Personal information processing system, personal information processing device, personal information processing method, and personal information processing program

WO2026176835A1PCT designated stage Publication Date: 2026-08-27PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2026/001434
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-02-18
Filing Date
2026-01-19
Publication Date
2026-08-27

Smart Images

  • Figure JP2026001434_27082026_PF_FP_ABST
    Figure JP2026001434_27082026_PF_FP_ABST
Patent Text Reader

Abstract

[Problem] To determine whether or not a user satisfies a provision condition of a target service by using digitized personal information of the user. [Solution] A personal information processing system 1 comprises: a service provision device 3 that executes processing related to provision of a service to a user; a personal information acquisition device 4 that acquires digitized personal information of the user; and a user determination device 2 that determines whether or not the user is a provision target of the service. The service provision device 3 sets a provision condition of the service that can be provided to the user, the user determination device 2 determines whether or not the personal information of the user satisfies the provision condition of the service, and the service provision device 3 executes the processing related to provision of the service to the user only when the personal information of the user satisfies the provision condition of the service as a result of the determination related to the provision condition of the service.
Need to check novelty before this filing date? Find Prior Art

Description

Personal information processing system, personal information processing device, personal information processing method, and personal information processing program

[0001] The present disclosure relates to a personal information processing device, a personal information processing system, a personal information processing method, and a personal information processing program that use personal information included in a user's identity card.

[0002] In recent years, as application software for mobile devices such as smartphones and tablets, digital wallets that enable unified management of electronic payment information related to credit cards and the like have become widespread. In addition, digital wallets are not limited to simply a payment function, and the adoption of various functions such as an identity verification function (that is, a function as a digital ID wallet), a ticket function, and a point card function is underway.

[0003] In the technical development of digital wallets, reduction of security risks, improvement of interoperability between different services, and improvement of the user interface are required. For example, as a technology related to the security of digital wallets, technologies for authenticating user identification information and protecting data using biometric information have been disclosed (see Patent Document 1).

[0004] Japanese Patent Application Laid-Open No. 2022-508773

[0005] By the way, when providing a predetermined service to a user, it is conceivable to determine the availability of service provision using the digitized personal information (for example, identity card data) of the user stored in a digital wallet or a physical card (for example, a personal identification number card). In such a process for determining the availability of service provision, it is conceivable to set the service provision conditions for the user's personal information. Thereby, when the personal information of the target user does not satisfy the service provision conditions, the service provider can exclude the user from the service provision target.

[0006] However, in the prior art described in Patent Document 1 above, no special consideration is given to whether the user satisfies the service provision conditions for the use of digitized personal information.

[0007] Therefore, the main purpose of this disclosure is to provide a personal information processing system, a personal information processing device, a personal information processing method, and a personal information processing program that can determine whether or not a user meets the conditions for providing the target service by utilizing the digitized personal information of the user.

[0008] The personal information processing system disclosed herein is a personal information processing system for processing digitized personal information, comprising: a service provision device that performs processing related to the provision of services to a user; a personal information acquisition device that acquires the digitized personal information of the user; and a user determination device that determines whether the user is eligible to receive the service. The service provision device sets the conditions for providing the service that can be provided to the user, the user determination device determines whether the user's personal information satisfies the conditions for providing the service, and the service provision device executes processing related to the provision of the service to the user only if, as a result of the determination regarding the conditions for providing the service, the user's personal information satisfies the conditions for providing the service.

[0009] The personal information processing device of this disclosure is a personal information processing device equipped with a processor for processing digitized personal information, wherein the processor acquires the conditions for providing services that can be provided to a user, acquires the digitized personal information of the user, determines whether the user's personal information satisfies the conditions for providing the services, and notifies other devices that perform processing related to the provision of the services of the result of the determination regarding the conditions for providing the services.

[0010] The personal information processing method described herein is a personal information processing method for processing digitized personal information, wherein a computer obtains the conditions for providing services that can be offered to a user, obtains the digitized personal information of the user, determines whether the user's personal information satisfies the conditions for providing the services, and notifies other devices that perform processing related to the provision of the services of the result of the determination regarding the conditions for providing the services.

[0011] The personal information processing program disclosed herein is a personal information processing program for processing digitized personal information, and is configured to cause a computer to obtain the conditions for providing services that can be offered to a user, to obtain the digitized personal information of the user, to determine whether the user's personal information satisfies the conditions for providing the services, and to notify other devices that perform processing related to the provision of the services of the result of the determination regarding the conditions for providing the services.

[0012] According to this disclosure, by using digitized personal information of users, it is possible to determine whether or not a user meets the conditions for providing the service in question.

[0013] Figure 10 shows an example of blacklist matching history log obtained in the blacklist matching process. Figure 8 shows an example of blacklist secondary data used in the list registration process. Figure 8 shows a sequence diagram showing a first modified version of the blacklist matching process. Figure 8 shows a sequence diagram showing a second modified version of the blacklist matching process. Figure 14 shows an example of blacklist judgment criterion information used in the blacklist matching process. Figure 14 shows an example of blacklist secondary data used in the blacklist matching process. Figure 7 shows a sequence diagram showing a third modified version of the blacklist matching process. Figure 14 shows an example of blacklist secondary data used in the blacklist matching process. Figure 7 shows a sequence diagram showing an overview of the blacklist removal process in the personal information processing system according to the first embodiment. Figure 24 shows an overall configuration diagram of the personal information processing system according to the second embodiment. Figure 3 shows a functional block diagram of the software in the personal information processing system according to the second embodiment. Figure 22 shows an example of rule setting information used in the rule registration process. (A) First example,(B) Second Example) An explanatory diagram showing an example of a rule setting master table used in the rule registration process shown in Figure 22. A sequence diagram showing an overview of the rule determination process in the personal information processing system according to the third embodiment. A sequence diagram showing a first modified example of the rule registration process shown in Figure 22. An explanatory diagram showing an example of rule setting information used in the rule registration process shown in Figure 26. ((A) First Example, (B) Second Example) An explanatory diagram showing an example of a rule setting master table used in the rule registration process shown in Figure 26. A sequence diagram showing a first modified example of the rule determination process shown in Figure 25. A sequence diagram showing a second modified example of the rule determination process shown in Figure 25. An explanatory diagram showing an example of a rule setting master table used in the rule determination process shown in Figure 30. An explanatory diagram showing an example of a usage history log used in the rule determination process shown in Figure 30.

[0014] The first invention made to solve the above problem is a personal information processing system for processing digitized personal information, comprising: a service provision device that performs processing related to the provision of services to a user; a personal information acquisition device that acquires the digitized personal information of the user; and a user determination device that determines whether the user is eligible to receive the service. The service provision device sets the conditions for providing the service that can be provided to the user, the user determination device determines whether the user's personal information satisfies the conditions for providing the service, and the service provision device executes processing related to the provision of the service to the user only if, as a result of the determination regarding the conditions for providing the service, the user's personal information satisfies the conditions for providing the service.

[0015] According to this, by using digitized personal information of users, it is possible to determine whether or not a user meets the conditions for providing the service in question.

[0016] Furthermore, the second invention is configured such that the digitized personal information of the user is information associated with a digital wallet on a user terminal used by the user, or information stored on a physical card used by the user.

[0017] According to this, it is possible to easily obtain the personal information of digitized users.

[0018] Furthermore, the third invention is configured such that the service provision conditions information includes information regarding benefits attached to the service, and the service provision device performs processing to provide the user with the service attached to the benefits.

[0019] According to this, it becomes easy to provide users with benefits associated with the service.

[0020] Furthermore, the fourth invention includes information on the number of times the service can be provided in the service provision condition information, and the user determination device determines whether the cumulative number of times the service has been provided to the user exceeds the number of times the service can be provided, and if the cumulative number exceeds the number of times the service can be provided, it determines that the user's personal information does not meet the service provision conditions.

[0021] This makes it easier to repeatedly provide the same service to users based on predetermined service provision conditions.

