WO2021085061A1 - 情報取引システム、情報取引装置、情報取引方法、プログラム - Google Patents
情報取引システム、情報取引装置、情報取引方法、プログラム Download PDFInfo
- Publication number
- WO2021085061A1 WO2021085061A1 PCT/JP2020/037969 JP2020037969W WO2021085061A1 WO 2021085061 A1 WO2021085061 A1 WO 2021085061A1 JP 2020037969 W JP2020037969 W JP 2020037969W WO 2021085061 A1 WO2021085061 A1 WO 2021085061A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- data set
- personal
- request
- trading
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims description 54
- 230000005540 biological transmission Effects 0.000 claims abstract description 106
- 230000008520 organization Effects 0.000 claims description 148
- 230000007717 exclusion Effects 0.000 claims description 30
- 230000006870 function Effects 0.000 claims description 18
- 238000012545 processing Methods 0.000 description 35
- 230000008569 process Effects 0.000 description 34
- 238000010586 diagram Methods 0.000 description 27
- 238000004364 calculation method Methods 0.000 description 26
- 238000004891 communication Methods 0.000 description 7
- 230000036772 blood pressure Effects 0.000 description 6
- 230000036760 body temperature Effects 0.000 description 6
- 238000003745 diagnosis Methods 0.000 description 6
- 238000007689 inspection Methods 0.000 description 6
- 230000029058 respiratory gaseous exchange Effects 0.000 description 6
- 125000002066 L-histidyl group Chemical group [H]N1C([H])=NC(C([H])([H])[C@](C(=O)[*])([H])N([H])[H])=C1[H] 0.000 description 5
- 230000007246 mechanism Effects 0.000 description 4
- 230000004044 response Effects 0.000 description 4
- 238000005516 engineering process Methods 0.000 description 2
- 238000012360 testing method Methods 0.000 description 2
- 238000004590 computer program Methods 0.000 description 1
- 239000012141 concentrate Substances 0.000 description 1
- 238000012937 correction Methods 0.000 description 1
- 239000012530 fluid Substances 0.000 description 1
- 230000010365 information processing Effects 0.000 description 1
- 239000004065 semiconductor Substances 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q10/00—Administration; Management
- G06Q10/10—Office automation; Time management
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/22—Indexing; Data structures therefor; Storage structures
- G06F16/2291—User-Defined Types; Storage management thereof
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q50/00—Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
- G06Q50/10—Services
- G06Q50/22—Social work or social welfare, e.g. community support activities or counselling services
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q50/00—Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
- G06Q50/10—Services
- G06Q50/26—Government or public services
- G06Q50/265—Personal security, identity or safety
Definitions
- the present invention relates to an information trading system, an information trading device, an information trading method, and a program.
- a computer system has been proposed in which personal information held in a hospital or the like is provided to a device to which information is provided, such as a user who wishes to utilize the personal information, based on the consent of the individual.
- an information trading device managed by an organization such as an information bank is made to communicate and connect an information providing device and an information providing destination device.
- the information provider device is a device managed by an organization such as an information provider company.
- the information providing destination device is a device managed by an information providing destination organization such as a utilization company.
- the information trading device stores the personal information sent from the information providing device, and transmits the personal information desired by the utilization business operator who manages the information providing device from the personal information to the information providing device. To do. Techniques related to such a system are disclosed in Patent Document 1 and Patent Document 2.
- Patent Document 1 when there is a request for personal information from a utilization business operator regarding personal information held by the holding business operator, the intermediary server is not allowed to disclose the attributes of the information provider and the information provider.
- a technique is disclosed in which a combination with the above information is replaced with dummy information so that name identification cannot be performed and the information is disclosed to the user terminal. With this technology, personal information is safely disclosed to the outside.
- Patent Document 2 discloses a technique of acquiring medical data without going through an external network, correcting the medical data based on a correction instruction, and outputting the medical data to the network. With this technology, the protection range of personal information contained in medical data can be changed in a fluid manner, and the medical data can be safely distributed to an external network.
- a computer system as described above, personal information generated by a plurality of information providers is provided outside the information provider device that manages the information provider, and information that mediates the provision of personal information to the information provider device.
- the information trading device holds a large amount of personal information generated by a plurality of information provider devices and the like. In such a case, especially when there are many information provider devices, the risk of unauthorized leakage of a large amount of personal information generated by the organization that manages the information provider devices is concentrated on the information transaction device. Will occur.
- An object of the present invention is to provide an information trading system, an information trading device, an information trading method, and a program that solve the above-mentioned problems.
- the information trading system includes an information providing device and an information trading device communication-connected to the information providing destination device, and the information trading device comprises the information from the information providing device.
- the information trading device comprises the information from the information providing device.
- the transmission request is output to the information providing source device.
- the information trading device stores catalog information including detailed information about one or more data sets including personal information that can be provided from the information providing device to the information providing destination device. Receives the data set provision request from the information providing destination device, and outputs the data set transmission request indicated by the providing request to the information providing source device.
- the information trading method is an information trading system including an information trading device connected to an information providing source device and an information providing destination device, and the information trading device provides the information.
- the program includes detailed information about one or more data sets including personal information capable of providing the computer of the information trading device from the information providing device to the information providing device. It functions as a means for storing catalog information, a means for receiving a request for providing the data set from the information providing destination device, and a means for outputting a transmission request for the data set indicated by the providing request to the information providing source device.
- the information trading method is data in which explanatory items relating to one or more data sets including personal information that can be provided from the information providing device to the information providing destination device are described for each of the data sets.
- the set designated web page is transmitted to the information providing destination device, and the selection of the data set to be provided is requested from the one or more data sets described in the data set designated web page is received from the information providing destination device.
- the request for transmission of the personal information to the information providing destination device is output to the information providing source device that stores the personal information.
- the information trading device is data in which explanatory items relating to one or more data sets including personal information that can be provided from the information providing device to the information providing destination device are described for each of the data sets.
- the set designated web page is transmitted to the information providing destination device, and the selection of the data set to be provided is requested from the one or more data sets described in the data set designated web page is received from the information providing destination device.
- the request for transmission of the personal information to the information providing destination device is output to the information providing source device that stores the personal information.
- the program recorded on the recording medium relates to one or more data sets including personal information capable of providing the computer of the information trading device from the information providing device to the information providing device.
- information that manages personal information without concentrating the risk of unauthorized leakage of a large amount of personal information generated by each of the plurality of information providers that manage the information provider device on the information trading device It is possible to provide a trading system, an information trading device, an information trading method, and a program.
- FIG. 1 is a first diagram showing a configuration of an information trading system according to the first embodiment.
- the information trading system 100A is configured by connecting an information trading device 1, an information providing source device 2, and an information providing destination device 3 by communication.
- the information provider device 2 is a computer device that manages personal information generated by an organization of the information provider.
- the organization that provides the information may be, for example, a hospital, a company, or the like.
- the information trading device 1 may communicate and connect with a plurality of information providing source devices 2 managed by a plurality of different information providing source organizations.
- the information providing source device 2 can also be directly connected to the information providing destination device 3.
- the information providing destination device 3 is a computer device that performs various information processing by utilizing the personal information provided by the information providing source device 2.
- the organization to which the information is provided may be, for example, a company, a public organization, or the like.
- the information trading device 1 may be connected to a plurality of information providing destination devices 3 managed by a plurality of different information providing destination organizations by communication.
- the information provider device 2 includes a first database 21 (hereinafter referred to as a first DB 21) and a second database 22 (hereinafter referred to as a second DB 22).
- the first DB 21 is a storage device that stores personal information generated by an information provider.
- the second DB 22 stores a data set including the personal information generated based on the personal information stored in the first DB 21.
- the information providing source device 2 transmits the data set indicated by the transmission request to the information providing destination device 3 based on the transmission request acquired from the information trading device 1.
- a personal terminal 4 is communicated and connected to the information trading device 1.
- the personal terminal 4 is a computer device used by an individual user who is a target of acquisition of personal information generated by an organization that provides information. The individual user approves the provision of personal information generated by the information providing organization as his / her own information to the information providing destination device 3, and uses the personal terminal 4 to obtain the approval result of the information trading device 1. Register at.
- FIG. 2 is a hardware configuration diagram of an information trading device in the information trading system according to the first embodiment.
- the information trading device 1a includes hardware such as a CPU (Central Processing Unit) 101, a ROM (Read Only Memory) 102, a RAM (Random Access Memory) 103, a database 104, and a communication module 105. It is a computer device.
- the information providing source device 2, the information providing destination device 3, and the personal terminal 4 are also computer devices having the same hardware configuration.
- FIG. 3 is a functional block diagram of the information trading device in the information trading system according to the first embodiment.
- the information transaction device 1b activates the information transaction management program in advance.
- the information trading device 1b includes the control unit 11, the personal terminal interface unit 12, the provider interface unit 13, the provider interface unit 14, the catalog information generation unit 15, the approval destination identification unit 16, the transmission request unit 17, and the provision consideration calculation.
- a unit 18 and a record consideration calculation unit 19 are provided.
- the control unit 11 controls each functional unit of the information trading device 1b.
- the personal terminal interface unit 12 processes the output of information to the personal terminal 4 and the acquisition of the information transmitted from the personal terminal 4.
- the provider interface unit 13 processes the output of information to the information provider device 2 and the acquisition of the information transmitted from the information provider device 2.
- the provider interface unit 14 processes the output of information to the information provider device 3 and the acquisition of the information transmitted from the information provider device 3.
- the catalog information generation unit 15 generates catalog information.
- the catalog information is information indicating detailed information about one or more data sets including personal information that can be provided from the information providing device to the information providing destination device. Details of the catalog information will be described later.
- the approval destination identification unit 16 identifies an individual user who is an approval destination for the provision of the data set based on the data set provision request transmitted by the information providing destination device 3.
- the transmission request unit 17 outputs the transmission request of the data set indicated by the provision request to the information providing source device 2.
- the provision consideration calculation unit 18 calculates the provision consideration based on the amount of personal information transmitted from the information providing source device 2 to the information providing destination device 3.
- the offer consideration indicates, for example, the amount of the offer consideration paid to an individual user.
- the record consideration calculation unit 19 calculates the record consideration based on the amount of information recorded in the storage device of the information provider device 2 as personal information transmitted by the information provider device 2 to the information provider device 3.
- the record consideration indicates, for example, the amount of the record consideration paid to an individual user.
- FIG. 4 is a diagram for explaining the details of the catalog information generated by the catalog information generation unit 15 of the information trading apparatus.
- the catalog information 40 includes a data set name related to a data set, the number of individuals corresponding to the personal information contained in the data set, the amount of data N per person, the details of data (personal information) per person, and data. Includes information such as occurrence attributes, offer consideration, and record consideration. For details of per capita data, for example, if the provider is a hospital, common items (personal identification code, gender, age), unique items (data acquisition date, vital signs (body temperature, pulse, respiration, blood pressure) ), Inspection items, inspection results, diagnosis results, information provider code), etc.
- the information provider code is identification information about the information provider organization that manages the information provider device.
- the data generation attribute includes whether personal information is information registered by a medical institution (medical institution), information input by an individual (individual input), or information automatically acquired from a device such as a sensor (personal device). Includes identification information of the source of personal information indicating (automatic acquisition). The person in charge of the organization of the information providing destination using the information providing destination device 3 confirms the detailed information about the data set included in the catalog information, and selects the data set to be provided.
- FIG. 5 is a diagram illustrating details of personal data location information supplied in the information trading system according to the first embodiment.
- the personal data location information 50 stores a personal identification code, an information provider code, a data set type, the number of data sets, and the like for each individual.
- the personal identification code is a code that identifies an individual user who provides personal information.
- the information provider code is the identification information of the organization that manages the information provider device 2 that stores the data set including the personal information of the individual indicated by the personal identification code.
- the data set type is a type or identifier of a data set including personal information of an individual indicated by a personal identification code.
- the number of data sets is the number of data sets including personal information of the individual indicated by the personal identification code.
- the information trading device 1b identifies the information providing source device 2 that stores the data set indicated by the providing request acquired from the information providing destination device 3 based on the personal data location information.
- the information trading system 100A includes an information trading device 1b connected to the information providing source device 2 and the information providing destination device 3.
- the information trading device 1b stores catalog information including detailed information about one or more data sets including personal information that can be provided from the information providing device 2 to the information providing device 3, and the information providing device 3 to the data set of the data set. Accept the offer request.
- the information trading device 1b outputs the data set transmission request indicated by the providing request to the information providing source device 2.
- FIG. 6 shows a processing flow performed between the information trading device and the information providing destination device in the information trading system according to the first embodiment.
- the information trading device 1b further stores the format definition information that defines the format format of the data set.
- the information providing source device 2 or the information providing destination device 3 requests the information trading device 1b to generate format definition information related to a data set including new personal information in which the format definition information stored in the information trading device 1b is undefined. can do.
- the person in charge of the information providing organization wants to receive the provision of a new data set
- the person in charge of the information providing destination device 3 connects the information providing destination device 3 to the information trading device 1b.
- the information providing destination device 3 and the information trading device 1b are connected and communicate with each other (step S101).
