age, a flag indicating that the person is 20 years of age or older, and information extracted only from the city / town portion of the address. However, the information included in specific personal information is not limited to these.
[0069] <Available Service ID List and Agreed Service ID List> Figure 5 shows an example of the configuration of the available service ID list 120 and the agreed service ID list 130 according to Embodiment 1.
[0070] The Available Service ID List 120 lists the availability of services for each user. The Available Service ID List 120 includes the service ID and the availability status as its items.
[0071] The service ID indicates the service ID registered in service master lists 100A and 100B. Availability indicates whether the service corresponding to the service ID is available to the user.
[0072] For example, if the personal attribute information in the user personal information record 110 satisfies the service usage conditions corresponding to the service ID in the service master list 100B, the DIW application 50 will set the availability of the service ID in the available service ID list 120 to "available". For example, if the personal attribute information in the user personal information record 110 does not satisfy the service usage conditions corresponding to the service ID in the service master list 100B, the DIW application 50 will set the availability of the service ID in the available service ID list 120 to "unavailable".
[0073] Furthermore, services corresponding to service IDs whose availability status is "available" in the available service ID list 120 may be displayed on the display device 16 of the user terminal 10 as selectable services.
[0074] The List of Consent Service IDs 130 is a list that extracts services from the List of Available Service IDs 120 that are "available" and indicates whether or not the user has consented to providing personal information to those services. The List of Consent Service IDs 130 has the following items: Service ID, User ID for the service, and Consent Status.
[0075] The service IDs are extracted from the list of available service IDs (120) and are those that are "available".
[0076] A service-specific user ID is a user ID assigned specifically for the service indicated by the service ID. In this embodiment, instead of using a common user ID, a unique service-specific user ID is generated and used for each service. The service-specific user ID may be generated based on the user ID assigned to the user. For example, DIW Cloud 20 may generate the service-specific user ID by combining the service ID and user ID and converting the result into a hash value. This allows the same user to use different service-specific user IDs for each service, thus preventing the misuse of personal information by matching user IDs across multiple services.
[0077] The "Consent Status" indicates whether the user has consented to providing personal information to the service provider corresponding to the service ID. If the consent status is "No," the service provider cannot provide the service to the user, even if it is technically possible to do so. In other words, the user cannot use the service.
[0078] <DIW Cloud Functions> Returning to the explanation of Figure 2, DIW Cloud 20 works in cooperation with DIW App 50 to control and manage the provision of personal information to services provided by each business operator. DIW Cloud 20 may be operated by a designated business operator different from the service provider. Hereinafter, the business operator operating DIW Cloud 20 may be referred to as the cloud operator.
[0079] The DIW Cloud 20 has the following functions: a service confirmation unit 81, a service master list management unit 82, an ID generation unit 83, an integrated personal information master list management unit 84, a user-linked service list management unit 85, a face matching unit 86, a request reception unit 87, a provided information extraction and output unit 88, and a personal information provision log management unit 89.
[0080] The service verification unit 81 verifies the services provided by the service provider. For example, the service verification unit 81 verifies the terms of service for the service and the personal attribute information requested by the service. This verification may be performed automatically by the service verification unit 81 or manually by the cloud operator.
[0081] The Service Master List Management Unit 82 generates, updates, and stores the Service Master List 100A, which is a list of services provided by businesses that have already linked with the DIW Cloud 20.
[0082] The ID generation unit 83 generates a user ID corresponding to the user. The ID generation unit 83 also generates a service-specific user ID corresponding to each service that the user has agreed to link with.
[0083] The Integrated Personal Information Master List Management Unit 84 generates, updates, and manages the Integrated Personal Information Master List 200, which is created by integrating the user personal information records 110 of each user.
[0084] The User-Linked Service List Management Unit 85 generates, updates, and stores the User-Linked Service List 210, which is a list of services that each user has agreed to link.
[0085] The face matching unit 86 checks whether the face image information of the user captured by the camera 43 of the user terminal 10 exists in the integrated personal information master list 200 as the face image information of the same person. In other words, the face matching unit 86 performs a one-to-N (N is an integer of 1 or more) match between the captured face image information and multiple face image information in the integrated personal information master list 200.
[0086] The request receiving unit 87 receives requests for personal information from the service application 70 or service terminal 40 when the service is used.
[0087] The information extraction and output unit 88 extracts personal information used when consenting to link or using the service, and outputs it to the service application 70 or service terminal 40.
[0088] The Personal Information Provision Log Management Department 89 generates, updates, and manages the Personal Information Provision Log 220, including storage.
[0089] <Integrated Personal Information Master List> Figure 6 shows an example of the configuration of the integrated personal information master list 200 according to Embodiment 1.
[0090] The Integrated Personal Information Master List 200 is a list compiled by integrating the user personal information records 110 for each user. The Integrated Personal Information Master List 200 is managed by DIW Cloud 20.
[0091] Since the items in the Integrated Personal Information Master List 200 are the same as the items in the User Personal Information Record 110, the explanation is omitted.
[0092] <User-Linked Service List> Figure 7 shows an example of the configuration of the user-linked service list 210 according to Embodiment 1.
[0093] The user-linked service list 210 is a list of services that the user has agreed to link with the DIW app 50. The user-linked service list 210 is managed by the DIW cloud 20.
[0094] The user-linked service list 210 includes the following items: user ID, service provider ID, service ID, service-specific user ID, linking date and time, provided information, and linking information.
[0095] In the user-linked service list 210, the service provider ID and service ID corresponding to the service that the user has agreed to link are associated with each user ID. Furthermore, the user-linked service list 210 also associates the service-specific user ID that is uniquely assigned to the agreed-upon service ID.
[0096] The linking date and time indicates the date and time when the user with the user ID agreed to link with the service corresponding to the service ID. The provided information indicates the personal attribute information provided (used) by the service corresponding to the service ID. The linking information indicates whether the service corresponding to the service ID is already linked or has been unlinked.
[0097] <Personal Information Provision Log> Figure 8 shows an example of the configuration of the personal information provision log 220 according to Embodiment 1.
[0098] The personal information provision log 220 records the services to which personal information was provided. The personal information provision log 220 is managed by DIW Cloud 20.
[0099] The personal information provision log 220 includes the following items: user ID, business ID, service ID, service-specific user ID, service name, service usage date and time, and provided information.
[0100] In the personal information provision log 220, the user ID is associated with the business ID, service ID, service-specific user ID, and service name to which the user's personal information was provided.
[0101] The "Service Usage Date and Time" indicates the date and time the user used the service. The "Provided Information" indicates the personal attribute information provided by the user when they used the service.
[0102] DIW Cloud 20, through the personal information provision log 220, can manage which users used which services from which businesses, when, and what personal attribute information was provided when using those services.
[0103] <Process for a business operator to apply for service integration with a cloud operator> Figure 9 is a sequence diagram showing an example of the process for a business operator to apply for service integration with a cloud operator according to Embodiment 1.
[0104] The service provider applies for service integration with the DIW Cloud 20 through the service provider server 30 (S101). For example, the service provider applies for service integration from a web page provided by the DIW Cloud 20.
[0105] Upon receiving the application in step S101, DIW Cloud 20 requests detailed information about the linked service (hereinafter referred to as "service details") from the service provider server 30. The service provider server 30 receives this request (S102).
[0106] The service provider server 30 transmits detailed service information of the linked services to the DIW cloud 20. The DIW cloud 20 receives the detailed service information (S103). The detailed service information includes the service terms of use and service usage conditions. These service usage conditions correspond to the service usage conditions of the service master lists 100A and 100B shown in Figure 3.
[0107] DIW Cloud 20 reviews whether to approve the integration of the service based on the service details (S104). This review may be performed manually by the cloud operator (staff) or automatically by DIW Cloud 20 according to predetermined rules.
[0108] If the DIW Cloud 20 determines in the review in step S104 to approve the service integration (S105: YES), it sends a review result indicating approval of the service integration to the service provider server 30 (S106). If the DIW Cloud 20 determines in the review in step S104 not to approve the service integration (S105: NO), it may send a review result indicating rejection of the service integration to the service provider server 30 (S107). In this case, this process ends.
[0109] The service provider server 30 receives the review result in step S106, which approves the service integration, and submits a service integration contract application to the DIW cloud 20 (S108). Then, a service integration contract is concluded between the service provider and the cloud operator (S109).
[0110] The service provider server 30 sends a request to the DIW cloud 20 for setting the service details of the linked service. The DIW cloud 20 receives the request (S110).
[0111] DIW Cloud 20 registers the contents of the received service details in the service master list 100A (S111). As a result, the linked services are registered in the service master list 100A. The service details may include the service terms of use and service usage conditions provided at the time of application for service linkage (S101), and may also include additional content (for example, a detailed explanation of the service).
[0112] DIW Cloud 20 sends a notification of completion of integration to the service provider server 30 (S112).
[0113] The DIW Cloud 20 sends the newly linked service details to the DIW app 50. The DIW app 50 receives this information (S113).
[0114] The DIW application 50 registers the received service details into the service master list 100B (S114). As a result, the newly linked services are added and updated in both the service master list 100A of the DIW cloud 20 and the service master list 100B of the DIW application 50.
[0115] The DIW application 50 may display the details of the newly linked services on the screen (for example, the display device 45 of the user terminal 10) (S115). This allows the user to learn about the newly available services.
[0116] Through the above process, the services newly provided by the service provider and approved by the cloud operator are registered (i.e., linked) in the DIW Cloud 20 service master list 100A.
[0117] <Process for registering user's personal information in the DIW app and DIW cloud> Figure 10A is a sequence diagram showing an example of the process for registering user's personal information in the DIW app 50 and DIW cloud 20 according to Embodiment 1. Figure 10B is a sequence diagram showing the continuation of the process in Figure 10A. Figure 11 is a diagram showing an example of the identity document reading screen according to Embodiment 1. Figure 12 is a diagram showing an example of the additional personal information input screen according to Embodiment 1.
[0118] DIW Cloud 20 already possesses the service master list 100A.
[0119] When a user launches the DIW app 50 for the first time (S201), the DIW app 50 displays the terms of service screen (S202).
[0120] Once the user agrees to the terms of service (S203), the DIW app 50 displays the identity document reading screen shown in Figure 11(a) (S204).
[0121] The DIW app 50 reads basic personal information from the identification document provided by the user (S205). For example, if the identification document is a My Number Card, the DIW app 50 reads four pieces of basic personal information (address, name, date of birth, gender) and facial image information from the IC chip of the My Number Card. At this time, the DIW app 50 may ask the user to enter the My Number Card verification number B, as shown in Figure 11(b). The verification number B is a 14-digit number consisting of the date of birth (6 digits), expiration date (4 digits), and security code (4 digits) printed on the My Number Card. Using the verification number B, the DIW app 50 can read the four pieces of information and facial image information from the IC chip of the My Number Card. If the identification document is a driver's license, the DIW app 50 may ask the user to enter the PIN set for the driver's license.
