WO2022249258A1 - 評価方法、評価プログラム、および情報処理装置 - Google Patents
評価方法、評価プログラム、および情報処理装置 Download PDFInfo
- Publication number
- WO2022249258A1 WO2022249258A1 PCT/JP2021/019686 JP2021019686W WO2022249258A1 WO 2022249258 A1 WO2022249258 A1 WO 2022249258A1 JP 2021019686 W JP2021019686 W JP 2021019686W WO 2022249258 A1 WO2022249258 A1 WO 2022249258A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- data
- information
- item group
- trust
- items
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
Definitions
- the present invention relates to an evaluation method, an evaluation program, and an information processing device.
- the present invention aims to facilitate prevention of information leakage.
- first data including presence/absence information indicating presence/absence of data corresponding to each of the plurality of items included in the first item group
- each of the plurality of items included in the second item group a plurality of second data each including necessity information indicating whether or not data corresponding to the
- the total number of necessary/unnecessary information indicating that the data corresponding to the item is requested is calculated, and each of the plurality of items included in the second item group is calculated.
- FIG. 1 is an explanatory diagram of an example of an evaluation method according to an embodiment.
- FIG. 2 is an explanatory diagram showing an example of the matching system 200.
- FIG. 3 is an explanatory diagram showing a usage example of the matching system 200.
- FIG. 4 is a block diagram showing a hardware configuration example of the information processing apparatus 100.
- FIG. 5 is an explanatory diagram showing an example of a trust vector 500.
- FIG. 6 is an explanatory diagram showing an example of trust requirements 600.
- FIG. FIG. 7 is an explanatory diagram showing an example of trust vector statistical data 700.
- FIG. 8 is an explanatory diagram showing an example of trust requirement statistical data 800.
- FIG. 9 is an explanatory diagram showing an example of the contents of the statistic table 900.
- FIG. 10 is an explanatory diagram showing an example of the contents of the anonymization table 1000.
- FIG. 11 is a block diagram showing a functional configuration example of the information processing apparatus 100.
- FIG. 12 is an explanatory diagram (Part 1) showing a first operation example of the information processing apparatus 100 .
- FIG. 13 is an explanatory diagram (Part 2) showing the first operation example of the information processing apparatus 100 .
- FIG. 14 is an explanatory diagram (part 1) showing a specific example of matching in operation example 1;
- FIG. 15 is an explanatory diagram (part 2) showing a specific example of matching in the operation example 1;
- FIG. 16 is an explanatory diagram (part 3) showing a specific example of matching in the operation example 1;
- FIG. 17 is a flowchart (part 1) showing an example of both conversion processing procedures.
- FIG. 18 is a flowchart (part 2) showing an example of both conversion processing procedures.
- FIG. 19 is an explanatory diagram showing a second operation example of the information processing apparatus 100.
- FIG. 20 is an explanatory diagram (part 1) showing a specific example of matching in the case of making it easier to prevent leakage of necessity information.
- FIG. 21 is an explanatory diagram (Part 2) showing a specific example of matching in the case of making it easier to prevent leakage of necessity information.
- FIG. 22 is an explanatory diagram (Part 1) showing a specific example of matching in the case of facilitating prevention of leakage of presence/absence information.
- FIG. 23 is an explanatory diagram (Part 2) showing a specific example of matching in the case of facilitating prevention of leakage of presence/absence information.
- FIG. 24 is a flow chart showing an example of the first partial conversion processing procedure.
- FIG. 25 is a flow chart showing an example of a second partial conversion processing procedure.
- FIG. 1 is an explanatory diagram of an example of an evaluation method according to an embodiment.
- the information processing apparatus 100 is a computer that can facilitate prevention of information leakage regarding a certain element in a system that evaluates matching situations between different elements.
- An element is, for example, a company.
- Elements are, for example, users.
- a user is, for example, a job seeker.
- this service for example, as a preliminary step for allowing the company to refer to the user's personal information, based on whether the user has predetermined qualification data and the like and whether the company requests the predetermined qualification data and the like, It may be desired to provisionally match a user and a company. For example, user data including presence/absence information indicating whether or not a user has predetermined qualification data, etc., is collated with company data including necessity information indicating whether or not a company requests predetermined qualification data, etc. , it is desirable to evaluate the degree of matching between users and companies.
- a method of suppressing the risk of information leakage by adding noise to the presence/absence information included in user data or the necessity information included in corporate data Accurate matching with companies becomes difficult.
- a method of inverting the presence/absence indicated by the presence/absence information or the necessity indicated by the necessity information can be considered. More specifically, if the presence/absence information is 1, it is reversed to 0, and if the presence/absence information is 0, it is reversed to 1. More specifically, if the necessity information is 1, it is reversed to 0, and if the necessity information is 0, it is reversed to 1.
- the information processing device 100 acquires the first data 101 .
- the first data 101 includes presence/absence information indicating the presence/absence of data corresponding to each of the plurality of items included in the first item group.
- the first data 101 is, for example, data corresponding to the first element.
- the first element is, for example, the user.
- the first item group includes, for example, a plurality of items related to the user's ability characteristics or physical characteristics. Items related to ability characteristics are items related to predetermined qualifications, for example.
- the presence/absence information is flag information that indicates with 0 or 1 whether or not data corresponding to the item exists.
- the information processing device 100 acquires the first data 101 by receiving it from another computer owned by the user.
- the information processing apparatus 100 receives first data 101 including presence/absence information indicating the presence/absence of data corresponding to item 1, item 2, item 3, and item 4, respectively. Obtained by receiving from a computer.
- the information processing device 100 acquires a plurality of second data 102 .
- the second data 102 includes necessity information indicating necessity of data corresponding to each of the plurality of items included in the second item group.
- the second data 102 is, for example, data corresponding to the second element.
- a second element is, for example, an enterprise.
- the second item group includes, for example, a plurality of items related to the user's ability characteristics or physical characteristics required by the company. Items related to ability characteristics are, for example, items related to qualifications.
- the second group of items for example, partially overlaps with the first group of items.
- the second group of items is, for example, identical to the first group of items.
- the necessity information is flag information indicating by 0 or 1 whether or not the data corresponding to the item is requested.
- the information processing device 100 acquires, for example, a plurality of second data 102 by receiving them from other computers owned by the company.
- the information processing apparatus 100 stores a plurality of second data 102 each including necessity information indicating necessity of data corresponding to each of item 1, item 2, item 3, and item 4. , obtained by receiving from other computers owned by the enterprise.
- the information processing apparatus 100 generates data corresponding to each of the plurality of items included in the second item group based on the plurality of pieces of necessity information included in each of the plurality of pieces of acquired second data 102. Calculate the total number of necessity information indicating the request. In the example of FIG. 1 , the information processing apparatus 100 calculates the total number of pieces of necessity information indicating a request for data corresponding to each of items 1, 2, 3, and 4 shown in table 110 . As a result, the information processing apparatus 100 obtains information that serves as a guideline for identifying items from the second item group, the necessity information of which is likely to leak, and as a guideline for determining which item should be converted. be able to.
- the information processing device 100 generates a third item group.
- the third item group includes, for example, a plurality of items related to the user's ability characteristics or physical characteristics. Items included in the third item group are generated, for example, based on each of the plurality of items included in the second item group. Specifically, the items included in the third item group are new items obtained by combining two or more items included in the second item group. Items included in the third item group may specifically be items included in the second item group.
- the information processing apparatus 100 generates a third item group, for example, based on each of the plurality of items included in the second item group and the calculated total number of pieces of necessity information. Specifically, the information processing apparatus 100 sets the third item group so that the total number of pieces of necessity information indicating that data corresponding to each of the plurality of items included in the third item group is requested is equal to or greater than the reference number. generates a group of items for
- the information processing apparatus 100 selects, from the second item group, an item whose total number of pieces of necessity information indicating that data is requested is less than the reference number, and then selects another item. . More specifically, the information processing apparatus 100 adds a cluster obtained by combining the two selected items as a new item to the third item group. Further, more specifically, the information processing apparatus 100 selects items in the second item group whose total number of necessity information indicating that data is requested is equal to or greater than the reference number and which has not yet been selected. Add to the third set of items.