- the provider interface unit 14 of the information trading device 1b has a function of updating the format definition information API (Application Programming Interface), and transmits the update interface screen of the format definition information to the connected information providing device 3 (step). S102).
- the information providing destination device 3 acquires the update interface screen and outputs the update interface screen of the format definition information to the display (step S103).
- the person in charge of the organization to which the information is provided inputs the format of the personal information to be newly included in the data set in the input field of the format definition information update interface screen, and inputs the transmission request.
- the information providing destination device 3 receives the transmission request (step S104).
- the information providing destination device 3 transmits a request for updating the format definition information including the format format of the personal information newly included in the data set to the information trading device 1b (step S105).
- This process is one aspect of the process of transmitting an additional request to the data set of new personal information other than the personal information that can be included in the data set indicated by the format definition information by the information providing destination device 3.
- the provider interface unit 14 of the information trading device 1b acquires a request for updating the format definition information.
- the provider interface unit 14 acquires the format format of the personal information newly included in the data set from the update request of the format definition information and outputs it to the control unit 11.
- the control unit 11 generates format definition information that defines the format of the data set and records it in the storage unit of its own device (step S106).
- the information provider device 2 uses the format definition information that defines the format of the data set to generate a data set that includes new personal information for which the format definition information has not been defined by the subsequent processing. Can be done.
- FIG. 7 shows a processing flow performed between the information trading device and the information providing source device in the information trading system according to the first embodiment.
- the information provider device 2 detects the recording of the personal information that can be provided in the first DB 21 in the generation of the data set including the personal information (step S201).
- the personal information may be data including personal information generated by a computer of the information providing organization connected to the information providing source device 2, or data including personal information automatically generated by a device such as a sensor. It may be.
- the data set may be data including personal information entered by an individual user on a computer or the like belonging to the information providing organization, or the individual user may use the personal terminal 4 to send the information to the information providing organization. It may be data including personal information transmitted to the computer to which it belongs.
- Personal information includes common items of the above-mentioned catalog information (personal identification code, gender, age associated with personal information included as a data set) and unique items (data acquisition date and data of personal information included as a data set). It may be information such as content, information provider identification information), data generation attribute (organization, individual, device that generated or input personal information). As an example, when the organization that provides the information is a hospital and a doctor at the hospital examines an individual user, the personal information contained in the data set generated by the hospital includes a personal identification code that identifies the individual and gender. , Age, data acquisition date, vital signs (body temperature, pulse, breathing, blood pressure), examination items in examination, examination results, diagnosis results, etc. are included.
- the information provider device 2 reads the personal information from the first DB 21. When the information provider device 2 generates the data set including the personal information, the information provider device 2 communicates with the information trading device 1b and requests the transmission of the format definition information (step S202). The provider interface unit 13 of the information trading device 1b accepts the designation of personal information and transmits the format definition information corresponding to the personal information to the information provider device 2 (step S203).
- the information provider device 2 acquires the format definition information (step S204).
- the information provider device 2 generates a data set including personal information according to the data format indicated by the format definition information (step S205).
- the information provider device 2 records the generated data set in the second DB 22 (step S206).
- the information provider device 2 stores the data set holding the personal information according to the data format indicated by the format definition information.
- the plurality of information providing source devices 2 generate a data set of the data format indicated by the format definition information.
- the information providing destination device 3 provided with those data sets can acquire a unified data set in the same data format transmitted from each information providing source device 2, and thus the individual included in the data set. Processing using information can be easily performed.
- the information provider device 2 transmits information about the generated data set to the information trading device 1b (step S207).
- the information about the contents related to the data set includes the name of the data set related to the data set, the number of individuals corresponding to the personal information contained in the data set, the amount of data N per person, the details of the data (personal information) per person, and the data. Contains information such as occurrence attributes, offer consideration, and record consideration. For details of per capita data, for example, if the provider is a hospital, common items (personal identification code, gender, age), unique items (data acquisition date, vital signs (body temperature, pulse, respiration, blood pressure) ), Inspection items, inspection results, diagnosis results, information provider code), etc.
- the catalog information generation unit of the information trading apparatus 1b generates catalog information including information on the contents related to the generated data set, and updates the catalog information already stored (step S208).
- the information provider device 2 Based on the generated data set, the information provider device 2 has an individual identification code of an individual corresponding to the personal information included in the data set, an information provider code indicating the information provider organization that generated the data set, and a data set.
- the location information including the type, the number of data sets, and the like is generated (step S209).
- the information provider device 2 transmits the location information to the information trading device 1b (step S210).
- the provider interface unit 13 of the information trading device 1b acquires the location information transmitted from the information provider device 2.
- the provider interface unit 13 generates personal data location information 50 including new location information and records it in the database 104 of its own device (step S211). As a result, the information trading device 1b can grasp which data set is held by which information provider device 2.
- the record consideration calculation unit 19 may calculate the amount of the record consideration to be provided to the individual user corresponding to the personal information included in the data set when the data set is recorded in the second DB 22. In this case, for example, the record consideration calculation unit 19 specifies the data set name recorded in the second DB 22. The record consideration calculation unit 19 acquires the amount of the record consideration per unit amount of the data set from the information trading apparatus 1b. The record consideration calculation unit 19 calculates the record consideration amount of the data set recorded in the second DB 22 based on the record consideration amount per unit amount of the data set, and transmits it to the information trading apparatus 1b. The information trading device 1b stores information on the amount of record consideration of the data set for each individual user.
- the information trading device 1b Based on the request from the personal terminal, the information trading device 1b transmits to the personal terminal 4 the amount of the recording consideration of the data set to be stored for the personal user who operates the personal terminal. As a result, the individual user can confirm the consideration when his / her personal information is recorded as a provision candidate in the information providing source device 2.
- the amount of the record consideration provided to the individual user may be calculated at predetermined intervals.
- FIG. 8 shows a processing flow performed between the information trading device, the information providing destination device, the personal terminal, and the information providing source device in the information trading system according to the first embodiment.
- the manager of the information providing destination such as the data utilization organization that manages the information providing destination device 3 wants to receive the provision of the data set
- the manager of the information providing destination device 3 connects the information providing destination device 3 to the information trading device 1b by communication.
- the information trading device 1b and the information providing destination device 3 are communicated and connected (step S401).
- the providing destination interface unit 14 of the information trading device 1b transmits a data set designation web page for accepting the designation of the data set to be provided to the connected information providing destination device 3 (step S402).
- the destination interface unit 14 of the information trading device 1b displays the data set designation web page, which is information generated based on the detailed information about each data set included in the catalog information, and displays the details of each data set and its list. To do. Therefore, when the information providing destination device 3 outputs the data set designation web page, the administrator of the information providing destination organization uses a list of data set names that can be provided by the information providing source listed in the catalog information as a catalog. You can check.
- the information providing destination device 3 acquires the data set designated web page and outputs the data set designated web page to the display (step S403).
- the person in charge of the organization to which the information is provided checks the check box of the dataset that he / she wants to provide among the check boxes displayed in association with the information about each dataset on the dataset specification web page, and requests the provision. Press the button.
- the information providing destination device 3 receives the providing request (step S404).
- the information providing destination device 3 transmits a providing request including one or a plurality of data set names received as the providing request to the information trading device 1b (step S405).
- the provision request may include information such as the ID of the information providing destination device 3 and the network address of the information providing destination device 3.
- the provider interface unit 14 of the information trading device 1b acquires the provision request (step S406).
- the provision destination interface unit 14 outputs the provision request to the approval destination identification unit 16.
- the approval destination identification unit 16 acquires the provision request.
- the approval destination identification unit 16 acquires the data set name included in the provision request.
- the approval destination identification unit 16 acquires all the personal identification codes included in the personal data location information 50 in association with the data set name (step S407).
- the approval destination identification unit 16 acquires the approval destination address stored in advance by the information trading device 1b in association with all the personal identification codes (step S408).
- the approval destination address is the address of the personal terminal 4. Alternatively, the approval destination address may be an address held by the application program held by the personal terminal 4.
- the approval destination identification unit 16 transmits an approval registration request page to each personal terminal 4 specified by the approval destination address (step S409).
- the approval registration request page includes information such as the data set name included in the provision request and the organization name of the information providing destination organization that manages the information providing destination device 3 that has transmitted the provision request.
- Each personal terminal 4 acquires the approval registration request page.
- the personal terminal 4 outputs an approval registration request page to the display (step S410).
- the approval registration request page includes the amount of the provision consideration and the record consideration associated with the data set name, and the approval registration request page including such information may be output to the display of the personal terminal 4.
- the individual user recognizes the data set name, the organization name of the information providing destination organization, the provision consideration and the record consideration displayed on the approval registration request page, and the personal information specified by the data set name is the information providing destination. Enter approval to provide to the organization.
- the approval registration request page further displays the approval OK and approval NG buttons, and the user presses any of the buttons using an input device such as a mouse to approve OK or approval NG. Approval input indicating any of the above can be input.
- each personal terminal 4 When the user presses the approval OK button, each personal terminal 4 generates an approval result including the approval OK flag (step S411).
- each personal terminal 4 When the user presses the approval NG button, each personal terminal 4 generates an approval result including the approval NG flag.
- the approval result may further include the data set name, the organization name of the information providing destination organization, the personal identification code of the individual user who uses the personal terminal 4, and the like, which are included in the approval request.
- Each personal terminal 4 transmits the generated approval result to the information trading device 1b (step S412).
- the personal terminal interface unit 12 of the information trading device 1b acquires the approval result received from each personal terminal 4 (step S413).
- the personal terminal interface unit 12 outputs the approval result to the transmission request unit 17.
- the transmission requesting unit 17 determines whether each approval result includes the approval OK flag (step S414).
- the transmission request unit 17 generates a transmission request when each approval result includes an approval OK flag (step S415).
- the transmission request may include the data set name included in the approval result, the organization name of the information providing destination organization, the ID of the information providing destination device 3, the network address of the information providing destination device 3, and the like.
- the transmission requesting unit 17 acquires the personal identification code included in the approval result and determines that the personal information corresponding to the personal identification code cannot be provided (step S416). ).
- the transmission request unit 17 acquires an information provider code that identifies each of the one or more information provider devices 2 included in the catalog information 40 in association with the data set name (step S417).
- the transmission request unit 17 stores the network address of the information provider device 2 in advance in association with the information provider code.
- the transmission request unit 17 acquires the network address of the information provider device 2 that is stored in association with the acquired information provider code.
- the transmission request unit 17 transmits a transmission request to the acquired network address (step S418).
- the personal identification code included in the approval result, which is approved in step S416, is stored as the personal identification code of the individual user corresponding to the personal information that cannot be provided.
- the information provider device 2 receives the transmission request.
- the information provider device 2 is a data set name included in a transmission request, an organization name of a provider organization, an ID of the information provider device 3, a network address of the information provider device 3, and an individual user corresponding to personal information that cannot be provided. Get your personal identification code.
- the information provider device 2 acquires the data set corresponding to the data set name from the second DB 22 (step S419).
- the information provider device 2 deletes the personal information corresponding to the personal identification code stored in the transmission request from the personal information included in the data set.
- the information providing source device 2 transmits the data set to the network address of the information providing destination device 3 included in the transmission request (step S420).
- the information providing destination device 3 receives the data set.
- the information providing destination device 3 records the received data set in a database or the like provided in the own device (step S421). The information providing destination device 3 then performs a predetermined process using the received data set.
- the information providing source device 2 may transmit the data set to be transmitted in response to the transmission request to the information providing destination device 3 via the information trading device 1b.
- the information providing source device 2 transfers the data sets acquired from a plurality of different information providing source devices 2 to one information providing destination device 3, the data sets may be collectively transferred.
- the information trading device 1b does not store the data set including the personal information generated by the plurality of information providing source devices 2 in its own device, but provides the information providing device 3 to the information providing destination device 3 desired to provide the data set. You can control the transmission of the dataset. As a result, a mechanism for managing personal information without concentrating the risk of unauthorized leakage of a large amount of personal information generated by each of the plurality of information providers that manage the information provider device 2 on the information trading device 1b. Can be provided.
- the provision consideration calculation unit 18 provides the provision consideration to the individual user corresponding to the personal information included in the data set in response to the data set being transmitted from the information providing source device 2 to the information providing destination device 3. You may calculate the amount. In this case, for example, the provision consideration calculation unit 18 acquires information regarding the transmission of the data set based on the transmission request from the information providing source device 2, and specifies the data set name transmitted by the information providing source device 2 to the information providing destination device 3. To do. The offer consideration calculation unit 18 acquires the amount of the offer consideration per unit amount of the data set from the information trading device 1b.
- the offer consideration calculation unit 18 calculates the offer consideration amount of the data set transmitted to the information providing destination device 3 based on the offer consideration amount per unit amount of the data set, and transmits the data set to the information trading device 1b.
- the information trading device 1b stores information on the amount of consideration for providing the data set for each individual user. Based on the request from the personal terminal, the information trading device 1b transmits to the personal terminal 4 the amount of consideration for providing the data set to be stored for the personal user who operates the personal terminal. As a result, the individual user can confirm the consideration for the provision of his / her personal information to the information providing destination device 3.
- the amount of consideration provided to individual users may be calculated at predetermined intervals.