[0022] Furthermore, the fifth invention is configured such that the personal information acquisition device acquires a first converted user personal information obtained by irreversibly converting the user's personal information according to the first rule, and a second converted user personal information obtained by irreversibly converting the user's personal information according to the second rule, and the user determination device stores the cumulative count information in association with the second converted user personal information.

[0023] According to this, information on the cumulative number of times the service has been provided is stored in association with the second set of converted user personal information. This reduces the need to retain the user's personal information, enhances security, and allows for the determination of whether or not the user meets the conditions for providing the target service.

[0024] Furthermore, the sixth invention is a personal information processing device equipped with a processor for processing digitized personal information, wherein the processor acquires the conditions for providing services that can be offered to a user, acquires the digitized personal information of the user, determines whether the user's personal information satisfies the conditions for providing the services, and notifies other devices that perform processing related to the provision of the services of the result of the determination regarding the conditions for providing the services.

[0025] According to this, by using digitized personal information of users, it is possible to determine whether or not a user meets the conditions for providing the service in question.

[0026] Furthermore, the seventh invention is a personal information processing method for processing digitized personal information, wherein a computer obtains the conditions for providing services that can be offered to a user, obtains the digitized personal information of the user, determines whether the user's personal information satisfies the conditions for providing the services, and notifies other devices that perform processing related to the provision of the services of the result of the determination regarding the conditions for providing the services.

[0027] According to this, by using digitized personal information of users, it is possible to determine whether or not a user meets the conditions for providing the service in question.

[0028] Furthermore, the eighth invention is a personal information processing program for processing digitized personal information, wherein the program causes a computer to obtain the conditions for providing services that can be offered to a user, to obtain the digitized personal information of the user, to determine whether the user's personal information satisfies the conditions for providing the services, and to notify other devices that perform processing related to the provision of the services of the result of the determination regarding the conditions for providing the services.

[0029] According to this, by using digitized personal information of users, it is possible to determine whether or not a user meets the conditions for providing the service in question.

[0030] The embodiments of this disclosure will be described below with reference to the drawings.

[0031] [First Embodiment] As shown in Figure 1, the personal information processing system 1 includes an identity verification server 2, a business server 3, a business terminal 4, and a user terminal 5. These identity verification server 2, business server 3, business terminal 4, and user terminal 5 are connected to each other so that they can communicate with one another via a communication network 6 consisting of the Internet or a LAN (Local Area Network), etc.

[0032] Furthermore, the personal information processing system 1 only needs to be equipped with at least an identity verification server 2. In other words, the administrator of the personal information processing system 1 is capable of managing at least the identity verification server 2. In this case, the business operator server 3, business operator terminal 4, and user terminal 5 are appropriately provided as devices capable of cooperating with the personal information processing system 1. In addition, application software for performing predetermined functions in the personal information processing system 1 is installed on the business operator server 3, business operator terminal 4, and user terminal 5 as needed.

[0033] Personal information processing system 1 performs processing using digitized personal information of users. For example, personal information processing system 1 can determine whether a user is a person of interest when verifying the identity of a user receiving services from a service provider (e.g., an individual, corporation, local government, or organization providing services).

[0034] Users may be offered different services by multiple different service providers. Services offered to users include, for example, the sale of goods and tickets, use of various facilities including transportation (e.g., stadiums), medical examinations and treatments at hospitals, login to devices such as computers, use of train stations and parcel lockers, rental and access control of buildings and parts thereof (e.g., rooms for holding events or meetings), use of tools and equipment, rental of vehicles (e.g., vehicle rental through car-sharing services), reservations of train cars and seats, and services related to various applications and applications for and use of various resident services at local governments.

[0035] In the personal information processing system 1, as shown in Figure 2(A), for example, a user U receiving a service can have their identity verified via a business terminal 4 installed in a store or other location. In this case, user U can have the business terminal 4 read (or transmit) personal information stored as identification data in a digital wallet installed in the user terminal 5. User U's personal information (or converted personal information) is sent from the business terminal 4 to the identity verification server 2 via the communication network 6 for identity verification. Alternatively, user U can have the business terminal 4 read personal information stored on a physical card (for example, a My Number Card) instead of the user's personal information stored in the user terminal 5. In the personal information processing system 1 according to the first embodiment, user identity verification is performed using the business terminal 4 in this manner.

[0036] On the other hand, as shown in Figure 2(B), for example, user U receiving the service can also access the identity verification server 2 from the user terminal 5 via the communication network 6 without going through the service provider terminal 4. In this case, user U's personal information (or converted personal information) is sent from the user terminal 5 to the identity verification server 2 via the communication network 6 for identity verification. In the personal information processing system 1 according to the second embodiment described later, user U's identity verification is performed without using the service provider terminal 4 in this manner.

[0037] For the sake of explanation, Figure 1 shows only one service provider server 3 and one service provider terminal 4, each managed by a single service provider. However, the number of service provider servers 3 and service provider terminals 4 can be changed. Also, the number of service providers involved in the personal information processing system 1 can be changed. If there are multiple service providers, multiple service provider servers will be provided, each managed by a different service provider.

[0038] Similarly, although Figure 1 shows only one user terminal 5, the personal information processing system 1 practically includes multiple user terminals 5. In other words, the personal information processing system 1 can be used by multiple users.

[0039] (Identity Verification Server 2) Identity verification server 2 (an example of a personal information processing device) includes a communication unit 11, a control unit 12, and a storage unit 13.

[0040] The communication unit 11 communicates wirelessly or via wired connection with other devices via the communication network 6 in accordance with a known communication protocol. This allows the identity verification server 2 to obtain necessary information and data from other devices while simultaneously transmitting the results of that processing to other devices. Other devices (an example of other computers) may include the operator server 3, operator terminal 4, and user terminal 5.

[0041] The control unit 12 performs a blacklist matching process (an example of identity verification) for users who are the target of the service. In the blacklist matching process, the control unit 12 determines whether the information used to identify a user (hereinafter referred to as "user identification information") matches any of the information used to identify multiple persons of concern (hereinafter referred to as "person of concern identification information"). The result of this determination indicates whether the target user is a person of concern (i.e., whether they are an unsuitable person to receive the service). User identification information may include the user's personal information (especially that stored as identity document data in the digital wallet; the same applies hereinafter) and information obtained by transforming that personal information according to predetermined rules. Person of concern identification information may include the personal information of persons of concern with a history of fraudulent activity and information obtained by transforming that personal information according to predetermined rules. Furthermore, the control unit 12 can control the operation necessary to realize the function of the identity verification server 2 as a publicly known server.

[0042] Furthermore, the control unit 12 can perform a rule determination process to determine whether the user's personal information satisfies the rules for providing services that can be offered to the user. The control unit 12 may perform the rule determination process independently of the blacklist matching process described above (i.e., regardless of whether the blacklist matching process is performed or not).

[0043] The storage unit 13 stores information and data necessary for information processing in the user authentication server 2. Such information and data include various types of information and data necessary for user determination information, person - to - be - watched determination information, and blacklist verification processing. In addition, the storage unit 13 may store various types of information and data necessary for rule determination processing. Further, the storage unit 13 stores application software (an example of a personal information processing program) for causing the control unit 12 to execute necessary information processing (such as blacklist verification processing, rule determination processing, etc.).

[0044] The user authentication server 2 is, for example, a computer having a hardware configuration for realizing the above - mentioned communication unit 11, control unit 12, and storage unit 13. As hardware for realizing the communication unit 11, the user authentication server 2 may include a network interface composed of an antenna, a communication circuit, etc. Further, as hardware for realizing the control unit 12, the user authentication server 2 may include one or more processors (for example, CPU, GPU, and DPU) and a memory. Also, as hardware for realizing the storage unit 13, the user authentication server 2 may include a memory, a storage, etc.

[0045] Further, at least a part of the functions provided by the user authentication server 2 can be realized as a cloud service. In that case, the user authentication server 2 may be composed of an aggregate of servers, data centers, storages, and network devices respectively connected to the communication network 6.