[0122] The DIW application 50 captures the user's face with the camera 14 of the user terminal 10 (S206) and acquires the captured face image information (S207).
[0123] The DIW app 50 checks whether the facial image information read from the identification document in step S205 and the captured facial image information obtained in step S207 belong to the same person (S208). In other words, the DIW app 50 determines whether the user who took the photo is the person on the identification document. This facial matching can be implemented using publicly known technology, and subsequent facial matching can be implemented in the same way.
[0124] If the DIW application 50 fails to perform the matching in step S208 (S209: NO), it displays a screen prompting the user to retake the image, indicating that the matching failed (S210). Then, the process returns to step S206.
[0125] If the DIW application 50 succeeds in the matching in step S208 (S209: YES), it displays "Matching successful" and the acquired personal information on the screen (S211).
[0126] The DIW application 50 displays an input screen for additional personal information, as shown in Figure 12 (S212). As mentioned above, the input screen for additional personal information is a screen for users to enter personal information that cannot be obtained from identification documents.
[0127] The user enters additional personal information on the additional personal information input screen. For example, as shown in Figure 12, the user enters their last name (phonetic spelling), first name (phonetic spelling), mobile phone number, email address, and password as additional personal information. The DIW application 50 acquires the entered additional personal information (S213).
[0128] The DIW app 50 extracts or calculates specific personal information of the user based on the basic personal information obtained from the identification document (S214). Examples of specific personal information include the user's age calculated from the date of birth in the basic personal information, and the address extracted from the basic personal information, such as the city or town.
[0129] The DIW application 50 integrates the basic personal information (including facial image information) obtained from the identification document, the additional personal information entered by the user, and the specific personal information extracted in step S214 to generate a user personal information record 110, which is stored in the data management unit 60 (S215).
[0130] The DIW application 50 requests the DIW cloud 20 to assign a user ID to the user. The DIW cloud 20 receives the request (S216).
[0131] The DIW Cloud 20 generates a user ID for the user in response to the request in step S216 (S217).
[0132] The DIW Cloud 20 sends the generated user ID to the DIW application 50. The DIW application 50 receives the user ID (S218).
[0133] The DIW application 50 associates the received user ID with the user personal information record 110 generated in step S215 (S219). This generates a user personal information record 110 as shown in Figure 4.
[0134] The DIW application 50 sends the user personal information record 110 from step S219 to the DIW cloud 20. The DIW cloud 20 receives the user personal information record 110 (S220).
[0135] The DIW Cloud 20 adds the received user personal information record 110 to the integrated personal information master list 200 (S221).
[0136] As a result of the above process, a user personal information record 110 for a new user of the DIW application 50 is added to the integrated personal information master list 200 managed by the DIW cloud 20.
[0137] <Example of process for registering user account information in the DIW app and DIW cloud> Figure 13 is a sequence diagram showing an example of the process for registering user account information in the DIW app and DIW cloud according to Embodiment 1.
[0138] The user installs the DIW application 50 on the user terminal 10 and launches the DIW application 50 (S231).
[0139] The DIW app 50 displays the account settings screen (S232).
[0140] The user enters their account information on the account settings screen of the DIW app 50 (S233). The account information may include an email address and password.
[0141] The DIW application 50 sends an account creation request containing the entered account information to the DIW cloud 20 (S234).
[0142] The DIW Cloud 20 receives an account creation request and sets and registers the account information included in the account creation request (S235). Then, the DIW Cloud 20 sends an account creation completion notification to the DIW application 50 (S236).
[0143] The DIW app 50 receives an account creation completion notification and displays the account creation completion screen (S237).
[0144] Through the above process, the user's account information is registered in the DIW application 50 and the DIW cloud 20.
[0145] <Example of a process for registering a user's personal information to the DIW app and DIW cloud via an external terminal> Figure 10A explains how to read basic personal information from an identification document using the DIW app 50, but Figures 14 to 16B below explain how to read basic personal information from an identification document via an external terminal 401. The external terminal 401 may be installed in, for example, a car dealership, a real estate agency, or a city hall, and may be a device on the side of the store or facility. An employee of the store or facility may have the user use the external terminal 401 while interacting with the user face-to-face. Alternatively, there may be no employee at the store or facility, and the user may use the external terminal 401 themselves. The configuration of the external terminal 401 may be the same as that of the service terminal 40, or it may be composed of, for example, a PC and a camera.
[0146] Figure 14 is a sequence diagram showing an example of the process of registering a user's personal information to the DIW application 50 and DIW cloud 20 via an external terminal 401 according to Embodiment 1. Figure 15 is a schematic diagram showing an example of a basic personal information confirmation screen of the external terminal 401 according to Embodiment 1.
[0147] The user visits the store or facility (S240) and operates the external terminal 401 to select the menu for reading identification documents (S241).
[0148] Upon receiving the selection in step S241, the external terminal 401 displays the identity document reading screen (S242).
[0149] The external terminal 401 reads basic personal information, including facial image information, from the identification document provided by the user and stores it in its internal memory (S243). The reading method is the same as in step S205 in Figure 10A. Note that the identification document is not limited to a card type. For example, if the user terminal 10's OS stores the identification document information, the external terminal 401 may read the basic personal information from the user terminal 10 and store it in its internal memory.
[0150] The external terminal 401 captures the user's face with its camera (S244) and acquires the captured face image information (S245). Then, the external terminal 401 performs face matching processing in the same manner as in steps S208 to S210 in Figure 10A (S246).
[0151] If the external terminal 401 succeeds in the face matching process, it displays a confirmation screen of the basic personal information read in step S243 and stored in its internal memory on the display device (S247), as illustrated in Figure 15. As shown in Figure 15, the confirmation screen may display the acquired basic four pieces of information and face image information. However, to prevent a third party from peeking at and illegally obtaining the basic personal information displayed on the confirmation screen, the external terminal 401 does not have to display the confirmation screen. This process then proceeds to either Figure 16A or Figure 16B. Which process proceeds from Figure 16A or Figure 16B may be determined by the configuration of the DIW system 1.
[0152] Figure 16A is a sequence diagram showing the first example of the continuation of the process shown in Figure 14.
[0153] If the user confirms that there are no problems after viewing the basic personal information confirmation screen displayed in step S247 of Figure 14, they perform an operation to instruct the external terminal 401 to register the basic personal information (S250).
[0154] Upon receiving the registration instruction in step S250, the external terminal 401 generates and displays a two-dimensional code containing the basic personal information read in step S243 (S251). The two-dimensional code may include basic four-person information and facial image information. Alternatively, the two-dimensional code may include basic four-person information and facial feature quantities from which facial image information can be obtained.
[0155] The user launches the DIW application 50 (S252). If the DIW application 50 is not installed on the user terminal 10, the user may install the DIW application 50 by performing the process shown in Figure 13 above before step S252.
[0156] The DIW application 50 reads the two-dimensional code displayed on the external terminal 401 via the camera 14 (S253).
[0157] The DIW app 50 obtains basic personal information, including facial image information, from the scanned two-dimensional code (S254). This allows the DIW app 50 to obtain basic personal information, including facial image information, from the user's identification document read by the external terminal 401.
[0158] When the user has finished acquiring basic personal information using the DIW app 50, they perform a completion instruction operation on the external terminal 401 (S255).
[0159] Upon receiving the completion instruction in step S255, the external terminal 401 deletes the basic personal information read in step S243 from its memory (S256). Even if the external terminal 401 does not receive the completion instruction in step S255 from the user, it may delete the basic personal information from its internal memory after a certain period of time has elapsed. This prevents the basic personal information from remaining on the external terminal 401.
[0160] Then, the user, the DIW application 50, and the DIW cloud 20 execute the processes from steps S211 to S221 in Figure 10B.
[0161] Through the above process, users can register their personal information with the DIW application 50 and the DIW cloud 20 via the external terminal 401.
[0162] In step S251, instead of displaying a two-dimensional code, the external terminal 401 may establish wireless communication with the user terminal 10 (DIW application 50) and transmit basic personal information to the DIW application 50 via this wireless communication. The DIW application 50 may then acquire the basic personal information via wireless communication. The wireless communication may be NFC, Bluetooth®, or Direct Wi-Fi, etc. In this case, after acquiring the basic personal information, the DIW application 50 may send a completion notification to the external terminal 401, and upon receiving this completion notification, the external terminal 401 may delete the basic personal information from its internal memory.
[0163] Figure 16B is a sequence diagram showing a second example of the process continuing from Figure 14.
[0164] If the user confirms that there are no problems after viewing the basic personal information confirmation screen displayed in step S247 of Figure 14, they perform an operation to instruct the external terminal 401 to register the basic personal information (S261).
[0165] Upon receiving the registration instruction in step S261, the external terminal 401 transmits a URL creation request and the basic personal information read in step S243 to a designated server 402 (S261). The external terminal 401 may also transmit the basic personal information along with the URL creation request. The server 402 only needs to be connected to the communication network 5. Alternatively, the DIW cloud 20 may be used as the server 402.
[0166] Server 402 receives the request in step S261, temporarily stores the basic personal information, and creates a URL to retrieve the basic personal information (S262).
[0167] Server 402 sends the URL created in step S262 to the external terminal 401 (S263).
[0168] The external terminal 401 receives the URL in step S263, generates and displays a two-dimensional code containing the information of the URL (S264).
[0169] The user launches the DIW application 50 (S265). If the DIW application 50 is not installed on the user terminal 10, the user may install the DIW application 50 by performing the process shown in Figure 13 above before step S265.
[0170] The DIW application 50 reads the two-dimensional code displayed on the external terminal 401 via the camera 14 (S256).
[0171] The DIW application 50 accesses the URL contained in the scanned 2D code (S267).
[0172] Upon receiving the access, server 402 sends the temporarily stored basic personal information to the DIW application (S268). After sending the basic personal information to the DIW application 50, server 402 sends a completion notification to the external terminal 401 (S269). Then, server 402 deletes the temporarily stored basic personal information (S270). This prevents the basic personal information from remaining on server 402.
[0173] The DIW application 50 receives the basic personal information transmitted in step S268 (S271). This allows the DIW application 50 to obtain the basic personal information, including the facial image information of the user's identification document read by the external terminal 401.
[0174] Then, the user, the DIW application 50, and the DIW cloud 20 execute the processes from steps S211 to S221 in Figure 10B.
[0175] Through the above process, users can register their personal information with the DIW application 50 and the DIW cloud 20 via the external terminal 401.
[0176] Alternatively, instead of sending the URL to the external terminal 401 in step S263, the server 402 may send an email containing the URL to the user terminal 10 (DIW application 50). The DIW application 50 may then access the URL contained in the received email and obtain basic personal information from the server 402.
[0177] <Process for users to register for a new service> Figure 17A is a sequence diagram showing an example of the process for users to register for a new service according to Embodiment 1. Figure 17B is a sequence diagram showing the continuation of the process in Figure 17A. Figure 18 is a diagram showing an example of the available service list screen according to Embodiment 1. Figure 19 is a diagram showing an example of the service linkage consent screen according to Embodiment 1.