- the information processing apparatus 100 combines items 3 and 4 such that the total number of necessary/unnecessary information indicating that data is requested is equal to or greater than the reference number, as shown in table 120. Generate a third set of items containing 3&4 and item 1 and item 2.
- the information processing device 100 converts the first data 101 into third data 103 including presence/absence information indicating the presence/absence of data corresponding to each of the plurality of items included in the third item group. .
- the information processing apparatus 100 combines the presence/absence information indicating the presence/absence of the data corresponding to the item 3 and the presence/absence information indicating the presence/absence of the data corresponding to the item 4 among the first data 101.
- presence/absence information indicating the presence/absence of data corresponding to items 3 and 4 is generated.
- Information processing apparatus 100 then generates third data 103 including the generated presence/absence information, presence/absence information indicating the presence/absence of data corresponding to item 1, and presence/absence information indicating the presence/absence of data corresponding to item 2. Generate.
- the information processing apparatus 100 converts each of the plurality of second data 102 into a fourth data set including necessity information indicating necessity of data corresponding to each of the plurality of items included in the third item group. Convert to data 104 .
- the information processing apparatus 100 stores the necessity information indicating whether or not the data corresponding to item 3 is necessary, and the necessity information indicating whether or not the data corresponding to item 4 in the second data 102. are combined to generate necessity information indicating necessity of data corresponding to items 3 & 4 . Then, the information processing apparatus 100 includes the generated necessity information, the necessity information indicating whether the data corresponding to item 1 is necessary, and the necessity information indicating whether the data corresponding to item 2 is necessary. 4 data 104 is generated.
- the information processing apparatus 100 compares the converted third data 103 and the converted fourth data 104, respectively, and determines the provider of the first data 101 and the second data 104. Evaluate the matching situation with the provider of the data 102 . For example, the information processing apparatus 100 determines whether or not the presence/absence information included in the third data 103 indicates that there is data indicating that the necessity information included in the fourth data 104 requires .
- the information processing apparatus 100 selects the provider of the first data 101 from which the third data 103 is converted and the source from which the fourth data 104 is converted. It is determined that the provider of the second data 102 matches. For example, if the presence/absence information does not indicate that data exists, the information processing apparatus 100 selects the provider of the first data 101 from which the third data 103 is converted and the source from which the fourth data 104 is converted. It is determined that the provider of the second data 102 does not match.
- the information processing apparatus 100 can easily prevent leakage of sensitive information.
- the information processing apparatus 100 can, for example, make it possible to evaluate the matching status between the first element and the second element while facilitating the prevention of leakage of the necessity information.
- the information processing apparatus 100 can easily prevent leakage of necessity information and can evaluate the matching status between the user and the company. Further, the information processing apparatus 100 can evaluate the matching status between the first element and the second element even if noise is included in the presence/absence information or the necessity information.
- the information processing apparatus 100 generates the third item group so that the total number of necessary/unnecessary information indicating that data is requested is greater than or equal to the reference number so as to facilitate prevention of leakage of necessary/unnecessary information.
- the present invention is not limited to this.
- the information processing apparatus 100 may generate the third item group such that the total number of presence/absence information indicating the presence of data is greater than or equal to a reference number so as to easily prevent leakage of the presence/absence information. There may be. A specific example in this case will be described later with reference to FIGS. 19 to 23, for example.
- the total number of presence/absence information indicating that data exists and the total number of necessity information indicating that data is requested are set so that the information processing apparatus 100 can easily prevent leakage of existence/non-existence information and necessity information.
- a third item group may be generated so that all of them are equal to or greater than the reference number. A specific example in this case will be described later with reference to FIGS. 12 to 16, for example.
- FIG. 2 is an explanatory diagram showing an example of the matching system 200.
- the matching system 200 includes an information processing device 100 , one or more user-side devices 201 and one or more company-side devices 202 .
- the information processing device 100 and the user device 201 are connected via a wired or wireless network 210.
- the network 210 is, for example, a LAN (Local Area Network), a WAN (Wide Area Network), the Internet, or the like.
- the information processing device 100 and the company device 202 are connected via a wired or wireless network 210 .
- the information processing device 100 is a computer that provides a matching service.
- the information processing apparatus 100 acquires a plurality of trust vectors including presence/absence information indicating whether or not data corresponding to each trust item in the trust item group exists.
- the information processing device 100 receives, for example, a trust vector from each user-side device 201 .
- the trust vector for example, corresponds to the first data shown in FIG. An example of the trust vector will be specifically described later with reference to FIG.
- the information processing apparatus 100 stores, for example, the acquired trust vectors collectively in trust vector statistical data 700 described later with reference to FIG.
- the information processing apparatus 100 acquires a plurality of trust requirements including necessity information indicating whether or not to request data corresponding to each trust item in the trust item group.
- the information processing device 100 receives, for example, trust requirements from each company-side device 202 .
- the trust requirement corresponds, for example, to the second data shown in FIG. An example of trust requirements will be specifically described later with reference to FIG.
- the information processing apparatus 100 stores, for example, the acquired trust requirements collectively in trust requirement statistical data 800, which will be described later with reference to FIG.
- the information processing apparatus 100 Based on at least one of the acquired trust vector and the acquired trust requirements, the information processing apparatus 100 generates a trust item group to be the conversion destination from the trust item group to be the conversion source. The information processing apparatus 100 calculates the total number of presence/absence information indicating that data exists for each trust item, based on the acquired trust vector, for example. The information processing apparatus 100 stores, for example, the total number of presence/absence information in a statistical table 900 described later with reference to FIG.
- the information processing apparatus 100 calculates the total number of pieces of necessity information indicating that data is requested for each trust item based on the acquired trust requirements.
- the information processing apparatus 100 stores, for example, the total number of pieces of necessity information in a statistical table 900, which will be described later with reference to FIG.
- the information processing apparatus 100 determines whether the total number of existence information and the total number of necessity information are equal to each trust item included in the trust item group to be converted.
- the information processing apparatus 100 stores the trust item group to be converted into an anonymization table 1000, which will be described later with reference to FIG.
- the information processing device 100 converts the trust vector based on the generated trust item group.
- the information processing apparatus 100 converts trust requirements based on the generated trust item group.
- the information processing apparatus 100 evaluates the matching status between the user and the company based on the converted trust vector and the converted trust requirement.
- the information processing apparatus 100 is, for example, a server or a PC (Personal Computer).
- the user-side device 201 is a computer used by the user.
- the user-side device 201 generates a trust vector based on the user's operation input and transmits it to the information processing device 100 .
- the user-side device 201 is, for example, a server, PC, tablet terminal, or smart phone.
- the company-side device 202 is a computer used by the company.
- the company-side device 202 generates a trust requirement based on the company's operation input, and transmits it to the information processing device 100 .
- the company-side device 202 is, for example, a server, PC, tablet terminal, or smart phone.
- FIG. 3 is an explanatory diagram showing a usage example of the matching system 200.
- a company-side device 202 generates trust requirements 302 including necessity information indicating whether or not to request data corresponding to each trust item included in a trust item group based on an operation input by a company employee. generated and transmitted to the information processing apparatus 100 .
- a trust item is, for example, address information. Data corresponding to the address information is, for example, a certificate of residence. A trust item is, for example, health information. The data corresponding to the health information is, for example, diagnostic results indicating no health problems. The trust item is language information, for example. Data corresponding to the language information is, for example, TOEFL test results with a prescribed score or more. This enables the company to specify what kind of users it wishes to match with the company.
- the information processing device 100 receives the trust requirements 302 from the company device 202 .
- the information processing device 100 receives from the user device 201 a trust vector 301 created from personal information whose authenticity is guaranteed by a trust service.