- FIG. 9 is a functional block diagram of the information trading device according to the second embodiment.
- the information trading device 1c according to the second embodiment is different from the function of the information trading device 1b according to the first embodiment in that it further exerts the function of the exclusion organization reception unit 10.
- the information trading device 1c receives from an individual user the selection of the organization to be excluded from the organizations that manage the information providing destination device 3.
- the information trading device 1c acquires the personal identification code included in the personal data location information related to the data set based on the data set indicated by the provision request transmitted by the information providing destination device 3, and the personal user makes the provision request.
- the organization associated with the transmitted information providing destination device 3 is selected as the organization to be excluded, the request for approval of the provision of personal information to the individual user or the information providing destination of the data set including the personal information. Stop at least one of the transmissions to the device 3.
- FIG. 10 shows a processing flow of an information trading system including an information trading device according to the second embodiment.
- the personal terminal interface unit 12 of the information trading device 1c is based on the access from each personal terminal 4.
- the exclusion organization selection page is transmitted (step S501).
- Each personal terminal 4 outputs the exclusion organization selection page to the display (step S502).
- Each individual user selects an organization to be excluded from the provision destinations of personal information on the exclusion organization selection page displayed on the personal terminal 4.
- a list of a plurality of organization categories to which candidates for organizations to which personal information is provided belongs and a check button for specifying exclusions thereof are displayed on the exclusion organization selection page.
- a registration button is displayed on the exclusion organization selection page.
- Each individual user operates the check button of the organization category to be excluded from the organization to which the personal information is provided to be ON, and presses the registration button.
- each personal terminal 4 detects the input of the organization category to which the organization to be excluded from the information providing destination organization of personal information belongs (step S503).
- Each personal terminal 4 generates filter information including at least a personal identification code and an organization category to which the information providing destination organization to be excluded belongs, and transmits the filter information to the information trading device 1c (step S504).
- the personal terminal interface unit 12 of the information trading device 1c acquires filter information from each personal terminal 4 (step S505).
- the personal terminal interface unit 12 records each filter information in a storage unit such as a database 104 (step S506).
- the filter information is information associated with the personal identification code and the organization category (provided exclusion destination category) of the organization excluded as the information providing destination organization selected by the individual user indicated by the personal identification code.
- the filter information regarding the plurality of individual users is recorded in the information trading device 1c.
- the information trading device 1c previously performs identification information of an organization category (provided exclusion destination category), an identification code of an information provider device 2 managed by an organization belonging to the organization category, a network address of the information provider device 2, and the like. It is assumed that the organization table associated and held is stored.
- step S406 acquires the provision request.
- the provision destination interface unit 14 outputs the provision request to the approval destination identification unit 16.
- the approval destination identification unit 16 acquires the provision request.
- the approval destination identification unit 16 acquires the data set name included in the provision request.
- the approval destination identification unit 16 acquires all the personal identification codes included in the personal data location information 50 in association with the data set name (step S407). This process is the same as in the first embodiment.
- the approval destination specifying unit 16 detects the identification code of the information providing destination device 3 that transmitted the providing request acquired in step S406 from the providing request (step S601).
- the approval destination identification unit 16 acquires the identification information of the provision exclusion destination category recorded in the organization table in association with the information provision destination device 3 (step S602).
- the approval destination identification unit 16 determines whether the individual user corresponding to the personal identification code specified in step S407 is excluded from the information providing destination organization. For example, the approval destination identification unit 16 determines whether or not each personal identification code specified in step S407 and the identification information of the provision exclusion destination category acquired in step S602 are linked and recorded in the filter information (step). S603).
- the approval destination identification unit 16 is specified in step S407 when the personal identification code specified in step S407 and the identification information of the offer exclusion destination category acquired in step S602 are linked and are not recorded in the filter information.
- the individual user corresponding to the personal identification code is specified as the approval destination (step S604).
- the approval destination identification unit 16 identifies each of the personal identification codes specified in step S407. The approval request for each individual user of the personal identification code is stopped, thereby stopping the provision of the data set containing the personal information of those personal users (step S605).
- the subsequent processing is the same as the processing after step S408 of the first embodiment. That is, the approval destination specifying unit 16 acquires the approval destination address stored in advance by the information trading device 1c in association with the personal identification code specified as the approval destination specified in step S407 (step S408).
- the approval destination address is the address of the personal terminal 4. Alternatively, the approval destination address may be an address held by the application program held by the personal terminal 4.
- the approval destination identification unit 16 transmits an approval registration request page to the personal terminal 4 specified by the approval destination address (step S409). Then, based on the approval of the individual user, the processes of steps S410 to S421 are performed in the same manner as in the first embodiment. However, in the third embodiment, in the process corresponding to step S416, the personal identification code of the individual user whose approval request is stopped in step S605 is further acquired, and the personal information corresponding to the personal identification code cannot be provided. judge.
- the information trading device 1c when the information trading device 1c receives a request for providing an organization to be excluded from the organization to which the personal information is provided, the information trading device 1c provides the data set (personal information) indicated by the request.
- the approval request is not made to the personal terminal 4. Therefore, an individual user can provide a mechanism of an information trading system that does not receive an unnecessary approval request for information provision by registering an organization to be excluded from the organization to which the information of personal information is provided in advance.
- FIG. 11 is a diagram showing a configuration of an information trading system according to the third embodiment.
- the information trading system 100B may have a configuration as shown in FIG. That is, in the information transaction system 100B, the data center 5 includes the second DB 22 included in the information provider device 2 in the first embodiment. Further, the data center 5 stores the catalog information 40 generated by the information trading device 1. When the information provider device 2 generates a data set, the information provider device 2 registers the data set in the second DB 22 provided in the data center 5. When the information trading device 1 uses the catalog information 40, the information trading device 1 may refer to the catalog information 40 of the data center 5 and perform the processing described in the other embodiment described above.
- the data set requested to be provided by the information providing destination device 3 is transmitted by the processing unit of the data center 5 instead of the information providing source device 2 based on the transmission request of the transmission requesting unit 17 of the information trading device 1.
- the data center 5 may store at least one of the data set and the catalog information.
- FIG. 12 is a diagram showing a minimum configuration information trading device included in the first to third embodiments.
- FIG. 13 is a diagram showing a processing flow by the information trading apparatus having the minimum configuration included in the first to third embodiments.
- the information trading device 1d includes at least a storage means 121, a provision request receiving means 122, and a transmission requesting means 123.
- the storage means stores catalog information including detailed information about one or more data sets including personal information that can be provided from the information providing device 2 to the information providing destination device 3 (step S131).
- the provision request receiving means receives a data set provision request from the information providing destination device 3 (step S132).
- the transmission request means outputs the transmission request of the data set indicated by the provision request to the information providing source device 2 (step S133).
- the information trading system including the information trading device according to the fourth embodiment of the present invention is the same as in FIG. 1, and the hardware configuration of the information trading device is the same as in FIG.
- FIG. 14 is a functional block diagram of the information trading device according to the fourth embodiment.
- the information trading device 1e activates the information trading management program in advance.
- the information trading device 1e includes the control unit 11, the personal terminal interface unit 12, the provider interface unit 13, the provider interface unit 14, the catalog information generation unit 15, the approval destination identification unit 16, the transmission request unit 17, and the provision consideration calculation.
- a unit 18 and a record consideration calculation unit 19 are provided.
- the control unit 11 controls each functional unit of the information trading device 1e.
- the personal terminal interface unit 12 processes the output of information to the personal terminal 4 and the acquisition of the information transmitted from the personal terminal 4.
- the provider interface unit 13 processes the output of information to the information provider device 2 and the acquisition of the information transmitted from the information provider device 2.
- the provider interface unit 14 processes the output of information to the information provider device 3 and the acquisition of the information transmitted from the information provider device 3.
- the catalog information generation unit 15 generates catalog information 40.
- the catalog information 40 is information that defines explanatory items for one or more data sets including personal information that can be provided from the information providing device to the information providing destination device for each data set.
- one data set includes personal information that is one or more personal information and is converted according to the data format indicated by the format definition information that is different for each personal information.
- a data set is a unit for providing personal information including one or more personal information.
- the approval destination identification unit 16 identifies an individual user who is an approval destination for the provision of the data set to be provided, based on the data set provision request transmitted by the information providing destination device 3.
- the transmission request unit 17 outputs the transmission request of the data set indicated by the provision request to the information providing source device 2.
- the provision consideration calculation unit 18 calculates the provision consideration based on the amount of personal information transmitted from the information providing source device 2 to the information providing destination device 3.
- the offer consideration indicates, for example, the amount of the offer consideration paid to an individual user.
- the record consideration calculation unit 19 calculates the record consideration based on the amount of information recorded in the storage device of the information provider device 2 as personal information transmitted by the information provider device 2 to the information provider device 3.
- the record consideration indicates, for example, the amount of the record consideration paid to an individual user.
- FIG. 15 is a diagram illustrating details of a web page for designating a data set in an information trading system including an information trading device according to a fourth embodiment.
- the data set designation web page 41 describes catalog information 40 in which explanatory items relating to one or more data sets including personal information are defined for each data set.
- the data set name as explanatory items related to the data set, the data set name, the number of individuals corresponding to the personal information included in the data set M, the amount of data N per person, and the data per person (personal information). Includes information such as details, data generation attributes, offer consideration, and record consideration.
- the information provider code is identification information about the information provider organization that manages the information provider device.
- the data generation attribute includes whether personal information is information registered by a medical institution (medical institution), information input by an individual (individual input), or information automatically acquired from a device such as a sensor (personal device). Includes identification information of the source of personal information indicating (automatic acquisition).
- the person in charge of the organization of the information providing destination using the information providing destination device 3 confirms the catalog information 40 included in the data set designation web page 41, and selects the data set to be the target of the provision request.
- FIG. 16 is a diagram illustrating details of personal data location information supplied in an information trading system including the information trading device according to the fourth embodiment.
- the personal data location information 50 stores a personal identification code, an information provider code, a data set type, the number of data sets, and the like for each individual.
- the information provider code is the identification information of the organization that manages the information provider device 2 that stores the data set including the personal information of the individual indicated by the personal identification code.
- the data set type is information indicating the type of the data set including the personal information of the individual indicated by the personal identification code.
- the number of data sets is the number of data sets including personal information of the individual indicated by the personal identification code.
- the information trading device 1e identifies the information providing source device 2 that stores the data set indicated by the providing request acquired from the information providing destination device 3 based on the personal data location information.
- the information trading system including the information trading device 1e according to the fourth embodiment includes an information providing source device 2 and an information providing destination device 3 connected to the information trading device 1e.
- the information trading device 1e provides a data set designation web page 41 in which explanatory items relating to one or more data sets including personal information that can be provided from the information providing device 2 to the information providing destination device 3 are described for each data set. It is transmitted to the device 3.
- the information trading device 1e receives from the information providing destination device 3 the selection of the data set to be requested to be provided from the one or more data sets described in the data set designation web page.
- the information trading device 1e When the information trading device 1e receives approval for the provision of personal information included in the data set to be requested to be provided, the information trading device 1e sends a request for transmission of the personal information to the information providing destination device 3 and information for storing the personal information. Output to the provider device 2.
- FIG. 17 shows a processing flow performed between the information trading device and the information providing destination device in the information trading system including the information trading device according to the fourth embodiment.
- the information trading device 1e further stores the format definition information that defines the format format of the personal information included in the data set.
- the information providing source device 2 or the information providing destination device 3 can request the information trading device 1e to generate format definition information related to new personal information in which the format definition information stored in the information trading device 1e is undefined. ..
- the person in charge of the information providing organization wants to receive the provision of the data set including new personal information
- the person in charge of the information providing destination device 3 connects the information providing destination device 3 to the information trading device 1e.
- the information providing destination device 3 and the information trading device 1e are connected (step S1101).
- the provider interface unit 14 of the information trading device 1e has a function of updating the format definition information API (Application Programming Interface), and transmits the update interface screen of the format definition information to the connected information providing device 3 (step). S1102).
- the information providing destination device 3 acquires the update interface screen and outputs the update interface screen of the format definition information to the display (step S1103).
- the person in charge of the organization to which the information is provided inputs the format of the personal information to be newly included in the data set in the input field of the format definition information update interface screen, and inputs the transmission request.
- the information providing destination device 3 receives the transmission request (step S1104).
- the information providing destination device 3 generates a request for updating the format definition information including the format format of the input personal information, and transmits the request to the information trading device 1e (step S1105).
- the provider interface unit 14 of the information trading device 1e acquires a request for updating the format definition information.
- the provider interface unit 14 acquires the format format of the personal information newly included in the data set from the update request of the format definition information and outputs it to the control unit 11.
- the control unit 11 generates format definition information that defines the format of personal information and records it in the storage unit of its own device (step S1106).
- the information provider device 2 uses the format definition information that defines the format of the personal information, and generates a data set including new personal information for which the format definition information has not been defined by the subsequent processing. Can be done.
- FIG. 18 shows a processing flow performed between the information trading device and the information provider device in the information trading system including the information trading device according to the fourth embodiment.
- the information providing source device 2 detects the recording of the personal information that can be provided in the first DB 21 in the generation of the data set including the personal information (step S1201).