[0178] When the DIW application 50 receives a request from the user to display a list of new services (S301), it starts the following process.
[0179] The DIW application 50 extracts (or filters) services available to the user from the service master list 100B based on the user personal information record 110 (S302). For example, the DIW application 50 extracts (filters) services that satisfy the service usage conditions in the service master list 100B based on the attribute personal information in the user personal information record 110 as available services.
[0180] The DIW application 50 generates a list of available service IDs 120 from the list extracted in step S302 (S303).
[0181] As shown in Figure 18, the DIW application 50 displays the contents of the available service ID list 120 (e.g., service name, etc.) from step S303 on the screen (S304).
[0182] From the screen in step S304, the user selects a new service to register for (link) (S305).
[0183] The DIW app 50 displays a screen (S306) asking whether the user consents to provide the service provider of the service selected in step S305 with the personal attribute information requested by that service from the user's personal information record 110. At this time, as shown in Figure 19(a), the DIW app 50 displays personal attribute information that is required to be provided and personal attribute information that is optional to be provided, and the user may optionally select which personal attribute information to provide.
[0184] If the user agrees, they select "Agree" from the screen in step S306 (S307).
[0185] If "Agree" is selected in step S307, the DIW application 50 takes a picture of the user's face with the camera 14 of the user terminal 10 (S308) and acquires the captured face image information (S309). At this time, when the DIW application 50 takes a picture of the user's face, it may display a screen prompting the user to place their face within a predetermined frame, as shown in Figure 19(b).
[0186] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S309 to determine whether they belong to the same person (S310). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0187] If the DIW application 50 fails to perform the verification in step S310 (S311: NO), it displays a screen prompting for verification failure and / or reshooting (S312). Then, the process returns to step S308.
[0188] If the DIW application 50 succeeds in the verification in step S310 (S311: YES), it sends a request to the DIW cloud 20 for the assignment of a user ID for the service. The DIW cloud 20 receives the request (S313). The request may include the user's user ID and the service ID of the new service to be registered, which was selected in step S305 and agreed to by the user.
[0189] In response to the request received in step S313, the DIW Cloud 20 generates a service-specific user ID for the newly registered service (S314).
[0190] The DIW Cloud 20 sends the generated service user ID to the DIW application 50. The DIW application 50 receives the service user ID (S315).
[0191] The DIW application 50 associates the service ID of the newly registered service with the service user ID for that service and registers it in the list of agreed-upon service IDs 130 (S316).
[0192] The DIW application 50 extracts personal information to be provided to the service provider of the newly registered service from the user's personal information record 110 (hereinafter referred to as "provided personal information") (S317).
[0193] The DIW app 50 transmits the personal information extracted in step S316 and the user ID for the service to the service app 70 of the service to be newly registered (S318).
[0194] The service application 70 receives and stores the personal information provided in step S318 and the user ID for the service (S319). This allows the service application 70 to use the personal information provided by the user (e.g., address, age, etc.) and the user ID for the service.
[0195] The DIW app 50 transmits the information of the business operator that provided the personal information, along with the provided personal information, to the DIW cloud 20 (S320), and displays a service registration completion screen (S321).
[0196] DIW Cloud 20 receives the information of the business operator that provided the personal information in step S320, as well as the provided personal information, and stores it in the personal information provision log 220 (S322).
[0197] DIW Cloud 20 adds rows to the user-linked service list 210 for newly registered user IDs, business IDs, service IDs, and service-specific user IDs (S323).
[0198] Through the above processing, the service application 70 can hold personal attribute information necessary for using the service and a service-specific user ID assigned to that service. In addition, the DIW cloud 20 can manage information about services that a user newly registers for as a user-linked service list 210.
[0199] Note that the processing in steps S308 to S312 may be executed immediately after step S305.
[0200] (Embodiment 2) Embodiment 2 describes several examples in which a user utilizes a linked service after the processing described in Embodiment 1. Note that the contents of Embodiment 1 may be incorporated into Embodiment 2. Also, in Embodiment 2, components already described in Embodiment 1 are given common reference numbers and their descriptions may be omitted.
[0201] <Processing when using the local currency service app> Figure 20 is a sequence diagram showing an example of the processing when using the local currency service app 70 that has been registered for use according to Embodiment 2.
[0202] The user launches the local currency service app 70 (S401).
[0203] The service application 70 displays a list of service items related to the use of local currency on the screen (S402).
[0204] The user selects, for example, the "Local Currency Charge" service item from the list of service items displayed in step S402 (S403). At this time, the user may also enter the charge amount.
[0205] The service application 70 sends a facial recognition request to the DIW application 50. The DIW application 50 receives the facial recognition request (S404). The facial recognition request may include the business ID of the business providing the local currency service and the service ID of the service selected in step S403 (local currency service).
[0206] The DIW application 50 captures the user's face with the camera 14 of the user terminal 10 (S405) and acquires the captured face image information (S406).
[0207] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S406 to determine whether they belong to the same person (S407). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0208] If the DIW application 50 fails to perform the matching in step S407 (S408: NO), it displays a screen prompting for matching failure and / or reshooting (S409). Then, the process returns to step S405.
[0209] If the DIW application 50 succeeds in the matching in step S407 (S408: YES), it sends a facial recognition success notification to the DIW cloud 20. The DIW cloud 20 receives the facial recognition success notification (S410). The facial recognition success notification may include the business ID of the regional currency service provider, the service ID of the regional currency service selected in step S403, and the service user ID for the selected service.
[0210] The DIW Cloud 20 registers the contents of the facial recognition success notification received in step S409 in the personal information provision log 220 (S411). As a result, information about the service for which personal information was provided is registered in the personal information provision log 220.
[0211] Furthermore, if the DIW application 50 succeeds in the matching in step S407 (S408: YES), it sends a facial recognition success response to the service application 70 (S412). The facial recognition success response may include the user's personal attribute information obtained from the user personal information record 110.
[0212] The service application 70 receives a response indicating successful facial recognition in step S412 and sends a request for local currency charge to the electronic money issuing server 91. This request may include the charge amount. The electronic money issuing server 91 receives the request (S413).
[0213] In response to the request in step S413, the electronic money issuing server 91 sends a regional currency charge instruction to the service application 70 (S414). The regional currency charge instruction may include the charge amount.
[0214] The service application 70 receives the regional currency charge instruction in step S414 and charges the amount (S415). At this time, the service application 70 may display a charge completion screen.
[0215] This allows users to use local currency through the local currency service app 70. Furthermore, the service app 70 can prevent third parties from arbitrarily charging local currency by receiving a response from the DIW app 50 confirming successful facial recognition and then charging the local currency.
[0216] The above example described the process of topping up local currency, but similar procedures may be followed when using local currency or sending it to others. Furthermore, local currency is just one example; the above content also applies to various types of electronic money and points.
[0217] <Processing when using the vending machine> Figure 21A is a sequence diagram showing an example of the processing when using the vending machine 92 according to Embodiment 2. Figure 21B is a sequence diagram showing the continuation of the processing in Figure 21A. The vending machine 92 is an example of the service terminal 40 shown in Figures 1 and 2.
[0218] When a user begins using the vending machine 92 (S501), the vending machine 92 displays a two-dimensional code (for example, a QR code (registered trademark)) (S502). The two-dimensional code contains information indicating the business ID of the business operator managing the vending machine 92, the service ID of the service provided by the vending machine 92, and the device ID that identifies the vending machine 92. Note that the two-dimensional code is just an example; any image containing information will suffice.
[0219] The user launches the DIW application 50 (S503). The DIW application 50 uses the camera 14 of the user terminal 10 to read the two-dimensional code displayed in step S502 (S504).
[0220] The DIW application 50 establishes wireless communication (e.g., BLE) with the vending machine 92 (S505).
[0221] The DIW application 50 obtains the business operator ID, service ID, and device ID of the vending machine 92 from the information contained in the two-dimensional code read in step S504 (S506).
[0222] The DIW application 50 captures the user's face with the camera 14 of the user terminal 10 (S507) and acquires the captured face image information (S508).
[0223] The DIW app 50 checks whether the facial image information in the user personal information record 110 and the captured facial image information obtained in step S508 belong to the same person (S509). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0224] If the DIW application 50 fails to perform the verification in step S509 (S510: NO), it displays a screen prompting the user to retake the image due to the verification failure (S511). The DIW application 50 then terminates the process or returns to the process in step S507.
[0225] If the DIW application 50 succeeds in the matching in step S509 (S510: YES), it extracts specific personal information from the user personal information record 110 based on the service ID row obtained in step S506 of the service master list 100B (S512). For example, if the service usage conditions in the service ID row obtained in step S506 of the service master list 100B include an age condition, the DIW application 50 extracts specific personal information including the user's age from the user personal information record 110.
[0226] The DIW application 50 transmits a service request, including the result of the successful matching and the user's specific personal information extracted in step S512, to the vending machine 92 via the wireless communication established in step S505 (S513).
[0227] The vending machine 92 receives the service usage request in step S513 and displays the result of the successful matching and the acquired specific personal information (S514).
[0228] The vending machine 92 determines whether or not a user can use the service based on specific personal information (S515). For example, if the service usage condition is that the user must be 20 years of age or older, the vending machine 92 determines that the user can use the service if the age indicated by the specific personal information is 20 years of age or older, and that the user cannot use the service if the age indicated by the specific personal information is under 20 years of age.
[0229] If the vending machine 92 determines in step S515 that the service is unavailable (S516: NO), it displays a screen indicating that the service is unavailable (S517) and terminates this process.
[0230] If the vending machine 92 determines in step S515 that the service is available (S516: YES), it provides the user with the service (for example, a product that can be purchased by someone 20 years of age or older) (S518).
[0231] Furthermore, if the vending machine 92 determines in step S515 that the service is available (S516: YES), it transmits service provision information to the service provider server 30 (S519). The service provision information may include the device ID and the details of the service provided (for example, information about the products provided to the user).
[0232] The service provider server 30 receives the service provision information in step S519 and manages the contents of that service provision information (S520). This allows the service provider server 30 to manage which service (product) was provided from which vending machine 92.
[0233] Furthermore, if the vending machine 92 determines in step S515 that the service is available (S516: YES), it sends a service availability response to the DIW application 50 (S521).
[0234] The DIW application 50 receives the response from step S521 and displays a screen indicating that the service is available (S522).
[0235] The DIW application 50 transmits service usage information to the DIW cloud 20 (S523). The service usage information may include the business ID of the vending machine 92 and specific personal information (or personal attribute information) provided to the vending machine 92.
[0236] The DIW Cloud 20 receives the service usage information in step S523 and stores its contents in the personal information provision log 220 (S524). This allows the DIW Cloud 20 to manage which specific personal information (or personal attribute information) it has provided to which business operator. In addition, users can check the personal attribute information they have provided to business operators by referring to the information stored in the personal information provision log 220 through the DIW app 50.