- Information processing apparatus 100 may receive personal information and generate trust vector 301 based on the personal information.
- the information processing device 100 evaluates the matching status between the user and the company based on the trust vector 301 and trust requirements 302 .
- the information processing apparatus 100 evaluates that the user and the company match, the information processing apparatus 100 provides the user's personal information to the company.
- the information processing apparatus 100 processes the user's personal information and transmits the processed personal information to the company-side apparatus 202 .
- the company determines whether or not to employ the user based on the processed personal information.
- the information processing apparatus 100 can evaluate the matching status between the user and the company before providing the user's personal information to the company, thereby preventing the user's personal information from being randomly provided to the company. can do. Therefore, the information processing apparatus 100 can improve security. Further, since the information processing apparatus 100 can convert the trust vector 301 and the trust requirement 302 at the time of matching, it is possible to easily prevent the leakage of the trust vector 301 and the trust requirement 302 .
- FIG. 4 is a block diagram showing a hardware configuration example of the information processing apparatus 100.
- the information processing apparatus 100 has a CPU (Central Processing Unit) 401 , a memory 402 , a network I/F (Interface) 403 , a recording medium I/F 404 and a recording medium 405 . Also, each component is connected by a bus 400 .
- CPU Central Processing Unit
- memory 402
- network I/F Interface
- the CPU 401 controls the entire information processing apparatus 100 .
- the memory 402 has, for example, a ROM (Read Only Memory), a RAM (Random Access Memory), a flash ROM, and the like. Specifically, for example, a flash ROM or ROM stores various programs, and a RAM is used as a work area for the CPU 401 .
- the program stored in the memory 402 causes the CPU 401 to execute coded processing by being loaded into the CPU 401 .
- the network I/F 403 is connected to the network 210 through a communication line, and is connected to other computers via the network 210.
- a network I/F 403 serves as an internal interface with the network 210 and controls input/output of data from other computers.
- Network I/F 403 is, for example, a modem or a LAN adapter.
- the recording medium I/F 404 controls reading/writing of data from/to the recording medium 405 under the control of the CPU 401 .
- the recording medium I/F 404 is, for example, a disk drive, SSD (Solid State Drive), USB (Universal Serial Bus) port, or the like.
- a recording medium 405 is a nonvolatile memory that stores data written under the control of the recording medium I/F 404 .
- the recording medium 405 is, for example, a disk, a semiconductor memory, a USB memory, or the like.
- the recording medium 405 may be removable from the information processing apparatus 100 .
- the information processing apparatus 100 may have, for example, a keyboard, mouse, display, printer, scanner, microphone, speaker, etc., in addition to the components described above. Further, the information processing apparatus 100 may have a plurality of recording medium I/Fs 404 and recording media 405 . Further, the information processing apparatus 100 may not have the recording medium I/F 404 and the recording medium 405 .
- FIG. 5 is an explanatory diagram showing an example of a trust vector 500.
- the trust vector 500 includes presence/absence information indicating whether data corresponding to the respective trust items of address information, health information, and language information exists, for example.
- the trust vector 500 may be noise added. For example, noise may be added to the presence/absence information indicating whether data corresponding to health information exists.
- FIG. 6 is an explanatory diagram showing an example of trust requirements 600.
- the trust requirement 600 includes, for example, necessity information indicating whether or not data corresponding to the respective trust items of address information, health information, and language information is requested.
- Trust requirements 600 may be noise-added.
- the trust vector statistical data 700 is implemented, for example, by a storage area such as the memory 402 or recording medium 405 of the information processing apparatus 100 shown in FIG.
- FIG. 7 is an explanatory diagram showing an example of trust vector statistical data 700.
- trust vector statistical data 700 includes, for each user, a trust vector 500 corresponding to the user as a record.
- the trust vector statistical data 700 specifically has fields for users and respective trust vectors 500 . Identification information for identifying a user is set in the user field. Presence/absence information corresponding to the trust vector 500 is set in the trust vector 500 field.
- the trust requirement statistical data 800 is realized, for example, by a storage area such as the memory 402 or recording medium 405 of the information processing apparatus 100 shown in FIG.
- FIG. 8 is an explanatory diagram showing an example of trust requirement statistical data 800.
- trust requirement statistical data 800 includes, for each company, trust requirement 600 corresponding to the company as a record, for example.
- the trust requirement statistical data 800 specifically has fields for companies and respective trust requirements 600 . Identification information for identifying a company is set in the company field. Necessity information corresponding to the trust requirement 600 is set in the field of the trust requirement 600 .
- Statisticalization table 900 is realized, for example, by a storage area such as memory 402 or recording medium 405 of information processing apparatus 100 shown in FIG.
- FIG. 9 is an explanatory diagram showing an example of the contents of the statistic table 900.
- the statistical table 900 has fields for Trust Item, Trust Vector 500 and Trust Requirement 600 .
- the statistical table 900 stores statistical information as a record by setting information in each field for each trust item.
- a trust item is set in the trust item field.
- the field of the trust vector 500 is set with the total number of presence/absence information indicating that data corresponding to the trust item exists in the trust vector 500 set.
- the total number of pieces of necessity information indicating that the data corresponding to the trust item is requested in the set of trust requirements 600 is set.
- the anonymization table 1000 is realized, for example, by a storage area such as the memory 402 or recording medium 405 of the information processing apparatus 100 shown in FIG.
- FIG. 10 is an explanatory diagram showing an example of the contents of the anonymization table 1000.
- the anonymization table 1000 has fields of aggregation information, trust vector 500 and trust requirement 600 .
- the anonymization table 1000 stores anonymization information as a record by setting information in each field for each grouped information.
- a trust item or a cluster that is a new trust item combining trust items is set.
- the field of the trust vector 500 is set with the total number of presence/absence information indicating that data corresponding to the trust item exists in the trust vector 500 set.
- the trust requirement 600 field the total number of pieces of necessity information indicating that the data corresponding to the trust item is requested in the set of trust requirements 600 is set.
- An example of the hardware configuration of the company-side device 202 is the same as the example of the hardware configuration of the information processing device 100 shown in FIG. 4, so description thereof is omitted.
- An example of the hardware configuration of the user-side device 201 is the same as the example of the hardware configuration of the information processing device 100 shown in FIG. 4, so description thereof will be omitted.
- FIG. 11 is a block diagram showing a functional configuration example of the information processing device 100.
- Information processing apparatus 100 includes storage unit 1100 , acquisition unit 1101 , calculation unit 1102 , conversion unit 1103 , evaluation unit 1104 , and output unit 1105 .
- the storage unit 1100 is realized, for example, by a storage area such as the memory 402 and recording medium 405 shown in FIG. A case where the storage unit 1100 is included in the information processing apparatus 100 will be described below, but the present invention is not limited to this.
- the storage unit 1100 may be included in a device different from the information processing device 100 , and the information stored in the storage unit 1100 may be referenced from the information processing device 100 .
- the acquisition unit 1101 to the output unit 1105 function as an example of a control unit. Specifically, the acquisition unit 1101 to the output unit 1105, for example, by causing the CPU 401 to execute a program stored in a storage area such as the memory 402 or the recording medium 405 shown in FIG. to realize its function. The processing result of each functional unit is stored in a storage area such as the memory 402 or recording medium 405 shown in FIG. 4, for example.
- the storage unit 1100 stores various information that is referred to or updated in the processing of each functional unit.
- Storage unit 1100 stores a first item group.
- the first item group includes, for example, a plurality of items related to the user's ability characteristics or physical characteristics. Items related to ability characteristics are items related to predetermined qualifications, for example. Items included in the first item group are specifically trust items.
- the storage unit 1100 stores the first data.
- Storage unit 1100 stores, for example, a plurality of first data.
- the first data includes presence/absence information indicating the presence/absence of data corresponding to each of the plurality of items included in the first item group.
- the first data is, for example, data corresponding to the first element.