[0046] (Business Operator Server 3) The business operator server 3 (an example of a blacklist acquisition device) includes a communication unit 21, a control unit 22, and a storage unit 23. <​​​The control unit 22 executes processes related to the acquisition (or generation) of information for determining a person of concern used in the blacklist verification process by the personal verification server 2 and the update of such information (hereinafter referred to as "blacklist acquisition process"). However, the acquisition of such information for determining a person of concern also includes cases where information is registered based on the input of the administrator of the business operator server 3. In addition, the control unit 22 can control operations for realizing the functions of a known server in the business operator server 3.

[0049] The storage unit 23 stores information and data necessary for information processing in the business operator server 3. Such information and data include various types of information and data necessary for the blacklist acquisition process in addition to the information for determining a person of concern. The storage unit 23 also stores application software for causing the control unit 22 to execute necessary information processing (such as the blacklist acquisition process).

[0050] The business operator server 3 is, for example, a computer having a hardware configuration for realizing the above-described communication unit 21, control unit 22, and storage unit 23. The hardware of the business operator server 3 can be configured in the same manner as the above-described personal verification server 2.

[0051] (Business Operator Terminal 4) The business operator terminal 4 (an example of a personal information acquisition device) includes a communication unit 31, an imaging unit 32, an operation unit 33, a display unit 34, a control unit 35, and a storage unit 36. [[ID=PROTECTED_ID_10]] [[ID=PROTECTED_ID_11]]

[0052] The communication unit 31 has a network communication function for communicating with other devices in the personal information processing system 1 via the communication network 6, similar to the above-described communication unit 21. Thereby, the business operator terminal 4 can transmit information and data necessary for the blacklist verification process to the personal verification server 2 and receive information and data regarding the result of the blacklist verification process from the personal verification server 2.

[0053] Furthermore, the communication unit 31 has a short-range communication function for communicating with other devices (e.g., user terminal 5) located around the operator terminal 4, in accordance with a known communication protocol. This short-range communication is performed in accordance with NFC. However, it is not limited to this, and the short-range communication may be performed in accordance with other known communication standards (such as Bluetooth® or Wi-Fi), or by a combination of multiple such known communication standards. In addition, the communication unit 31 may have an IC card reader function for communicating with the IC chip of a physical card used by the user.

[0054] The imaging unit 32 can acquire an image including the user's face (i.e., generate a user's face image) by photographing the user using the carrier terminal 4. However, if the carrier terminal 4 can acquire a user's face image from the user terminal 5 (such as a face image taken by the camera of the user terminal 5), the imaging unit 32 may be omitted.

[0055] The operation unit 33 accepts input operations from the user (in this case, the owner of the user terminal 5 and the operator of the business terminal 4). The display unit 34 displays a guidance screen to provide the user with instructions and information.

[0056] The control unit 35 performs authentication processing for users receiving services from a service provider. Such user authentication processing may be performed when a user makes a reservation (or application) for a service or when a user requests service provision. In this embodiment, the control unit 35 can perform user authentication processing based on the results of the blacklist matching process performed by the identity verification server 2. Furthermore, in the user authentication processing, the control unit 35 can perform tasks such as acquiring the user's personal information used in the blacklist matching process and notifying the user of the results of the blacklist matching process. In addition, the control unit 35 can also perform service reservation processing to accept service reservations (or applications) from users, and service provision processing to actually provide services in response to user requests. The service provider terminal 4 can perform such service reservation processing and service provision processing in cooperation with the service provider server 3.

[0057] The storage unit 36 ​​stores information and data necessary for information processing in the business terminal 4. Such information and data include the user's personal information, information for converting that personal information, and the converted personal information of the user. If the user's personal information is encrypted, the storage unit 36 ​​may also contain information such as a decryption key for decryption. The storage unit 36 ​​also stores application software for the control unit 35 to perform necessary information processing (such as user authentication processing). Note that the user's personal information in the storage unit 36 ​​may be deleted after the user authentication process is completed.

[0058] The operator terminal 4 is, for example, a computer equipped with hardware configurations to implement the communication unit 31, imaging unit 32, operation unit 33, display unit 34, control unit 35, and storage unit 36 ​​described above. The operator terminal 4 may include tablet terminals, notebook PCs, payment terminals, kiosk terminals, and ATM (Automatic Teller Machine) terminals. The operator terminal 4 may be deployed, for example, in stores or public facilities. The operator terminal 4 can employ the same hardware configurations as the communication unit 11, control unit 12, and storage unit 13 described above, respectively, for implementing the communication unit 31, control unit 35, and storage unit 36. Furthermore, the operator terminal 4 may include a camera, keyboard (or input buttons), and display device, respectively, as hardware for implementing the imaging unit 32, operation unit 33, and display unit 34. A touch panel display may be used for the operation unit 33 and display unit 34.

[0059] (User terminal 5) The user terminal 5 includes a communication unit 41, an imaging unit 42, an operation unit 43, a display unit 44, a control unit 45, and a storage unit 46.

[0060] The communication unit 41, like the communication unit 31 described above, has network communication and short-range communication functions. The imaging unit 42, like the imaging unit 32 described above, can acquire an image including the user's face by photographing the user using the user terminal 5. The operation unit 43 accepts input operations from the user (i.e., the operator of the user terminal 5). The display unit 44 displays a guidance screen to provide the user with instructions and information.

[0061] The control unit 45 performs processing (hereinafter referred to as "personal information provision processing") to provide the user's personal information stored in the user terminal 5 to the business terminal 4. Such personal information provision processing may be performed in response to a request from the business terminal 4.

[0062] The storage unit 46 stores information and data necessary for information processing on the user terminal 5. Such information and data include the user's personal information (identity card data, etc.) and application software (digital wallet application) for the control unit 45 to perform necessary information processing (personal information provision processing, etc.). The user's personal information stored in the storage unit 46 is, for example, information equivalent to the information contained in the user's physical identification card (e.g., My Number Card, IC driver's license, IC passport, etc.) issued by a public institution and stored in the digital wallet.

[0063] The user terminal 5 is, for example, a computer equipped with hardware configurations to implement the communication unit 41, imaging unit 42, operation unit 43, display unit 44, control unit 45, and storage unit 46 described above. The user terminal 5 may be a smartphone or tablet used personally by the user. The hardware of the user terminal 5 can be configured in the same way as the carrier terminal 4 described above. The user terminal 5 may include an integrated circuit (IC) chip that constitutes part of the storage unit 46 and contains a secure element where the user's personal information is stored. Note that in the personal information processing system 1, if the user's personal information is provided by reading a physical card by the carrier terminal 4, the user terminal 5 may be omitted.

[0064] Next, referring to Figure 3, the functions of the application software (hereinafter referred to as "software") installed on the identity verification server 2, business operator server 3, business operator terminal 4, and user terminal 5 that constitute the personal information processing system 1 will be described.

[0065] The user terminal 5 has a wallet application 51 (an example of a digital wallet) installed as software (digital wallet application) that handles the user's personal information. Here, "wallet" is a concept that includes a digital ID wallet. The wallet application 51 has an identity verification function. This allows the user terminal 5 to display identity verification data 52 containing the user's personal information on the display unit 44 or to transmit it to other devices (for example, the business terminal 4). The storage of identity verification data 52 in the wallet application 51 (i.e., association with the wallet application 51) may be carried out in accordance with international standards such as ISO / IEC 18013 and ISO / IEC 23220.

[0066] The identification document data 52 includes three basic pieces of information as the user's personal information: name, date of birth, and gender. However, the identification document data 52 may also include four basic pieces of information as the user's personal information: name, date of birth, gender, and address. Furthermore, in addition to the three or four basic pieces of information, the identification document data 52 may also include a facial image of the user. In addition, if the identification document data 52 is driver's license data, it may include information such as the license number, and if it is passport data, it may include information such as the passport number, as specified according to the type of identification document.

[0067] The service provider terminal 4 has a service provider application 61 installed as software to perform user authentication. However, the service provider application 61 may also perform service reservation processing and service provision processing. In addition, a general-purpose browser application may be used as the service provider application 61, and service reservation processing and service provision processing may be performed on the service provider's website via the browser.