[0237] Through the above process, the vending machine 92 can verify the user's personal attribute information (e.g., age) through the DIW app 50 and determine whether or not to provide the service depending on whether the personal attribute information meets the service usage conditions.
[0238] <Processing when using the evacuation center authentication terminal (first example)> Figure 22A is a sequence diagram showing an example of the process of performing personal authentication using the DIW application 50 on the evacuation center authentication terminal 93 according to Embodiment 2. Figure 22B is a sequence diagram showing the continuation of the process in Figure 22A. The evacuation center authentication terminal 93 is an example of the service terminal 40 shown in Figures 1 and 2. Figures 22A and 22B describe the case in which the evacuation center authentication terminal 93 does not have a camera 43 and authentication function.
[0239] When a user begins using the evacuation center authentication terminal 93 installed at the evacuation center (S601), the evacuation center authentication terminal 93 displays a two-dimensional code (S602). The two-dimensional code contains information indicating the business ID of the local government managing the evacuation center authentication terminal 93, the service ID corresponding to this evacuation, and the device ID that identifies the evacuation center authentication terminal 93. Note that the two-dimensional code is just an example; any image containing information will suffice.
[0240] The user launches the DIW application 50 (S603). The DIW application 50 uses the camera 14 of the user terminal 10 to read the two-dimensional code displayed in step S602 (S604).
[0241] The DIW application 50 uses the communication setting information read from the two-dimensional code to establish wireless communication (e.g., BLE) with the evacuation center authentication terminal 93 (S605).
[0242] The DIW application 50 obtains the business ID, service ID, and device ID of the evacuation center authentication terminal 93 from the information contained in the two-dimensional code read in step S604 (S606).
[0243] The DIW application 50 captures the user's face with the camera 14 of the user terminal 10 (S607) and acquires the captured face image information (S608).
[0244] The DIW app 50 checks whether the facial image information in the user personal information record 110 and the captured facial image information obtained in step S608 belong to the same person (S609). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0245] If the DIW application 50 fails to perform the verification in step S609 (S610: NO), it displays a screen prompting the user to retake the image due to the verification failure (S611). The DIW application 50 then terminates the process or returns to the process in step S607.
[0246] If the DIW application 50 succeeds in the verification in step S609 (S610: YES), it sends the verification success result to the evacuation center authentication terminal 93 (S612).
[0247] The evacuation center authentication terminal 93 receives the verification success result from step S612 and displays the verification success result (S613).
[0248] The evacuation center authentication terminal 93 sends a request for the user's personal attribute information to the DIW application 50 (S614). This request may include the business operator ID, service ID, and device ID.
[0249] The DIW application 50 receives the request in step S614 and extracts at least some personal attribute information (e.g., name and address, etc.) from the user personal information record 110 based on the service ID row obtained in step S606 of the service master list 100B (S615).
[0250] The DIW application 50 transmits the user's personal attribute information and evacuation center admission information to the evacuation center authentication terminal 93 (S616). The evacuation center admission information may include the business ID and the device ID.
[0251] The evacuation shelter authentication terminal 93 receives the information from step S616 and displays a screen for guiding users into the evacuation shelter (S617). The evacuation shelter authentication terminal 93 provides the user with services related to evacuation (S618).
[0252] If the communication network is down due to a disaster or other reason, processing will be terminated here, and the following processing may be carried out after the communication network is restored.
[0253] The DIW application 50 transmits service usage information to the DIW cloud 20 (S619). The service usage information may include the carrier ID and the device ID.
[0254] The DIW Cloud 20 receives the service usage information in step S619 and stores the contents of the service usage information in the personal information provision log 220 (S620). This allows the user to check when, where, and what kind of personal attribute information they provided to the service provider by referring to the information stored in the personal information provision log 220 through the DIW app 50.
[0255] The evacuation center authentication terminal 93 transmits the user's personal attribute information and evacuation center admission information to the service provider server 30 managed by the local government (S621).
[0256] The operator server 30 receives the information from step S621 and stores and manages that information (S622). Based on the information managed in step S622, the operator server 30 creates a list of evacuation shelters indicating which person is in which shelter (S623).
[0257] Through the above process, local governments can manage which individuals evacuated to which shelters.
[0258] <Processing when using the evacuation shelter authentication terminal (second example)> Figure 23A is a sequence diagram showing an example of the process of performing personal authentication on the evacuation shelter authentication terminal 93 according to Embodiment 2 without using the DIW application 50. Figure 23B is a sequence diagram showing the continuation of the process in Figure 23A. The evacuation shelter authentication terminal 93 is an example of the service terminal 40 shown in Figures 1 and 2. Figures 23A and 23B describe the case in which the evacuation shelter authentication terminal 93 has a camera 43 and does not have an authentication function.
[0259] When a user begins using the evacuation center authentication terminal 93 installed at the evacuation center (S701), the evacuation center authentication terminal 93 displays a screen prompting facial recognition (S702).
[0260] The evacuation center authentication terminal 93 captures the user's face with the camera 43 (S703) and acquires the captured facial image information (S704).
[0261] The evacuation center authentication terminal 93 sends a face recognition request to the DIW cloud 20 (S705). The face recognition request may include the captured face image information obtained in step S704, the business ID of the local government managing the evacuation center authentication terminal 93, the service ID corresponding to the current evacuation, and the device ID that identifies the evacuation center authentication terminal 93.
[0262] The DIW Cloud 20 receives the face matching request in step S705 and compares the captured face image information included in the face matching request with the face image information of all users included in the integrated personal information master list 200 (i.e., a one-to-many match) (S706). In other words, the DIW Cloud 20 determines whether or not the same person as the captured face image information exists in the integrated personal information master list 200.
[0263] In step S706, if the captured facial image information fails to match with any of the facial image information in the integrated personal information master list 200 (i.e., if the one-to-many matching fails) (S707: NO), the DIW Cloud 20 displays a screen indicating the matching failure on the evacuation center authentication terminal 93 (S708). Then, the DIW Cloud 20 terminates this process or returns to step S703.
[0264] In step S706, if the captured facial image information is successfully matched with one facial image information in the integrated personal information master list 200 (i.e., a one-to-many match is successful) (S707: YES), the DIW cloud 20 transmits the successful match result to the evacuation center authentication terminal 93 (S709).
[0265] The evacuation center authentication terminal 93 receives the verification success result from step S708 and displays a screen indicating that the verification success result and the user's personal information will be used (S710).
[0266] The evacuation center authentication terminal 93 sends a request for the user's personal information to the DIW cloud 20 (S711). This request may include the business ID, service ID, and device ID.
[0267] The DIW Cloud 20 receives the request in step S711 and extracts at least some of the personal attribute information (e.g., name and address) of the user who succeeded in the matching in step S707 from the Integrated Personal Information Master List 200 (S712).
[0268] The DIW cloud 20 sends a response to the request in step S711 to the evacuation center authentication terminal 93 (S713). This response may include at least some of the user's personal attribute information extracted in step S712, as well as the business operator ID, service ID, and device ID.
[0269] The DIW cloud 20 stores the response content and authentication result from step S713 in the personal information provision log 220 (S714).
[0270] The evacuation center authentication terminal 93 receives the response from step S713 and transmits the user's personal attribute information and evacuation center admission information to the service provider server 30 managed by the local government (S715). The evacuation center admission information may include the service provider ID and the device ID.
[0271] The evacuation shelter authentication terminal 93 displays a screen for guiding people into the evacuation shelter (S716).
[0272] The operator server 30 receives, retains, and manages the information from step S715 (S717). Based on the information from step S714, the operator server 30 creates a list of evacuation shelters indicating which person is in which shelter (S718).
[0273] Through the above process, local governments can manage which individuals evacuated to which shelters.
[0274] <Processing when using a facial recognition payment terminal> Figure 24A is a sequence diagram showing an example of the process of performing personal authentication on the facial recognition payment terminal 94 according to Embodiment 2. Figure 24B is a sequence diagram showing the continuation of the process in Figure 24A. The facial recognition payment terminal 94 is an example of the service terminal 40 shown in Figure 1. Figures 24A and 24B describe the case in which the facial recognition payment terminal 94 has a camera 43 and has an authentication function.
[0275] When a user begins using the facial recognition payment terminal 94 (S801), the facial recognition payment terminal 94 displays a screen prompting the user to scan the two-dimensional code with the DIW application 50 (S802). Note that the two-dimensional code is just an example; any image containing information will suffice.
[0276] The user launches the DIW application 50 and reads the two-dimensional code in step S802 with the camera 14 of the user terminal 10 (S803).
[0277] The DIW app 50 establishes wireless communication (e.g., BLE) with the facial recognition payment terminal 94 using communication setting information read from the two-dimensional code (S804).
[0278] The facial recognition payment terminal 94 transmits a request for facial image information to the DIW application 50 via wireless communication (S805).
[0279] The DIW application 50 receives the request in step S805 and obtains consent from the user to provide facial image information (S806).
[0280] The DIW application 50 extracts facial image information from the user personal information record 110 (S807).
[0281] The DIW app 50 transmits the facial image information extracted in step S807 to the facial recognition payment terminal 94. The facial recognition payment terminal 94 receives the facial image information (S808).
[0282] The facial recognition payment terminal 94 captures the user's face with the camera 43 (S809) and acquires the captured facial image information (S810).
[0283] The facial recognition payment terminal 94 checks whether the facial image information received in step S808 and the captured facial image information acquired in step S809 belong to the same person (S811). In other words, the facial recognition payment terminal 94 determines whether the user captured by the camera 43 is the person whose facial image information was provided by the DIW application 50.
[0284] If the facial recognition payment terminal 94 fails to perform the verification in step S811 (S812: NO), it displays a screen indicating that the facial verification failed (S813). The facial recognition payment terminal 94 then terminates the process or returns to step S809.
[0285] If the facial recognition payment terminal 94 succeeds in matching in step S811 (S812: YES), it displays a screen indicating that facial recognition was successful (S814).
[0286] The facial recognition payment terminal 94 sends a request for the user's personal information to the DIW application 50 (S815). This request may include the business ID, service ID, and terminal ID.
[0287] The DIW application 50 receives the request in step S814 and extracts the user's specific personal information from the user personal information record 110 (S816). This specific personal information includes the user's age.
[0288] The DIW app 50 transmits the specific personal information extracted in step S816 to the facial recognition payment terminal 94 (S817).
[0289] The DIW application 50 also sends the content of step S817 to the DIW cloud 20 (S818). The DIW cloud 20 receives the content and stores it in the personal information provision log 220 (S819).
[0290] The facial recognition payment terminal 94 receives the specific personal information in step S817 and determines whether the user can make a payment based on that specific personal information (S820). For example, if the age included in the specific personal information is under 20 years old, the facial recognition payment terminal 94 determines that payment is not possible, and if the age included in the specific personal information is 20 years old or older, it determines that payment is possible.
[0291] If the facial recognition payment terminal 94 determines in step S820 that payment is not possible (S821: NO), it displays a screen indicating that payment is not possible (S822) and terminates this process.
