WO2022153826A1 - Système, serveur de recherche, procédé permettant de commander un serveur de recherche, et support d'enregistrement - Google Patents

Système, serveur de recherche, procédé permettant de commander un serveur de recherche, et support d'enregistrement Download PDF

Info

Publication number
WO2022153826A1
WO2022153826A1 PCT/JP2021/047881 JP2021047881W WO2022153826A1 WO 2022153826 A1 WO2022153826 A1 WO 2022153826A1 JP 2021047881 W JP2021047881 W JP 2021047881W WO 2022153826 A1 WO2022153826 A1 WO 2022153826A1
Authority
WO
WIPO (PCT)
Prior art keywords
data
user
server
search
distribution control
Prior art date
Application number
PCT/JP2021/047881
Other languages
English (en)
Japanese (ja)
Inventor
雄亮 佐藤
泰正 光畑
雅視 井上
由梨香 道下
Original Assignee
日本電気株式会社
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 日本電気株式会社 filed Critical 日本電気株式会社
Priority to JP2022575502A priority Critical patent/JPWO2022153826A5/ja
Publication of WO2022153826A1 publication Critical patent/WO2022153826A1/fr

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/20Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
    • G06F16/24Querying
    • G06F16/245Query processing
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q50/00Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
    • G06Q50/10Services