- the first data is specifically the trust vector 500 .
- the first element is, for example, the user.
- the first element is specifically a user who is a job seeker.
- the first element may specifically be a user who is a test taker.
- a first element may specifically be a user of a certain gender.
- the presence/absence information is flag information that indicates with 0 or 1 whether or not data corresponding to the item exists.
- the first data is obtained by the obtaining unit 1101, for example.
- the storage unit 1100 stores the trust vector 500 as the first data in the trust vector statistical data 700 .
- the storage unit 1100 stores the second item group.
- the second item group includes, for example, a plurality of items related to the user's ability characteristics or physical characteristics required by the company. Items related to ability characteristics are, for example, items related to qualifications. Items included in the second item group are specifically trust items.
- the second group of items for example, partially overlaps with the first group of items.
- the second group of items is, for example, identical to the first group of items.
- the storage unit 1100 stores one or more second data.
- Storage unit 1100 stores, for example, a plurality of second data.
- the second data includes necessity information indicating necessity of data corresponding to each of the plurality of items included in the second item group.
- the second data is, for example, data corresponding to the second element.
- the second data is specifically trust requirements 600 .
- a second element is, for example, an enterprise.
- the second element is specifically companies that recruit employees.
- the second element may specifically be an entity such as a testing company.
- the second element may specifically be a user of another gender than the first element.
- the necessity information is flag information indicating by 0 or 1 whether or not the data corresponding to the item is requested.
- the second data is obtained by the obtaining unit 1101, for example.
- the storage unit 1100 stores the trust requirement 600 as the second data in the trust requirement statistical data 800 .
- the storage unit 1100 stores the total number of presence/absence information indicating that there is data corresponding to each of the plurality of items included in the first item group.
- the total number of presence/absence information is calculated by the calculation unit 1102, for example.
- Storage unit 1100 specifically stores the total number of presence/absence information in statistical table 900 .
- the storage unit 1100 stores the total number of pieces of necessity information indicating that data corresponding to each of the items included in the second item group is requested.
- the total number of pieces of necessity information is calculated by the calculation unit 1102, for example.
- Storage unit 1100 specifically stores the total number of pieces of necessity information in statistical table 900 .
- the storage unit 1100 stores a third item group.
- the third item group includes, for example, a plurality of items related to the user's ability characteristics or physical characteristics. Items included in the third item group are generated, for example, based on each of the plurality of items included in the second item group. Specifically, the items included in the third item group are new items obtained by combining two or more items included in the second item group. Items included in the third item group may specifically be items included in the second item group. Items included in the third item group are, for example, trust items or clusters that are new trust items that are a combination of trust items.
- the third item group is generated by the conversion unit 1103, for example.
- Storage unit 1100 specifically stores the third item group in anonymization table 1000 .
- the storage unit 1100 stores the third data.
- the third data is data after conversion of the first data.
- the third data is generated by the conversion unit 1103, for example.
- Storage unit 1100 stores the fourth data.
- the fourth data is data after conversion of the second data.
- the fourth data is generated by the conversion unit 1103, for example.
- the acquisition unit 1101 acquires various types of information used for processing of each functional unit. Acquisition unit 1101 stores various kinds of acquired information in storage unit 1100 or outputs the information to each functional unit. Further, the acquisition unit 1101 may output various information stored in the storage unit 1100 to each functional unit. Acquisition unit 1101 acquires various types of information, for example, based on the operation input of the service administrator. The acquisition unit 1101 may receive various types of information from a device different from the information processing device 100, for example.
- the acquisition unit 1101 acquires the first data.
- Acquisition unit 1101 acquires, for example, a plurality of first data. Specifically, the acquisition unit 1101 acquires the first data by receiving it from the user-side device 201 . Specifically, the acquisition unit 1101 may acquire the first data by accepting the input of the first data based on the operation input by the service manager.
- a service manager is, for example, a user of the information processing apparatus 100 .
- Acquisition unit 1101 adds noise to any of the presence/absence information included in the acquired first data. Accordingly, the acquisition unit 1101 can easily prevent leakage of presence/absence information.
- the acquisition unit 1101 acquires the second data.
- Acquisition unit 1101 acquires, for example, a plurality of second data. Specifically, the acquisition unit 1101 acquires the second data by receiving it from the company-side device 202 . Specifically, the acquisition unit 1101 may acquire the second data by accepting the input of the second data based on the operation input by the service manager. The acquisition unit 1101 may add noise to any of the necessity information included in the acquired second data. Accordingly, the acquisition unit 1101 can easily prevent leakage of the necessity information.
- the acquisition unit 1101 may accept a start trigger for starting the processing of any functional unit.
- the start trigger is, for example, a predetermined operation input by the service administrator.
- the start trigger may be, for example, reception of predetermined information from another computer.
- the start trigger may be, for example, the output of predetermined information by any of the functional units.
- the acquisition unit 1101 receives acquisition of the first data and the second data as a start trigger for starting the processes of the calculation unit 1102 , the conversion unit 1103 and the evaluation unit 1104 .
- Calculation unit 1102 calculates presence/absence information indicating that data corresponding to each of the plurality of items included in the first item group exists, based on the plurality of items of presence/absence information included in each of the plurality of acquired first data. Calculate the total number. As a result, the calculation unit 1102 serves as a guideline for specifying items in the first item group whose presence/absence information is likely to leak, and serves as a guideline for determining which item is preferable to be converted by the conversion unit 1103. information can be obtained.
- the calculation unit 1102 indicates whether or not to request data corresponding to each of the plurality of items included in the second item group, based on the plurality of pieces of necessity information included in each of the plurality of acquired second data. Calculate the total number of information.
- the calculation unit 1102 serves as a guideline for specifying items in the second item group, the necessity information of which is likely to leak, and is a guideline for determining which item is preferable to be converted by the conversion unit 1103. You can get the information that will be
- the conversion unit 1103 generates a third item group.
- the conversion unit 1103 generates the third item group, for example, based on each of the plurality of items included in the second item group and the calculated total number of pieces of necessity information. Specifically, the conversion unit 1103 performs Generate a third group of items.
- the conversion unit 1103 more specifically sets the third item group to an empty set.
- conversion unit 1103 selects items that are included in the second item group and whose total number of necessity information is less than the first reference number, and further selects other items. More specifically, the conversion unit 1103 sets a cluster as a new item combining the two selected items, and adds it to the third item group. Also, the conversion unit 1103 adds the unselected items to the third item group as they are. As a result, conversion unit 1103 generates a third item group. Thereby, the conversion unit 1103 can obtain a guideline for converting the first data and the second data in order to easily prevent leakage of the necessity information.
- the conversion unit 1103 more specifically sets the third item group to an empty set.
- conversion unit 1103 selects items that are included in the first item group and whose total number of presence/absence information is less than the second reference number, and further selects other items. More specifically, the conversion unit 1103 sets a cluster as a new item combining the two selected items, and adds it to the third item group. Also, the conversion unit 1103 adds the unselected items to the third item group as they are. As a result, conversion unit 1103 generates a third item group. As a result, the conversion unit 1103 can obtain a guideline for converting the first data and the second data in order to facilitate prevention of leakage of presence/absence information.
- the conversion unit 1103 converts each of the plurality of items included in the first item group or each of the plurality of items included in the second item group, the calculated total number of necessity information, and the calculated total number of presence/absence information. and generate a third set of items. Specifically, for each of the plurality of items included in the third item group, the converting unit 1103 determines that the total number of necessity information is equal to or greater than the first reference number, and that the total number of presence/absence information is equal to or greater than the first reference number. A third group of items is generated so that the number of criteria is greater than or equal to two.
- the conversion unit 1103 more specifically sets the third item group to an empty set. Next, more specifically, conversion unit 1103 selects items that are included in the second item group and whose total number of necessity information is less than the first reference number, and further selects other items. More specifically, the conversion unit 1103 sets a cluster as a new item combining the two selected items, and adds it to the third item group. Also, the conversion unit 1103 adds the unselected items to the third item group as they are.