[0292] If the facial recognition payment terminal 94 determines in step S820 that payment is possible (S821: YSE), it sends a payment processing request to the business server 30 (S823).
[0293] The service provider server 30 receives the request in step S823 and processes the payment (S824). The service provider server 30 sends a payment completion response to the facial recognition payment terminal 94 (S825).
[0294] The facial recognition payment terminal 94 transmits service provision information to the business operator server 30 (S826). The service provision information may include a payment terminal ID that identifies the facial recognition payment terminal 94 and the details of the service provided.
[0295] The service provider server 30 receives the service provision information in step S826 and manages the service provision information (S827).
[0296] Through the above process, the facial recognition payment terminal 94 can determine whether or not to approve a payment based on the user's specific personal information (or personal attribute information) provided from the DIW application 50.
[0297] Furthermore, the following are examples of how users can utilize linked services: (1) Silver Pass (an example of Service App 70) works in conjunction with DIW App 50 to verify the user's identity, and if the verification is successful, discounts are applied. (2) Library Pass (an example of Service App 70) available to users works in conjunction with DIW App 50 to verify the user's identity, and if the verification is successful, users can reserve, borrow, or return books. (3) Bank Pass (an example of Service App 70) works in conjunction with DIW App 50 to verify the user's identity, and if the verification is successful, users can open an account or perform various procedures. (4) Online services work in conjunction with DIW App 50 to verify the user's identity, and if the verification is successful, users can perform online payments, deposits, reservations, or membership registration. (5) The monitoring service works in conjunction with DIW App 50 to verify the parent's identity, and if the parent's identity is successful, information about the elderly person's family and children is provided. In other words, users can receive monitoring services.
[0298] (Embodiment 3) Embodiment 3 describes the process when personal information is changed after the process described in Embodiment 1. Note that the contents of Embodiments 1 and 2 may be incorporated into Embodiment 3. Also, in Embodiment 3, components that have already been described in Embodiment 1 are given a common reference number and their description may be omitted.
[0299] <Process for reflecting updated identification documents in the DIW application> Figure 25A is a sequence diagram showing an example of the process for reflecting updated identification documents in the DIW application 50 according to Embodiment 3. Figure 25B is a sequence diagram showing the continuation of the process in Figure 25A. Figure 26 is a diagram for explaining the update of the user personal information record 110 according to Embodiment 3.
[0300] The user launches the DIW app 50 (S1001) and instructs the DIW app 50 to update the identification document (S1002).
[0301] The DIW app 50 displays the terms of service screen (S1003).
[0302] Once the user agrees to the terms of service (S1004), the DIW app 50 displays a screen for reading the identification document (see Figure 11) (S1005).
[0303] The DIW application 50 reads basic personal information from the updated identification document provided by the user (S1006). The reading method is the same as in step S205 in Figure 10A.
[0304] The DIW application 50 captures the user's face with the camera 14 of the user terminal 10 (S1007) and acquires the captured face image information (S1008).
[0305] The DIW app 50 checks whether the facial image information read from the updated identification document in step S1006 and the captured facial image information obtained in step S1008 belong to the same person (S1009). In other words, the DIW app 50 determines whether the user whose face was photographed is the person on the updated identification document.
[0306] If the DIW application 50 fails to perform the verification in step S1009 (S1010: NO), it displays a screen prompting for verification failure and / or reshooting (S1011), and returns to step S1007.
[0307] If the DIW application 50 succeeds in the matching in step S1009 (S1010: YES), it displays "Matching successful" and the basic personal information obtained in step S1006 on the screen (S1012).
[0308] The DIW app 50 displays a screen for entering additional personal information (see Figure 12) (S1013).
[0309] The user enters additional personal information on the additional personal information input screen. The DIW app 50 also displays previously entered additional personal information on the additional personal information input screen, and the user may update only the parts that need updating. The DIW app 50 then acquires the entered additional personal information (S1014).
[0310] The DIW app 50 extracts or calculates the user's specific personal information based on the basic personal information obtained from the identification document (S1015).
[0311] The DIW app 50 reintegrates the basic personal information (including facial image information) obtained from the updated identification document, the additional personal information entered (modified) by the user, and the specific personal information extracted in step S1015, and updates the user personal information record 110 held in the data management unit 60 (S1016). As a result, the contents of the updated identification document are reflected in the user personal information record 110.
[0312] For example, if a user's surname changes due to marriage or other reasons, as shown in Figure 26, the name in the basic personal information of the user's personal information record 110 will be updated from "Yamada" to "Yamamoto," and the phonetic spelling of the surname in the additional personal information will be updated from "Yamada" to "Yamamoto." For example, if a user moves from "Adachi Ward, Tokyo" to "Shinagawa Ward, Tokyo," as shown in Figure 26, the address in the basic personal information of the user's personal information record 110 will be updated from "Adachi Ward, Tokyo" to "Shinagawa Ward, Tokyo," and accordingly, the residential area in the specific personal information will be updated from "Adachi Ward" to "Shinagawa Ward."
[0313] The DIW application 50 sends the user personal information record 110, which was updated in step S1015, along with the user ID to the DIW cloud 20 (S1017).
[0314] The DIW Cloud 20 receives the updated user personal information record 110 and user ID, and updates the row in the integrated personal information master list 200 corresponding to the user ID with the contents of the updated user personal information record 110 (S1018).
[0315] Through the above process, when an identity document is updated, the updated information can be reflected in the user personal information record 110 of the DIW application 50 and the integrated personal information master list 200 of the DIW cloud 20.
[0316] <Processing when service availability changes due to identity document renewal> Figure 27A is a sequence diagram showing an example of processing when service availability changes due to identity document renewal according to Embodiment 3. Figure 27B is a sequence diagram showing the continuation of the processing in Figure 27A. Figure 28 is a diagram for explaining the extraction of services that have become available or unavailable due to identity document renewal according to Embodiment 3.
[0317] The DIW application 50 obtains the service master list 100A from the DIW cloud 20 and stores it in the data management unit 60 as the service master list 100B (S1101).
[0318] Based on the user's personal information record 110, the DIW application 50 extracts (or filters) the services available to the user from the service master list 100B obtained in step S1101 (S1102).
[0319] The DIW application 50 generates a list of available service IDs 120 from the list extracted in step S1102 (S1103).
[0320] The DIW application 50 displays the contents of the available service ID list 120 from step S1103 on the screen (S1104). At this time, if there are any services that have become unavailable, the DIW application 50 may display those services as unavailable on the screen.
[0321] For example, if a user moves from Adachi Ward to Shinagawa Ward, as shown in Figure 28, services in Adachi Ward become unavailable, while services in Shinagawa Ward become available. In this case, in step S1104, services in Shinagawa Ward are displayed as available services, and services in Adachi Ward are displayed as unavailable services. Services that remain available before and after the move are also displayed.
[0322] Furthermore, if the user agrees to unlink the Adachi Ward service that has become unavailable (for example, if the user presses the unlink button on the screen displaying the unavailable service and the user's face is successfully verified), the following process may be performed. Specifically, the DIW app 50 sends a request to unlink the unavailable service to the DIW cloud 20. The DIW cloud 20 receives the request to unlink and sends a request to the business server 30 managed by Adachi Ward to dispose of the user's personal information. The business server 30 receives the disposal request and disposes of the user's personal information. After disposal, the business server 30 sends a notification of completion of unlinking to the DIW cloud 20, and if the DIW cloud 20 receives the notification of completion of unlinking, it may send the notification of completion of unlinking to the DIW app 50. When the DIW app 50 receives the notification that the unlinking process has been completed, it may display on the screen that the unlinking process has been completed for the service that the user agreed to unlink (i.e., that the service provider (Adachi Ward) has discarded the user's personal information). This allows the user to confirm that the personal information they provided to a service has been discarded if that service becomes unavailable.
[0323] The user looks at the screen displayed in step S1104 and selects the service they wish to register for (S1105).
[0324] The DIW app 50 displays a screen (S1106) asking whether the user consents to provide the service provider of the service selected in step S1105 with the personal attribute information requested by that service in the user's personal information record 110.
[0325] If the user agrees, they select "Agree" from the screen in step S1106 (S1107).
[0326] If "Agree" is selected in step S1107, the DIW app 50 takes a picture of the user's face with the camera 14 of the user terminal 10 (S1108) and obtains the captured face image information (S1109).
[0327] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S1109 to determine whether they belong to the same person (S1110). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0328] If the DIW application 50 fails to perform the verification in step S1110 (S1111: NO), it displays a screen prompting for verification failure and / or reshooting (S1112). Then, the process returns to step S1108.
[0329] If the DIW application 50 succeeds in the matching in step S1110 (S1111: YES), it extracts the updated personal attribute information to be provided from the updated user personal information record 110 (S1113).
[0330] The DIW app 50 sends the updated personal attribute information extracted in step S1113 to the service app 70 of the service that the user wants to register for (S1114). This allows the service app 70 to use the user's updated personal attribute information (e.g., address, age, etc.).
[0331] The DIW app 50 transmits the information of the business operator that provided the updated personal attribute information, along with the updated personal attribute information, to the DIW cloud 20 (S1115). Then, the DIW app 50 displays that registration is complete (S1116).
[0332] The service application 70 receives the updated personal attribute information from step S1114 and updates the personal information it holds (S1117).
[0333] The DIW Cloud 20 receives the updated personal attribute information from step S1115 and stores it in the personal information provision log 220 (S1118).
[0334] DIW Cloud 20 updates the user-linked service list 210 with the received updated personal attribute information (S1119).
[0335] Through the above process, users can recognize which services have become available or unavailable due to the renewal of their identification document, and register for new services as needed.
[0336] <Process to update services that become available or unavailable due to the user's age> Figure 29A is a sequence diagram showing an example of the process to update services that become available or unavailable due to the user's age according to Embodiment 3. Figure 29B is a sequence diagram showing the continuation of the process in Figure 29A. Figure 30 is a diagram for explaining the process to update services that become available or unavailable due to the user's age according to Embodiment 3.
[0337] The process shown in Figure 29A may be started when the DIW Cloud 20 checks checkpoints such as age conditions using a daily batch or the like, and detects a status change (age update in this embodiment).
[0338] The DIW application 50 obtains the service master list 100A from the DIW cloud 20 and stores it in the data management unit 60 as the service master list 100B (S1201).
[0339] Based on the user's personal information record 110, the DIW application 50 extracts (or filters) the services available to the user from the service master list 100B obtained in step S1201 (S1202).
[0340] The DIW application 50 generates a list of available service IDs 120 from the list extracted in step S1202 (S1203).
[0341] The DIW application 50 displays the contents of the available service ID list 120 from step S1203 on the screen (S1204). At this time, if there are any services that have become unavailable, the DIW application 50 may display those services as unavailable on the screen. For example, if the user's age increases from 19 to 20, as shown in Figure 30, services for users under 20 become unavailable, and services for users 20 and over become available. In this case, in step S1204, services for users 20 and over are displayed as available services, and services for users under 20 are displayed as unavailable services. Services that can be used continuously regardless of age are also displayed.