- the personal information may be data including personal information generated by a computer of the information providing organization connected to the information providing source device 2, or data including personal information automatically generated by a device such as a sensor. It may be.
- the data set may be data including personal information entered by an individual user on a computer or the like belonging to the information providing organization, or the individual user may use the personal terminal 4 to send the information to the information providing organization. It may be data including personal information transmitted to the computer to which it belongs.
- Personal information may be information such as common items and unique items of the above-mentioned data set designation web page 41.
- the common items may be, for example, an individual's personal identification code, gender, and age associated with personal information included as a data set.
- the unique item may be, for example, a data acquisition date, data content, and information provider identification information of personal information included as a data set.
- the personal information contained in the data set generated by the hospital includes a personal identification code that identifies the individual and gender.
- Age, data acquisition date, vital signs, examination items in examination, examination results, diagnosis results, etc. are included.
- the vital signs are, for example, body temperature, pulse, respiration, blood pressure, and the like.
- the information provider device 2 reads the personal information from the first DB 21.
- the information provider device 2 communicates with the information trading device 1e and requests the transmission of the format definition information (step S1202).
- the provider interface unit 13 of the information trading device 1e accepts the designation of personal information and transmits the format definition information corresponding to the personal information to the information provider device 2 (step S1203).
- the format definition information is information that defines the format of personal information contained in the data set.
- the information provider device 2 acquires the format definition information (step S1204).
- the information provider device 2 generates a data set including personal information according to the data format indicated by the format definition information (step S1205).
- the information provider device 2 records the generated data set in the second DB 22 (step S1206).
- the information provider device 2 stores the data set holding the personal information according to the data format indicated by the format definition information.
- the plurality of information providing source devices 2 generate a data set of the data format indicated by the format definition information.
- the information providing destination device 3 provided with those data sets can acquire a unified data set in the same data format transmitted from each information providing source device 2, and thus the individual included in the data set. Processing using information can be easily performed.
- the information provider device 2 identifies the explanatory items of the generated data set, and transmits the explanatory items of the data set to the information trading device 1e (step S1207).
- the description items of the data set include the data set name related to the data set, the number of individuals corresponding to the personal information contained in the data set, the amount of data N per person, and the data per person (personal information). It contains information such as details, data generation attributes, offer consideration, and record consideration.
- the details of the per capita data include, for example, common items, unique items, etc. if the provider is a hospital.
- the common items may be, for example, a personal identification code, gender, and age.
- the unique items may be, for example, a data acquisition date, vital signs (body temperature, pulse, respiration, blood pressure), test items, test results, diagnosis results, information provider code, and the like.
- the catalog information generation unit 15 of the information trading apparatus 1e acquires the explanatory items of the data set.
- the catalog information generation unit 15 generates new catalog information 40 by adding the catalog information 40 including the explanation items of the generated data set to the past catalog information 40, and updates the past catalog information 40 already stored. (Step S1208).
- the catalog information 40 is information in which explanatory items relating to one or more data sets are defined for each data set as a provision unit.
- the information provider device 2 Based on the generated data set, the information provider device 2 has an individual identification code of an individual corresponding to the personal information included in the data set, an information provider code indicating the information provider organization that generated the data set, and a data set.
- the location information including the type, the number of data sets, and the like is generated (step S1209).
- the information provider device 2 transmits the location information to the information trading device 1e (step S1210).
- the provider interface unit 13 of the information trading device 1e acquires the location information transmitted from the information provider device 2.
- the provider interface unit 13 generates personal data location information 50 including new location information and records it in the database 104 of its own device (step S1211). As a result, the information trading device 1e can grasp which data set is held by which information provider device 2.
- the record consideration calculation unit 19 may calculate the amount of the record consideration to be provided to the individual user corresponding to the personal information included in the data set when the data set is recorded in the second DB 22. In this case, for example, the record consideration calculation unit 19 specifies the data set name recorded in the second DB 22. The record consideration calculation unit 19 acquires the amount of the record consideration per unit amount of the data set from the information trading apparatus 1e. The record consideration calculation unit 19 calculates the record consideration amount of the data set recorded in the second DB 22 based on the record consideration amount per unit amount of the data set, and transmits it to the information trading apparatus 1e. The information trading device 1e stores information on the amount of record consideration of the data set for each individual user.
- the information trading device 1e Based on the request from the personal terminal, the information trading device 1e transmits to the personal terminal 4 the amount of the record consideration of the data set to be stored for the personal user who operates the personal terminal. As a result, the individual user can confirm the consideration when his / her personal information is recorded as a provision candidate in the information providing source device 2.
- the amount of the record consideration provided to the individual user may be calculated at predetermined intervals.
- FIG. 19 shows a processing flow performed between the information trading device, the information providing destination device, the personal terminal, and the information providing source device in the information trading system including the information trading device according to the fourth embodiment.
- the manager of the information providing destination such as the data utilization organization that manages the information providing destination device 3 wants to receive the provision of the data set
- the manager of the information providing destination device 3 connects the information providing destination device 3 to the information trading device 1e by communication.
- the information trading device 1 and the information providing destination device 3 are communicated and connected (step S1401).
- the provider interface unit 14 of the information trading apparatus 1e generates a data set designation web page 41 in which the catalog information 40 is described.
- the catalog information 40 described on the data set designation web page 41 includes explanatory items for each data set for one or more data sets. Therefore, the data set designation web page 41 serves as a catalog of data sets in which information on explanatory items of a plurality of data sets is included for each data set.
- the providing destination interface unit 14 of the information trading device 1e transmits the data set designation web page 41 to the connected information providing destination device 3 (step S1402).
- the information providing destination device 3 acquires the data set designated web page 41 and outputs the data set designated web page 41 to the display (step S1403).
- the person in charge of the organization to which the information is provided fills in the check column of the catalog information 40 corresponding to the dataset requested to be provided among the check columns displayed in association with each catalog information 40 of the dataset designation web page 41. Check it and press the offer request button.
- the information providing destination device 3 receives the providing request (step S1404).
- the information providing destination device 3 identifies the data set name included in one or more catalog information 40 received as the providing request, and transmits the providing request including the data set name to the information trading device 1e (step S1405). ..
- the provision request may include information such as the ID of the information providing destination device 3 and the network address of the information providing destination device 3.
- the provider interface unit 14 of the information trading device 1e acquires the provision request (step S1406).
- the provision destination interface unit 14 outputs the provision request to the approval destination identification unit 16.
- the approval destination identification unit 16 acquires the provision request.
- the approval destination identification unit 16 acquires the data set name included in the provision request.
- the approval destination identification unit 16 acquires all the personal identification codes included in the personal data location information 50 in association with the data set name (step S1407).
- the approval destination identification unit 16 acquires the approval destination address stored in advance by the information trading device 1e in association with all the personal identification codes (step S1408).
- the approval destination address is the address of the personal terminal 4. Alternatively, the approval destination address may be an address held by the application program held by the personal terminal 4.
- the approval destination identification unit 16 transmits an approval registration request page to each personal terminal 4 (approval request destination) specified by the approval destination address (step S1409).
- the approval registration request page includes information such as the data set name included in the provision request and the organization name of the information providing destination organization that manages the information providing destination device 3 that has transmitted the provision request.
- Each personal terminal 4 acquires the approval registration request page.
- the personal terminal 4 outputs an approval registration request page to the display (step S1410).
- the approval registration request page includes the amount of the provision consideration and the record consideration associated with the data set name, and the approval registration request page including such information may be output to the display of the personal terminal 4.
- the individual user recognizes the data set name, the organization name of the information providing destination organization, the provision consideration and the record consideration displayed on the approval registration request page, and the personal information specified by the data set name is the information providing destination. Enter approval to provide to the organization.
- the approval registration request page further displays the approval OK and approval NG buttons, and the user presses any of the buttons using an input device such as a mouse to approve OK or approval NG.
- each personal terminal 4 When the user presses the approval OK button, each personal terminal 4 generates an approval result including the approval OK flag (step S1411). When the user presses the approval NG button, each personal terminal 4 generates an approval result including the approval NG flag.
- the approval result may further include the data set name, the organization name of the information providing destination organization, the personal identification code of the individual user who uses the personal terminal 4, and the like, which are included in the approval request.
- Each personal terminal 4 transmits the generated approval result to the information trading device 1e (step S1412).
- the personal terminal interface unit 12 of the information trading device 1e acquires the approval result received from each personal terminal 4 (step S1413).
- the personal terminal interface unit 12 outputs the approval result to the transmission request unit 17.
- the transmission requesting unit 17 determines whether each approval result includes the approval OK flag (step S1414).
- the transmission request unit 17 generates a transmission request when each approval result includes an approval OK flag (step S1415).
- the transmission request may include the data set name included in the approval result, the organization name of the information providing destination organization, the ID of the information providing destination device 3, the network address of the information providing destination device 3, and the like.
- the transmission requesting unit 17 acquires the personal identification code included in the approval result and determines that the personal information corresponding to the personal identification code cannot be provided (step S1416). ).
- the transmission request unit 17 acquires an information provider code that identifies each of the one or more information provider devices 2 included in the dataset designation web page 41 in association with the dataset name (step S1417).
- the transmission request unit 17 stores the network address of the information provider device 2 in advance in association with the information provider code.
- the transmission request unit 17 acquires the network address of the information provider device 2 that is stored in association with the acquired information provider code.
- the transmission request unit 17 transmits a transmission request to the acquired network address (step S1418).
- the personal identification code included in the approval result that is approved in step S1416 is stored as the personal identification code of the individual user corresponding to the personal information that cannot be provided.
- the information provider device 2 receives the transmission request.
- the information provider device 2 is a data set name included in a transmission request, an organization name of a provider organization, an ID of the information provider device 3, a network address of the information provider device 3, and an individual user corresponding to personal information that cannot be provided. Get your personal identification code.
- the information provider device 2 acquires the data set corresponding to the data set name from the second DB 22 (step S1419).
- the information provider device 2 deletes the personal information corresponding to the personal identification code stored in the transmission request from the personal information included in the data set.
- the information providing source device 2 transmits the data set to the network address of the information providing destination device 3 included in the transmission request (step S1420).
- the information providing destination device 3 receives the data set.
- the information providing destination device 3 records the received data set in a database or the like provided in the own device (step S1421). The information providing destination device 3 then performs a predetermined process using the received data set.
- the information providing source device 2 may transmit the data set to be transmitted in response to the transmission request to the information providing destination device 3 via the information trading device 1e.
- the information providing source device 2 transfers the data sets acquired from a plurality of different information providing source devices 2 to one information providing destination device 3, the data sets may be collectively transferred.
- the information trading device 1e does not store the data set including the personal information generated by the plurality of information providing source devices 2 in its own device, but provides the information providing device 3 to the information providing destination device 3 desired to provide the data set. You can control the transmission of the dataset.
- a mechanism for managing personal information without concentrating the risk of unauthorized leakage of a large amount of personal information generated by each of the plurality of information providers that manage the information provider device 2 on the information trading device 1e. Can be provided.
- the provision consideration calculation unit 18 provides the provision consideration to the individual user corresponding to the personal information included in the data set in response to the data set being transmitted from the information providing source device 2 to the information providing destination device 3. You may calculate the amount. In this case, for example, the provision consideration calculation unit 18 acquires information regarding the transmission of the data set based on the transmission request from the information providing source device 2, and specifies the data set name transmitted by the information providing source device 2 to the information providing destination device 3. To do. The offer consideration calculation unit 18 acquires the amount of the offer consideration per unit amount of the data set from the information trading device 1e.
- the offer consideration calculation unit 18 calculates the offer consideration amount of the data set transmitted to the information providing destination device 3 based on the offer consideration amount per unit amount of the data set, and transmits the data set to the information trading device 1e.
- the information trading device 1e stores information on the amount of consideration for providing the data set for each individual user. Based on the request from the personal terminal, the information trading device 1e transmits to the personal terminal 4 the amount of consideration for providing the data set to be stored for the personal user who operates the personal terminal. As a result, the individual user can confirm the consideration for the provision of his / her personal information to the information providing destination device 3.
- the amount of consideration provided to individual users may be calculated at predetermined intervals.
- FIG. 20 is a functional block diagram of the information trading device according to the fifth embodiment.
- the information trading device 1f according to the fifth embodiment is different from the function of the information trading device 1f according to the fourth embodiment in that it further exerts the function of the exclusion organization reception unit 10.
- the information trading device 1f receives from an individual user the selection of the organization to be excluded from the organizations that manage the information providing destination device 3.
- the information trading device 1f identifies the personal data location information associated with the data set name based on the data set name indicated by the provision request transmitted by the information providing destination device 3, and personal identification included in the personal data location information. Get the code.
- the information trading device 1f refers to the individual user. At least one of the request for approval of the provision of personal information or the transmission of the data set containing the personal information to the information providing destination device 3 is stopped.
- FIG. 21 is a diagram showing a processing flow of an information trading system including the information trading device 1f according to the fifth embodiment.
- the personal terminal interface unit 12 of the information trading device 1f is based on the access from each personal terminal 4.
- the exclusion organization selection page is transmitted (step S1501).