Definitions

  • the present invention relates to a system, a search server, a control method of a search server, and a recording medium.
  • an information distribution system that provides personal information held in hospitals, etc. to devices to which information is provided, such as businesses, based on the consent of the individual.
  • an information transaction device managed by an information bank or the like an information provider device managed by an information provider company, and an information provider device managed by an information provider are provided.
  • the information transaction device stores personal information acquired from the information provider device.
  • the information transaction device transmits the personal information desired by the utilization business operator or the like from the stored personal information to the information providing destination device.
  • Patent Documents 1 and 2 disclose techniques related to information distribution systems and the like.
  • Patent Document 1 describes that the distribution of user information is activated.
  • the information trading device of Patent Document 1 has a trading unit and a determination unit.
  • the trading unit controls the transaction processing related to the transaction of user information between the information provider who provides the user information and the information user who uses the user information.
  • the decision-making department determines the remuneration for the parties involved in the transaction other than the information provider and the information user.
  • the determination unit determines the reward to the person concerned who is the providing supporter who assists the information provider in providing the user information to the information trading device.
  • Patent Document 2 one's personal information is utilized in a correct way and at a reasonable price with the consent of the person, and the information user side selects an individual who matches the target attribute and sends a DM. It is stated that it will provide a personal information utilization system with a high hit rate.
  • the mutual aid association secretariat of the provider is established between the personal information provider and the personal information user, and the personal information can be collected and disclosed at the individual's free will.
  • the present invention provides a system, a search server, a control method for a search server, and a recording medium that contribute to enabling the distribution of high-value information for a data utilization business operator while protecting the privacy of an individual. Is the main purpose.
  • the service server that stores the data generated by the service provider providing the service to the user and the data stored by the service server are sold to the data utilization provider.
  • the transaction server that controls the data the distribution control server that controls the data provision from the service provider to the data utilization provider, the data stored in the service provider, and the user ID of the user.
  • the transaction server includes a search server for storing encrypted data, and the transaction server receives a provision request including a search condition from the data utilization business operator and receives the received provision request from the distribution control server.
  • the distribution control server determines whether or not the search condition is an advanced search in which a result cannot be obtained only by the data type and it is necessary to refer to the data content, and the search condition is the said.
  • the search condition is transmitted to the search server, the search server identifies a user who matches the search condition, and the target person list including the user ID of the specified user is described.
  • the distribution control server instructs the service server to provide the data of the user included in the target person list to the data utilization business operator. Will be done.
  • the encrypted data acquisition means for acquiring the data stored in the service provider and the data in which the user ID of the user is encrypted and the search condition included in the provision request are provided.
  • An advanced search which is a search that requires reference to the data content because the result cannot be obtained only by the data type, is received from the distribution control server, the user who matches the search condition is identified, and the specified user
  • a search server is provided that includes a target person list generation means that generates a target person list including a user ID and transmits the generated target person list to the distribution control server.
  • the search server acquires the data stored in the service provider and the data in which the user ID of the user is encrypted, and the search condition included in the provision request is only the data type. Receives an advanced search from the distribution control server, which is a search for which no result can be obtained and it is necessary to refer to the data contents, identifies a user who matches the search conditions, and obtains the user ID of the specified user.
  • a method for controlling a search server is provided, which generates a target person list including the target person and transmits the generated target person list to the distribution control server.
  • the fourth viewpoint of the present invention it is included in the process of acquiring the data stored in the service provider and the data in which the user ID of the user is encrypted on the computer mounted on the search server, and the provision request.
  • the process of receiving an advanced search from the distribution control server which is a search that requires reference to the data content because the result cannot be obtained only with the data type, and the process of identifying the user who matches the search condition.
  • a readable recording medium is provided.
  • a system, a search server, a control method and a record of a search server which contribute to enabling the distribution of high-value information for a data utilization business operator while protecting the privacy of an individual.
  • the medium is provided.
  • the effect of the present invention is not limited to the above. According to the present invention, other effects may be produced in place of or in combination with the effect.
  • the system includes a service server 101, a transaction server 102, a distribution control server 103, and a search server 104 (see FIG. 1).
  • the service server 101 stores data generated when a service provider provides a service to a user.
  • the transaction server 102 controls to sell the data stored in the service server to the data utilization business operator.
  • the distribution control server 103 controls the provision of data from the service provider to the data utilization provider.
  • the search server 104 is a server that stores data stored in the service provider and data in which the user ID of the user is encrypted.
  • the transaction server 102 receives the provision request including the search condition from the data utilization business operator, and transmits the received provision request to the distribution control server 103.
  • the distribution control server 103 determines whether or not the search condition is an advanced search, which is a search in which a result cannot be obtained only by the data type and it is necessary to refer to the data content, and when the search condition is an advanced search, the search is performed.
  • the condition is transmitted to the search server 104.
  • the search server 104 identifies a user who matches the search conditions, and transmits a target user list including the user ID of the specified user to the distribution control server 103.
  • the distribution control server 103 instructs the service server 101 to provide the data of the user included in the target person list to the data utilization business operator.
  • the distribution control server 103 When the distribution control server 103 cannot identify the corresponding user unless the request of the data utilization business operator refers to the content of the data, the distribution control server 103 requests the search server 104 to identify the user who satisfies the request.
  • the search server 104 encrypts and holds the data obtained by the service provider providing the service to the user, and can perform arbitrary calculations while the data is encrypted.
  • the search server 104 identifies a user corresponding to data that matches the request of the data utilization business operator in response to the request from the distribution control server 103. At that time, since the search server 104 identifies the user by using the secret calculation, the privacy of the user is protected.
  • the distribution control server 103 acquires a list of users satisfying the search conditions from the search server 104, and instructs the service server 101 to provide the acquired user data to the data utilization business operator.
  • the data utilization business operator can acquire high-value information while protecting the privacy of the user.
  • FIG. 2 is a diagram showing an example of a schematic configuration of an information distribution system according to the first embodiment.
  • the participating members (actors) of the information distribution system include an information distribution business operator, a service business operator, a data utilization business operator, and a trading business operator.
  • the information distribution business operator is the entity that controls the data distribution between the service business operator and the data utilization business operator.
  • the information distribution business operator includes at least one distribution control server 10.
  • the distribution control server 10 is a device that controls (realizes) data distribution between a service provider and a data utilization provider.
  • the distribution control server 10 controls the provision of data from the service provider to the data utilization provider.
  • a service provider is an entity that provides services to individuals.
  • the service provider may be a private operator or a public institution.
  • Examples of service providers include medical institutions (hospitals, pharmacies, etc.), retailers, education providers that teach languages, sports, arts, etc. to customers.
  • Each service provider is equipped with a service server 20 for providing services to customers.
  • the service server 20 stores (stores) data (user data) generated when a service provider provides a service to a user.
  • a data utilization business operator is an entity that does not directly provide services to individuals.
  • An example of a data utilization business operator is a business operator that conducts business using data acquired by a service business operator such as a pharmaceutical company.
  • a search business is included as a form of data utilization business.
  • a search business operator is a business operator that searches for information in response to a request (consignment) from an information distribution business operator.
  • the data utilization business operator is equipped with a business operator terminal 30 for acquiring data from a service business operator.
  • the search business operator includes a plurality of search servers 31.
  • the search business operator uses a plurality of search servers 31 as a secret calculation server and submits the result of the secret calculation.
  • the search server 31 is a server that stores data stored in the service provider (service server 20) and data in which the user ID of the user is encrypted, and can perform calculations while the data is encrypted.
  • the transaction business operator is the entity that realizes the transaction between the service business operator and the data utilization business operator.
  • the trading business operator realizes data distribution between the data generator (service business operator) and the data consumer (data utilization business operator).
  • the transaction business operator is equipped with a transaction server 40 for realizing the data distribution.
  • the transaction server 40 controls to sell the data stored in the service server 20 to the data utilization business operator.
  • the user who uses the information distribution system uses the terminal 50.
  • Each device shown in FIG. 2 is connected to each other via a network.
  • the distribution control server 10 and the service server 20 are connected by a wired or wireless communication means and are configured to be able to communicate with each other.
  • the configuration shown in FIG. 2 is an example, and does not mean to limit the configuration of the information distribution system disclosed in the present application.
  • the information distribution business operator may include two or more distribution control servers 10.