[0068] The business application 61 incorporates an identity verification library 62. The identity verification library 62 enables the exchange of information and data between the business application 61 and the digital wallet (app) on the user terminal 5. Furthermore, the identity verification library 62 enables the exchange of information and data between the business application 61 and the business server 3. The identity verification library 62 can be implemented, for example, as multiple software modules included in an SDK (Software Development Kit).

[0069] The identity verification library 62 has functions for user inquiry 63, data conversion 64, and face matching 65 related to user authentication processing, as well as a rule verification 66 function related to at least one of service reservation processing and service provision processing.

[0070] In user inquiry 63, the target user is checked. In user inquiry, the business terminal 4 requests the identity verification server 2 to perform a blacklist matching process for the target user.

[0071] In data conversion 64, the user's personal information is transformed. Here, the transformed user personal information is obtained by hashing the user's personal information (an example of irreversible transformation). The transformed user personal information is used, for example, in the blacklist matching process on the identity verification server 2.

[0072] In the facial matching process 65, the user's facial image captured by the user terminal 5 is compared with the facial image contained in the identification document data 52.

[0073] Rule confirmation 66 verifies the rules governing the provision of services to the target user. During the verification of service provision rules, the service provider terminal 4 requests the identity verification server 2 to execute the rule determination process.

[0074] In addition, in the personal information processing system 1 according to the first embodiment, the functions of face matching 65 and rule confirmation 66 can be omitted.

[0075] The operator server 3 has software-based functions for blacklist management 71 and rule registration 72 related to the blacklist acquisition process.

[0076] In the blacklist management system 71, a blacklist master table (see Figure 5) is generated that includes multiple individuals of interest with a history of fraudulent activity. The information about individuals of interest included in the blacklist master table (in this case, the personal information of individuals of interest) can be used as converted information about individuals of interest, which has been transformed according to predetermined rules. At least a portion of the information included in the blacklist master table obtained through the blacklist acquisition process is provided to the identity verification server 2.

[0077] In Rule Registration 72, the rules for providing services offered by the service provider (for example, conditions such as the user's age and address) are set. This generates the rule setting master table (see Figure 24, described later).

[0078] In addition, in the personal information processing system 1 according to the first embodiment, the rule registration 72 function can be omitted.

[0079] The identity verification server 2 has software that provides functions for data matching 81, data conversion 82, and blacklist history management 83 related to blacklist matching processing, as well as rule determination 84 related to rule determination processing and service provision history management 85 related to service provision processing.

[0080] In data matching 81, it is determined whether the user information obtained from the business terminal 4 matches any of the information on multiple persons of concern included in the blacklist master table obtained from the business server 3.

[0081] In data conversion 82, the personal information of the person of interest is converted. Here, the converted person of interest information is obtained by hashing (an example of irreversible conversion) of the personal information of the person of interest. The converted person of interest information constitutes part of the information contained in the blacklist master table and is used, for example, in blacklist matching processing.

[0082] The blacklist history management system 83 manages the history of the results of data matching 81. Such history includes, for example, the cumulative number of times that information about a user matches any of the information about a person of interest.

[0083] In the rule determination 84, it is determined whether the user's identity data 52 obtained from the service provider terminal 4 satisfies the rules for providing services to that user. The service provision rules are obtained, for example, from the service provider server 3 managed by the service provider that provides the service.

[0084] The service provision history management system 85 manages the history of service provision to users. The service provision history includes the cumulative number of times the service has been provided. This cumulative number can be used as part of the service provision rules in the rule determination system 84.

[0085] (Blacklist Registration Process) Next, with reference to Figure 4, an overview of the blacklist registration process in personal information processing system 1 will be explained.

[0086] The operator server 3 identifies users who have committed fraudulent acts in the past as persons of interest and generates a blacklist master table containing information about those persons of interest (ST101). The blacklist master table includes data for each person of interest, such as the user ID, basic 3 information, and primary hash ID (an example of the first converted person of interest information), as shown in Figure 5. The blacklist master table in step ST101 may be provided to the operator server 3 from another device.

[0087] The primary hash ID is a hash value obtained by hashing the personal information of a person of interest (in this case, the three basic pieces of information) using the first hash function (an example of the first rule). Hashing is performed by adding a random value (salt) to the personal information of the person of interest. Note that the primary hash ID may also be generated by hashing the user ID.

[0088] Next, the business server 3 sends a blacklist registration request to the identity verification server 2 to register information about those persons of interest. The blacklist registration request that is sent is accompanied by primary blacklist data. As shown in Figure 6, for example, the primary blacklist data includes a primary hash ID and the random value used to hash it for each person of interest.

[0089] Therefore, when the identity verification server 2 receives the blacklist registration request, it generates a secondary hash ID (information for determining persons of concern, an example of second converted persons of concern information) by hashing the primary hash ID (information for determining persons of concern, an example of first converted persons of concern information) in the primary blacklist data using a second hash function (an example of second rule) (ST102). The hashing of the primary hash ID is performed by adding a random value (salt). As shown in Figure 7, for example, the identity verification server 2 stores the secondary hash ID, the random value used for hashing, and the primary hash ID before conversion as secondary blacklist data for each person of concern (ST103).

[0090] Subsequently, the identity verification server 2 sends a notification to the business server 3 that the blacklist registration has been completed (ST104).

[0091] In this blacklist registration process, the identity verification server 2 stores a secondary hash ID, which is a converted version of the personal information of the person of concern, as information about the person of concern. In other words, the identity verification server 2 can identify individuals unsuitable for service provision based on the secondary hash ID, without using the personal information of the person of concern.

[0092] (Blacklist matching process) Next, with reference to Figure 8, an overview of the blacklist matching process (an example of identity verification process) in the personal information processing system 1 will be explained.

[0093] When the blacklist matching process is initiated on the business terminal 4, the business application 61 loads the identity verification library 62 and requests the identity verification library 62 to retrieve information from the user terminal 5. Subsequently, the business terminal 4 (identity verification library 62) issues instructions to the user to perform user authentication (ST201). Here, as instructions to the user, a message prompting the user to hold the user terminal 5 over the device is displayed on the guidance screen. The identity verification server 2 stores the blacklist secondary data, which includes the secondary hash IDs of multiple persons of interest, as shown in Figure 4 (ST103).

[0094] The user holds the user terminal 5 over the service provider terminal 4 (i.e., brings it close to the service provider terminal 4) according to the instructions. Upon detecting the user terminal 5, the service provider terminal 4 initiates short-range wireless communication with the user terminal 5. Subsequently, the service provider terminal 4 (identity verification library 62) requests the user terminal 5 to provide data on the user's personal information (in this case, the three basic pieces of information).

[0095] Upon receiving the request, user terminal 5 displays a screen to obtain the user's consent to provide the information. When the user agrees (ST202), it provides the encrypted basic 3 information to carrier terminal 4 (i.e., transmits it via short-range communication).

[0096] The business terminal 4 (identity verification library 62) decrypts the received encrypted basic 3 information (ST203). The business terminal 4 can share the information used to decrypt the encrypted basic 3 information with the user terminal 5 in advance. For example, the business terminal 4 can obtain the information used for decryption when requesting the basic 3 information data from the user terminal 5. Alternatively, when requesting the basic 3 information data, the business terminal 4 may notify the user terminal 5 of its public key, and the user terminal 5 may send the basic 3 information encrypted with the public key (in this case, the information used for decryption will be the business terminal 4's private key).

[0097] Next, the business terminal 4 (identity verification library 62) hashes the decrypted basic three pieces of information using a first hash function (an example of the first rule) to obtain a primary hash ID (user identification information, an example of the first converted user personal information). Furthermore, the business terminal 4 (identity verification library 62) hashes the primary hash ID using a second hash function (an example of the second rule) to obtain the user's secondary hash ID (user identification information, an example of the second converted user personal information) (ST204). Note that the identity verification library 62 in the business terminal 4 can notify (share) the basic three pieces of information with the business application 61 as needed.

[0098] Therefore, the business terminal 4 (identity verification library 62) sends a blacklist matching request to the identity verification server 2. The blacklist matching request that is sent has the user's secondary hash ID obtained in step ST204 attached to it.