- Each personal terminal 4 outputs the excluded organization selection page to the display (step S1502).
- Each individual user selects an organization to be excluded from the provision destinations of personal information on the exclusion organization selection page displayed on the personal terminal 4.
- a list of a plurality of organization categories to which candidates for organizations to which personal information is provided belongs and a check button for specifying exclusions thereof are displayed on the exclusion organization selection page.
- a registration button is displayed on the exclusion organization selection page.
- Each individual user operates the check button of the organization category to be excluded from the organization to which the personal information is provided to be ON, and presses the registration button.
- each personal terminal 4 detects the input of the organization category to which the organization excluded from the information providing destination organization of personal information belongs (step S1503).
- Each personal terminal 4 generates filter information including at least a personal identification code and an organization category to which the information providing destination organization to be excluded belongs, and transmits the filter information to the information trading device 1f (step S1504).
- the personal terminal interface unit 12 of the information trading device 1f acquires filter information from each personal terminal 4 (step S1505).
- the personal terminal interface unit 12 records each filter information in a storage unit such as a database 104 (step S1506).
- the filter information is information associated with the personal identification code and the organization category (provided exclusion destination category) of the organization excluded as the information providing destination organization selected by the individual user indicated by the personal identification code.
- the filter information regarding the plurality of individual users is recorded in the information trading device 1f.
- the information trading device 1f previously performs identification information of an organization category (provided exclusion destination category), an identification code of an information provider device 2 managed by an organization belonging to the organization category, a network address of the information provider device 2, and the like. It is assumed that the organization table associated and held is stored.
- step S1406 acquires the provision request.
- the provision destination interface unit 14 outputs the provision request to the approval destination identification unit 16.
- the approval destination identification unit 16 acquires the provision request.
- the approval destination identification unit 16 acquires the data set name included in the provision request.
- the approval destination identification unit 16 acquires all the personal identification codes included in the personal data location information 50 in association with the data set name (step S1407). This process is the same as in the fourth embodiment.
- the approval destination specifying unit 16 detects the identification code of the information providing destination device 3 that transmitted the providing request acquired in step S1406 from the providing request (step S1601).
- the approval destination identification unit 16 acquires the identification information of the provision exclusion destination category recorded in the organization table in association with the information provision destination device 3 (step S1602).
- the approval destination specifying unit 16 determines whether the individual user corresponding to the personal identification code specified in step S1407 excludes the organization associated with the information providing destination device 3 that has sent the provision request from the information providing destination organization. To do.
- the approval destination identification unit 16 determines whether or not each personal identification code specified in step S1407 and the identification information of the provision exclusion destination category acquired in step S1602 are linked and recorded in the filter information (step). S1603).
- the approval destination identification unit 16 is specified in step S1407 when the personal identification code specified in step S1407 and the identification information of the offer exclusion destination category acquired in step S1602 are linked and are not recorded in the filter information.
- the individual user corresponding to the personal identification code is specified as the approval destination (step S1604).
- the approval destination identification unit 16 identifies each of the personal identification codes specified in step S1407. Stop the approval request for each individual user of the personal identification code. As a result, the approval destination identification unit 16 stops providing the data set including the personal information of those individual users (step S1605).
- the subsequent processing is the same as the processing after step S1408 of the fourth embodiment. That is, the approval destination specifying unit 16 acquires the approval destination address stored in advance by the information trading device 1f in association with the personal identification code specified as the approval destination specified in step S1407 (step S1408).
- the approval destination address is the address of the personal terminal 4. Alternatively, the approval destination address may be an address held by the application program held by the personal terminal 4.
- the approval destination identification unit 16 transmits an approval registration request page to the personal terminal 4 specified by the approval destination address (step S1409). Then, based on the approval of the individual user, the processes of steps S1410 to S1421 are performed in the same manner as in the fourth embodiment. However, in the sixth embodiment, in the process corresponding to step S1416, the personal identification code of the individual user whose approval request is stopped in step S1605 is further acquired, and the personal information corresponding to the personal identification code cannot be provided. judge.
- the information trading device 1f when the information trading device 1f receives a request for providing an organization to be excluded from the organization to which the personal information is provided, the information trading device 1f provides the data set (personal information) indicated by the request.
- the approval request is not made to the personal terminal 4. Therefore, an individual user can provide a mechanism of an information trading system that does not receive an unnecessary approval request for information provision by registering an organization to be excluded from the organization to which the information of personal information is provided in advance.
- FIG. 22 is a diagram showing a configuration of an information trading system according to the sixth embodiment.
- the information trading system 100C may have a configuration as shown in FIG. That is, in the information trading system 100C, the data center 5 includes the second DB 22 included in the information providing source device 2 in another embodiment. Further, the data center 5 stores the catalog information 41 generated by the information trading device 1. Then, when the information provider device 2 generates a data set, the information provider device 2 registers the data set in the second DB 22 provided in the data center 5. When the catalog information 40 is used by the information trading device 1, the information trading device 1 may refer to the catalog information 40 of the data center 5 and perform the processing described in the other embodiment described above.
- the catalog information generation unit 15 obtains the explanatory items of the generated data set.
- New catalog information 40 is generated by adding the included catalog information 40 to the past catalog information 40 acquired from the data center 5. Then, in step S1208 described above, the catalog information generation unit 15 updates the past catalog information 40 already stored in the data center 5.
- the providing destination interface unit 14 of the information trading device 1 when the information trading device 1 and the information providing destination device 3 are connected by communication in step S1401, the providing destination interface unit 14 of the information trading device 1 sends data.
- the catalog information 40 is acquired from the center 5.
- the provider interface unit 14 generates a data set designation web page 41 that describes the acquired catalog information 40.
- the providing destination interface unit 14 transmits the data set designation web page 41 to the connected information providing destination device 3.
- the transmission requesting unit 17 transmits a transmission request to the data center 5.
- the personal identification code included in the approval result that is approved in step S1416 is stored as the personal identification code of the individual user corresponding to the personal information that cannot be provided.
- the data center 5 receives the transmission request.
- the data center 5 is a data set name included in a transmission request, an organization name of a provider organization, an ID of an information provider device 3, a network address of the information provider device 3, and an individual user corresponding to personal information that cannot be provided. Get a personal identification code.
- the data center 5 acquires the data set corresponding to the data set name from the second DB 22.
- the data center 5 deletes the personal information corresponding to the personal identification code stored in the transmission request from the personal information contained in the data set.
- the data center 5 transmits the data set to the network address of the information providing destination device 3 included in the transmission request.
- the data center 5 may store at least one of the data set and the catalog information 40.
- FIG. 23 is a diagram showing 1 g of the information trading device having the minimum configuration included in the fourth to sixth embodiments.
- FIG. 24 is a diagram showing processing by the information trading device 1g having the minimum configuration included in the fourth to sixth embodiments.
- the information trading device 1g includes at least transmission means 124, provision request reception means 122, and transmission request means 123.
- the transmission means 124 provides a data set designation web page 41 in which explanatory items relating to one or more datasets including personal information that can be provided from the information provider device 2 to the information provider device 3 are described for each dataset. It is transmitted to 3 (step S1131).
- the provision request receiving means 122 receives the selection of the data set to be provided request target from the information providing destination device 3 from the one or more data sets described on the data set designation web page 41 (step S1132).
- the transmission requesting means 123 receives approval for the provision of personal information included in the data set to be provided
- the transmission request means 123 sends a request for transmission of the personal information to the information providing destination device 3 to store the personal information. Output to the provider device 2 (step S1133).
- Each of the above devices has a computer system inside.
- the process of each process described above is stored in a computer-readable recording medium in the form of a program, and the process is performed by the computer reading and executing this program.
- the computer-readable recording medium refers to a magnetic disk, a magneto-optical disk, a CD-ROM, a DVD-ROM, a semiconductor memory, or the like.
- this computer program may be distributed to a computer via a communication line, and the computer receiving the distribution may execute the program.
- the above program may be for realizing a part of the above-mentioned functions.
- a so-called difference file difference program
- difference program difference program
- the information trading device includes an information providing device and an information trading device connected to the information providing destination device.
- a catalog information including detailed information about one or more data sets including personal information that can be provided from the information providing device to the information providing destination device is stored.
- An information trading system that outputs a transmission request of the data set indicated by the provision request to the information providing destination device to the information providing source device.
- the information trading device is The identification information of the individual user and the location information indicating which data set including the personal information of the individual user is recorded in the information providing device are stored. The identification information of the individual user included in the location information regarding the data set indicated by the provision request is acquired, and an approval request for provision of the personal information is made to the individual user.
- the information provider device is The information trading system according to Appendix 1 or Appendix 2, which generates and stores the dataset including the personal information based on the format definition information of the dataset.
- the information providing destination device is A request for adding new personal information other than personal information that can be included in the data set indicated by the format definition information to the data set is transmitted.
- the information provider device is The information trading system according to Appendix 3, which generates the data set using the new format definition information generated based on the additional request.
- the information trading device is Accepts the selection of the organization to be excluded from the organizations that manage the information providing destination device, Acquire the identification information of the individual user included in the location information regarding the data set indicated by the provision request, and obtain the identification information of the individual user.
- the individual user has selected the organization associated with the information providing destination device to which the providing request has been sent as the organization to be excluded, the request for approval of the provision of personal information to the individual user or the individual.
- the information trading system according to Appendix 2, which stops at least one of transmission of a data set containing information to the information providing destination device.
- (Appendix 7) Stores catalog information, including detailed information about one or more datasets, including personal information that can be provided from the source device to the destination device.
- An information trading device that outputs a transmission request to the information providing destination device of the data set indicated by the providing request to the information providing source device.
- an information trading system including an information trading device that is communication-connected to an information providing device and an information providing destination device, the information trading device is A catalog information including detailed information about one or more data sets including personal information that can be provided from the information providing device to the information providing destination device is stored.
- An information transaction method for outputting a transmission request of a data set indicated by the provision request to the information providing destination device to the information providing source device.
- the computer of the information trading device A means of storing catalog information, including detailed information about one or more datasets, including personal information that can be provided from the source device to the destination device.
- a means for receiving a request for providing the data set from the information providing destination device A means for outputting a transmission request of the data set indicated by the provision request to the information providing destination device to the information providing source device.
- a recording medium that records a program that functions as.
- a dataset designation web page that describes each of the datasets with explanatory items regarding one or more datasets including personal information that can be provided from the information provider device to the information provider device is transmitted to the information provider device.
- the information providing destination device accepts the selection of the data set to be requested to be provided from the one or more data sets described in the data set designation web page.
- the request for transmission of the personal information to the information providing destination device is output to the information providing device that stores the personal information.
- Information trading method is
- Appendix 12 Generate format definition information based on the specification of the new personal information format format, The information trading method according to Appendix 11, which transmits the format definition information to the information provider device that generates the data set including the personal information corresponding to the format format indicated by the format definition information.
- Appendix 13 Accepts the selection of the organization to be excluded from the organizations that manage the information providing destination device, Acquire the identification information of the individual user included in the location information regarding the data set to be provided, and obtain the identification information.
- the individual user selects the organization associated with the information providing destination device that has received the selection of the data set to be provided as the exclusion target organization, the personal information for the individual user
- a dataset designation web page that describes each of the datasets with explanatory items regarding one or more datasets including personal information that can be provided from the information provider device to the information provider device is transmitted to the information provider device.
- the information providing destination device accepts the selection of the data set to be requested to be provided from the one or more data sets described in the data set designation web page.
- the request for transmission of the personal information to the information providing destination device is output to the information providing device that stores the personal information.
- Information trading device is
- the computer of the information trading device A means for transmitting a dataset-designated web page that describes each of the datasets with explanatory items regarding one or more datasets including personal information that can be provided from the information provider device to the information provider device to the information provider device.
- the request for transmission of the personal information to the information providing destination device is output to the information providing device that stores the personal information.
- a recording medium that records a program that functions as.
- Appendix 16 A computer of the information trading device that stores identification information of an individual user and location information indicating which information provider device records the personal information of the individual user. Further, the identification information of the individual user corresponding to the personal information specified from the explanation item regarding the data set to be provided is acquired from the location information, and the approval request destination for the identification information of the individual user is requested to approve. Means to do, A recording medium on which the program according to Appendix 15 is recorded.
- Appendix 17 The computer of the information trading device, For the information provider device that generates format definition information based on the designation of a new format of personal information and generates the data set including personal information corresponding to the format indicated by the format definition information.
- a means for transmitting the format definition information A recording medium on which the program according to Appendix 16 is recorded.
- Appendix 18 The computer of the information trading device, A means for accepting selection of an organization to be excluded from the organizations that manage the information providing destination device, A means for acquiring identification information of an individual user included in the location information regarding the data set to be provided.
- the personal information for the individual user A means of stopping at least one of a request for approval of provision or transmission of a data set containing the personal information to the information providing destination device.
- an information trading system that does not concentrate the risk of unauthorized leakage of a large amount of personal information generated by each of a plurality of information providers that manage the information providing device on the information trading device. be able to.