  • the information distribution system includes the business terminal 30 and the transaction server 40 according to the number of business operators participating in the system.
  • the explanation will be given by taking a "medical institution" as an example as a service provider.
  • a “medical institution” as an example as a service provider.
  • the medical institution A is provided with the medical A server 20-1
  • the medical institution B is provided with the medical B server 20-2.
  • Provision exists as a means of data distribution in the information distribution system.
  • Provision is a means for a data utilization business operator to acquire data accumulated by another service business operator. For example, when a pharmaceutical company acquires a diagnosis result (patient's disease name; current disease), vital data, or the like from medical institutions A and B, data distribution by "providing" is used.
  • Provision is a means used by data utilization businesses that do not directly provide services to users, so in principle, compensation for data distribution is incurred. That is, “offer” is used for the user to receive compensation from the data utilization business operator.
  • the user registers as a user when joining the system.
  • the user operates the possessed terminal 50 to input his / her personal information (name, contact information, account information, etc.) into the distribution control server 10.
  • the distribution control server 10 generates a user ID (Identifier) for identifying the user, and issues the generated user ID to the user.
  • the distribution control server 10 stores the generated user ID and the acquired personal information (name, etc.) in association with each other. More specifically, the distribution control server 10 stores the user ID and personal information in association with each other in the "user information database". Details of the user information database will be described later.
  • ⁇ Sending personal identification code> When the user registration is completed, the user receives the service provided by the service provider (see FIG. 4). When receiving a service from a service provider, the user informs the service provider of his / her name and the like.
  • the user receives a medical examination from medical institution A.
  • the medical institution A medical A server 20-1
  • the medical institution A notifies the user of the name of the disease.
  • a service provider When a service provider provides a service to a new customer (user), it generates a "personal identification code" for identifying the new user. Since the name of the system registrant is transmitted from the distribution control server 10 at regular intervals or at a predetermined timing, the medical A server 20-1 responds to the transmission of the name and provides new customer information (user). Information) is transmitted to the distribution control server 10.
  • the user information includes the above-generated personal identification code of the user and the operator code of the service provider.
  • the business operator code is identification information (ID) for identifying a service business operator participating in the information distribution system.
  • the distribution control server 10 stores the acquired personal identification code in the user information database.
  • the service provider accumulates the data generated by providing the service to the user. For example, as shown in FIG. 5, when the medical institution A examines each of the users U1 to U3, the disease names A1 to A3 are notified to each user, and these disease names are accumulated for each user.
  • the service provider (medical A server 20-1) stores the personal identification code of each user in association with the data obtained as a result of providing the service.
  • the medical A server 20-1 uses the “accumulation database” to associate and store the personal identification codes of the users U1 to U3 and the disease names A1 to A3. The details of the storage database will be described later.
  • the service provider transmits "location information" to the distribution control server 10 every time data (data generated as a result of service provision) is accumulated.
  • the location information is information on the storage location of the data accumulated in the service provider (data storage entity; service provider) and the like.
  • the location information includes a personal identification code, a business operator code, the type of accumulated data, and the like.
  • the distribution control server 10 stores the acquired location information in the "location information database". Details of the location information database will be described later.
  • the database stores the personal identification code, the business operator code, and the data type in association with each other.
  • the service server 20 generates the user's personal identification code, and stores the generated personal identification code and the stored data (data generated by providing the service to the user) in association with each other.
  • the generated personal identification code is transmitted to the distribution control server 10.
  • the distribution control server 10 stores the user ID and the personal identification code in association with each other.
  • the transaction business operator makes a tie-up with at least one service business operator out of a plurality of service business operators participating in the information distribution system. For example, a business operator that handles medical data cooperates with medical institutions (hospitals, pharmacies, etc.). Alternatively, a business operator that handles data related to education cooperates with an educational business operator. The transaction operator remembers the operator code for the service operator of the partner.
  • the transaction business operator sells the data accumulated by the service business operator of the partner to the data utilization business operator.
  • the affiliated service providers shown in FIG. 6 are medical institutions A and B
  • the trading business operator sells the data accumulated by these business operators to a pharmaceutical company or the like. All or part of the consideration obtained from the sale of data will be paid to the users involved in the provided data.
  • a user who wants to obtain consideration by providing data through a transaction business operator needs to open an account with the transaction business operator (transaction server 40).
  • the users who want to earn profits by providing data open an "information account" on the transaction server 40 are examples of the users who want to earn profits by providing data open an "information account" on the transaction server 40.
  • the user presents the user ID issued from the distribution control server 10 to the transaction server 40 and opens an information account.
  • the transaction server 40 stores the acquired user ID.
  • the transaction server 40 manages the user ID of the user who opened the account by the account opener list. In this way, the transaction server 40 stores the account opener list including the user ID of the user who opened the account for providing data.
  • Catalog information is information showing details of data that can be sold by an information distribution system to a data utilization business operator.
  • the dataset name included in the catalog information is information for identifying the catalog information. For example, a data set name such as "diagnosis result 1" is given to the current disease (current disease) and “diagnosis result 2" is given to the past disease (history).
  • the operator code is as described above.
  • the data type indicates the type of data accumulated by the service provider.
  • the data format is information that defines in what format the data is provided.
  • the data utilization business operator acquires the catalog information through the trading business operator. More specifically, the business terminal 30 transmits a "catalog information presentation request" to the transaction server 40.
  • the transaction server 40 Upon receiving the catalog information presentation request, the transaction server 40 transmits a "catalog information transmission request" to the distribution control server 10.
  • the distribution control server 10 transmits the catalog information defined by the information distribution company to the transaction server 40.
  • the transaction server 40 selects catalog information about the service provider of the partner and transmits it to the provider terminal 30. For example, in the above example, the transaction server 40 selects catalog information related to the business of the medical institution and transmits it to the data utilization business operator. The data utilization business operator browses the received catalog information and identifies the catalog information necessary for its own business.
  • the data utilization business operator refers to the catalog information presented by the trading business operator and identifies the necessary catalog information.
  • the business operator terminal 30 transmits a provision request including a data set name of the specified catalog information and a condition required for the provided data (hereinafter, referred to as a search condition) to the transaction server 40 (S11).
  • the search condition includes, for example, "3 or more current diseases”.
  • the transaction server 40 examines the acquired offer request. If no problem is found by the examination, the transaction server 40 transmits the acquired offer request and the account opener list to the distribution control server 10 (S12).
  • the distribution control server 10 identifies the personal identification code of the user listed in the account opener list and related to the requested catalog information.
  • the distribution control server 10 transmits an inquiry regarding data provision to the contact information (email address that the terminal 50 can receive) of the user corresponding to the specified personal identification code (S13).
  • the data provision inquiry includes the data provision request source (data utilization business operator), the data storage person (medical institution A), and the data type requested to be provided (current disease).
  • the terminal 50 that has received the data provision inquiry displays a GUI (Graphical User Interface) for acquiring the intention of each user regarding the data provision.
  • the terminal 50 uses the GUI to acquire the user's intention (agreement or disagreement with the data provision).
  • the terminal 50 transmits a response to an inquiry for data provision (agreeing to provide data or refusing to provide data) to the distribution control server 10 (S14).
  • the distribution control server 10 transmits a provision instruction to the data accumulator (medical institution A) regarding the user for whom consent has been obtained (S15). For example, as described above, when the provision of three or more current diseases is requested, the distribution control server 10 provides the medical A server 20-1 with respect to the three or more users who have agreed to provide the data. Send instructions.
  • the distribution control server 10 pays a consideration to the user who has agreed to provide the data.
  • the medical institution A (medical A server 20-1) that received the provision instruction refers to the storage database and transmits the data of the agreed user to the designated data provision destination (S16).
  • the medical institution A medical A server 20-1 that received the provision instruction refers to the storage database and transmits the data of the agreed user to the designated data provision destination (S16).
  • the disease names A1 to A3 are transmitted to the business terminal 30.
  • the first search condition is a condition that identifies the target person for data distribution regardless of the content of the data.
  • the first search condition is referred to as "normal search condition”
  • the search by the first search condition is referred to as "normal search”.
  • the second search condition is a condition for identifying the target person for data distribution in consideration of the content of the data.
  • the second search condition is referred to as "advanced search condition”
  • the search by the second search condition is referred to as "advanced search”.
  • the operation of "providing” explained with reference to FIG. 8 above is data distribution at the time of normal search.
  • the normal search is executed by the distribution control server 10.
  • the distribution control server 10 narrows down the target persons by using the location information database.
  • the distribution control server acquires the following search conditions (normal search conditions) and narrows down the target persons who match the conditions.
  • Normal search condition example (1) 5 or more current illnesses in the past year.
  • Example of normal search condition (2) 100 or more medications taken in the past year.
  • Example of normal search condition (3) 50 or more SPO2s for the past year.