[0342] If any services become unavailable, the DIW application 50 sends a request to the DIW cloud 20 to unlink the unavailable services, after obtaining the user's consent (S1205). At this time, the DIW application 50 performs facial recognition of the user, and if the facial recognition is successful, it may unlink the services, assuming that the user's consent has been obtained.
[0343] When DIW Cloud 20 receives a request to unlink in step S1205, it unlinks the service from the user-linked service list 210 (S1206). At this time, DIW Cloud 20 sends a request to the service provider server 30 of the service provider that provides the service that has become unavailable to dispose of the user's personal information. The service provider server 30 receives the disposal request and disposes of the user's personal information. After disposal, the service provider server 30 sends a notification of completion of unlinking to DIW Cloud 20, and if DIW Cloud 20 receives the notification of completion of unlinking, it may send the notification to DIW App 50. If DIW App 50 receives the notification of completion of unlinking, it may display on the screen that the unlinking has been completed for the service that the user agreed to unlink (i.e., that the service provider has disposed of the user's personal information). This allows the user to confirm that the personal information they provided to a service has been disposed of when the service becomes unavailable.
[0344] The user looks at the screen displayed in step S1204 and selects the service they wish to register for from the newly available services (S1207).
[0345] The DIW app 50 displays a screen (S1208) asking whether the user consents to provide the service provider of the service selected in step S1207 with the personal attribute information requested by that service in the user's personal information record 110.
[0346] If the user agrees, they select "Agree" from the screen in step S1208 (S1209).
[0347] If "Agree" is selected in step S1209, the DIW app 50 takes a picture of the user's face with the camera 14 of the user terminal 10 (S1210) and obtains the captured face image information (S1211).
[0348] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S1211 to determine whether they belong to the same person (S1212). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0349] If the DIW application 50 fails to perform the verification in step S1212 (S1213: NO), it displays a screen prompting the user to retake the image due to the verification failure (S1214). The process then returns to step S1210.
[0350] If the DIW application 50 succeeds in the matching in step S1212 (S1213: YES), it extracts the updated personal attribute information to be provided from the updated user personal information record 110 (S1215).
[0351] The DIW app 50 transmits the updated personal attribute information extracted in step S1215 to the service app 70 of the service that the user wishes to register for (S1216). This allows the service app 70 to use the user's updated personal attribute information (e.g., address, age, etc.).
[0352] The DIW app 50 transmits the information of the business operator that provided the updated personal attribute information, along with the updated personal information provided, to the DIW cloud 20 (S1217). The DIW app 50 then displays a message indicating that registration is complete (S1218).
[0353] The service application 70 receives the updated personal attribute information from step S1216 and updates the personal information using the updated personal attribute information (S1219).
[0354] The DIW Cloud 20 receives the updated personal attribute information from step S1216 and stores it in the personal information provision log 220 (S1220).
[0355] DIW Cloud 20 updates the user-linked service list 210 with the received updated personal attribute information (S1221).
[0356] Through the above process, users can recognize which services have become available or unavailable due to their age, and register for new services as needed.
[0357] <Processing when a business operator changes personal attribute information used for service provision> Figure 31A is a sequence diagram showing an example of processing when a business operator changes (including adding) personal attribute information used for a service according to Embodiment 3. Figure 31B is a sequence diagram showing the continuation of the processing in Figure 31A. Figure 32 is a diagram for explaining the change of personal attribute information used for a service operator according to Embodiment 3.
[0358] The service provider server 30 determines the modified personal attribute information to be used for the service, the purpose of use, and the terms of use (S1301). For example, as shown in Figure 32, the service provider changes the service to newly use "age," which is one of the personal attribute information (or specific personal information).
[0359] The service provider server 30 transmits the information determined in step S1301 to the DIW cloud 20. The DIW cloud 20 receives this information and obtains the modified personal attribute information, purpose of use, and terms of use, etc., to be used for service provision (S1302).
[0360] The DIW Cloud 20 transmits to the DIW App 50 the modified personal attribute information, purpose of use, and terms of use used for service provision, which were obtained in step S1302 (S1303).
[0361] The DIW application 50 receives the information from step S1403 and, based on that information, displays a screen for consenting to the purpose of use and terms of use (S1304).
[0362] The user looks at the screen in step S1304 and enters "Agree" if they wish to continue using the service (S1305). If the user does not wish to continue using the service and enters "Disagree", the DIW application 50 may coordinate with the DIW cloud 20, etc., to perform a process to cancel the user's registration for the service.
[0363] If "Agree" is entered in step S1305, the DIW app 50 displays a screen (S1306) asking whether the user agrees to provide the service provider with the modified personal attribute information used for the service. For example, as shown in Figure 32, if "age," which is one of the personal attribute information (or specific personal information), is to be newly used for the service, the DIW app 50 displays a screen in step S1306 asking whether the user agrees to provide the service provider with the new "age" information.
[0364] If the user agrees, they select "Agree" from the screen in step S1306 (S1307).
[0365] If "Agree" is selected in step S1307, the DIW app 50 takes a picture of the user's face with the camera 14 of the user terminal 10 (S1308) and obtains the captured face image information (S1309).
[0366] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S1310 to determine whether they belong to the same person (S1310). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0367] If the DIW application 50 fails to perform the verification in step S1310 (S1311: NO), it displays a screen prompting for verification failure and / or reshooting (S1312). Then, the process returns to step S1308.
[0368] If the DIW application 50 succeeds in the matching in step S1310 (S1311: YES), it extracts the modified personal attribute information to be provided from the user personal information record 110 (S1313).
[0369] The DIW application 50 sends the modified personal attribute information extracted in step S1313 to the service application 70, which has changed the personal attribute information it uses (S1314). This allows the service application 70 to use the modified personal attribute information. The modified personal attribute information sent in step S1314 may include only the changed parts (only the differences). For example, if only the surname has been changed, the modified personal attribute information may include only the changed "full name" and "surname phonetic spelling". For example, if only the "address" has been changed, the modified personal attribute information may include only the changed "address". Alternatively, the modified personal attribute information sent in step S1314 may include all of the changed and unchanged parts.
[0370] The DIW app 50 transmits the information of the business operator that provided the modified personal attribute information, along with the modified personal attribute information, to the DIW cloud 20 (S1315). The DIW app 50 then displays that the modification is complete (S1316). The modified personal information transmitted in step S1314 may also include only the modified parts, or it may include all parts, both modified and unchanged, as described above.
[0371] The service application 70 receives the modified personal attribute information from step S1314 and updates the personal information with the modified personal attribute information (S1317).
[0372] The DIW cloud 20 receives the modified personal attribute information from step S1315 and stores it in the personal information provision log 220 (S1318).
[0373] DIW Cloud 20 updates the user-linked service list 210 with the received modified personal attribute information (S1319).
[0374] Through the above process, if a service provider changes the personal attribute information used for the service, they can obtain the user's consent, provide the user's updated personal attribute information to the service application 70, and manage it in the DIW cloud 20.
[0375] <Processing when personal information of a service application is changed using a DIW application> Figure 33A is a sequence diagram showing an example of the processing when personal information of a service application 70 according to Embodiment 3 is changed using a DIW application 50. Figure 33B is a sequence diagram showing the continuation of the processing shown in Figure 33A. Figure 34A is a diagram showing a first example screen of the service application 70 in the processing shown in Figures 33A and 33B according to Embodiment 3. Figure 34B is a diagram showing a screen example of the DIW application 50 in the processing shown in Figures 33A and 33B according to Embodiment 3. Figure 34C is a diagram showing a second example screen of the service application 70 in the processing shown in Figures 33A and 33B according to Embodiment 3.
[0376] The user selects the menu 301 for the personal attribute information to be changed from the screen of the service app 70 (S1401). For example, if the service app 70 is a banking app and the user wants to change the address and phone number registered with the bank, the user selects the menu 301 for changing the address and phone number from the banking app, as shown in Figure 34A(a).
[0377] The service app 70 displays currently registered personal information corresponding to the personal attribute information to be changed selected in step S1401 (S1402). For example, the banking app displays the registered address and telephone number, as shown in Figure 34A(b).
[0378] When a user presses (touches) the "Change" button 302 on the screen of the service app 70 shown in Figure 34A(b), the service app 70 displays the personal attribute information it requests from the DIW app 50, as shown in Figure 34A(c) (S1403). For example, the bank app displays that the information linked from the DIW app 50 (i.e., the information to be changed) is the address and telephone number, as shown in Figure 34A(c).
[0379] When a user presses (touches) the "Launch DIW app" button 303 on the screen shown in Figure 34A(c), the service app 70 sends a command to the DIW app 50 to launch the DIW app 50 and the requested personal attribute information (S1404).
[0380] The DIW application 50 receives the startup instruction in step S1404 and starts up (S1405).
[0381] As shown in Figure 34B(a), the DIW app 50 displays a screen (S1406) confirming that it will share (link) personal information (e.g., address and telephone number) corresponding to the requested personal attribute information with the requesting service app 70 (e.g., a banking app). As shown in Figure 34B(a), the screen may display the name of the requesting service app 70, the purpose of using the personal information, and the personal attribute information to be shared. The screen shown in Figure 34B(a) may also display the type of identification document (e.g., My Number Card).
[0382] When a user presses (touches) the "Recognize Face and Share" button 304 on the screen shown in Figure 34B(a), the DIW application 50 takes a picture of the user's face with the camera 14 of the user terminal 10 (S1407) and acquires the captured face image information (S1408), as shown in Figure 34B(b).
[0383] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S1409 to determine whether they belong to the same person (S1409). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0384] If the DIW application 50 fails to perform the verification in step S1410 (S1410: NO), it displays a screen prompting for verification failure and / or reshooting (S1411). Then, the process returns to step S1407.
[0385] If the DIW application 50 succeeds in the matching in step S1409 (S1410: YES), it extracts personal information corresponding to the personal attribute information requested in step S1404 from the user personal information record 110 (S1412).
[0386] As shown in Figure 34B(c), the DIW application 50 displays a confirmation screen (S1413) to share the personal information extracted in step S1412 with the service application 70. If the telephone number, etc., shown in Figure 34B(c) is manually entered information, the user may manually change the telephone number, etc., from the screen of the DIW application 50 shown in Figure 34B(c). In this case, the telephone number, etc., in the user personal information record 110 may also be changed. Alternatively, the user may manually change the telephone number, etc., from the service application 70.
[0387] If the user presses (touches) the "Cancel" button 305 from the confirmation screen in step S1413 (S1414: NO), the DIW application 50 may terminate this process without sharing personal information.
[0388] If the user presses (touches) the "Share" button 306 from the confirmation screen in step S1413 (S1414: YES), the DIW application 50 executes the following process. That is, the DIW application 50 sends the personal information extracted in step S1412 to the service application 70 as personal information corresponding to the personal attribute information requested in step S1404 (S1415), and then sends information regarding the personal information sent to the service application 70 to the DIW cloud 20 (S1416). This information regarding personal information includes, for example, the service ID corresponding to the service application 70 and the personal attribute information provided.