- the conversion unit 1103 selects items that are included in the third item group and whose total number of presence/absence information is less than the second reference number, and further selects other items. More specifically, the conversion unit 1103 sets a cluster as a new item combining the two selected items, and adds it to the third item group instead of the two selected items. As a result, conversion unit 1103 generates a third item group. As a result, the conversion unit 1103 can obtain a guideline for converting the first data and the second data in order to easily prevent leakage of the presence/absence information and the necessity information.
- the conversion unit 1103 more specifically sets the third item group to an empty set. Next, more specifically, conversion unit 1103 selects items that are included in the first item group and whose total number of presence/absence information is less than the second reference number, and further selects other items. More specifically, the conversion unit 1103 sets a cluster as a new item combining the two selected items, and adds it to the third item group. Also, the conversion unit 1103 adds the unselected items to the third item group as they are.
- the conversion unit 1103 selects items that are included in the third item group and whose total number of necessity information is less than the first reference number, and further selects other items. More specifically, the conversion unit 1103 sets a cluster as a new item combining the two selected items, and adds it to the third item group instead of the two selected items. As a result, conversion unit 1103 generates a third item group. As a result, the conversion unit 1103 can obtain a guideline for converting the first data and the second data in order to easily prevent leakage of the presence/absence information and the necessity information.
- the conversion unit 1103 converts the third item group based on, for example, the semantic distance between items included in the first item group or the semantic distance between items included in the second item group. may be generated. Specifically, when selecting items included in the second item group, the conversion unit 1103 selects items included in the second item group and having the total number of necessity information less than the first reference number. In addition, another item having a relatively close semantic distance to the item may be selected. As a result, the conversion unit 1103 can further facilitate prevention of leakage of presence/absence information and necessity information.
- the conversion unit 1103 selects items included in the first item group and whose total number of presence/absence information is less than the second reference number. It is also possible to select an item and then select another item having a close semantic distance to the item. As a result, the conversion unit 1103 can further facilitate prevention of leakage of presence/absence information and necessity information.
- the conversion unit 1103 sets the total number of presence/absence information indicating that there is data corresponding to each of the plurality of items included in the third item group to a maximum number that is equal to or greater than the reference number. , may generate a third group of items. It is considered that the larger the total number, the easier it is to conceal sensitive information. Specifically, for example, assume that the first item group includes item a, item b, and item c. The number of presence/absence information indicating that data corresponding to item a exists is 1, the number of presence/absence information indicating that data corresponding to item b exists is 2, and the presence/absence information indicating that data corresponding to item c exists. number 3.
- the conversion unit 1103 determines that it is preferable to make the items included in the third item group a combination of item a and item c, and to make the total number relatively large, and generates the third item group. .
- the conversion unit 1103 can further facilitate prevention of leakage of presence/absence information and necessity information.
- the conversion unit 1103 sets the total number of necessary/unnecessary information indicating that data corresponding to each of the plurality of items included in the third item group is requested to be the maximum number that can be obtained above the reference number.
- a third group of items may be generated.
- the conversion unit 1103 can further facilitate prevention of leakage of presence/absence information and necessity information.
- the conversion unit 1103 converts the first data into third data containing presence/absence information indicating the presence/absence of data corresponding to each of the plurality of items included in the third item group. As a result, the conversion unit 1103 can easily prevent leakage of presence/absence information or necessity information, and can evaluate the matching status between the provider of the first data and the provider of the second data. .
- the conversion unit 1103 converts the second data into fourth data including necessity information indicating necessity of data corresponding to each of the plurality of items included in the third item group. As a result, the conversion unit 1103 can easily prevent leakage of presence/absence information or necessity information, and can evaluate the matching status between the provider of the first data and the provider of the second data. .
- the evaluation unit 1104 evaluates the matching status between the provider of the first data and the provider of the second data based on the result of comparing the converted third data and the converted fourth data. evaluate. For example, the evaluation unit 1104 evaluates the data indicated to exist by the presence/absence information included in the third data, and the data indicated to be requested by the necessity information included in any of the fourth data. match or not.
- the evaluation unit 1104 evaluates that the provider of the first data matches the provider of the second data corresponding to any of the fourth data. Specifically, the evaluation unit 1104 evaluates that the user and the company are matched. This allows the evaluation unit 1104 to evaluate the matching status between the first data provider and the second data provider.
- the evaluation unit 1104 evaluates the degree of matching between the provider of the first data and the provider of the second data based on the result of comparing the converted third data and the converted fourth data. can be calculated. For example, the evaluation unit 1104 evaluates the data indicated to exist by the presence/absence information included in the third data, and the data indicated to be requested by the necessity information included in any of the fourth data. match or not.
- the evaluation unit 1104 calculates the degree of matching between the first data provider and the second data provider so that the degree of matching increases as the number of matches increases. Specifically, the evaluation unit 1104 calculates the degree of matching between the user and the company. This allows the evaluation unit 1104 to evaluate the matching status between the first data provider and the second data provider.
- the output unit 1105 outputs the processing result of at least one of the functional units.
- the output format is, for example, display on a display, print output to a printer, transmission to an external device via the network I/F 403, or storage in a storage area such as the memory 402 or recording medium 405.
- the output unit 1105 can notify the service manager of the processing result of at least one of the functional units, and the convenience of the information processing apparatus 100 can be improved.
- the output unit 1105 outputs, for example, the result of evaluating the matching status between the provider of the first data and the provider of the second data.
- the output unit 1105 outputs, for example, the result of evaluating the matching status between the first data provider and the second data provider so that the second data provider can refer to it.
- the output unit 1105 outputs the result of calculating the degree of matching between the first data provider and the second data provider so that the second data provider can refer to it. good too. This allows the output unit 1105 to make the matching status available.
- the information processing apparatus 100 generates presence/absence information and necessity information based on the total number of existence/non-existence information indicating that data exists and the total number of necessity information indicating that the data is requested. This is an example of operation in the case of making it easier to prevent the leakage of
- FIG. 12 and 13 are explanatory diagrams showing a first operation example of the information processing device 100.
- the information processing apparatus 100 acquires multiple trust vectors 500 and multiple trust requirements 600 .
- the information processing apparatus 100 acquires, for example, the trust vector 500 of user A, user B, and user C, and the like.
- the information processing apparatus 100 acquires, for example, the trust requirements 600 among company X, company Y, and company Z.
- the information processing apparatus 100 collectively stores the acquired plurality of trust vectors 500 in the trust vector statistical data 700 . Based on the trust vector statistical data 700 , the information processing apparatus 100 calculates the number of occurrences of presence/absence information indicating the presence of data for each trust item, and stores it in the statistical table 900 .
- the information processing apparatus 100 collectively stores the acquired trust requirements 600 in the trust requirement statistical data 800 . Based on the trust requirement statistical data 800 , the information processing apparatus 100 calculates the number of occurrences of necessity information indicating that data is requested for each trust item, and stores it in the statistical table 900 .
- the information processing apparatus 100 can identify trust items with a relatively high possibility of leakage. For example, the information processing apparatus 100 identifies a trust item for which the calculated number of occurrences is less than k as a trust item with a relatively high possibility of leakage of presence/absence information or necessity information. k is 2, for example.
- the information processing apparatus 100 refers to the statistical table 900, combines trust items, and performs k-anonymization, thereby reducing the possibility of leakage of presence/absence information or necessity information. to Next, the description of FIG. 13 will be described.
- the information processing apparatus 100 selects a trust item whose appearance count is less than k, selects another trust item, combines the selected two trust items, and creates a new trust item. create a cluster that is a valid trust item.
- the information processing apparatus 100 stores the generated clusters that are new trust items in the anonymization table 1000 . If there is a trust item that has not been selected, the information processing apparatus 100 stores the trust item as it is in the anonymization table 1000 .