  • the advanced search is a search that cannot be realized by the distribution control server 10 because it narrows down the target people by using the contents of the data.
  • a search company search server 31
  • search server 31 is used to realize "advanced search”.
  • An example of advanced search is as follows. In the advanced search, users who meet the following conditions are identified (narrowed down).
  • Advanced search example More than 50 data of users who have been diagnosed with pneumonia in the past year, took Cravit tablets for 14 days, and measured SPO2 (percutaneous arterial oxygen saturation).
  • ⁇ User registration for advanced search service Among the users registered as users in the information distribution system, the users who wish to be the target of the advanced search (users who want to obtain more consideration) use the advanced search service for the distribution control server 10. Register your wishes (see Figure 9). Specifically, the user operates the terminal 50 and inputs the user ID issued from the distribution control server 10. That is, the distribution control server 10 acquires the user ID of the person who wants to be the target of the advanced search.
  • the distribution control server 10 identifies a user who wants to use the user ID, and stores the specified user as an advanced search target in the user information database.
  • the service provider accumulates the data generated by providing the service to the user. At that time, the service server 20 transmits the location information including the user's personal identification code to the distribution control server 10.
  • the distribution control server 10 that has received the location information identifies the user corresponding to the acquired personal identification code, and determines whether or not the specified user is the target of the advanced search.
  • the distribution control server 10 If the user wishes to use the advanced search service, the distribution control server 10 notifies the service provider to that effect.
  • the distribution control server 10 transmits an "encrypted data transmission instruction" including the user ID of the applicant to the service server 20. More specifically, the distribution control server 10 transmits an encrypted data transmission instruction including the personal identification code, the user ID, and the data transmission destination of the applicant to the service server 20.
  • the service server 20 that received the instruction identifies the user based on the personal identification code.
  • the service provider encrypts the stored data and the user ID of the specified user, and transmits the encrypted data to the data transmission destination. More specifically, the service provider transmits the encrypted data to the search server 31.
  • the service server 20 identifies the data to be encrypted based on the personal identification code (stored data), and the encrypted data (encrypted stored data, user ID) relating to the target applicant for the advanced search. Is transmitted to the search server 31.
  • the search server 31 is a server (secret calculation server) that supports secret calculation.
  • the encrypted data is distributed and arranged on a plurality of secret calculation servers, and arbitrary calculation can be performed using the distributed data.
  • a secret sharing using three search servers 31 will be described as an example.
  • the following references can be referred to. [Reference: International Publication No. 2018/061391]
  • the current disease (disease name A1) of the user U1 is accumulated in the medical A server 20-1
  • the vital data (SPO2) of the same user U1 is accumulated in the medical B server 20-2.
  • the medical A server 20-1 secretly shares the user ID of the user U1 and the disease name A1, and transmits the secretly shared data to each of the three search servers 31.
  • the medical B server 20-2 secretly shares the user ID of the user U1 and the measured value of the SPO2, and transmits the secretly shared data to each of the three search servers 31.
  • Medical A server 20-1 and medical B server 20-2 each transmit their own business code together with encrypted data to each search server 31.
  • Each search server 31 acquires and stores secretly-distributed accumulated data related to the current disease and vital data.
  • Each search server 31 stores the user ID of the user and the acquired data (disease name, vital data, etc.) in association with each other in the ciphertext database.
  • the person in charge of the data utilization business operator operates the business operator terminal 30 and inputs a "provision request" to the transaction server 40.
  • the business operator terminal 30 transmits a provision request including the above search condition to the transaction server 40 (S21).
  • the business operator terminal 30 transmits a provision request including any of the above-mentioned normal search condition examples (1) to (3) to the transaction server 40.
  • the business operator terminal 30 transmits a provision request including the above-mentioned advanced search condition to the transaction server 40.
  • the transaction server 40 examines the offer request (S22). When the examination is completed, the transaction server 40 transmits the provision request including the search conditions and the account opener list to the distribution control server 10 (S23). In this way, when the transaction server 40 receives the provision request including the search condition from the data utilization business operator, the transaction server 40 examines the provision request and transmits the provision request that has passed the examination to the distribution control server 10.
  • the distribution control server 10 determines whether the search condition included in the request corresponds to the normal search condition or the advanced search condition (S24). Specifically, the distribution control server 10 determines that a search condition that can identify the target person only by the data type is a normal search condition. On the other hand, the distribution control server 10 determines that the search condition that the target person cannot be specified only by the data type and the target person cannot be specified without confirming the content of the data is the advanced search condition. In other words, the distribution control server 10 determines that the search condition is "advanced search" when the search condition is a search in which the search result cannot be obtained only by the data type and it is necessary to refer to the data content (data itself). .. For example, a search such as "male pneumonia patient” is determined to be “advanced search” because it requires specific information such as "male” and "pneumonia".
  • the distribution control server 10 transmits the search condition (advanced search condition) to each of the plurality of search servers 31 (S25).
  • Each search server 31 identifies a target person who matches the search conditions from the data that is secretly distributed and stored in advance.
  • the search server 31 transmits a list (target person list) including the specified user ID and business code to the distribution control server 10 (S26).
  • the user ID described in the target user list is a user ID of a user who matches the search conditions input to the transaction server 40 by the data utilization business operator.
  • the business operator code described in the target person list is the business operator code of the service business operator that stores necessary information.
  • the distribution control server 10 acquires the intention (agreement or disagreement for data distribution by provision) of each user corresponding to the user ID for data provision.
  • the distribution control server 10 instructs the service server 20 to provide the data of the user included in the target user list to the data utilization business operator. More specifically, the distribution control server 10 requests the corresponding service provider to "provide" the accumulated data regarding the user for whom consent has been obtained to the data utilization provider (sends the provision instruction). .. The service provider transmits data to the data utilization provider according to the instruction from the distribution control server 10.
  • each user registers in advance the desire to use the advanced search service.
  • the service provider transmits the accumulated data to the search server 31.
  • the search server 31 identifies the target person and notifies the distribution control server 10. At that time, the search server 31 identifies the target person by using a secret calculation from the viewpoint of protecting the privacy of the target person.
  • FIG. 12 is a diagram showing an example of a processing configuration (processing module) of the distribution control server 10 according to the first embodiment.
  • the distribution control server 10 includes a communication control unit 201, a user registration unit 202, a personal identification code management unit 203, a location information management unit 204, a data distribution control unit 205, and a catalog information management.
  • a unit 206 and a storage unit 207 are provided.
  • the communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the service server 20. Further, the communication control unit 201 transmits data to the service server 20. The communication control unit 201 delivers the data received from the other device to the other processing module. The communication control unit 201 transmits the data acquired from the other processing module to the other device. In this way, the other processing module transmits / receives data to / from the other device via the communication control unit 201.
  • the user registration unit 202 is a means for realizing the above-mentioned user registration (user system registration).
  • the user registration unit 202 acquires personal information (name, contact information, account information, etc.) from the user's terminal 50.
  • the user registration unit 202 When the user registration unit 202 acquires the personal information, it generates a user ID for identifying the user. For example, the user registration unit 202 assigns a unique value to each user's system registration and uses it as a user ID.
  • the user registration unit 202 stores the user ID and personal information in the user information database (see FIGS. 13A and 13B). For example, when the user is registered for the user U1, the entry shown at the bottom of FIG. 13A is added.
  • the user registration unit 202 transmits the generated user ID to the terminal 50.
  • the user registration unit 202 registers users who use the advanced search service.
  • the user registration unit 202 acquires the user ID of the user together with the fact that the advanced search service is used
  • the user registration unit 202 sets the user corresponding to the acquired user ID as the advanced search target person.
  • the user registration unit 202 sets "target person" in the advanced search field of the specified user.
  • the personal identification code management unit 203 is a means for managing the "personal identification code" transmitted and received between the distribution control server 10 and the service server 20.
  • the personal identification code management unit 203 transmits information (for example, a name) that identifies a user whose user registration has been completed to each service provider (service server 20) at regular or predetermined timings.
  • the personal identification code management unit 203 receives user information from the service server 20 in response to the transmission of the name. As described above, the user information includes a personal identification code and a business operator code. The personal identification code management unit 203 stores the acquired personal identification code in the corresponding business operator code field of the user information database.
  • the medical A server 20-1 sends the user information to the distribution control server 10 as a response to the presented name. Send.
  • the personal identification code management unit 203 extracts the personal identification code of the user U1 and the business code of the medical institution A from the user information, and stores the personal identification code in the user information database.
  • "IDA1" is set as the personal identification code of the user U1 in the medical A field (field of the medical institution A) in the final entry of the user information database shown in FIG. 13B.
  • the personal identification code management unit 203 stores the user ID of the user and the personal identification code generated by each service provider (service server 20) in association with each other. Since the personal identification code generated differs depending on the service provider, the user information database stores the personal identification code for each service provider.
  • the location information management unit 204 is a means for managing the location information acquired from the service provider.