[0389] The DIW cloud 20 receives the information from step S1416 and records it in the personal information provision log 220 (S1417).
[0390] The service application 70 receives the personal information in step S1415 and displays a verification completion screen as shown in Figure 34C(a). When the user presses (touches) the "Next" button 307 on the completion screen shown in Figure 34C(a), the service application 70 then displays the registered personal information and the personal information received in step S1415 (i.e., the modified personal information) as shown in Figure 34C(b) (S1418). On this screen, the user may further modify the displayed personal information or enter additional personal information. For example, as shown in Figure 34C(b), the service application 70 may display the modified address and telephone number obtained from the DIW application 50 in an editable text box.
[0391] When the user presses (touches) the "Next" button 308 on the screen shown in Figure 34C(b), the service application 70 modifies the registered personal information with the personal information from step S1415 and displays a change completion screen as shown in Figure 34C(c) (S1419).
[0392] The service application 70 sends the modified personal information to the service provider server 30 (S1420). The service provider server 30 updates the registered personal information with the modified personal information sent from the service application 70 (S1421).
[0393] Examples of service apps 70 include banking apps for using banking services, securities apps for using securities services, insurance apps for using insurance services, and online shopping apps for using online shops.
[0394] Furthermore, the user personal information record 110 of the DIW app 50 may also hold personal information such as bank account numbers, securities account numbers, insurance policy numbers, credit card numbers, and a designated service common ID, in addition to the personal information described above. The service app 70 may request the user personal information recorded in the user personal information record 110 from the DIW app 50. In this case, the DIW app 50 may perform the facial recognition described above, and if the facial recognition is successful, it may provide the requested personal information to the service app 70.
[0395] Through the above process, users can easily change their personal information in each service application 70 by changing their personal information in the DIW application 50. In other words, users are freed from the hassle of changing their personal information for each service application 70 when changes to their personal information are necessary.
[0396] In step S1412 of Figure 33B, the DIW application 50 may determine whether the personal information to be extracted is valid or not, depending on the type of personal information being extracted. For example, if the requested personal attribute information is "previous year's withholding tax data," the DIW application 50 may determine in step S1412 whether the extracted withholding tax data is from the previous year (i.e., whether it is valid or not). If the DIW application 50 determines that the extracted withholding tax data is expired, it may display a message indicating that it cannot provide the requested data. The DIW application 50 may then update the user personal information record 110, extract the withholding tax data, and then determine again whether the extracted withholding tax data is from the previous year. If the determination is positive, the DIW application 50 may proceed to step S1413. The service application 70 may also perform the aforementioned determination of whether the extracted withholding tax data is from the previous year (i.e., whether it is valid or not).
[0397] Furthermore, if the service application 70 is a securities account opening application or a utility bill payment application, and a bank account number is already registered in the user personal information record 110, the DIW application 50 may include the bank account number in the personal information and send it to the service application 70 (securities account opening application or utility bill payment application, etc.) in step S1415. Also, if multiple bank account numbers are already registered in the user personal information record 110, the DIW application 50 may, on the screen in step S1413, have the user select which bank account number to provide to the service application 70 (securities account opening application or utility bill payment application, etc.) from among the multiple bank account numbers. The DIW application 50 may then include the selected bank account number in the personal information and send it to the service application 70 (securities account opening application or utility bill payment application, etc.) in step S1415.
[0398] <Processing when a user checks the personal information provision log> Figure 35A is a sequence diagram showing an example of the processing when a user checks the personal information provision log according to Embodiment 3. Figure 35B is a sequence diagram showing the continuation of Figure 35A. Figure 36A is a diagram showing an example screen of the DIW application 50 relating to the processing shown in Figures 35A and 35B according to Embodiment 3. Figure 36B is a diagram showing an example screen of the DIW application 50, continuing from Figure 36A.
[0399] The user launches the DIW application 50 (S1501) and selects the link history menu 321 as shown in Figure 35A(a) (S1502).
[0400] As shown in Figure 35A(b), the DIW application 50 captures the user's face with the camera 14 of the user terminal 10 (S1503) and acquires the captured face image information (S1504).
[0401] The DIW app 50 checks whether the facial image information in the user personal information record 110 and the captured facial image information obtained in step S1504 belong to the same person (S1505). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0402] If the DIW application 50 fails to perform the verification in step S1505 (S1506: NO), it displays a screen prompting for verification failure and / or reshooting (S1507). Then, the process returns to step S1503.
[0403] If the DIW application 50 succeeds in the matching in step S1505 (S1506: YES), it requests a list of personal information to be provided from the DIW cloud 20 (S1507). The request for the list of personal information to be provided may include the user's user ID.
[0404] Upon receiving the request in step S1507, the DIW cloud 20 extracts a personal information provision list (a list of service linkage history) corresponding to the user ID from the personal information provision log 220 (S1508) and sends it to the DIW application 50 (S1509).
[0405] The DIW application 50 receives the personal information provision list (service linkage history list) in step S1509 (S1510), and displays the personal information provision list (service linkage history list) in a list format as shown in Figure 36B(c) (S1511).
[0406] When a user selects a service linkage history (for example, row 322) from the list displayed (S1512), the DIW application 50 displays detailed information of the selected service linkage history (S1513), as shown in Figure 36B(d).
[0407] Through the above process, only the user who successfully undergoes facial recognition can view the contents of the personal information provision log 220, preventing anyone other than the user from viewing the user's personal information provision log 220. Furthermore, by performing facial recognition when the link history menu is selected in step S1502, and omitting individual facial recognition within the menu, the user can easily perform the operations in steps S1511 and S1512 within the menu.
[0408] (Summary of this disclosure) Based on the above descriptions of embodiments 1 to 3, the following technology is disclosed.
[0409] <Technical A1> The personal information management program (e.g., DIW app 50) that is executed on the processor (11) of the user terminal (10) owned by the user, according to this disclosure, reads the user's basic personal information from the user's identification document, displays an input screen for the user's additional personal information, obtains the additional personal information based on the user's input operation on the input screen, transmits the user personal information (e.g., user personal information record 110) including the basic personal information and the additional personal information to a predetermined external server (e.g., DIW cloud 20), and stores the user personal information in the memory (12) of the user terminal. As a result, the user terminal can store in memory the user personal information including the basic personal information read from the identification document and the additional personal information entered by the user.
[0410] <Technology A2> In the personal information management program described in Technology A1, specific personal information is generated based on the basic personal information and the additional personal information, and the specific personal information is included in the user personal information. As a result, the user terminal can store specific personal information, including information that is frequently used, in its memory along with the user personal information.
[0411] <Technology A3> In the personal information management program described in Technology A1 or A2, a first screen is displayed to obtain the user's first consent to provide the user's personal information to the external server, and if the first consent is obtained from the user on the first screen, the user's personal information is transmitted to the external server. As a result, the user terminal can transmit the user's personal information to the external server after obtaining the user's consent.
[0412] <Technical A4> In the personal information management program described in Technical A3, each piece of information included in the user's personal information is designated as personal attribute information, and information including at least one piece of personal attribute information used by the business operator for the service and a second purpose of use of said personal attribute information is displayed. A second screen is displayed to obtain a second consent from the user to provide the personal attribute information to the business operator. If the second consent is obtained from the user on the second screen, the personal attribute information is transmitted to a business operator server managed by the business operator. As a result, the user terminal can provide personal attribute information to the business operator for use in the service with the user's consent.
[0413] <Technical A5> In the personal information management program described in Technical A4, if the second consent is obtained from the user on the second screen, information including at least the user ID of the user who gave the second consent and the service ID of the service for which the second consent was obtained is sent to the external server. This allows the external server (e.g., DIW Cloud 20) to manage the user and service that provided personal information as a personal information provision log 220.
[0414] <Technology A6> In the personal information management program described in any one of Technologies A1 to A5, the basic personal information includes facial image information, which is the user's face image. The user terminal's camera (14) captures the user's face to obtain captured facial image information. The captured facial image information is then compared to the facial image information to determine if it belongs to the same person. If the comparison is successful, the input screen is displayed. As a result, the user terminal can display an input screen for additional personal information if it successfully matches the user's face, i.e., if the user is the person whose personal information is stored in the user terminal.
[0415] <Technology A7> In the personal information management program described in any one of Technologies A4 to A6, when the contents of the identification document are updated, the basic personal information is read from the updated identification document, the first screen is displayed, and if the user gives their consent again, the user's personal information, including the updated basic personal information, is sent to the external server, and the second screen is displayed, and if the user gives their consent again, the updated user's personal information is sent to the business operator's server. As a result, when the contents of the identification document are updated, the user terminal can obtain the user's consent again and then send the updated user's personal information to the external server and the business operator.
[0416] <Technical A8> The personal information management method described herein, which is performed on a user terminal owned by the user, reads the user's basic personal information from the user's identification document, displays an input screen for the user's additional personal information, obtains the additional personal information based on the user's input operation on the input screen, transmits the user personal information, including the basic personal information and the additional personal information, to a predetermined external server, and stores the user personal information in the memory of the user terminal. As a result, the user terminal can store in its memory the user personal information, including the basic personal information read from the identification document and the additional personal information entered by the user.
[0417] <Technical A9> The user terminal possessed by the user according to this disclosure is equipped with a processor and memory. The processor reads the user's basic personal information from the user's identification document, displays an input screen for the user's additional personal information, acquires the additional personal information based on the user's input operation on the input screen, transmits the user personal information, including the basic personal information and the additional personal information, to a predetermined external server, and stores the user personal information in the memory. As a result, the user terminal can store in memory the user personal information, including the basic personal information read from the identification document and the additional personal information entered by the user.
[0418] <Technical B1> The personal information management program (e.g., DIW app 50) that is executed on the processor (11) of the user terminal (10) owned by the user, according to this disclosure, acquires user personal information (e.g., user personal information record 110) from the memory (12) of the user terminal, which includes at least basic personal information obtained from the user's identification document, and treats each piece of information contained in the user personal information as personal attribute information. It receives service usage condition information, which includes the conditions for using the service provider's services, from a predetermined external server (e.g., DIW cloud 20), and determines whether the user personal information satisfies the conditions shown in the service usage condition information. If it determines that the user personal information satisfies the conditions shown in the service usage condition information, it generates the service corresponding to the service usage condition information as available service information indicating the services available to the user, and stores it in the memory. As a result, the user terminal can store in its memory, as available service information, services that satisfy the conditions shown in the service usage condition information, based on the user's personal attribute information.
[0419] <Technology B2> In the personal information management program described in Technology B1, multiple service usage condition information corresponding to each of multiple services is received, the above determination is made for each of the multiple service usage condition information, and the multiple available service information generated when it is determined that the conditions are met is listed and stored in the memory. As a result, the user terminal can store the available service information in memory as a list (for example, an available service ID list 120).