- the information processing apparatus 100 selects health information in which the number of occurrences of presence/absence information is less than k, selects address information having a relatively close semantic distance from the health information, and selects address information that is relatively close in semantic distance to the health information. Create a cluster that will be a new trust item by combining Further, the information processing apparatus 100 selects the language information 2 in which the number of appearances of the necessity information is less than k, selects the language information 1 whose semantic distance is relatively close to the language information 2, and selects the language information 1 and the language information. 2 to create a new trust item cluster.
- the information processing device 100 stores the cluster, which becomes the new trust item, in the anonymization table 1000 .
- the number of occurrences of presence/absence information and the number of occurrences of necessity information corresponding to a cluster that becomes a new trust item are both k or more. Therefore, the information processing apparatus 100 can perform k-anonymization, and can easily prevent leakage of presence/absence information and necessity information. Further, the information processing apparatus 100 can match a user with a company even if noise is added to the presence/absence information. A specific example of matching will be described later with reference to FIGS. 14 to 16, for example.
- the information processing apparatus 100 selects another trust item whose semantic distance is relatively close to the selected trust item has been described, but the present invention is not limited to this.
- the information processing apparatus 100 may select another trust item whose number of appearances is relatively close to the selected trust item.
- FIG. 14 to 16 are explanatory diagrams showing specific examples of matching in Operation Example 1.
- FIG. 14 (14-1) the information processing apparatus 100 converts the trust vector 500 of user A and the trust vector 500 of user B into an anonymization vector 1401 based on the anonymization table 1000 .
- the information processing apparatus 100 combines the presence/absence information of the address information and the presence/absence information of the health information included in the trust vector 500 of Mr. A to obtain the address information and the health information. Information and cluster presence/absence information. Specifically, based on the anonymization table 1000, the information processing apparatus 100 combines the presence/absence information of the language information 1 and the presence/absence information of the language information 2 included in the trust vector 500 of Mr. A to obtain the language information. 1 and language information 2 into cluster presence/absence information.
- the information processing device 100 converts the trust requirements 600 of company X and the trust requirements 600 of company Y into anonymization requirements 1402 based on the anonymization table 1000 .
- the information processing apparatus 100 combines the necessity information of the address information and the necessity information of the health information included in the trust requirements 600 of the company X, and obtains the address information. and health information into cluster necessity information. Specifically, based on the anonymization table 1000, the information processing apparatus 100 combines the necessity information of the language information 1 and the necessity information of the language information 2 included in the trust requirements 600 of the company X, The information is converted into cluster necessity information of language information 1 and language information 2.
- the information processing apparatus 100 Either the necessity information or the necessity information of the language information 2 is treated as the necessity information of the cluster. In this way, the information processing apparatus 100 converts the trust requirements 600 of Company X into the anonymization requirements 1402 of Company X. Next, the description of FIG. 15 will be described.
- FIG. 15 a case of matching a user and a company by directly referring to the trust vector 500 and the trust requirement 600 will be described. For example, if the presence/absence information included in the user's trust vector 500 indicates that the data exists for all trust items whose necessity information included in the company's trust requirements 600 indicates that data is required, , companies and users are matched.
- Company Y requests a German language test corresponding to language information 2, but as shown in Table 1500, matching only Company Y with user B leaks sensitive information that the German language test is required. There is a problem that it becomes easier to User B has only a relatively trivial problem with his health information, and as shown in table 1500, he is not matched with company X. This is a problem. Next, the description of FIG. 16 will be described.
- the information processing apparatus 100 determines that the presence/absence information included in the user's anonymization vector indicates that the data exists for all trust items that indicate that the data is requested. It is determined whether or not the The information processing apparatus 100 evaluates that the company and the user are matched if data exists for all trust items.
- company X can be matched with a relatively large number of users, as shown in table 1600. Unlike the example in FIG. 15, even if user A wishes to keep his health information confidential and adds noise to the health information presence/absence information, as shown in table 1600, company X and user A can be matched with
- Company Y is also matched with users other than Mr. B, so it is easy to prevent leakage of sensitive information such as Company Y's request for a German language test. .
- user B can be matched with company X, as shown in table 1600, even though he has relatively minor problems with his health information. In this way, the information processing apparatus 100 can effectively match users and companies while facilitating prevention of leakage of sensitive information.
- FIG. Both conversion processes are realized by, for example, the CPU 401, storage areas such as the memory 402 and the recording medium 405, and the network I/F 403 shown in FIG.
- FIGS. 17 and 18 are flowcharts showing an example of both conversion processing procedures.
- the information processing apparatus 100 acquires the trust requirement statistical data 800 (step S1701).
- the information processing apparatus 100 selects one unselected trust item whose number of appearances in the set of trust requirements 600 ⁇ k from among the trust item group. (Step S1702). Then, the information processing apparatus 100 extracts another trust item that is relatively similar in number of appearances or properties to the selected trust item from the trust item group (step S1703).
- the information processing apparatus 100 selects the trust item with the largest number of appearances in the set of trust vectors 500 from among the extracted trust items (step S1704).
- the information processing apparatus 100 then converts the selected trust item into a cluster that combines the selected trust items, and updates the trust item group (step S1705).
- the information processing apparatus 100 determines whether or not there is a trust item whose number of occurrences ⁇ k that has not yet been selected exists among the trust item group (step S1706). Here, if there is a trust item whose number of appearances ⁇ k that has not yet been selected (step S1706: Yes), the information processing apparatus 100 returns to the process of step S1702. On the other hand, if there is no unselected trust item whose number of occurrences ⁇ k (step S1706: No), the information processing apparatus 100 proceeds to the process of step S1801 in FIG.
- the information processing apparatus 100 acquires the trust vector statistical data 700 (step S1801).
- the information processing apparatus 100 selects one unselected trust item whose number of appearances in the trust vector 500 set ⁇ k from among the trust item group. (Step S1802). Then, the information processing apparatus 100 extracts another trust item relatively similar in number of appearances or properties to the selected trust item from the trust item group (step S1803).
- the information processing apparatus 100 selects the trust item with the largest number of appearances in the set of trust requirements 600 from among the extracted trust items (step S1804).
- the information processing apparatus 100 then converts the selected trust item into a cluster that combines the selected trust items, and updates the trust item group (step S1805).
- the information processing apparatus 100 determines whether or not there is a trust item whose number of occurrences ⁇ k that has not yet been selected exists among the trust item group (step S1806). Here, if there is a trust item whose appearance count ⁇ k that has not yet been selected (step S1806: Yes), the information processing apparatus 100 returns to the process of step S1802. On the other hand, if there is no unselected trust item whose number of occurrences ⁇ k (step S1806: No), the information processing apparatus 100 proceeds to the process of step S1807.
- the information processing apparatus 100 generates the anonymization table 1000 based on the trust item group (step S1807). Then, the information processing apparatus 100 ends both conversion processes. As a result, the information processing apparatus 100 can easily prevent leakage of sensitive information.
- the information processing apparatus 100 determines the presence/absence information and the requirement information based on either the total number of the presence/absence information indicating that the data exists or the total number of the necessity information indicating that the data is requested. It is an example of operation in the case of making it easy to prevent leakage of any of the negative information.
- FIG. 19 is an explanatory diagram showing a second operation example of the information processing apparatus 100.
- the information processing apparatus 100 acquires multiple trust vectors 500 and multiple trust requirements 600 .
- the information processing apparatus 100 acquires, for example, the trust vector 500 of user A, user B, and user C, and the like.
- the information processing apparatus 100 acquires, for example, the trust requirements 600 among company X, company Y, and company Z.
- the information processing apparatus 100 collectively stores the acquired trust vectors 500 in the trust vector statistical data 700 . Based on the trust vector statistical data 700 , the information processing apparatus 100 calculates the number of occurrences of presence/absence information indicating the presence of data for each trust item, and stores it in the statistical table 900 .