  • the location information management unit 204 stores the location information acquired from each service server 20 in the location information database (see FIG. 14). As shown in FIG. 14, the location information database stores the personal identification code, the business operator code, and the data type in association with each other.
  • the location information management unit 204 searches the user information database using the personal identification code and the business operator code acquired from the service server 20 as keys. The location information management unit 204 confirms the advanced search field of the specified entry, and determines whether or not "target person" is described in the field.
  • the location information management unit 204 transmits an encrypted data transmission instruction including the user's personal identification code, user ID, and data transmission destination to the service server 20.
  • the location information management unit 204 specifies the entry in the second line from the bottom of FIG. 13B. Since "target person” is set in the advanced search field of the entry, the location information management unit 204 includes the personal identification code "IDA2" and the user ID "ID02" for the medical A server 20-1. Send the encrypted data transmission instruction.
  • the data transmission destination included in the instruction is the address of each of the three search servers 31.
  • the data distribution control unit 205 is a means for controlling data distribution by "providing".
  • the data distribution control unit 205 receives the provision request and the account opener list from the transaction server 40.
  • the data distribution control unit 205 identifies the catalog information requested to be provided from the dataset name included in the provision request.
  • the data distribution control unit 205 determines whether the search condition included in the provision request is "normal search condition" or "advanced search condition". Specifically, when the parameter included in the search condition matches the data type of the specified catalog information, the data distribution control unit 205 determines that the search is normal. That is, a search in which the personal identification code can be specified only by the data type is determined to be a "normal search". For example, in the above-mentioned normal search condition example (1), if the parameter "current disease" included in the search condition is included in the data type of the specified catalog information, the search condition is determined to be "normal search condition".
  • the data distribution control unit 205 determines that the advanced search conditions are met. For example, a search condition such as "male pneumonia patient" is determined to be an advanced search condition.
  • the distribution control server 10 only grasps what kind of data the service server 20 stores, and does not grasp the specific contents of the data. Therefore, the distribution control server 10 cannot know whether the disease name of the user corresponding to the personal identification code described in the location information is "pneumonia" or another disease. A search that requires the contents of such accumulated data is determined to be an "advanced search".
  • the data distribution control unit 205 refers to the location information database and identifies the data type included in the specified catalog information and the personal identification code corresponding to the business operator code.
  • the personal identification codes “IDA1” to “IDA3” corresponding to the users U1 to U3 are specified.
  • the data distribution control unit 205 refers to the user information database and determines whether or not the above-specified personal identification code is listed in the account opener list.
  • the data distribution control unit 205 refers to the user information database and acquires the contact information of each user who is a user corresponding to the above-specified personal identification code and is listed in the account opener list.
  • the data distribution control unit 205 transmits an inquiry regarding data provision to the acquired contact information. In the above example, if each of the users U1 to U3 has opened an information account with the transaction business operator, an inquiry for data provision is transmitted to the terminal 50 possessed by each user.
  • the data provision inquiry includes the data provision request source, the data accumulator, and the data type requested to be provided.
  • an inquiry including a data utilization business operator as a data provision request source, a medical institution A as a data storage person, and a current disease as a data type requested to be provided is transmitted to each terminal 50.
  • the data distribution control unit 205 sends a provision instruction to the data accumulator regarding the user for whom consent has been obtained.
  • the provision instruction includes the personal identification code of the user who has consented to the data provision, the information regarding the data provision destination (address of the business terminal 30), and the data type of the data to be provided.
  • the data distribution control unit 205 pays a predetermined amount to the user who has agreed to provide the data.
  • the data distribution control unit 205 makes the payment by referring to the account information of each user.
  • the data distribution control unit 205 transmits the search condition (advanced search condition) to each of the plurality of search servers 31.
  • the data distribution control unit 205 receives the target person list from the search server 31 in response to the transmission of the search conditions.
  • the target user list includes a user ID and a business code of a user who matches the advanced search conditions.
  • the data distribution control unit 205 determines whether or not the user ID included in the target person list is listed in the account opener list.
  • the data distribution control unit 205 acquires the contact information of each user included in the target user list and listed in the account opener list. The data distribution control unit 205 transmits an inquiry regarding data provision to the acquired contact information.
  • the data distribution control unit 205 sends a provision instruction to the data accumulator regarding the user for whom consent has been obtained.
  • the provision instruction includes the personal identification code of the user who has agreed to provide the data, and the information regarding the data provision destination (address of the business terminal 30).
  • the target user list acquired from the search server 31 includes the user IDs of users U1 to U3, the business code of medical institution A, and the business code of medical institution B.
  • the data distribution control unit 205 will refer to the medical A server 20-1 with the personal identification code of the users U1 to U3.
  • a provision instruction including "IDA1” to "IDA3” is transmitted.
  • the data distribution control unit 205 transmits a provision instruction including the personal identification codes “IDB1” to “IDB3” of the users U1 to U3 to the medical B server 20-2.
  • the data distribution control unit 205 also pays the target person for the advanced search for the data provision.
  • the catalog information management unit 206 is a means for managing catalog information.
  • the catalog information management unit 206 stores the catalog information created by the system administrator in the storage unit 207.
  • the catalog information management unit 206 receives the "catalog information transmission request" from the transaction server 40. In response to the reception of the request, the catalog information management unit 206 transmits the catalog information stored in the storage unit 207 to the transaction server 40.
  • the storage unit 207 stores information necessary for the operation of the distribution control server 10.
  • FIG. 15 is a diagram showing an example of a processing configuration (processing module) of the service server 20 according to the first embodiment.
  • the service server 20 includes a communication control unit 301, a personal identification code generation unit 302, a data storage unit 303, a secret sharing unit 304, a data distribution unit 305, and a storage unit 306. ..
  • the communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the distribution control server 10. Further, the communication control unit 301 transmits data to the distribution control server 10. The communication control unit 301 delivers the data received from the other device to the other processing module. The communication control unit 301 transmits the data acquired from the other processing module to the other device. In this way, the other processing module transmits / receives data to / from the other device via the communication control unit 301.
  • the personal identification code generation unit 302 is a means for generating a personal identification code. When providing a service to a new customer, the personal identification code generation unit 302 generates the personal identification code of the customer.
  • the personal identification code generation unit 302 transmits the corresponding user information in response to receiving the user's name from the distribution control server 10.
  • the user information includes a personal identification code and a business operator code.
  • the data storage unit 303 is a means for storing data generated as a result of providing a service to a user.
  • the data storage unit 303 stores the personal identification code of the user and the data generated as a result of providing the service to the user in the storage database in association with each other (see FIG. 16).
  • the data storage unit 303 stores the information of the generated data in the fields corresponding to the types of the generated data.
  • FIG. 16 shows an example of the storage database constructed on the medical A server 20-1.
  • the data storage unit 303 transmits the location information to the distribution control server 10 each time the data is stored in the storage database. For example, in the example of FIG. 16, a service is provided to the user U1 of the personal identification code "IDA1", and when the disease name is found, the personal identification code "IDA1", the business code "medical A”, and the data type "current disease” are obtained. The location information including the above is transmitted to the distribution control server 10.
  • the secret sharing unit 304 is a means for secretly sharing the stored data by transmitting the encrypted data of the stored data to the search server 31.
  • the secret sharing unit 304 receives an encrypted data transmission instruction from the distribution control server 10.
  • the secret sharing unit 304 searches the storage database using the personal identification code included in the instruction as a key, and identifies the corresponding user.
  • the secret sharing unit 304 generates information for secret sharing the data of the specified user and the user ID included in the encrypted data transmission instruction, and transmits the information to each search server 31.
  • the secret sharing unit 304 when the encrypted data transmission instruction including the personal identification code "IDA2" is received, the secret sharing unit 304 describes the accumulated data "pneumonia” and “Clavit lock” described in the entry on the second line from the top. And the ciphertext of the user ID "ID02" of the user U2 is transmitted.
  • the data distribution unit 305 is a means for realizing data distribution by "providing”.
  • the data distribution unit 305 processes the "providing instruction" received from the distribution control server 10.
  • the data distribution unit 305 refers to the storage database and identifies the personal identification code included in the provision instruction and the entry corresponding to the data type. For example, when a provision instruction including the personal identification code "IDA1" and the data type "current disease” is received, the data distribution unit 305 identifies the entry shown at the top of FIG.
  • the data distribution unit 305 transmits the accumulated data described in the corresponding data type field of the specified entry to the data providing destination specified in the providing instruction.
  • the current disease "pneumonia" is transmitted to the data utilization business operator.
  • the data distribution unit 305 transmits each accumulated data of the entry specified by the personal identification code to the data provision destination.
  • the storage unit 306 stores information necessary for the operation of the service server 20.
  • the business terminal 30 may present information to the user (staff of the data utilization business, etc.) and accept operations from the user. Specifically, the business terminal 30 displays a list of catalog information acquired from the transaction server 40, and sends a request for provision including the data set name and search conditions of the catalog information selected by the user to the transaction server 40. Just send it.