[0099] The identity verification server 2 performs a comparison between the received user's secondary hash ID and the blacklist secondary data (i.e., the secondary hash IDs of multiple persons of interest) (ST205). At this time, it is determined whether the user's secondary hash ID matches any of the secondary hash IDs of the multiple persons of interest (i.e., whether the information about the user matches the information about the person of interest) (ST206).

[0100] Therefore, only if the user's secondary hash ID matches any of the secondary hash IDs of multiple persons of interest (Yes in ST206), the identity verification server 2 sends a blacklist match notification to the business server 3. The blacklist match notification is appended with the primary hash ID of the person of interest that matched the user's secondary hash ID in step ST206. Upon receiving the primary hash ID of the person of interest, the business server 3 records the primary hash ID in the blacklist determination history log (ST207). The blacklist determination history log includes, for example, the date and time of the blacklist match (for example, the date and time the blacklist match notification was received) and the primary hash ID of the matching person of interest, as shown in Figure 9.

[0101] Subsequently, the identity verification server 2 sends a verification result notification containing information about the result of the determination in step ST206 to the business terminal 4 (identity verification library 62, business application 61). The verification result notification indicating that the verification in step ST206 was successful will have the user's secondary hash ID attached. On the other hand, the verification result notification indicating that the verification in step ST206 failed will not have the user's secondary hash ID attached. This allows the business terminal 4 to recognize the result of the determination by the identity verification server 2.

[0102] Based on the matching result notification (including the user's secondary hash ID), the business terminal 4 (business application 61) determines that the target user's secondary hash ID matches the secondary hash ID of a person of concern (Yes in ST208), and displays a procedure cancellation screen on its display indicating that the procedure will be canceled (ST209). Furthermore, by storing the user's secondary hash ID, the business terminal 4 can determine if the user is a person of concern again without relying on the identity verification server 2 if that user becomes the target of processing again.

[0103] On the other hand, in step ST208, if it is determined that the target user's secondary hash ID does not match the secondary hash ID of the person of interest (No), a completion screen is displayed indicating that the user authentication process (or blacklist matching process) has been successfully completed (ST210). If a procedure cancellation screen is displayed on the display (Yes in ST208), the display of the completion screen is omitted.

[0104] Such blacklist matching processing can be performed on the service provider terminal 4 when user authentication is required (such as when booking (or applying for) a service or when requesting service provision). In addition, the identity verification server 2 and the service provider terminal 4 (identity verification library 62) can share information necessary for hashing the personal information of persons of interest (such as the first hash function and the second hash function) in advance.

[0105] Note that here, processing is performed using the secondary hash IDs of the user and the person of interest (see step ST205, etc.), but the same processing may be performed using the primary hash ID instead of the secondary hash ID.

[0106] Although not shown in the diagram, in step ST202, if the user performs an action to refuse to consent to providing information, the user terminal 5 sends a notification to the business terminal 4 (identity verification library 62) indicating that the user's consent could not be obtained. Upon receiving this notification, the business terminal 4 notifies (shares) the business application 61 from the identity verification library 62 that the user's consent could not be obtained. The business terminal 4 (business application 61) can then display a procedure completion screen on its display indicating that the procedure is being terminated. The procedure completion screen may also display a message indicating that information to identify the user (in this case, the three basic pieces of information) could not be confirmed (i.e., the reason for terminating the procedure). In this way, if the user's consent cannot be obtained in step ST202, the blacklist matching process is terminated.

[0107] (First Modification of the Blacklist Registration Process) Next, with reference to Figure 10, the first modification of the blacklist registration process shown in Figure 4 will be described.

[0108] In the first modified example of the blacklist registration process, steps ST301-ST303 are executed, which roughly correspond to steps ST101-ST103 in Figure 4. Furthermore, matters not specifically mentioned below are the same as those in the blacklist registration process shown in Figure 4.

[0109] As shown in Figure 10, in the first modified example, the blacklist registration request sent from the business server 3 to the identity verification server 2 is further accompanied by blacklist judgment criterion information (an example of judgment application conditions).

[0110] The blacklist determination criteria information is information used to confirm the validity of the result of the match (i.e., successful matching) determination in step ST206 shown in Figure 8 above. Even if the user's secondary hash ID matches the secondary hash ID of a person of interest in step ST206 (Yes), the determination result may be effectively invalid (similar to No) based on the blacklist determination criteria information. In other words, the blacklist determination criteria information includes information for setting the application conditions for the determination result based on the blacklist secondary data (i.e., the secondary hash IDs of multiple persons of interest) (i.e., conditions for applying to whether or not a user can use the service based on the result of the match determination with the blacklist secondary data).

[0111] The blacklist determination criteria information includes, for example, the determination content regarding the application of the determination result based on secondary blacklist data, as shown in Figure 11, and the corresponding determination criteria information. In this blacklist determination criteria information, for example, regarding the number of matches on the blacklist (i.e., the cumulative number of times the same person of concern has been determined to be Yes in step ST206 in the past), the application of the determination result based on secondary blacklist data is permitted only if the number is n or more. In other words, if the number is less than n, processing such as suspending the procedure is postponed for the person determined to be a person of concern (as a result, for example, the prescribed service is provided). Also, for example, regarding the frequency of matches on the blacklist (i.e., the cumulative number of times the same person of concern has been determined to be Yes in step ST206 within one month), the application of the determination result based on secondary blacklist data is permitted only if the number is N or more. Furthermore, regarding the blacklist matching interval (i.e., the number of days elapsed since the last time a "Yes" was determined for the same person of interest in step ST206), the application of the judgment result based on secondary blacklist data is permitted only if that number of days is within one week.

[0112] The criteria and content of the blacklist determination information can be modified in various ways. Furthermore, if there are multiple criteria and content, one or more combinations of them may be used.

[0113] The identity verification server 2 can, for example as shown in Figure 12, save a history of predetermined judgment content (in this case, the number of matches on the blacklist) in the blacklist judgment criteria information as part of the secondary blacklist data in step ST303.

[0114] (First Modification of Blacklist Matching Process) Next, with reference to Figure 13, the first modification of the blacklist matching process shown in Figure 8 will be described.

[0115] In the first modified example of the blacklist matching process, steps ST401-ST410 are executed, which roughly correspond to steps ST201-ST210 in Figure 8. Furthermore, matters not specifically mentioned below are the same as those in the blacklist matching process shown in Figure 8.

[0116] As shown in Figure 13, in the first modified example, if the user's secondary hash ID matches any of the secondary hash IDs of multiple persons of interest (Yes in ST406), additional steps ST411 and ST412 are performed. Here, an example is shown in which the number of matches on the blacklist is used as the blacklist determination criterion information.

[0117] In step ST411, the identity verification server 2 updates the history of the number of matches in the secondary blacklist data (see Figure 12) saved in step ST303. Subsequently, in step ST412, the identity verification server 2 determines whether the updated number of matches in the blacklist meets the criteria (see Figure 11) in the blacklist judgment criteria information.

[0118] Therefore, if the number of matches on the blacklist does not meet the criteria (in this case, n times or more), the determination in step ST406 that the secondary hash IDs of the user and the person of interest match (Yes) becomes invalid. In other words, if the number of matches on the blacklist does not meet the criteria in step ST412, it is treated the same as if the secondary hash IDs of the user and the person of interest did not match (No) in step ST406.

[0119] On the other hand, in step ST412, if the number of matches in the blacklist meets the criteria, the determination in step ST406 that the secondary hash IDs of the user and the person of interest match (Yes) is valid.

[0120] If step ST412 is executed, the identity verification server 2 sends a judgment result notification to the business server 3, which includes the result of the judgment in step ST412, instead of the blacklist match notification shown in Figure 8 above. The judgment result notification is appended with the primary hash ID of the person of interest that matched the user's secondary hash ID in step ST406. On the other hand, if step ST412 is not executed (i.e., No in step ST406), the judgment result notification sent to the business server 3 is the same as the blacklist match notification shown in Figure 8.