- the information processing apparatus 100 collectively stores the acquired trust requirements 600 in the trust requirement statistical data 800 . Based on the trust requirement statistical data 800 , the information processing apparatus 100 calculates the number of occurrences of necessity information indicating that data is requested for each trust item, and stores it in the statistical table 900 . As a result, the information processing apparatus 100 can identify trust items with a relatively high possibility of leakage.
- the first situation where it is desirable to easily prevent leakage of the presence/absence information included in the trust vector 500 is as follows. Conceivable.
- a second situation where it is desirable to easily prevent leakage of the necessity information included in the trust requirement 600 out of the existence/non-existence information included in the trust vector 500 and the necessity information included in the trust requirement 600. can be considered.
- the information processing apparatus 100 selects a trust item whose calculated presence/absence information appearance count is less than k, then selects another trust item, and selects the two selected trust items. are combined to generate a cluster that will be a new trust item. Then, information processing apparatus 100 stores the generated new cluster as a trust item in anonymization table 1000-1. If there is a trust item that has not been selected, information processing apparatus 100 stores the trust item as it is in anonymization table 1000-1.
- the information processing apparatus 100 selects health information in which the number of appearances of presence/absence information is less than k, selects address information having a relatively close semantic distance from the health information, and selects address information that is relatively close in semantic distance to the health information. Create a cluster that will be a new trust item by combining Then, information processing apparatus 100 stores language information 1 and language information 2 that have not been selected and the cluster that will be the new trust item generated in anonymization table 1000-1.
- the information processing apparatus 100 can perform k-anonymization, and can easily prevent leakage of presence/absence information. Further, the information processing apparatus 100 can match a user with a company even if noise is added to the presence/absence information. A specific example of matching will be described later with reference to FIGS. 22 and 23, for example.
- the information processing apparatus 100 selects a trust item for which the calculated number of occurrences of necessity information is less than k, selects another trust item, and selects the two selected trust items. Combine items to create a cluster that is a new trust item. Then, information processing apparatus 100 stores the generated new cluster as a trust item in anonymization table 1000-2. If there is a trust item that has not been selected, information processing apparatus 100 stores the trust item as it is in anonymization table 1000-2.
- the information processing apparatus 100 selects language information 2 whose appearance number of necessity information is less than k, selects language information 1 whose semantic distance is relatively close to language information 2, and selects health information. and address information to create a new trust item cluster. Then, information processing apparatus 100 stores the address information and health information that have not been selected and the cluster that will be the new trust item that has been generated in anonymization table 1000-2.
- the information processing apparatus 100 can perform k-anonymization, and can easily prevent leakage of necessity information. Further, the information processing apparatus 100 can match a user with a company even if noise is added to the necessity information. A specific example of matching will be described later with reference to FIGS. 20 and 21, for example.
- the information processing apparatus 100 calculates, for each trust item, the number of occurrences of existence/non-existence information indicating that data exists and the number of occurrences of necessity information indicating that the data is requested. , but the present invention is not limited to this. For example, when facilitating prevention of leakage of presence/absence information, the information processing apparatus 100 does not need to calculate the number of occurrences of necessity information indicating a request for data. For example, when facilitating prevention of leakage of necessity information, the information processing apparatus 100 does not need to calculate the number of occurrences of existence information indicating existence of data.
- FIGS. 20 and 21 are explanatory diagrams showing a specific example of matching when making it easier to prevent leakage of necessity information. Referring directly to trust vector 500 and trust requirement 600 in FIG. 20, a case of matching a user and a company will be described.
- the presence/absence information included in the user's trust vector 500 indicates that the data exists for all trust items whose necessity information included in the company's trust requirements 600 indicates that data is required, , companies and users are matched.
- the information processing device 100 converts the trust vector 500 of user A and the trust vector 500 of user B into an anonymization vector 2101 based on the anonymization table 1000 .
- the information processing apparatus 100 combines the presence/absence information of the language information 1 and the presence/absence information of the language information 2 included in the trust vector 500 of Mr. A to obtain the language information. 1 and language information 2 into cluster presence/absence information.
- the information processing apparatus 100 converts the trust vector 500 of Mr. User A into the anonymization vector 2101 of Mr. A.
- the information processing device 100 converts the trust requirements 600 of company X and the trust requirements 600 of company Y into anonymization requirements 2102 based on the anonymization table 1000 . Specifically, based on the anonymization table 1000, the information processing apparatus 100 combines the necessity information of the language information 1 and the necessity information of the language information 2 included in the trust requirements 600 of the company X, The information is converted into cluster necessity information of language information 1 and language information 2. FIG. Thus, the information processing apparatus 100 converts the trust requirements 600 of Company X into the anonymization requirements 2102 of Company X.
- the information processing apparatus 100 determines that the presence/absence information included in the user's anonymization vector is the data exists. The information processing apparatus 100 evaluates that the company and the user are matched if data exists for all trust items.
- Company Y is matched with users other than Mr. B, so sensitive information that Company Y requires a German language test may not be leaked. It becomes easier to prevent In this way, the information processing apparatus 100 can effectively match users and companies while facilitating prevention of leakage of sensitive information.
- the information processing apparatus 100 does not combine trust items with respect to presence/absence information, it is possible to reduce the amount of processing.
- the information processing apparatus 100 does not combine trust items with respect to presence/absence information, it is possible to suppress deterioration in matching accuracy.
- FIGS. 22 and 23 are explanatory diagrams showing a specific example of matching when making it easier to prevent leakage of presence/absence information. Referring directly to trust vector 500 and trust requirement 600 in FIG. 22, a case of matching a user and a company will be described.
- the information processing apparatus 100 converts the trust vector 500 of user A and the trust vector 500 of user B into an anonymization vector 2301 based on the anonymization table 1000 . Specifically, based on the anonymization table 1000, the information processing apparatus 100 combines the presence/absence information of the address information and the presence/absence information of the health information included in the trust vector 500 of Mr. A to obtain the address information and the health information. information and cluster presence/absence information. Thus, the information processing apparatus 100 converts the trust vector 500 of Mr. User A into the anonymization vector 2301 of Mr. A.
- the information processing device 100 converts the trust requirements 600 of company X and the trust requirements 600 of company Y into anonymization requirements 2302 based on the anonymization table 1000 . Specifically, based on the table 1000, the information processing apparatus 100 combines the necessity information of the address information and the necessity information of the health information included in the trust requirements 600 of the company X to obtain the address information and the health information. It converts to the necessity information of the cluster with the information. In this way, the information processing apparatus 100 converts the trust requirements 600 of Company X into the anonymization requirements 2302 of Company X.
- the information processing device 100 determines that the presence/absence information included in the user's anonymization vector is the data exists.
- the information processing apparatus 100 evaluates that the company and the user are matched if data exists for all trust items.
- company Y matches with users other than Mr. B, so that user B has a relatively minor problem with health information. It becomes easier to prevent sensitive information from leaking. In this way, the information processing apparatus 100 can effectively match users and companies while facilitating prevention of leakage of sensitive information.
- the information processing apparatus 100 does not combine trust items regarding the necessity information, it is possible to reduce the amount of processing.
- the information processing apparatus 100 does not combine trust items with respect to the necessity information, it is possible to suppress a decrease in matching accuracy.
- the first piece conversion process is realized by, for example, the CPU 401, storage areas such as the memory 402 and the recording medium 405, and the network I/F 403 shown in FIG.
- the first one-sided conversion process corresponds to the case of making it easier to prevent leakage of necessity information.
- FIG. 24 is a flow chart showing an example of the first partial conversion processing procedure.
- the information processing apparatus 100 acquires the trust requirement statistical data 800 (step S2401).
- the information processing apparatus 100 selects one unselected trust item whose number of appearances in the set of trust requirements 600 ⁇ k from among the trust item group. (Step S2402). Then, the information processing apparatus 100 extracts another trust item relatively close to the selected trust item in terms of the number of appearances or properties from the trust item group (step S2403).