  • FIG. 17 is a diagram showing an example of a processing configuration (processing module) of the search server 31 according to the first embodiment.
  • the search server 31 includes a communication control unit 401, an encrypted data acquisition unit 402, a target person list generation unit 403, and a storage unit 404.
  • the communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the distribution control server 10. Further, the communication control unit 401 transmits data to the distribution control server 10. The communication control unit 401 delivers the data received from the other device to the other processing module. The communication control unit 401 transmits the data acquired from the other processing module to the other device. In this way, the other processing module transmits / receives data to / from the other device via the communication control unit 401.
  • the encrypted data acquisition unit 402 is a means for acquiring the encrypted data received from the service server 20.
  • the encrypted data acquisition unit 402 stores the data (encrypted stored data) included in the acquired encrypted data separately for each user ID and business code.
  • the encrypted data acquisition unit 402 stores the encrypted stored data in the ciphertext database (see FIG. 18).
  • FIG. 18 shows information (user ID, stored data) in a state in which the code has been decrypted for easy understanding.
  • each search server 31 since the data stored in each search server 31 is secretly shared, each search server 31 does not hold the information as shown in FIG. When the information held by the three search servers 31 is integrated, the information shown in FIG. 18 can be obtained.
  • the target user list generation unit 403 is a means for executing a secret calculation and generating a list of users matching the search conditions acquired from the distribution control server 10. For example, consider the case where an advanced search condition such as "a user who takes Cravit tablets in a patient with pneumonia and whose SPO2 is measured" is acquired.
  • the target user list generation unit 403 uses the ciphertext database shown in FIG. 18 to determine that the user in the first line is a user who matches the above advanced search conditions.
  • the user in the second line is out of scope because SOP2 is not measured, and the user in the fourth line is out of scope because he is not taking Cravit tablets.
  • the target user list generation unit 403 generates a target user list including the user ID of the user specified by using the ciphertext database and the business operator code of the service provider that stores the data required by the advanced search conditions. Then, it is transmitted to the distribution control server 10. In the above example, the target person list including the user ID "ID01", the business code "medical A” and “medical B" is transmitted to the distribution control server 10.
  • the storage unit 404 stores information necessary for the operation of the service server 20.
  • FIG. 19 is a diagram showing an example of a processing configuration (processing module) of the transaction server 40 according to the first embodiment.
  • the transaction server 40 includes a communication control unit 501, an account opening unit 502, a catalog information request unit 503, a provision request processing unit 504, and a storage unit 505.
  • the communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the distribution control server 10. Further, the communication control unit 501 transmits data to the distribution control server 10. The communication control unit 501 delivers the data received from the other device to the other processing module. The communication control unit 501 transmits the data acquired from the other processing module to the other device. In this way, the other processing module transmits / receives data to / from the other device via the communication control unit 501.
  • the account opening unit 502 is a means for opening an account of a user who wishes to distribute data by providing the data.
  • the account opening unit 502 acquires the user ID from the user's terminal 50.
  • the account opening unit 502 adds the acquired user ID to the account opening person list (see FIG. 20).
  • the catalog information request unit 503 is a means for transmitting a "catalog information transmission request" to the distribution control server 10.
  • the catalog information request unit 503 When the catalog information request unit 503 receives the "catalog information presentation request" from the business terminal 30, it transmits the "catalog information transmission request" to the distribution control server 10.
  • the catalog information request unit 503 acquires the catalog information stored in the distribution control server 10.
  • the catalog information requesting unit 503 selects the catalog information related to the service provider with which the own device is affiliated, and transmits it to the data utilization provider (business terminal 30).
  • the catalog information requesting unit 503 selects catalog information about the service provider of the partner based on the business code of the service provider of the partner and the business code included in the catalog information.
  • the provision request processing unit 504 is a means for processing the provision request received from the business terminal 30.
  • the offer request processing unit 504 examines the offer request. Specifically, the provision request processing unit 504 examines the consistency between the data usage purpose of the data utilization business operator and the usage purpose of the target data type. For example, if the content is "Purpose of use: Drug development, Data type: Current illness, Medication", the examination will pass. In other words, the data utilization business operator (business terminal 30) also inputs the above-mentioned purpose of use and data type into the transaction server 40 when requesting data provision.
  • the provision request processing unit 504 transmits the account opener list to the distribution control server 10 together with the provision request acquired from the business terminal 30.
  • the storage unit 505 stores information necessary for the operation of the transaction server 40.
  • the storage unit 405 stores the operator code of the service provider of the partner.
  • FIG. 21 is a diagram showing an example of a processing configuration (processing module) of the terminal 50 according to the first embodiment.
  • the terminal 50 includes a communication control unit 601, a personal information input unit 602, an inquiry processing unit 603, an account information input unit 604, and a storage unit 605.
  • the communication control unit 601 is a means for controlling communication with other devices. For example, the communication control unit 601 receives data (packets) from the distribution control server 10. Further, the communication control unit 601 transmits data to the distribution control server 10. The communication control unit 601 delivers the data received from the other device to the other processing module. The communication control unit 601 transmits the data acquired from the other processing module to the other device. In this way, the other processing module transmits / receives data to / from the other device via the communication control unit 601.
  • the personal information input unit 602 is a means for inputting personal information to the distribution control server 10 at the time of user registration.
  • the personal information input unit 602 inputs personal information (name, contact information, account information, etc.) to the distribution control server 10 by any means.
  • the personal information input unit 602 acquires the personal information using the GUI and transmits it to the distribution control server 10.
  • the personal information input unit 602 stores the user ID issued from the distribution control server 10 in the storage unit 605.
  • the personal information input unit 602 also performs processing related to the use of the advanced search service of the user.
  • the personal information input unit 602 may desire or acquire the user to use the advanced search service on the menu screen of the user registration or the menu screen different from the user registration.
  • the personal information input unit 602 notifies the distribution control server 10 of the desire to use the advanced search service together with the user ID of the user.
  • the inquiry processing unit 603 is a means for processing an inquiry received from the distribution control server 10 at the time of data distribution by provision.
  • the inquiry processing unit 603 acquires the user's intention (agreement or disagreement with data transmission) by using a GUI that matches the content of the inquiry (providing data).
  • the inquiry processing unit 603 transmits a response including the intention of the user to the distribution control server 10.
  • the account information input unit 604 is a means for inputting information for opening an information account required for data distribution by provision into the transaction server 40.
  • the account information input unit 604 transmits the user ID of the user to the transaction server 40.
  • the storage unit 605 stores information necessary for the operation of the terminal 50.
  • FIG. 22 is a sequence diagram showing an example of the operation of the information distribution system according to the first embodiment. A case where a data utilization business operator requests data provision by advanced search will be described with reference to FIG. 22.
  • the transaction server 40 receives a provision request including advanced search conditions from the business terminal 30 (step S101).
  • the transaction server 40 examines the offer request (step S102).
  • step S103 If the examination does not pass (step S103, No branch), the transaction server 40 transmits to the business operator terminal 30 that data cannot be provided (step S104). The transaction server 40 transmits a negative response to the business terminal 30.
  • step S103 If the examination is passed (step S103, Yes branch), the transaction server 40 transmits the provision request and the account opener list to the distribution control server 10 (step S105).
  • the distribution control server 10 determines the search conditions included in the provision request (step S106).
  • step S107 If the search condition is a normal search condition (step S107, No branch), the distribution control server 10 executes the normal search process. A detailed description of the processing flow will be omitted.
  • the distribution control server 10 transmits the advanced search condition to the search server 31 (step S108).
  • Each search server 31 identifies a user (user ID) that corresponds to (matches) the advanced search conditions by secret calculation (step S109).
  • the search server 31 (one of the three search servers 31) transmits a target person list including the specified user ID to the distribution control server 10 (step S110).
  • the distribution control server 10 makes an inquiry regarding data provision to the users listed in the account opener list and the target person list (step S111).
  • the distribution control server 10 instructs the service server 20 to provide the data of the user who has agreed to provide the data.
  • the distribution control server 10 transmits the provision instruction to the service server 20 (step S112).
  • the service server 20 Upon receiving the instruction, the service server 20 transmits the stored data to the data utilization business operator.
  • the distribution control server 10 causes the service server 20 to provide the data of the user corresponding to the user ID described in the account opener list and the target person list to the data utilization business operator. Instruct.
  • the distribution control server 10 instructs the data provision when the user corresponding to the user ID described in the top two lists agrees to the data provision.
  • the data utilization business operator makes a request for providing information including search conditions (a request that may require a search using the data contents) to the business operator. ..
  • the transaction server 40 managed by the transaction company transmits the request to the distribution control server 10.
  • the distribution control server 10 determines whether or not advanced search is necessary based on the search conditions included in the provision request. It should be noted that the advanced search is a search in which a result cannot be obtained only by the data type and it is necessary to refer to the data content (a search in which the data itself is required).
  • the distribution control server 10 transmits the search conditions to the search server 31 and instructs the service server 20 to transmit the stored data to the search server 31.