[0420] <Technology B3> In the personal information management program described in Technology B2, a list of available service information is displayed, and when the user selects the available service information of a service they wish to use from the list, the personal attribute information requested by the service, which is included in the service usage conditions information corresponding to the selected available service information, is identified, and a consent screen is displayed to obtain the user's consent to provide the identified personal attribute information requested by the service to the service provider from the user's personal information. If the user gives consent on the consent screen, the personal attribute information requested by the service is extracted from the user's personal information and provided to the service provider. This allows the user terminal to quickly display a list of services available to the user. Furthermore, when the user starts using a new service, the user terminal can, with the user's consent, provide the personal attribute information requested by that service to the service provider.
[0421] <Technology B4> In the personal information management program described in Technology B3, the basic personal information includes facial image information, which is the user's facial image. The camera (14) on the user terminal captures the user's face to acquire captured facial image information, and the captured facial image information is compared to the facial image information to determine whether it is the same person. If the comparison is successful, the consent screen is displayed. As a result, the user terminal can display the consent screen and obtain consent from the user if it successfully matches the user's face, that is, if the user is the person whose personal information is stored on the user terminal.
[0422] <Technology B5> In the personal information management program described in Technology B3 or B4, when the service usage conditions information is updated, the updated service usage conditions information is received from the external server, and it is determined whether the user's personal information satisfies the conditions indicated in the updated service usage conditions information. If it is determined that the user's personal information satisfies the conditions indicated in the service usage conditions information, the personal attribute information requested by the service, which is included in the updated service usage conditions information corresponding to the available service information selected by the user, is re-identified, and a consent screen is displayed to obtain the user's consent to provide the re-identified personal attribute information requested by the service to the business operator. If the user gives their consent on the consent screen, the personal attribute information requested by the service, extracted from the user's personal information, is provided to the business operator again. As a result, when the business operator updates the service usage conditions information, the user terminal can provide the business operator with the personal attribute information requested by the service after obtaining the user's consent again.
[0423] <Technical B6> The personal information management method performed on a user terminal (10) owned by a user according to this disclosure acquires user personal information, including at least basic personal information obtained from the user's identification document, from the memory (12) of the user terminal, receives service usage conditions information, including the conditions for using the service provider's services, determines whether the user personal information satisfies the conditions indicated in the service usage conditions information, and if it is determined that the user personal information satisfies the conditions indicated in the service usage conditions information, generates the service corresponding to the service usage conditions information as available service information indicating the services available to the user, and stores it in the memory. As a result, the user terminal can store in its memory, as available service information, services that satisfy the conditions indicated in the service usage conditions information, based on the user's personal attribute information.
[0424] <Technical B7> The user terminal (10) possessed by the user according to this disclosure is equipped with a processor (11) and a memory (12). The processor obtains user personal information from the memory, which includes at least basic personal information obtained from the user's identification document. The processor receives service usage conditions information from a predetermined external server, which includes the conditions for using the service provider's services. The processor determines whether the user personal information satisfies the conditions shown in the service usage conditions information. If it determines that the user personal information satisfies the conditions shown in the service usage conditions information, the processor generates the service corresponding to the service usage conditions information as available service information indicating the services available to the user, and stores it in the memory. As a result, the user terminal can store in its memory, as available service information, services that satisfy the conditions shown in the service usage conditions information, based on the user's personal attribute information.
[0425] <Technical C1> The personal information management program described herein, which is executed on the processor (11) of a user terminal (10) owned by the user, acquires user personal information from the memory of the user terminal, including at least basic personal information obtained from the user's identification document, when the user uses a service provided by the business operator. The basic personal information includes facial image information, which is the user's face image. Each piece of information included in the user personal information is designated as personal attribute information. The camera (14) of the user terminal captures the user's face to acquire captured facial image information. The captured facial image information is compared to the facial image information to determine whether it is the same person. If the comparison is successful, the personal attribute information requested by the service is extracted from the user personal information and transmitted to a designated service terminal (40) managed by the business operator. As a result, when the user terminal successfully matches the user's face, i.e., when the user is the person whose personal information is stored in the user terminal, the user terminal can extract the personal attribute information requested by the service from that user personal information and transmit it to the service terminal.
[0426] <Technology C2> In the personal information management program described in Technology C1, if the service terminal determines that the received personal attribute information satisfies the conditions indicated in the service usage conditions information corresponding to the service, it transmits a positive determination result to the user terminal, and upon receiving the positive determination result, displays information indicating that the user can use the service. As a result, if the service terminal determines that the personal attribute information transmitted from the user terminal satisfies the conditions indicated in the service usage conditions information, the user terminal can display that the service is available and inform the user.
[0427] <Technical C3> The personal information management method performed on a user terminal (10) owned by a user according to this disclosure, when the user uses a service provided by a business operator, acquires user personal information from the memory (12) of the user terminal, which includes at least basic personal information obtained from the user's identification document, the basic personal information includes facial image information which is the user's face image, each piece of information included in the user personal information is considered personal attribute information, the user terminal's camera takes a picture of the user's face and acquires captured facial image information, the captured facial image information is compared to the facial image information to determine whether it is the same person, and if the comparison is successful, the personal attribute information requested by the service is extracted from the user personal information and transmitted to a predetermined service terminal managed by the business operator. As a result, when the user terminal successfully matches the user's face, that is, when the user is the person whose personal information is stored in the user terminal, the user terminal can extract the personal attribute information requested by the service from that user personal information and transmit it to the service terminal.
[0428] <Technical C4> The user terminal (10) possessed by the user according to this disclosure is equipped with a processor (11), memory (12), and camera (14). When the user uses a service provided by the business operator, the processor acquires user personal information from the memory, which includes at least basic personal information obtained from the user's identification document. The basic personal information includes facial image information, which is the user's face image. Each piece of information included in the user personal information is designated as personal attribute information. The camera captures the user's face to acquire captured facial image information. The captured facial image information is compared to the facial image information to determine if it belongs to the same person. If the comparison is successful, the personal attribute information requested by the service is extracted from the user personal information and transmitted to a designated service terminal managed by the business operator. As a result, when the user terminal successfully matches the user's face, i.e., when the user is the person whose personal information is stored in the user terminal, the user terminal can extract the personal attribute information requested by the service from that user personal information and transmit it to the service terminal.
[0429] While embodiments have been described above with reference to the attached drawings, this disclosure is not limited to such examples. It is clear to those skilled in the art that various modifications, alterations, substitutions, additions, deletions, and equivalents can be conceived within the scope of the claims, and these are also understood to fall within the technical scope of this disclosure. Furthermore, the components of the embodiments described above can be combined in any way without departing from the spirit of the invention.
[0430] This application is based on the Japanese Patent Application No. 2025-7136 filed on January 17, 2025, the Japanese Patent Application No. 2025-109258 filed on June 27, 2025, and the Japanese Patent Application No. 2025-181180 filed on October 27, 2025, the contents of which are incorporated by reference in this application.
[0431] The technology disclosed herein is useful for realizing services that utilize personal information.
[0432] 1 DIW System 5 Communication Network 10 User Terminal 11 Processor 12 Memory 13 Storage 14 Camera 15 Input Device 16 Display Device 17 Communication Device 20 DIW Cloud 21 Processor 22 Memory 23 Storage 24 Communication Device 30 Operator Server 40 Service Terminal 41 Processor 42 Memory 43 Camera 44 Input Device 45 Display Device 46 Communication Device 50 DIW App 51 Service Master List Acquisition Unit 52 User Personal Information Acquisition Unit 53 Available Service Extraction Unit 54 Service Usage Conditions Output Unit 55 Linkage Consent Acquisition Unit 56 Face Recognition Unit 57 Request Reception Unit 58 Provided Information Extraction Unit 59 Log Output Unit 60 Data Management Unit 70 Service App 81 Service Confirmation Unit 82 Service Master List Management Unit 83 ID Generation Unit 84 Integrated Personal Information Master List Management Unit 85 User-linked service list management unit 86 Face recognition unit 87 Request reception unit 88 Output unit 89 Personal information provision log management unit 91 Electronic money issuance server 92 Vending machine 93 Shelter authentication terminal 94 Face recognition payment terminal 100A, 100B Service master list 110 User personal information record 120 Available service ID list 130 Consent service ID list 200 Integrated personal information master list 210 User-linked service list 220 Personal information provision log 401 External terminal 402 Server
Claims
1. A personal information management program that is executed on the processor of a user terminal owned by a user, the program reads the user's basic personal information from the user's identification document, displays an input screen for the user's additional personal information, obtains the additional personal information based on the user's input operation on the input screen, transmits the user's personal information, including the basic personal information and the additional personal information, to a predetermined external server, and stores the user's personal information in the memory of the user terminal.
2. The personal information management program according to claim 1, which generates specific personal information based on the basic personal information and the additional personal information, and includes the specific personal information in the user personal information.
3. A personal information management program according to claim 1, which displays a first screen for obtaining a first consent from the user to provide the user's personal information to the external server, and if the first consent is obtained from the user on the first screen, transmits the user's personal information to the external server.
4. A personal information management program according to claim 3, wherein each piece of information contained in the user's personal information is designated as personal attribute information, the program displays information including at least one piece of personal attribute information used by the business operator for the service and a second purpose of use of the personal attribute information, the program displays a second screen for obtaining a second consent from the user to provide the personal attribute information to the business operator, and if the second consent is obtained from the user on the second screen, the program transmits the personal attribute information to a business operator server managed by the business operator.
5. The personal information management program according to claim 4, which, when the user gives the second consent on the second screen, transmits to the external server information including at least the user ID of the user who gave the second consent and the service ID of the service for which the second consent was given.
6. The personal information management program according to any one of claims 1 to 5, wherein the basic personal information includes facial image information which is a facial image of the user, the program takes a picture of the user's face with a camera provided in the user terminal to acquire captured facial image information, verifies whether the captured facial image information is of the same person as the facial image information, and if the verification is successful, displays the input screen.
7. Personal information management program according to claim 4, wherein if the contents of the identification document are updated, the program reads the basic personal information from the updated identification document, displays the first screen, and if the user gives the first consent again, it transmits the user's personal information, including the updated basic personal information, to the external server, and displays the second screen, and if the user gives the second consent again, it transmits the updated user's personal information to the business server.
8. A personal information management method performed on a user terminal owned by a user, comprising: reading the user's basic personal information from the user's identification document; displaying an input screen for the user's additional personal information; obtaining the additional personal information based on the user's input operation on the input screen; transmitting the user personal information, including the basic personal information and the additional personal information, to a predetermined external server; and storing the user personal information in the memory of the user terminal.
9. A user terminal owned by a user, comprising a processor and memory, wherein the processor reads the user's basic personal information from the user's identification document, displays an input screen for the user's additional personal information, obtains the additional personal information based on the user's input operation on the input screen, transmits the user's personal information, including the basic personal information and the additional personal information, to a predetermined external server, and stores the user's personal information in the memory.