[0121] In other words, the judgment result notification includes information indicating whether or not to permit the provision of the service to the target user. For example, in step ST412, if the number of matches in the blacklist does not meet the judgment criteria, even though the target user has been determined to be a person of interest (Yes in ST406), the judgment result notification includes information indicating that the provision of the service to that user is permitted. Such information indicating whether or not to permit the provision of the service can later be used by the business terminal 4 (business application 61) to determine whether or not to send a service usage request to the business server 3, etc. In other words, the business terminal 4 can determine whether or not to send a service usage request according to the information indicating whether or not to permit the provision of the service.

[0122] (Second Modification of Blacklist Matching Process) Next, with reference to Figure 14, a second modification of the blacklist matching process shown in Figure 8 will be described.

[0123] In the second modified version of the blacklist matching process, steps ST501-ST512 are executed, which roughly correspond to steps ST401-ST412 in Figure 13. Furthermore, matters not specifically mentioned below are the same as those in the blacklist matching process shown in Figure 8 or Figure 13.

[0124] This second modification differs from the first modification shown in Figure 13 in that it utilizes a service provider ID, which is the identification information of the service provider, and a service ID, which is the identification information of the service provided to the user.

[0125] When the blacklist matching process is initiated on the business terminal 4, the business application 61 loads the identity verification library 62 and requests the identity verification library 62 to retrieve information from the user terminal 5. Subsequently, the business terminal 4 (business application 61) displays a menu selection screen for the services the user wishes to receive in the operation instruction to the user (ST501). The business terminal 4 (business application 61) can recognize the services to be provided to the user based on the user's personal information and the user's input operations on the business terminal 4. As a result, the business application 61 can notify the identity verification library 62 of the business ID and service ID related to the services provided to the user.

[0126] Subsequently, the business terminal 4 (identity verification library 62) obtains the user's secondary hash ID (ST 504) and sends a blacklist matching request to the identity verification server 2. In addition to the secondary hash ID, the business ID and service ID are added to the blacklist matching request that is sent.

[0127] In this second modification, instead of the blacklist judgment criteria information shown in Figure 11 above, the blacklist judgment criteria information shown in Figure 15 is used. In this blacklist judgment criteria information, an upper limit on the number of blacklist matches is set for each combination of business ID and service ID (i.e., for each service provided by each service provider). For example, for the service with service ID "0001" provided by the service provider with business ID "AAA", the upper limit on the number of blacklist matches is set to 3. Such an upper limit on the number of blacklist matches generally corresponds to the judgment criteria regarding the number of blacklist matches shown in Figure 11.

[0128] Furthermore, in the second modification, instead of the secondary blacklist data shown in Figure 12 above, secondary blacklist data shown in Figure 16 is used. In the secondary blacklist data of Figure 16, unlike Figure 12, a history of the number of blacklist matches is set for each combination of business ID and service ID. For example, the service with service ID "0001" provided by the service provider with business ID "AAAA" has a history of 2 blacklist matches (past cumulative). Also, the service with service ID "0002" provided by the same service provider (business ID "AAAA") has a history of 1 blacklist match.

[0129] In step ST511, the identity verification server 2 updates the history of the number of matches in the secondary blacklist data (see Figure 16) saved in step ST303. Subsequently, in step ST512, the identity verification server 2 determines whether the updated number of matches in the blacklist meets the criteria (see Figure 15) in the blacklist judgment criteria information. After that, processing is performed in the same manner as the blacklist matching process shown in Figure 13.

[0130] (Third Modification of Blacklist Matching Process) Next, with reference to Figure 17, a third modification of the blacklist matching process shown in Figure 8 will be described.

[0131] In the third modified version of the blacklist matching process, steps ST601-ST604 are executed, which roughly correspond to steps ST201-ST204 in Figure 8. However, in the third modified version, a new process is executed between steps ST603 and ST604. Although not shown in the figures, in the third modified version, after step ST604, processes corresponding to steps ST205-ST210 in Figure 8 are executed. Unless otherwise specified below, the process is the same as the blacklist matching process shown in Figure 8.

[0132] In this third variation, the business terminal 4 (identity verification library 62) requests a facial image from the user terminal 5 as user personal information data, in addition to the three basic pieces of information.

[0133] Upon receiving the request, the user terminal 5 displays a screen to obtain the user's consent to provide information. When the user agrees (ST602), the terminal 5 transmits the encrypted basic information and facial image (hereinafter referred to as "registered facial image") stored in the wallet application 51 to the business terminal 4.

[0134] The business terminal 4 (identity verification library 62) decodes the received basic three pieces of information and facial image (ST603). Subsequently, the business terminal 4 receives a request from the identity verification library 62 to acquire the user's facial image, and the business application 61 activates the camera (image capture unit 32) (ST611). Next, the business terminal 4 (business application 61) displays a facial capture instruction (for example, a message prompting the user to take a picture of their own face) on the display (display unit 34) (ST612). In addition, the identity verification library 62 in the business terminal 4 can notify the business application 61 of the basic three pieces of information as needed, similar to the process shown in Figure 8.

[0135] The user, following the instructions to take a photo of their face, points their face towards the camera of the service provider terminal 4. As a result, the service provider terminal 4 (service provider application 61) detects the user's face and generates a photo of the user's face (hereinafter referred to as the "photographed face image") by taking a photo of it with its camera (ST613).

[0136] Subsequently, the business terminal 4 (identity verification library 62) performs face matching on the captured face image (ST614). Here, a one-to-one match is performed between the registered face image and the captured face image. If the business terminal 4 (identity verification library 62) determines that the face matching was successful (Yes in ST615), it obtains the user's secondary hash ID (ST604), similar to step ST204 in Figure 8. After that, the processes corresponding to steps ST205-ST210 in Figure 8 are executed.

[0137] On the other hand, if the business terminal 4 (identity verification library 62) determines that face verification has failed (No in ST615), it displays a procedure cancellation screen on its display indicating that the procedure will be canceled (ST616). As a result, the process is stopped before the blacklist verification request shown in Figure 8 is made from the business terminal 4 (identity verification library 62) to the identity verification server 2.

[0138] Thus, in this third modified version of the blacklist matching process, inappropriate users (i.e., individuals not registered in the user terminal 5) can be excluded by facial recognition in step ST615. As a result, unnecessary processing (such as matching the secondary hash ID for inappropriate users) can be avoided by the identity verification server 2.

[0139] (Blacklist Removal Process) Next, with reference to Figure 18, the blacklist removal process in the personal information processing system 1 will be explained.

[0140] If the information in the aforementioned blacklist master table (see Figure 5) becomes fixed, then any person registered in it will always be treated as a person of interest, which is not necessarily appropriate. Therefore, the personal information processing system 1 can perform a blacklist removal process to delete the information of a person registered in the blacklist master table.

[0141] In step ST207 (see Figure 8), the operator server 3 extracts users to be removed (i.e., persons of concern) from the blacklist master table (see Figure 5) based on the blacklist history log recorded and predetermined removal criteria (ST701). Such removal criteria include, for example, if a person has not been recorded in the blacklist history log for a certain period of time (e.g., more than one month) since the last time that person was recorded, that person will be removed. Alternatively, if there is no record of a person in the blacklist history log for that person, that person will be removed.

[0142] When the service provider server 3 extracts the users to be removed from the blacklist, it sends a request to the identity verification server 2 to remove them from the blacklist. The blacklist removal request sent will have a primary hash ID related to the user to be removed attached to it.

[0143] When the identity verification server 2 receives the request to remove the user from the blacklist, it deletes the user's record corresponding to the attached primary hash ID from the secondary blacklist data (see Figure 7) (ST702). Subsequently, the identity verification server 2 sends a notification to the business server 3 indicating that the user's record to be removed from the secondary blacklist data has been deleted.

[0144] When the service provider server 3 receives the notification that the blacklist removal is complete, it removes the user who was removed from the blacklist master table (see Figure 5) (ST703).

[0145] This blacklist removal process allows for the deletion of information from the blacklist master table, such as information about individuals who were mistakenly registered or individuals who have not engaged in fraudulent activities for a long period of time.