  • the service server 20 transmits the stored data to the search server 31.
  • the search server 31 transmits a list of users satisfying the received search conditions to the distribution control server 10.
  • the distribution control server 10 requests the service server 20 to provide the data utilization business operator with the data corresponding to the users of the acquired list.
  • the search server 31 is a server capable of performing arbitrary operations while the data is encrypted. Therefore, the search server 31 itself does not know the content of the data used for the calculation and the process thereof, and outputs a list of users who match the advanced search conditions. As a result, the user who meets the conditions desired by the data utilization business operator is identified while the privacy of the user is protected.
  • the personal information of the user (especially the user who does not meet the advanced search conditions) is known to a third party (information distribution business operator, service business operator, transaction business operator, search business operator) other than the user.
  • a third party information distribution business operator, service business operator, transaction business operator, search business operator
  • users who match the search conditions are identified.
  • the data utilization business operator can obtain information useful for his / her business (search result of advanced search).
  • FIG. 23 is a diagram showing an example of the hardware configuration of the search server 31.
  • the search server 31 can be configured by an information processing device (so-called computer), and includes the configuration illustrated in FIG. 23.
  • the search server 31 includes a processor 311, a memory 312, an input / output interface 313, a communication interface 314, and the like.
  • the components such as the processor 311 are connected by an internal bus or the like so that they can communicate with each other.
  • the search server 31 may include hardware (not shown) or may not include an input / output interface 313 if necessary. Further, the number of processors 311 and the like included in the search server 31 is not limited to the example shown in FIG. 23, and for example, a plurality of processors 311 may be included in the search server 31.
  • the processor 311 is a programmable device such as a CPU (Central Processing Unit), an MPU (Micro Processing Unit), and a DSP (Digital Signal Processor). Alternatively, the processor 311 may be a device such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit). The processor 311 executes various programs including an operating system (OS).
  • OS operating system
  • the memory 312 is a RAM (RandomAccessMemory), a ROM (ReadOnlyMemory), an HDD (HardDiskDrive), an SSD (SolidStateDrive), or the like.
  • the memory 312 stores an OS program, an application program, and various data.
  • the input / output interface 313 is an interface of a display device or an input device (not shown).
  • the display device is, for example, a liquid crystal display or the like.
  • the input device is, for example, a device that accepts user operations such as a keyboard and a mouse.
  • the communication interface 314 is a circuit, module, etc. that communicates with other devices.
  • the communication interface 314 includes a NIC (Network Interface Card) and the like.
  • the function of the search server 31 is realized by various processing modules.
  • the processing module is realized, for example, by the processor 311 executing a program stored in the memory 312.
  • the program can also be recorded on a computer-readable storage medium.
  • the storage medium may be a non-transient such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product.
  • the program can be downloaded via a network or updated using a storage medium in which the program is stored.
  • the processing module may be realized by a semiconductor chip.
  • the distribution control server 10, the service server 20, the business terminal 30, the transaction server 40, the terminal 50, etc. can also be configured by the information processing device in the same manner as the search server 31, and the basic hardware configuration thereof is the search server 31. Since there is no difference from the above, the description is omitted.
  • the search server 31 is equipped with a computer, and the function of the search server 31 can be realized by causing the computer to execute a program. Further, the search server 31 executes the control method of the search server by the program.
  • the distribution control server 10 includes a user information database and the like has been described.
  • these databases may be built on a database server different from the distribution control server 10.
  • the information distribution system may include various means (for example, data distribution control unit 205, etc.) described in the above embodiment.
  • the distribution control server 10 is notified of the personal identification code of the user who uses the service provider for the first time.
  • the user's name is transmitted from the distribution control server 10 to the service provider, and the personal identification code is notified to the distribution control server 10 in a format corresponding to the transmission of the name.
  • the user ID of the user may be used.
  • the user presents the user ID to the service provider who uses it for the first time.
  • the service provider (service server 20) transmits the user information including the user's personal identification code, the operator code, and the presented user ID to the distribution control server 10.
  • the distribution control server 10 may identify the user for whom the personal identification code has been generated based on the user ID included in the user information.
  • the method of secret calculation is not limited to secret sharing and may be another method.
  • a "homomorphic encryption" that can be operated as a ciphertext may be used.
  • a search server 31 having a high security level may be prepared, and the data encrypted inside the search server 31 with enhanced security may be decrypted and the calculation may be performed.
  • the determination may be made using a learning model obtained by machine learning or the like.
  • a learning model (discriminator) may be generated by performing machine learning using teacher data in which labels (advanced search conditions, normal search conditions) are added to search conditions.
  • the distribution control server 10 may input the acquired search conditions into the learning model and acquire the determination results (advanced search conditions, normal search conditions).
  • Any algorithm such as a support vector machine, boosting, or neural network can be used to generate the learning model. Since a known technique can be used for the algorithm such as the support vector machine, the description thereof will be omitted.
  • the search server 31 transmits a target person list including the user ID of the user and the business operator code of the service provider to the distribution control server 10.
  • the search server 31 may transmit the target person list including the data type to the distribution control server 10 in addition to the user ID and the business operator code.
  • a target person list including data types such as "current disease”, "medication", and "SOPS" may be transmitted to the distribution control server 10.
  • the distribution control server 10 may notify the service server 20 of the data type, and the service server 20 may transmit the accumulated data corresponding to the notified data type to the data utilization business operator.
  • each device distributed control server 10, service server 20, business operator terminal 30, transaction server 40, terminal 50
  • the form of data transmission / reception between these devices is not particularly limited, but the data transmitted / received between these devices is encrypted. May be good.
  • each embodiment may be used alone or in combination. For example, it is possible to replace a part of the configuration of the embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of the embodiment. Further, it is possible to add, delete, or replace a part of the configuration of the embodiment with another configuration.
  • the present invention is suitably applicable to an information distribution system or the like in which the data accumulated by the service provider is the target of distribution.
  • [Appendix 1] A service server that stores data generated by a service provider providing services to users, A transaction server that controls the sale of the data stored in the service server to the data utilization business operator. A distribution control server that controls the provision of data from the service provider to the data utilization provider, A search server that stores data stored in the service provider and data in which the user ID of the user is encrypted. Including The transaction server receives a provision request including a search condition from the data utilization business operator, and transmits the received provision request to the distribution control server.
  • the distribution control server determines whether or not the search condition is an advanced search, which is a search in which a result cannot be obtained only by the data type and it is necessary to refer to the data content, and when the search condition is the advanced search.
  • the search server identifies a user who matches the search condition, transmits a target person list including a user ID of the specified user to the distribution control server, and then sends the user ID to the distribution control server.
  • the distribution control server is a system that instructs the service server to provide data of users included in the target person list to the data utilization business operator.
  • [Appendix 3] The system according to Appendix 2, wherein the search server generates the target person list by secret calculation.
  • Appendix 4 The system according to any one of Supplementary note 1 to 3, wherein the transaction server examines the received provision request and transmits the provision request that has passed the examination to the distribution control server.
  • the transaction server stores the account opener list including the user ID of the user who opened the account for providing the data, and transmits the provision request and the account opener list to the distribution control server.
  • [Appendix 6] The distribution control server instructs the data utilization business operator to provide the data of the user corresponding to the user ID described in the account opener list and the target person list, according to Appendix 5. System.
  • the distribution control server obtains the data of the user who consents to the data provision.
  • the distribution control server acquires the user ID of the applicant who wishes to be the target of the advanced search, and transmits an encrypted data transmission instruction including the user ID of the applicant to the service server.
  • the service server generates a personal identification code of the user, stores the generated personal identification code in association with the data, and transmits the generated personal identification code to the distribution control server.
  • the system according to Appendix 8 wherein the distribution control server stores the user ID and the personal identification code in association with each other.
  • the distribution control server transmits the encrypted data transmission instruction including the user ID of the applicant and the personal identification code to the service server.
  • An encrypted data acquisition unit that acquires data stored in the service provider and data in which the user ID of the user is encrypted, and Receives an advanced search from the distribution control server, which is a search that requires reference to the data content because the search condition included in the provision request cannot be obtained only by the data type, and identifies the user who matches the search condition.
  • a target person list generation unit that generates a target person list including the user ID of the specified user and transmits the generated target person list to the distribution control server.
  • Search server including.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Physics & Mathematics (AREA)
  • Tourism & Hospitality (AREA)
  • General Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Primary Health Care (AREA)
  • Strategic Management (AREA)
  • Marketing (AREA)
  • General Business, Economics & Management (AREA)
  • Human Resources & Organizations (AREA)
  • Economics (AREA)
  • Health & Medical Sciences (AREA)
  • Computational Linguistics (AREA)
  • Data Mining & Analysis (AREA)
  • Databases & Information Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Information Retrieval, Db Structures And Fs Structures Therefor (AREA)