- Information trading device 1, 1a, 1b, 1c, 1d, 1e, 1f Information trading device 2 Information provider device 3 Information provider device 4 Personal terminal 5 Data center 10 Excluded organization reception unit 11 Control unit 12 Personal terminal interface unit 13 Provider interface unit 14 Provider interface unit 15 Catalog information generation unit 16 Approval destination identification unit 17 Transmission request unit 18 Provision consideration calculation unit 19 Record consideration calculation unit 21 First DB 22 Second DB 100A, 100B, 100C information trading system
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Theoretical Computer Science (AREA)
- Tourism & Hospitality (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Strategic Management (AREA)
- Human Resources & Organizations (AREA)
- Economics (AREA)
- General Business, Economics & Management (AREA)
- Health & Medical Sciences (AREA)
- Marketing (AREA)
- Data Mining & Analysis (AREA)
- Entrepreneurship & Innovation (AREA)
- Primary Health Care (AREA)
- General Health & Medical Sciences (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Databases & Information Systems (AREA)
- Quality & Reliability (AREA)
- Child & Adolescent Psychology (AREA)
- Operations Research (AREA)
- Computer Security & Cryptography (AREA)
- Development Economics (AREA)
- Educational Administration (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
以下、本発明の一実施形態による情報取引装置を含む情報取引システムを、図面を参照して説明する。
図1は第一本実施形態による情報取引システムの構成を示す第一の図である。
情報取引システム100Aは、情報取引装置1、情報提供元装置2、情報提供先装置3が通信接続されて構成される。
図2に示すように、情報取引装置1aは、CPU(Central Processing Unit)101、ROM(Read Only Memory)102、RAM(Random Access Memory)103、データベース104、通信モジュール105等の各ハードウェアを備えたコンピュータ装置である。なお、情報提供元装置2、情報提供先装置3、個人端末4も、同様のハードウェア構成を備えたコンピュータ装置である。
情報取引装置1bは、予め情報取引管理プログラムを起動する。これにより情報取引装置1bは、制御部11、個人端末インタフェース部12、提供元インタフェース部13、提供先インタフェース部14、カタログ情報生成部15、承認先特定部16、送信要求部17、提供対価算出部18、記録対価算出部19の構成を備える。
個人端末インタフェース部12は、個人端末4への情報の出力と、個人端末4から送信された情報の取得を処理する。
提供元インタフェース部13は、情報提供元装置2への情報の出力と、情報提供元装置2から送信された情報の取得を処理する。
提供先インタフェース部14は、情報提供先装置3への情報の出力と、情報提供先装置3から送信された情報の取得を処理する。
承認先特定部16は、情報提供先装置3の送信したデータセットの提供要求に基づいて、そのデータセットの提供の承認先の個人ユーザを特定する。
送信要求部17は、提供要求が示すデータセットの送信要求を、情報提供元装置2へ出力する。
カタログ情報40は、一例としては、データセットに関するデータセット名、データセットに含まれる個人情報に対応する個人の人数M、一人当たりのデータ量N、一人当たりのデータ(個人情報)の詳細、データ発生属性、提供対価、記録対価などの情報が含まれる。一人当たりのデータの詳細には、一例としては、提供元が病院であれば、共通項目(個人識別コード、性別、年齢)、固有項目(データ取得日、バイタルサイン(体温、脈拍、呼吸、血圧)、検査項目、検査結果、診断結果、情報提供元コード)などが含まれる。情報提供元コードは、情報提供元装置を管理する情報提供元の組織に関する識別情報である。またデータ発生属性には、個人情報が、医療機関によって登録された情報か(医療機関)、個人が入力した情報か(個人入力)、センサなどの機器から自動的に取得した情報か(個人機器自動取得)、を示す個人情報の発生元の識別情報が含まれる。情報提供先装置3を利用する情報提供先の組織の担当者は、カタログ情報に含まれるデータセットに関する詳細情報を確認して、提供を希望するデータセットを選択する。
個人データ所在情報50は、個人識別コード、情報提供元コード、データセット種類、データセット数などを、個人ごとに記憶する。個人識別コードは、個人情報を提供する個人ユーザを識別するコードである。情報提供元コードは、個人識別コードが示す個人の個人情報を含むデータセットを記憶する情報提供元装置2を管理する組織の識別情報である。データセット種類は、個人識別コードが示す個人の個人情報を含むデータセットの種類または識別子である。データセット数は個人識別コードが示す個人の個人情報を含むデータセットの数である。情報取引装置1bは、個人データ所在情報に基づいて、情報提供先装置3から取得した提供要求が示すデータセットを記憶する情報提供元装置2を特定する。
情報取引装置1bは、データセットのフォーマット形式を定義したフォーマット定義情報をさらに記憶している。情報提供元装置2または情報提供先装置3は、情報取引装置1bが記憶するフォーマット定義情報が未定義の、新たな個人情報を含むデータセットに関するフォーマット定義情報の生成を、情報取引装置1bへ要求することができる。
情報提供元装置2は、個人情報を含むデータセットの生成において、提供可能な個人情報の第一DB21への記録を検知する(ステップS201)。当該個人情報は情報提供元装置2に接続する情報提供元の組織のコンピュータが発生させた個人情報を含むデータであってもよいし、センサなどの機器が自動的に生成した個人情報を含むデータであってもよい。またはデータセットは、情報提供元の組織に属するコンピュータ等に個人ユーザが自身で入力した個人情報を含むデータであってもよいし、個人ユーザが個人端末4を用いて、情報提供元の組織に属するコンピュータに送信した個人情報を含むデータであってもよい。
情報提供先装置3を管理するデータ活用組織などの情報提供先の管理者は、データセットの提供を受けたい場合、情報提供先装置3を情報取引装置1bに通信接続させる。これにより、情報取引装置1bと情報提供先装置3が通信接続する(ステップS401)。情報取引装置1bの提供先インタフェース部14は、接続した情報提供先装置3へ、提供対象のデータセットの指定を受け付けるためのデータセット指定ウェブページを送信する(ステップS402)。情報取引装置1bの提供先インタフェース部14は、データセット指定ウェブページはカタログ情報に含まれる各データセットに関する詳細な情報に基づいて生成された情報であり、各データセットの詳細とその一覧を表示する。従って、情報提供先装置3がデータセット指定ウェブページを出力することにより、情報提供先の組織の管理者は、カタログ情報に掲載されている情報提供元が提供できるデータセット名の一覧をカタログとして確認することができる。
図9は第二実施形態による情報取引装置の機能ブロック図である。
第二実施形態による情報取引装置1cは、第一実施形態による情報取引装置1bの機能と比較して、除外組織受付部10の機能をさらに発揮する点で相違する。
個人ユーザの個人情報を含むデータセットの情報提供先としての組織から除外する組織の選択を受け付ける処理において、情報取引装置1cの個人端末インタフェース部12は、各個人端末4からのアクセスに基づいて、除外組織選択ページを送信する(ステップS501)。各個人端末4は除外組織選択ページをディスプレイに出力する(ステップS502)。各個人ユーザは、個人端末4に表示された除外組織選択ページにおいて、個人情報の提供先から除外する組織を選択する。一例としては、個人情報の情報提供先の組織の候補が属する複数の組織カテゴリの一覧と、それらの除外を指定するチェックボタンが除外組織選択ページに表示される。また登録ボタンが除外組織選択ページに表示される。各個人ユーザは、個人情報の情報提供先の組織から除外する組織カテゴリのチェックボタンをONに操作し、登録ボタンを押下操作する。各個人端末4は、当該操作に基づいて、個人情報の情報提供先の組織から除外する組織の属する組織カテゴリの入力を検出する(ステップS503)。各個人端末4は、個人識別コード、除外対象となる情報提供先の組織の属する組織カテゴリとを少なくとも含むフィルタ情報を生成し、情報取引装置1cへ送信する(ステップS504)。
図11は第三実施形態による情報取引システムの構成を示す図である。
情報取引システム100Bは、図11に示すような構成を有していてもよい。つまり情報取引システム100Bにおいて、第一実施形態で情報提供元装置2が備える第二DB22を、データセンタ5が備える。またデータセンタ5は、情報取引装置1が生成したカタログ情報40を記憶する。情報提供元装置2はデータセットを生成した場合、そのデータセットをデータセンタ5に備わる第二DB22に登録する。情報取引装置1がカタログ情報40を用いる場合には、情報取引装置1がデータセンタ5のカタログ情報40を参照し、上述の他の実施形態で説明した処理を行えばよい。情報提供先装置3が提供要求したデータセットの送信は、情報取引装置1の送信要求部17の送信要求に基づいて、情報提供元装置2に代わって、データセンタ5の処理部が行う。なおデータセンタ5はデータセットまたはカタログ情報の少なくとも一方を記憶するようにしてもよい。
図13は第一から第三実施形態に含まれる最小構成の情報取引装置による処理フローを示す図である。
情報取引装置1dは、少なくとも記憶手段121、提供要求受付手段122と、送信要求手段123とを備える。
記憶手段は、情報提供元装置2から情報提供先装置3へ提供できる個人情報を含む一つ以上のデータセットに関する詳細情報を含むカタログ情報を記憶する(ステップS131)。
提供要求受付手段は、情報提供先装置3よりデータセットの提供要求を受け付ける(ステップS132)。
送信要求手段は、提供要求が示すデータセットの送信要求を、情報提供元装置2へ出力する(ステップS133)。
情報取引装置1eは、予め情報取引管理プログラムを起動する。これにより情報取引装置1eは、制御部11、個人端末インタフェース部12、提供元インタフェース部13、提供先インタフェース部14、カタログ情報生成部15、承認先特定部16、送信要求部17、提供対価算出部18、記録対価算出部19の構成を備える。
個人端末インタフェース部12は、個人端末4への情報の出力と、個人端末4から送信された情報の取得を処理する。
提供元インタフェース部13は、情報提供元装置2への情報の出力と、情報提供元装置2から送信された情報の取得を処理する。
提供先インタフェース部14は、情報提供先装置3への情報の出力と、情報提供先装置3から送信された情報の取得を処理する。
承認先特定部16は、情報提供先装置3の送信したデータセットの提供要求に基づいて、提供要求対象となるデータセットの提供の承認先の個人ユーザを特定する。
送信要求部17は、提供要求が示すデータセットの送信要求を、情報提供元装置2へ出力する。
データセット指定ウェブページ41には、一例としては、個人情報を含む一つ以上のデータセットに関する説明項目をデータセット毎に規定したカタログ情報40が記述される。1つのカタログ情報40には、データセットに関する説明項目として、データセット名、データセットに含まれる個人情報に対応する個人の人数M、一人当たりのデータ量N、一人当たりのデータ(個人情報)の詳細、データ発生属性、提供対価、記録対価などの情報が含まれる。一人当たりのデータの詳細には、一例としては、提供元が病院であれば、共通項目(個人識別コード、性別、年齢)、固有項目(データ取得日、バイタルサイン(体温、脈拍、呼吸、血圧)、検査項目、検査結果、診断結果、情報提供元コード)などが含まれる。情報提供元コードは、情報提供元装置を管理する情報提供元の組織に関する識別情報である。またデータ発生属性には、個人情報が、医療機関によって登録された情報か(医療機関)、個人が入力した情報か(個人入力)、センサなどの機器から自動的に取得した情報か(個人機器自動取得)、を示す個人情報の発生元の識別情報が含まれる。情報提供先装置3を利用する情報提供先の組織の担当者は、データセット指定ウェブページ41に含まれるカタログ情報40を確認して、提供要求の対象となるデータセットを選択する。
個人データ所在情報50は、個人識別コード、情報提供元コード、データセット種類、データセット数などを、個人ごとに記憶する。個人情報を提供する個人ユーザを識別するコードである。情報提供元コードは、個人識別コードが示す個人の個人情報を含むデータセットを記憶する情報提供元装置2を管理する組織の識別情報である。データセット種類は、個人識別コードが示す個人の個人情報を含むデータセットの種類を示す情報である。データセット数は個人識別コードが示す個人の個人情報を含むデータセットの数である。例えば、ある個人の個人情報が30個の各データセットに含まれる場合、その個人の個人情報を含むデータセットの数は30となる。情報取引装置1eは、個人データ所在情報に基づいて、情報提供先装置3から取得した提供要求が示すデータセットを記憶する情報提供元装置2を特定する。
情報取引装置1eは、データセットに含まれる個人情報のフォーマット形式を定義したフォーマット定義情報をさらに記憶している。情報提供元装置2または情報提供先装置3は、情報取引装置1eが記憶するフォーマット定義情報が未定義の、新たな個人情報に関するフォーマット定義情報の生成を、情報取引装置1eへ要求することができる。
情報提供元装置2は、個人情報を含むデータセットの生成において、提供可能な個人情報の第一DB21への記録を検知する(ステップS1201)。当該個人情報は情報提供元装置2に接続する情報提供元の組織のコンピュータが発生させた個人情報を含むデータであってもよいし、センサなどの機器が自動的に生成した個人情報を含むデータであってもよい。またはデータセットは、情報提供元の組織に属するコンピュータ等に個人ユーザが自身で入力した個人情報を含むデータであってもよいし、個人ユーザが個人端末4を用いて、情報提供元の組織に属するコンピュータに送信した個人情報を含むデータであってもよい。
情報提供先装置3を管理するデータ活用組織などの情報提供先の管理者は、データセットの提供を受けたい場合、情報提供先装置3を情報取引装置1eに通信接続させる。これにより、情報取引装置1と情報提供先装置3とが通信接続する(ステップS1401)。情報取引装置1eの提供先インタフェース部14は、カタログ情報40を記述したデータセット指定ウェブページ41を生成する。データセット指定ウェブページ41に記述されるカタログ情報40は、一つ以上のデータセットについて、データセット毎の説明項目が含まれる。従ってデータセット指定ウェブページ41は、複数のデータセットの説明項目の情報がデータセット毎に含まれる、データセットのカタログとしての役割を果たす。情報取引装置1eの提供先インタフェース部14は、接続した情報提供先装置3へ、データセット指定ウェブページ41を送信する(ステップS1402)。