[0146] [Second Embodiment] Next, a personal information processing system according to the second embodiment will be described. With respect to the personal information processing system according to the second embodiment, components similar to those in the first embodiment will be denoted by the same reference numerals and detailed descriptions will be omitted. Furthermore, with respect to the personal information processing system according to the second embodiment, matters not specifically mentioned below will be the same as in the first embodiment.

[0147] As shown in Figure 19, the personal information processing system 1 according to the second embodiment has a configuration in which the business operator terminal 4 is omitted compared to the personal information processing system 1 shown in Figure 1.

[0148] As shown in Figure 20, the user terminal 5 (an example of a personal information acquisition device) according to the second embodiment has a wallet application 51, along with a business application 161 and an identity verification application 162 installed as software for handling the user's personal information.

[0149] The business application 161 has the same functions as the business application 61 shown in Figure 3. However, the business application 161 does not need to have the identity verification library 62 incorporated as the business application 61.

[0150] The identity verification application 162 has the same functions as the identity verification library 62 shown in Figure 3. In other words, the identity verification application 162 has the functions of user inquiry 63, data conversion 64, face matching 65, and rule verification 66 described above. In this case, the functions of user inquiry 63 and others may be realized by incorporating the identity verification library into the identity verification application 162, similar to the business application 61 shown in Figure 3.

[0151] (Blacklist matching process) Next, with reference to Figure 21, the blacklist matching process in the personal information processing system 1 according to the second embodiment will be described.

[0152] When the user executes the identity verification menu (ST801), the user terminal 5 (business application 161) launches the identity verification application 162. The identity verification application 162 then requests the business application 161 to obtain the user's consent to provide information. The business application 161 then displays a consent acquisition screen to obtain the user's consent to provide information, and the user performs an operation to consent to provide information (ST802). As a result, the business application 161 notifies the identity verification application 162 that the user has given consent to provide information.

[0153] Therefore, the user terminal 5 (identity verification app 162) requests identity document data 52 from the wallet app 51. As a result, the encrypted basic 3 pieces of information in the identity document data 52 stored in the wallet app 51 become available to the identity verification app 162.

[0154] Subsequently, the user terminal 5 (identity verification application 162) sends a blacklist matching request to the identity verification server 2. Encrypted basic information 3 is attached to the blacklist matching request that is sent.

[0155] Next, the identity verification server 2 decrypts the three basic pieces of user information it has received (ST803). Furthermore, the identity verification server 2 hashes the decrypted three basic pieces of information using a first hash function (an example of the first rule) to obtain a primary hash ID (user identification information, an example of the first converted user personal information). Furthermore, the identity verification server 2 hashes the primary hash ID using a second hash function (an example of the second rule) to obtain the user's secondary hash ID (user identification information, an example of the second converted user personal information) (ST804).

[0156] Subsequently, the processes corresponding to steps ST206-ST210 in Figure 8 are executed.

[0157] Thus, in the personal information processing system 1 according to the second embodiment, as shown in Figure 2(B) above, users receiving the service can perform the same processing as in the personal information processing system 1 according to the first embodiment from the user terminal 5 without needing the service provider terminal 4.

[0158] [Third Embodiment] Next, a personal information processing system according to the third embodiment will be described. With respect to the personal information processing system according to the third embodiment, components that are the same as those in the first or second embodiment will be denoted by the same reference numerals and detailed descriptions will be omitted. Furthermore, with respect to the personal information processing system according to the third embodiment, matters not specifically mentioned below will be the same as in the first or second embodiment.

[0159] (Rule registration process) First, with reference to Figure 22, the rule registration process in the personal information processing system 1 according to the third embodiment will be described.

[0160] The service provider server 3 (an example of a service provider device) sets the rules for providing services offered by the service provider (ST901). This setting of service provision rules is performed by each service provider (usually by multiple service provider servers 3 managed by multiple service providers).

[0161] Setting such service provision rules generates rule setting information (an example of service provision conditions), such as shown in Figure 23. Figure 23(A) shows that the service provider (provider ID "AAA") can only provide services to users who are 20 years of age or older. Figure 23(B) shows that the service provider (provider ID "BBBB") can only provide services to users who are under 20 years of age and whose address is in XX Prefecture, △ City, □ Town.

[0162] Next, the service provider server 3 sends a rule registration request to the identity verification server 2 (an example of a user determination device) to request the registration of the service provision rules. The sent rule registration request includes the service provider ID and rule setting information related to the service provider in question.

[0163] Therefore, when the identity verification server 2 receives a rule registration request, it registers the rule setting information in the rule setting master table (ST902). The rule setting master table includes, for example, the service provision rules set by each service provider, as shown in Figure 24.

[0164] (Rule determination process) Next, with reference to Figure 25, the rule determination process in the personal information processing system 1 according to the third embodiment will be described.

[0165] When rule determination processing begins on the business terminal 4, the business application 61 loads the identity verification library 62 and requests information retrieval from the identity verification library 62. Subsequently, the business terminal 4 (business application 61) issues an action instruction to the user (ST1001). Here, as an action instruction to the user, a message prompting the user to hold the user terminal 5 over the terminal is displayed on the guidance screen. The business terminal 4 (business application 61) can recognize the services provided to the user based on the user's personal information and the user's input operations on the business terminal 4. As a result, the business application 61 can notify the identity verification library 62 of the business ID related to the services provided to the user.

[0166] The user holds the user terminal 5 over the business terminal 4 (an example of a personal information acquisition device) according to the instructions. Upon detecting the user terminal 5, the business terminal 4 initiates short-range wireless communication with the user terminal 5.

[0167] Subsequently, the service provider terminal 4 (identity verification library 62) requests the user terminal 5 to provide data on the user's personal information, specifically their attribute information (in this case, date of birth and address).

[0168] Upon receiving the request, user terminal 5 displays a screen to obtain the user's consent to provide information. When the user agrees (ST1002), encrypted user attribute information is provided to carrier terminal 4 (i.e., transmitted via short-range communication).

[0169] The business terminal 4 (identity verification library 62) decrypts the received encrypted user attribute information (in this case, date of birth and address) (ST1003). Subsequently, the business terminal 4 (identity verification library 62) sends a rule judgment request to the identity verification server 2. At this time, the rule judgment request is accompanied by information on the user's attributes (the user's date of birth and address, and the business ID from which the user receives services). The identity verification library 62 in the business terminal 4 can, if necessary, notify (share) the user attribute information with the business application 61.

[0170] When the identity verification server 2 receives the rule determination request, it performs a rule determination (ST1004). At this time, the identity verification server 2 determines whether the user's attributes satisfy the rule setting information for the target service provider in the rule setting master table (see Figure 24). For example, in step ST1004, if the service provider ID of the target service provider is "AAA", it is determined whether the user is 20 years of age or older.

[0171] Subsequently, the identity verification server 2 sends a rule judgment response (an example of the result of a judgment regarding the conditions for providing the service) to the business terminal 4 (identity verification library 62). The rule judgment response includes the result of the judgment in step ST1004 (i.e., information on whether the user's personal information meets the conditions for providing the service). Based on the rule judgment response, the business terminal 4 (business application 61) displays the result of the rule judgment on the display (display unit 34) (ST1005).

[0172] If the service provider terminal 4 (service provider application 61) determines, based on the rule check, that the user meets the service provision conditions, it sends a service usage request to the service provider server 3 to request the provision of the service to the user.

[0173] When the service provider server 3 receives a service request, it executes a process (an example of a process related to service provision) to provide the service (or apply the service). Such a process to provide the service (or apply the service) includes, for example, providing information regarding the receipt of goods or providing ticket information.

[0174] (First Modification of Rule Registration Process) Next, with reference to Figure 26, a first modification of the rule registration process in the personal information processing system 1 shown in Figure 22 will be described.

[0175] In the first modified example of the rule registration process, steps ST1101 and ST1102 are executed, which roughly correspond to steps ST1001 and ST1002 in Figure 22, respectively. Furthermore, matters not specifically mentioned below are the same as those in the rule registration process shown in Figure 22.