Abstract

Afin de fournir un système qui permet de distribuer des informations de valeur élevée à un fournisseur d'utilisation de données tout en maintenant la confidentialité individuelle, ce serveur de recherche stocke des données stockées par un fournisseur de services, et des données dans lesquelles les ID d'utilisateur des utilisateurs sont cryptés. Un serveur de transaction transmet des demandes de fourniture comprenant des conditions de recherche à un serveur de commande de distribution. Le serveur de commande de distribution détermine si une condition de recherche est une recherche à haut niveau, qui est une recherche dans laquelle un résultat ne peut pas être obtenu sur la base uniquement du type de données, mais nécessite un examen du contenu de données, et transmet la condition de recherche au serveur de recherche lorsque la condition de recherche est une recherche à haut niveau. Le serveur de recherche spécifie des utilisateurs correspondant à la condition de recherche et transmet une liste cible comprenant les ID d'utilisateur des utilisateurs spécifiés au serveur de commande de distribution. Le serveur de commande de distribution ordonne au serveur de service de fournir les données pour les utilisateurs inclus dans la liste cible au fournisseur d'utilisation de données.
PCT/JP2021/047881 2021-01-18 2021-12-23 Système, serveur de recherche, procédé permettant de commander un serveur de recherche, et support d'enregistrement WO2022153826A1 (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
JP2022575502A JPWO2022153826A5 (ja) 2021-12-23 システム、検索サーバ、検索サーバの制御方法及びコンピュータプログラム

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2021005438 2021-01-18
JP2021-005438 2021-01-18

Publications (1)

Publication Number Publication Date
WO2022153826A1 true WO2022153826A1 (fr) 2022-07-21

Family

ID=82447773

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2021/047881 WO2022153826A1 (fr) 2021-01-18 2021-12-23 Système, serveur de recherche, procédé permettant de commander un serveur de recherche, et support d'enregistrement

Country Status (1)

Country Link
WO (1) WO2022153826A1 (fr)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH1032598A (ja) * 1996-07-17 1998-02-03 Toshiba Corp 電子掲示板システム
JP2002024225A (ja) * 2000-07-11 2002-01-25 Komatsu Ltd 情報提供システム、および情報提供方法、ならびに情報提供方法を実行させるコンピュータプログラムを記憶した記憶媒体
JP2003288468A (ja) * 2002-03-28 2003-10-10 Hitachi Ltd P2p個人売買方法及びシステム
JP2004078515A (ja) * 2002-08-16 2004-03-11 Mitsui Sumitomo Insurance Co Ltd 個人情報管理サーバ及びプログラム
JP2005044292A (ja) * 2003-07-25 2005-02-17 Sony Corp 情報処理システム、情報処理装置および方法、記録媒体、並びにプログラム

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH1032598A (ja) * 1996-07-17 1998-02-03 Toshiba Corp 電子掲示板システム
JP2002024225A (ja) * 2000-07-11 2002-01-25 Komatsu Ltd 情報提供システム、および情報提供方法、ならびに情報提供方法を実行させるコンピュータプログラムを記憶した記憶媒体
JP2003288468A (ja) * 2002-03-28 2003-10-10 Hitachi Ltd P2p個人売買方法及びシステム
JP2004078515A (ja) * 2002-08-16 2004-03-11 Mitsui Sumitomo Insurance Co Ltd 個人情報管理サーバ及びプログラム
JP2005044292A (ja) * 2003-07-25 2005-02-17 Sony Corp 情報処理システム、情報処理装置および方法、記録媒体、並びにプログラム

Also Published As

Publication number Publication date
JPWO2022153826A1 (fr) 2022-07-21

Similar Documents

Publication Publication Date Title
Chen et al. Blockchain-based medical records secure storage and medical service framework
Panda et al. Drug traceability and transparency in medical supply chain using blockchain for easing the process and creating trust between stakeholders and consumers
Firouzi et al. AI-driven data monetization: The other face of data in IoT-based smart and connected health
US8661453B2 (en) Managing healthcare information in a distributed system
CN108959945A (zh) 医疗数据共享方法、装置、计算机可读介质及电子设备
Gan et al. Blockchain-based access control scheme with incentive mechanism for eHealth systems: patient as supervisor
Colliers et al. Improving Care And Research Electronic Data Trust Antwerp (iCAREdata): a research database of linked data on out-of-hours primary care
US20220414599A1 (en) Remotely diagnosing conditions and providing prescriptions using a multi-access health care provider portal
Singh et al. A conceptual model for Indian public distribution system using consortium blockchain with on-chain and off-chain trusted data
US20210280306A1 (en) Methods for managing health care information
WO2020126558A1 (fr) Procédé et système de partage sécurisé de données
Carlini et al. The Genesy model for a blockchain-based fair ecosystem of genomic data
US20130110540A1 (en) Method of Collecting Patient Information in an Electronic System
KR20220068024A (ko) 인공지능 및 개인건강기록을 이용한 보험정보 제공 시스템 및 그 방법
AU2020101898A4 (en) MHOC- Blockchain Technology: Medicine and Healthcare Observation Care using Blockchain Technology
CN104521209B (zh) 用于提供定制网络的方法和系统
WO2022153826A1 (fr) Système, serveur de recherche, procédé permettant de commander un serveur de recherche, et support d'enregistrement
Chute et al. The Southeastern Minnesota Beacon Project for community-driven health information technology: origins, achievements, and legacy
JP2001357131A (ja) 通信ネットワークを介して漢方薬の処方を提供する方法
WO2022153885A1 (fr) Système, serveur de commande de distribution, procédé de distribution de données et support d'enregistrement
Blohel Onconet: A secure infrastructure to improve cancer patients' care
WO2023188135A1 (fr) Système, serveur de commande de distribution, procédé de commande pour serveur de commande de distribution et support d'enregistrement
WO2023188136A1 (fr) Système, serveur de commande de distribution, procédé de commande de serveur de commande de distribution et support de stockage
WO2024009336A1 (fr) Système et procédé
WO2023242933A1 (fr) Système et procédé

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21919713

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2022575502

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21919713

Country of ref document: EP

Kind code of ref document: A1