図20は第五実施形態による情報取引装置の機能ブロック図である。
第五実施形態による情報取引装置1fは、第四実施形態による情報取引装置1fの機能と比較して、除外組織受付部10の機能をさらに発揮する点で相違する。
個人ユーザの個人情報を含むデータセットの情報提供先としての組織から除外する組織の選択を受け付ける処理において、情報取引装置1fの個人端末インタフェース部12は、各個人端末4からのアクセスに基づいて、除外組織選択ページを送信する(ステップS1501)。各個人端末4は除外組織選択ページをディスプレイに出力する(ステップS1502)。各個人ユーザは、個人端末4に表示された除外組織選択ページにおいて、個人情報の提供先から除外する組織を選択する。一例としては、個人情報の情報提供先の組織の候補が属する複数の組織カテゴリの一覧と、それらの除外を指定するチェックボタンが除外組織選択ページに表示される。また登録ボタンが除外組織選択ページに表示される。各個人ユーザは、個人情報の情報提供先の組織から除外する組織カテゴリのチェックボタンをONに操作し、登録ボタンを押下操作する。各個人端末4は、当該操作に基づいて、個人情報の情報提供先の組織から除外する組織の属する組織カテゴリの入力を検出する(ステップS1503)。各個人端末4は、個人識別コード、除外対象となる情報提供先の組織の属する組織カテゴリとを少なくとも含むフィルタ情報を生成し、情報取引装置1fへ送信する(ステップS1504)。
図22は第六実施形態による情報取引システムの構成を示す図である。
情報取引システム100Cは、図22に示すような構成を有していてもよい。つまり情報取引システム100Cにおいて、他の実施形態で情報提供元装置2が備える第二DB22を、データセンタ5が備える。またデータセンタ5は、情報取引装置1が生成したカタログ情報41を記憶する。そして情報提供元装置2はデータセットを生成した場合、そのデータセットをデータセンタ5に備わる第二DB22に登録する。カタログ情報40を情報取引装置1が用いる場合には、情報取引装置1がデータセンタ5のカタログ情報40を参照し、上述の他の実施形態で説明した処理を行えばよい。
図24は第四から第六実施形態に含まれる最小構成の情報取引装置1gによる処理を示す図である。
情報取引装置1gは、少なくとも送信手段124、提供要求受付手段122と、送信要求手段123とを備える。
送信手段124は、情報提供元装置2から情報提供先装置3へ提供できる個人情報を含む一つ以上のデータセットに関する説明項目をデータセット毎に記述したデータセット指定ウェブページ41を情報提供先装置3へ送信する(ステップS1131)。
提供要求受付手段122は、データセット指定ウェブページ41に記述された一つ以上のデータセットのうち提供要求対象のデータセットの選択を情報提供先装置3より受け付ける(ステップS1132)。
送信要求手段123は、提供要求対象となるデータセットに含まれる個人情報の提供の承認を受けた場合に、当該個人情報の情報提供先装置3への送信要求を、当該個人情報を記憶する情報提供元装置2へ出力する(ステップS1133)。
情報提供元装置と情報提供先装置に接続された情報取引装置とを備え、前記情報取引装置は、
前記情報提供元装置から前記情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する詳細情報を含むカタログ情報を記憶し、
前記情報提供先装置から前記データセットの提供要求を受け付け、
前記提供要求が示すデータセットの前記情報提供先装置への送信要求を前記情報提供元装置へ出力する
情報取引システム。
前記情報取引装置は、
個人ユーザの識別情報と、前記個人ユーザの個人情報を含むデータセットが何れの前記情報提供元装置に記録されているかを示す所在情報とを記憶し、
前記提供要求が示すデータセットに関する前記所在情報に含まれる前記個人ユーザの識別情報を取得し、前記個人ユーザに対する個人情報の提供の承認要求を行い、
前記承認要求の結果が個人情報の提供が可能であることを示す場合に、前記提供要求が示すデータセットの送信要求を前記情報提供元装置へ出力する
付記1に記載の情報取引システム。
前記情報提供元装置は、
前記データセットのフォーマット定義情報に基づいて前記個人情報を含む前記データセットを生成し記憶する
付記1または付記2に記載の情報取引システム。
前記情報提供先装置は、
前記フォーマット定義情報が示す前記データセットに含めることのできる個人情報以外の新たな個人情報の前記データセットへの追加要求を送信し、
前記情報提供元装置は、
前記追加要求に基づいて生成された新たな前記フォーマット定義情報を用いて前記データセットを生成する
付記3に記載の情報取引システム。
前記情報取引装置は、
前記情報提供先装置を管理する組織のうち除外対象の組織の選択を受け付け、
前記提供要求が示すデータセットに関する前記所在情報に含まれる個人ユーザの識別情報を取得し、
前記個人ユーザが、前記提供要求を送信した前記情報提供先装置に紐づく組織について、前記除外対象の組織であると選択している場合、その個人ユーザに対する個人情報の提供の承認要求または前記個人情報を含むデータセットの前記情報提供先装置への送信の少なくとも一方を停止する
付記2に記載の情報取引システム。
前記データセットまたは前記カタログ情報の少なくとも一方をデータセンタが記憶する付記1から付記5の何れか一項に記載の情報取引システム。
情報提供元装置から情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する詳細情報を含むカタログ情報を記憶し、
前記情報提供先装置から前記データセットの提供要求を受け付け、
前記提供要求が示すデータセットの前記情報提供先装置への送信要求を前記情報提供元装置へ出力する
情報取引装置。
情報提供元装置と情報提供先装置に通信接続した情報取引装置を備えた情報取引システムにおいて、前記情報取引装置は、
前記情報提供元装置から前記情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する詳細情報を含むカタログ情報を記憶し、
前記情報提供先装置から前記データセットの提供要求を受け付け、
前記提供要求が示すデータセットの前記情報提供先装置への送信要求を前記情報提供元装置へ出力する
情報取引方法。
情報取引装置のコンピュータを、
情報提供元装置から情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する詳細情報を含むカタログ情報を記憶する手段、
前記情報提供先装置から前記データセットの提供要求を受け付ける手段、
前記提供要求が示すデータセットの前記情報提供先装置への送信要求を前記情報提供元装置へ出力する手段、
として機能させるプログラムを記録した記録媒体。
情報提供元装置から情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する説明項目を前記データセットそれぞれについて記述したデータセット指定ウェブページを前記情報提供先装置へ送信し、
前記データセット指定ウェブページに記述された前記一つ以上のデータセットのうち提供要求対象のデータセットの選択を前記情報提供先装置から受け付け、
前記提供要求対象となるデータセットに含まれる個人情報の提供の承認を受けた場合に、前記個人情報の前記情報提供先装置への送信要求を前記個人情報を記憶する情報提供元装置へ出力する
情報取引方法。
個人ユーザの識別情報と、前記個人ユーザの個人情報が何れの前記情報提供元装置に記録されているかを示す所在情報とを記憶し、
前記提供要求対象のデータセットに関する前記説明項目から特定した個人情報に対応する前記個人ユーザの識別情報を前記所在情報の中から取得し、前記個人ユーザの識別情報に対応する承認要求先に承認要求を行う
付記10に記載の情報取引方法。
新たな個人情報のフォーマット形式の指定に基づいてフォーマット定義情報を生成し、
前記フォーマット定義情報の示す前記フォーマット形式に合わせた個人情報を含む前記データセットを生成する前記情報提供元装置に対して、前記フォーマット定義情報を送信する
付記11に記載の情報取引方法。
前記情報提供先装置を管理する組織のうち除外対象の組織の選択を受け付け、
前記提供要求対象となるデータセットに関する前記所在情報に含まれる個人ユーザの識別情報を取得し、
前記個人ユーザが、前記提供要求対象となるデータセットの選択を受け付けた前記情報提供先装置に紐づく組織について、前記除外対象の組織であると選択している場合、その個人ユーザに対する個人情報の提供の承認要求または前記個人情報を含むデータセットの前記情報提供先装置への送信の少なくとも一方を停止する
付記11または付記12に記載の情報取引方法。
情報提供元装置から情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する説明項目を前記データセットそれぞれについて記述したデータセット指定ウェブページを前記情報提供先装置へ送信し、
前記データセット指定ウェブページに記述された前記一つ以上のデータセットのうち提供要求対象のデータセットの選択を前記情報提供先装置から受け付け、
前記提供要求対象となるデータセットに含まれる個人情報の提供の承認を受けた場合に、前記個人情報の前記情報提供先装置への送信要求を前記個人情報を記憶する情報提供元装置へ出力する
情報取引装置。
情報取引装置のコンピュータを、
情報提供元装置から情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する説明項目を前記データセットそれぞれについて記述したデータセット指定ウェブページを前記情報提供先装置へ送信する手段、
前記データセット指定ウェブページに記述された前記一つ以上のデータセットのうち提供要求対象のデータセットの選択を前記情報提供先装置から受け付ける手段、
前記提供要求対象となるデータセットに含まれる個人情報の提供の承認を受けた場合に、前記個人情報の前記情報提供先装置への送信要求を前記個人情報を記憶する情報提供元装置へ出力する手段、
として機能させるプログラムを記録した記録媒体。
個人ユーザの識別情報と、その個人ユーザの個人情報が何れの前記情報提供元装置に記録されているかを示す所在情報を記憶する前記情報取引装置のコンピュータを、
さらに、前記提供要求対象のデータセットに関する前記説明項目から特定した個人情報に対応する前記個人ユーザの識別情報を前記所在情報の中から取得し、前記個人ユーザの識別情報に対する承認要求先に承認要求を行う手段、
として機能させる付記15に記載のプログラムを記録した記録媒体。
前記情報取引装置のコンピュータを、さらに、
新たな個人情報のフォーマット形式の指定に基づいてフォーマット定義情報を生成し、 前記フォーマット定義情報の示す前記フォーマット形式に合わせた個人情報を含む前記データセットを生成する前記情報提供元装置に対して、前記フォーマット定義情報を送信する手段、
として機能させる付記16に記載のプログラムを記録した記録媒体。
前記情報取引装置のコンピュータを、さらに、
前記情報提供先装置を管理する組織のうち除外対象の組織の選択を受け付ける手段、
前記提供要求対象となるデータセットに関する前記所在情報に含まれる個人ユーザの識別情報を取得する手段、
前記個人ユーザが、前記提供要求対象となるデータセットの選択を受け付けた前記情報提供先装置に紐づく組織について、前記除外対象の組織であると選択している場合、その個人ユーザに対する個人情報の提供の承認要求または前記個人情報を含むデータセットの前記情報提供先装置への送信の少なくとも一方を停止する手段、
として機能させる付記16に記載のプログラムを記録した記録媒体。
2 情報提供元装置
3 情報提供先装置
4 個人端末
5 データセンタ
10 除外組織受付部
11 制御部
12 個人端末インタフェース部
13 提供元インタフェース部
14 提供先インタフェース部
15 カタログ情報生成部
16 承認先特定部
17 送信要求部
18 提供対価算出部
19 記録対価算出部
21 第一DB
22 第二DB
100A、100B、100C 情報取引システム
Claims (18)
- 情報提供元装置と情報提供先装置に接続された情報取引装置とを備え、前記情報取引装置は、
前記情報提供元装置から前記情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する詳細情報を含むカタログ情報を記憶し、
前記情報提供先装置から前記データセットの提供要求を受け付け、
前記提供要求が示すデータセットの前記情報提供先装置への送信要求を前記情報提供元装置へ出力する
情報取引システム。 - 前記情報取引装置は、
個人ユーザの識別情報と、前記個人ユーザの個人情報を含むデータセットが何れの前記情報提供元装置に記録されているかを示す所在情報とを記憶し、
前記提供要求が示すデータセットに関する前記所在情報に含まれる前記個人ユーザの識別情報を取得し、前記個人ユーザに対する個人情報の提供の承認要求を行い、
前記承認要求の結果が個人情報の提供が可能であることを示す場合に、前記提供要求が示すデータセットの送信要求を前記情報提供元装置へ出力する
請求項1に記載の情報取引システム。 - 前記情報提供元装置は、
前記データセットのフォーマット定義情報に基づいて前記個人情報を含む前記データセットを生成し記憶する
請求項1または請求項2に記載の情報取引システム。 - 前記情報提供先装置は、
前記フォーマット定義情報が示す前記データセットに含めることのできる個人情報以外の新たな個人情報の前記データセットへの追加要求を送信し、
前記情報提供元装置は、
前記追加要求に基づいて生成された新たな前記フォーマット定義情報を用いて前記データセットを生成する
請求項3に記載の情報取引システム。 - 前記情報取引装置は、
前記情報提供先装置を管理する組織のうち除外対象の組織の選択を受け付け、
前記提供要求が示すデータセットに関する前記所在情報に含まれる個人ユーザの識別情報を取得し、
前記個人ユーザが、前記提供要求を送信した前記情報提供先装置に紐づく組織について、前記除外対象の組織であると選択している場合、その個人ユーザに対する個人情報の提供の承認要求または前記個人情報を含むデータセットの前記情報提供先装置への送信の少なくとも一方を停止する
請求項2に記載の情報取引システム。 - 前記データセットまたは前記カタログ情報の少なくとも一方をデータセンタが記憶する請求項1または請求項2に記載の情報取引システム。
- 情報提供元装置から情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する詳細情報を含むカタログ情報を記憶し、
前記情報提供先装置から前記データセットの提供要求を受け付け、
前記提供要求が示すデータセットの前記情報提供先装置への送信要求を前記情報提供元装置へ出力する
情報取引装置。 - 情報提供元装置と情報提供先装置に通信接続した情報取引装置を備えた情報取引システムにおいて、前記情報取引装置は、
前記情報提供元装置から前記情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する詳細情報を含むカタログ情報を記憶し、
前記情報提供先装置から前記データセットの提供要求を受け付け、
前記提供要求が示すデータセットの前記情報提供先装置への送信要求を前記情報提供元装置へ出力する
情報取引方法。 - 情報取引装置のコンピュータを、
情報提供元装置から情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する詳細情報を含むカタログ情報を記憶する手段、
前記情報提供先装置から前記データセットの提供要求を受け付ける手段、
前記提供要求が示すデータセットの前記情報提供先装置への送信要求を前記情報提供元装置へ出力する手段、
として機能させるプログラムを記録した記録媒体。 - 情報提供元装置から情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する説明項目を前記データセットそれぞれについて記述したデータセット指定ウェブページを前記情報提供先装置へ送信し、
前記データセット指定ウェブページに記述された前記一つ以上のデータセットのうち提供要求対象のデータセットの選択を前記情報提供先装置から受け付け、