[0176] In this first modified example, setting the service provision rules in step ST1101 generates rule setting information (an example of service provision conditions) as shown in Figure 27. Figure 27(A) shows that the service provider (business ID "AAA") can only provide services to users aged 20 or older, and that they receive a 10% discount as a benefit. Figure 27(B) shows that the service provider (business ID "BBBB") can only provide services to users under 20 years of age whose address is in XX Prefecture, △ City, □ Town, and that they receive points (e.g., loyalty points) equivalent to 5% of the cost as a benefit. In other words, the first modified example differs from the rule registration process shown in Figure 22 in that benefit information (an example of information regarding benefits associated with the service) is added to the rule setting information.

[0177] Furthermore, in step ST1102, in the rule setting master table that the identity verification server 2 registers, benefit information is added to the service provision rules set by each service provider, for example, as shown in Figure 28.

[0178] (First Modification of Rule Determination Process) Next, with reference to Figure 29, a first modification of the rule determination process in the personal information processing system 1 shown in Figure 25 will be described. Unless otherwise specified below, the process is the same as that shown in Figure 25.

[0179] In the first modified example of the rule determination process, steps ST1201 to ST1205 are executed, which roughly correspond to steps ST1001 to ST1005 in Figure 25, respectively.

[0180] In the first modified example, if the user meets the service provision conditions, the service provider terminal 4 (service provider application 61) displays the result of the rule determination (ST1205), and then further displays on the display (display unit 34) that the benefit will be applied (ST1206).

[0181] Subsequently, the identity verification server 2 (business application 61) sends a service usage request to the business server 3 to request the provision of services to the target user. A request for the application of benefits is attached to this service usage request.

[0182] When the service provider server 3 receives the service request, it executes a process to provide the service (or apply the service) (an example of a process to provide a service with attached benefits). This process to provide the service includes the application of benefits.

[0183] (Second Modification of Rule Determination Process) Next, with reference to Figure 30, a second modification of the rule determination process in the personal information processing system 1 shown in Figure 25 will be described. Unless otherwise specified below, the process is the same as that shown in Figure 25.

[0184] In the second modified example of the rule determination process, steps ST1301 to ST1303 are executed, which generally correspond to steps ST1001 to ST1003 in Figure 25, respectively.

[0185] In the second modified example, the business application 61 requests three pieces of basic information, including the user's name, from the user terminal 5.

[0186] Next, when the business terminal 4 (business application 61) receives encrypted basic 3 information from the user terminal 5 (wallet application 51), it decrypts the received basic 3 information (ST1303).

[0187] Therefore, the business terminal 4 (identity verification library 62) obtains a secondary hash ID from the user's basic three pieces of information, similar to step ST204 shown in Figure 8 (ST1304).

[0188] Next, the business terminal 4 (identity verification library 62) sends a rule judgment request to the identity verification server 2. At this time, the rule judgment request is accompanied by information such as the user's date of birth, address, business ID, and secondary hash ID.

[0189] When the identity verification server 2 receives the rule determination request, it saves or updates the usage history log for the target secondary hash ID, for example, as shown in Figure 31 (ST1305).

[0190] Next, the identity verification server 2 performs a rule determination (ST1306) in the same manner as in step ST1004 described above. However, in this rule determination, instead of the rule setting master table shown in Figure 24, a rule setting master table such as the one shown in Figure 32 is used. More specifically, in step ST1306, with respect to the corresponding business ID, it is determined whether the cumulative number of uses in the usage history log (see Figure 31) for the secondary hash ID satisfies the upper limit of the number of uses in the rule setting master table (an example of information on the number of times the service can be provided).

[0191] The subsequent processing, such as the rule determination response, is the same as the rule determination process shown in Figure 25.

[0192] In the personal information processing system 1 according to the third embodiment, the components related to the blacklist registration process and blacklist matching process according to the first or second embodiment may be omitted. However, the rule registration process and rule determination process described above can be executed in combination with the blacklist registration process and blacklist matching process according to the first or second embodiment. For example, in the personal information processing system 1, the blacklist matching process can be executed before the rule determination process. This allows the personal information processing system 1 to avoid the service being inappropriately provided (i.e., to persons of concern) even if the personal information of the target user meets the service provision conditions.

[0193] As described above, embodiments have been explained as examples of the technology disclosed in this application. However, the technology in this disclosure is not limited to these embodiments and can be applied to embodiments that have been modified, replaced, added, or omitted. Furthermore, it is possible to create new embodiments by combining the components described in the above embodiments.

[0194] The personal information processing system, personal information processing device, personal information processing method, and personal information processing program related to this disclosure enable the determination of whether a user meets the conditions for providing the target service by utilizing the user's digitized personal information, and are useful as personal information processing devices, personal information processing systems, personal information processing methods, and personal information processing programs that utilize personal information contained in the user's identification document.

[0195] 1: Personal Information Processing System 2: Identity Verification Server 3: Business Server 4: Business Terminal 5: User Terminal 6: Communication Network 11: Communication Unit 12: Control Unit 13: Storage Unit 21: Communication Unit 22: Control Unit 23: Storage Unit 31: Communication Unit 32: Imaging Unit 33: Operation Unit 34: Display Unit 35: Control Unit 36: Storage Unit 41: Communication Unit 42: Imaging Unit 43: Operation Unit 44: Display Unit 45: Control Unit 46: Storage Unit 51: Wallet App 52: Identity Document Data 61: Business App 62: Identity Verification Library 63: User Inquiry 64: Data Conversion 65: Face Recognition 66: Rule Confirmation 71: Blacklist Management 72: Rule Registration 81: Data Verification 82 : Data conversion 83: Blacklist history management 84: Rule judgment 85: Service provision history management 161: Business app 162: Identity verification app U: User

Claims

1. A personal information processing system for processing digitized personal information, comprising: a service provision device that performs processing related to the provision of services to a user; a personal information acquisition device that acquires the digitized personal information of the user; and a user determination device that determines whether the user is eligible to receive the service, wherein the service provision device sets the conditions for providing the service that can be provided to the user; the user determination device determines whether the user's personal information satisfies the conditions for providing the service; and the service provision device performs processing related to the provision of the service to the user only if, as a result of the determination regarding the conditions for providing the service, the user's personal information satisfies the conditions for providing the service.

2. The personal information processing system according to claim 1, wherein the digitized personal information of the user is information associated with a digital wallet on a user terminal used by the user, or information stored on a physical card used by the user.

3. The personal information processing system according to claim 1, wherein the service provision conditions information includes information relating to benefits attached to the service, and the service provision device performs processing to provide the user with the service attached to the benefits.

4. The personal information processing system according to claim 1, wherein the service provision conditions information includes information on the number of times the service can be provided, the user determination device determines whether the cumulative number of times the service has been provided to the user exceeds the number of times the service can be provided, and if the cumulative number exceeds the number of times the service can be provided, the device determines that the user's personal information does not meet the service provision conditions.

5. The personal information acquisition device acquires a first converted user personal information obtained by irreversibly converting the user's personal information according to the first rule, and a second converted user personal information obtained by irreversibly converting the user's personal information according to the second rule, and the user determination device stores the cumulative count information in association with the second converted user personal information, the personal information processing system according to claim 4.

6. A personal information processing device comprising a processor for processing digitized personal information, wherein the processor obtains the conditions for providing services that can be offered to a user, obtains the digitized personal information of the user, determines whether the user's personal information satisfies the conditions for providing the services, and notifies other devices that perform processing related to the provision of the services of the result of the determination regarding the conditions for providing the services.

7. A personal information processing method for processing digitized personal information, wherein a computer obtains the conditions for providing services that can be offered to a user, obtains the digitized personal information of the user, determines whether the user's personal information satisfies the conditions for providing the services, and notifies other devices that perform processing related to the provision of the services of the result of the determination regarding the conditions for providing the services.

8. A personal information processing program for processing digitized personal information, the program causes a computer to obtain the conditions for providing services that can be offered to a user, to obtain the digitized personal information of the user, to determine whether the user's personal information satisfies the conditions for providing the services, and to notify other devices that perform processing related to the provision of the services of the result of the determination regarding the conditions for providing the services.