前記提供要求対象となるデータセットに含まれる個人情報の提供の承認を受けた場合に、前記個人情報の前記情報提供先装置への送信要求を前記個人情報を記憶する情報提供元装置へ出力する
情報取引方法。 - 個人ユーザの識別情報と、前記個人ユーザの個人情報が何れの前記情報提供元装置に記録されているかを示す所在情報とを記憶し、
前記提供要求対象のデータセットに関する前記説明項目から特定した個人情報に対応する前記個人ユーザの識別情報を前記所在情報の中から取得し、前記個人ユーザの識別情報に対応する承認要求先に承認要求を行う
請求項10に記載の情報取引方法。 - 新たな個人情報のフォーマット形式の指定に基づいてフォーマット定義情報を生成し、
前記フォーマット定義情報の示す前記フォーマット形式に合わせた個人情報を含む前記データセットを生成する前記情報提供元装置に対して、前記フォーマット定義情報を送信する
請求項11に記載の情報取引方法。 - 前記情報提供先装置を管理する組織のうち除外対象の組織の選択を受け付け、
前記提供要求対象となるデータセットに関する前記所在情報に含まれる個人ユーザの識別情報を取得し、
前記個人ユーザが、前記提供要求対象となるデータセットの選択を受け付けた前記情報提供先装置に紐づく組織について、前記除外対象の組織であると選択している場合、その個人ユーザに対する個人情報の提供の承認要求または前記個人情報を含むデータセットの前記情報提供先装置への送信の少なくとも一方を停止する
請求項11または請求項12に記載の情報取引方法。 - 情報提供元装置から情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する説明項目を前記データセットそれぞれについて記述したデータセット指定ウェブページを前記情報提供先装置へ送信し、
前記データセット指定ウェブページに記述された前記一つ以上のデータセットのうち提供要求対象のデータセットの選択を前記情報提供先装置から受け付け、
前記提供要求対象となるデータセットに含まれる個人情報の提供の承認を受けた場合に、前記個人情報の前記情報提供先装置への送信要求を前記個人情報を記憶する情報提供元装置へ出力する
情報取引装置。 - 情報取引装置のコンピュータを、
情報提供元装置から情報提供先装置へ提供できる個人情報を含む一つ以上のデータセットに関する説明項目を前記データセットそれぞれについて記述したデータセット指定ウェブページを前記情報提供先装置へ送信する手段、
前記データセット指定ウェブページに記述された前記一つ以上のデータセットのうち提供要求対象のデータセットの選択を前記情報提供先装置から受け付ける手段、
前記提供要求対象となるデータセットに含まれる個人情報の提供の承認を受けた場合に、前記個人情報の前記情報提供先装置への送信要求を前記個人情報を記憶する情報提供元装置へ出力する手段、
として機能させるプログラムを記録した記録媒体。 - 個人ユーザの識別情報と、その個人ユーザの個人情報が何れの前記情報提供元装置に記録されているかを示す所在情報を記憶する前記情報取引装置のコンピュータを、
さらに、前記提供要求対象のデータセットに関する前記説明項目から特定した個人情報に対応する前記個人ユーザの識別情報を前記所在情報の中から取得し、前記個人ユーザの識別情報に対する承認要求先に承認要求を行う手段、
として機能させる請求項15に記載のプログラムを記録した記録媒体。 - 前記情報取引装置のコンピュータを、さらに、
新たな個人情報のフォーマット形式の指定に基づいてフォーマット定義情報を生成し、 前記フォーマット定義情報の示す前記フォーマット形式に合わせた個人情報を含む前記データセットを生成する前記情報提供元装置に対して、前記フォーマット定義情報を送信する手段、
として機能させる請求項16に記載のプログラムを記録した記録媒体。 - 前記情報取引装置のコンピュータを、さらに、
前記情報提供先装置を管理する組織のうち除外対象の組織の選択を受け付ける手段、
前記提供要求対象となるデータセットに関する前記所在情報に含まれる個人ユーザの識別情報を取得する手段、
前記個人ユーザが、前記提供要求対象となるデータセットの選択を受け付けた前記情報提供先装置に紐づく組織について、前記除外対象の組織であると選択している場合、その個人ユーザに対する個人情報の提供の承認要求または前記個人情報を含むデータセットの前記情報提供先装置への送信の少なくとも一方を停止する手段、
として機能させる請求項16に記載のプログラムを記録した記録媒体。
Priority Applications (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
JP2021554249A JP7334793B2 (ja) | 2019-10-31 | 2020-10-07 | 情報取引システム、情報取引装置、情報取引方法、プログラム |
US17/768,603 US20240104080A1 (en) | 2019-10-31 | 2020-10-07 | Information transaction system, information transaction device, information transaction method, and program |
Applications Claiming Priority (4)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
JP2019-199142 | 2019-10-31 | ||
JP2019199142 | 2019-10-31 | ||
JP2020-029851 | 2020-02-25 | ||
JP2020029851 | 2020-02-25 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2021085061A1 true WO2021085061A1 (ja) | 2021-05-06 |
Family
ID=75715238
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/JP2020/037969 WO2021085061A1 (ja) | 2019-10-31 | 2020-10-07 | 情報取引システム、情報取引装置、情報取引方法、プログラム |
Country Status (3)
Country | Link |
---|---|
US (1) | US20240104080A1 (ja) |
JP (1) | JP7334793B2 (ja) |
WO (1) | WO2021085061A1 (ja) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2023079818A1 (ja) * | 2021-11-05 | 2023-05-11 | 株式会社日立製作所 | データ価値評価演算装置、データ流通システム |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2003316965A (ja) * | 2002-04-19 | 2003-11-07 | Omron Corp | 情報収集システム,情報提供装置,仲介処理装置,情報匿名化装置,情報提供処理用のプログラム,情報中継処理用のプログラム |
WO2009101755A1 (ja) * | 2008-02-13 | 2009-08-20 | Nec Corporation | 個人情報流通制御システムおよび個人情報流通制御方法 |
JP2009199573A (ja) * | 2008-01-25 | 2009-09-03 | Nippon Telegr & Teleph Corp <Ntt> | 属性情報開示システム、属性情報開示方法および属性情報開示処理プログラム |
JP2014229039A (ja) * | 2013-05-22 | 2014-12-08 | 株式会社日立製作所 | プライバシ保護型データ提供システム |
Family Cites Families (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP6096692B2 (ja) | 2014-02-28 | 2017-03-15 | ヤフー株式会社 | 情報取引装置、情報取引方法及び情報取引プログラム |
JP6431584B1 (ja) | 2017-08-29 | 2018-11-28 | 三菱電機インフォメーションシステムズ株式会社 | 情報管理装置、情報管理方法及び情報管理プログラム |
-
2020
- 2020-10-07 WO PCT/JP2020/037969 patent/WO2021085061A1/ja active Application Filing
- 2020-10-07 JP JP2021554249A patent/JP7334793B2/ja active Active
- 2020-10-07 US US17/768,603 patent/US20240104080A1/en active Pending
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2003316965A (ja) * | 2002-04-19 | 2003-11-07 | Omron Corp | 情報収集システム,情報提供装置,仲介処理装置,情報匿名化装置,情報提供処理用のプログラム,情報中継処理用のプログラム |
JP2009199573A (ja) * | 2008-01-25 | 2009-09-03 | Nippon Telegr & Teleph Corp <Ntt> | 属性情報開示システム、属性情報開示方法および属性情報開示処理プログラム |
WO2009101755A1 (ja) * | 2008-02-13 | 2009-08-20 | Nec Corporation | 個人情報流通制御システムおよび個人情報流通制御方法 |
JP2014229039A (ja) * | 2013-05-22 | 2014-12-08 | 株式会社日立製作所 | プライバシ保護型データ提供システム |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2023079818A1 (ja) * | 2021-11-05 | 2023-05-11 | 株式会社日立製作所 | データ価値評価演算装置、データ流通システム |
JP7473514B2 (ja) | 2021-11-05 | 2024-04-23 | 株式会社日立製作所 | データ価値評価演算装置、データ流通システム |
Also Published As
Publication number | Publication date |
---|---|
JP7334793B2 (ja) | 2023-08-29 |
US20240104080A1 (en) | 2024-03-28 |
JPWO2021085061A1 (ja) | 2021-05-06 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US7051012B2 (en) | User interface system for maintaining organization related information for use in supporting organization operation | |
Topazian et al. | Joining forces to overcome cancer: the Kenya cancer research and control stakeholder program | |
KR101863882B1 (ko) | 카드사 시스템을 이용한 의료 보험금 간편 청구 대행 서비스 시스템 및 그 방법 | |
JP5796236B2 (ja) | 保健情報統合管理方法および統合管理システム、並びにその記録媒体 | |
Makinde | Physicians as medical tourism facilitators in Nigeria: Ethical issues of the practice | |
Bausewein et al. | National strategy for palliative care of severely ill and dying people and their relatives in pandemics (PallPan) in Germany-study protocol of a mixed-methods project | |
JP2019096242A (ja) | 地域サービス仲介システム | |
Patsioura et al. | Evaluation of Greek public hospital websites | |
WO2021085061A1 (ja) | 情報取引システム、情報取引装置、情報取引方法、プログラム | |
KR102379919B1 (ko) | 복수의 디바이스 간 통신을 지원하는 인터페이스 관리 시스템 및 방법 | |
US8375057B2 (en) | Database system, server device, terminal device, and data presentation method | |
JP6499070B2 (ja) | 調剤予約装置、調剤予約方法、プログラム、及び記録媒体 | |
JP2019028911A (ja) | データ提供システム、データ生成装置およびデータ提供方法 | |
JP2004199663A (ja) | 健康管理企業内のイメージング及び情報システムのために患者識別子を支えるシステム及び方法 | |
Royall et al. | From access to collaboration: four African pathologists profile their use of the internet and social media | |
US20200234819A1 (en) | System and method for coordination of surgical procedures | |
EP1304639A1 (en) | A system for maintaining organization related information for use in supporting organization operation | |
US11120374B2 (en) | Memorial event management system | |
Teso et al. | Defining the role of service design in healthcare | |
JP7052473B2 (ja) | 医療情報管理サーバー及び医療情報管理システム | |
JP2017208039A (ja) | 医療情報システム | |
JP6854552B1 (ja) | 管理サーバおよび訃報自動送信システム | |
KR102489067B1 (ko) | 인공지능 기반 맞춤형 의료정보 제공 시스템 및 그 방법 | |
KR101644683B1 (ko) | 대기 순번 서비스를 제공하는 방법, 사용자 단말기 및 서비스 서버 | |
JP6757013B1 (ja) | 取引業者情報表示システム |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20881387 Country of ref document: EP Kind code of ref document: A1 |
|
ENP | Entry into the national phase |
Ref document number: 2021554249 Country of ref document: JP Kind code of ref document: A |
|
WWE | Wipo information: entry into national phase |
Ref document number: 17768603 Country of ref document: US |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 20881387 Country of ref document: EP Kind code of ref document: A1 |