- the information processing apparatus 100 selects the trust item with the largest number of appearances in the set of trust vectors 500 from among the extracted trust items (step S2404).
- the information processing apparatus 100 then converts the selected trust item into a cluster that combines the selected trust items, and updates the trust item group (step S2405).
- the information processing apparatus 100 determines whether or not there is a trust item whose number of occurrences ⁇ k that has not yet been selected exists among the trust item group (step S2406).
- step S2406: Yes the information processing apparatus 100 returns to the process of step S2402.
- step S2406: No the information processing apparatus 100 proceeds to the process of step S2407.
- the information processing apparatus 100 generates the anonymization table 1000 based on the trust item group (step S2407). Then, the information processing apparatus 100 ends the first half conversion process. As a result, the information processing apparatus 100 can generate information that serves as a guideline for converting between the trust vector 500 and the trust requirement 600 in order to easily prevent leakage of sensitive information.
- the second piece conversion process is realized by, for example, the CPU 401, storage areas such as the memory 402 and the recording medium 405, and the network I/F 403 shown in FIG.
- the second single conversion process corresponds to the case of making it easier to prevent leakage of presence/absence information.
- FIG. 25 is a flowchart showing an example of the second half conversion processing procedure.
- the information processing apparatus 100 acquires the trust vector statistical data 700 (step S2501).
- the information processing apparatus 100 selects one unselected trust item whose number of appearances in the trust vector 500 set ⁇ k from among the trust item group. (Step S2502). Then, the information processing apparatus 100 extracts another trust item relatively similar in appearance number or nature to the selected trust item from the trust item group (step S2503).
- the information processing apparatus 100 selects the trust item with the largest number of appearances in the set of trust requirements 600 from among the extracted trust items (step S2504).
- the information processing apparatus 100 then converts the selected trust item into a cluster that combines the selected trust items, and updates the trust item group (step S2505).
- the information processing apparatus 100 determines whether or not there is a trust item whose number of occurrences ⁇ k that has not yet been selected exists among the trust item group (step S2506).
- step S2506: Yes the information processing apparatus 100 returns to the process of step S2502.
- step S2506: No the information processing apparatus 100 proceeds to the process of step S2507.
- the information processing apparatus 100 generates the anonymization table 1000 based on the trust item group (step S2507). Then, the information processing apparatus 100 ends the second half conversion process. As a result, the information processing apparatus 100 can generate information that serves as a guideline for converting between the trust vector 500 and the trust requirement 600 in order to easily prevent leakage of sensitive information.
- the information processing apparatus 100 it is possible to acquire the first data including presence/absence information indicating the presence/absence of data corresponding to each of the plurality of items included in the first item group.
- the information processing apparatus 100 it is possible to acquire a plurality of second data each including necessity information indicating necessity of data corresponding to each of the plurality of items included in the second item group.
- the information processing apparatus 100 it is possible to request data corresponding to each of the plurality of items included in the second item group based on the plurality of pieces of necessity information included in each of the plurality of acquired pieces of second data. The total number of necessary/unnecessary information to be displayed can be calculated.
- the information processing apparatus 100 based on the calculated total number of necessary/unnecessary information, the total number of necessary/unnecessary information indicating that data corresponding to each of the plurality of items included in the third item group is requested is the reference.
- a third group of items can be generated to be greater than or equal to the number.
- the first data can be converted into the third data including presence/absence information indicating the presence/absence of data corresponding to each of the plurality of items included in the third item group.
- each of the plurality of second data is converted into fourth data including necessity information indicating necessity of data corresponding to each of the plurality of items included in the third item group. be able to.
- the information processing apparatus 100 based on the result of comparing the converted third data and the converted fourth data, the provider of the first data and the provider of the second data are determined. Matching status can be evaluated. As a result, the information processing apparatus 100 can match the provider of the first data and the provider of the second data while facilitating the prevention of leakage of the necessity information, which is sensitive information.
- a plurality of first data each including presence/absence information indicating the presence/absence of data corresponding to each of the plurality of items included in the first item group, and a plurality of second data.
- data corresponding to each of the plurality of items included in the first item group exists based on the plurality of pieces of existence information included in each of the plurality of acquired first data.
- the information processing apparatus 100 based on the calculated total number of necessity information and the calculated total number of existence information, the total number of necessity information is equal to or greater than the first reference number, and the total number of existence information are equal to or greater than the second reference number.
- the information processing apparatus 100 can easily prevent leakage of the necessity information and the presence/absence information, which are sensitive information.
- the information processing apparatus 100 based on the calculated total number of presence/absence information, the total number of presence/absence information indicating that there is data corresponding to each of the plurality of items included in the third item group is the second total.
- a third group of items can be generated to meet or exceed the reference number. As a result, the information processing apparatus 100 can easily prevent leakage of presence/absence information, which is sensitive information.
- the third item group can be generated based on the semantic distance between the items included in the second item group.
- the information processing apparatus 100 can suppress deterioration in matching accuracy while facilitating prevention of leakage of sensitive information.
- data indicated to exist by the presence/absence information included in the third data and data indicated to be requested by the necessity information included in any of the fourth data match or not. According to the information processing apparatus 100, if they match, it can be evaluated that the provider of the first data matches the provider of the second data corresponding to any of the fourth data. Thereby, the information processing apparatus 100 can correctly evaluate the matching.
- the information processing apparatus 100 based on the calculated total number of necessary/unnecessary information, the total number of necessary/unnecessary information indicating that data corresponding to each of the plurality of items included in the third item group is requested is the reference.
- a third set of items can be generated to be the maximum possible number greater than or equal to. Thereby, the information processing apparatus 100 can further facilitate prevention of leakage of sensitive information.
- noise can be added to any of the presence/absence information included in the acquired first data.
- the information processing apparatus 100 can easily prevent leakage of sensitive information.
- the evaluation method described in this embodiment can be realized by executing a program prepared in advance on a computer such as a PC or workstation.
- the evaluation program described in this embodiment is recorded in a computer-readable recording medium and executed by being read from the recording medium by a computer.
- Recording media include a hard disk, flexible disk, CD (Compact Disc)-ROM, MO (Magneto Optical disc), DVD (Digital Versatile Disc), and the like.
- the evaluation program described in this embodiment may be distributed via a network such as the Internet.
- Information Processing Device 101 First Data 102 Second Data 103 Third Data 104 Fourth Data 110, 120, 1500, 1600, 2000, 2100, 2200, 2300 Table 200 Matching System 201 User Side Device 202 Company Side Device 210 Network 400 Bus 401 CPU 402 memory 403 network I/F 404 recording medium I/F 405 recording medium 500 trust vector 600 trust requirement 700 trust vector statistical data 800 trust requirement statistical data 900 statistical table 1000 anonymization table 1100 storage unit 1101 acquisition unit 1102 calculation unit 1103 conversion unit 1104 evaluation unit 1105 output unit 1401, 2101, 2301 Anonymization vector 1402, 2102, 2302 Anonymization requirements
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
情報処理装置(100)は、第2の項目群に含まれる複数の項目それぞれに対応するデータを要求することを示す要否情報の総数を算出する。情報処理装置(100)は、第2の項目群と、要否情報の総数とに基づいて、第3の項目群に含まれる複数の項目それぞれに対応するデータを要求することを示す要否情報の総数がいずれも基準数以上となるよう、第3の項目群を生成する。情報処理装置(100)は、第3の項目群に基づいて、第1のデータ(101)を、第3のデータ(103)に変換する。情報処理装置(100)は、第3の項目群に基づいて、複数の第2のデータ(102)それぞれを、第4のデータ(104)に変換する。情報処理装置(100)は、第3のデータ(103)と第4のデータ(104)それぞれとを比較した結果に基づいて、第1のデータ(101)の提供元と第2のデータ(102)の提供元とのマッチング状況を評価する。
Description
本発明は、評価方法、評価プログラム、および情報処理装置に関する。
従来、ユーザが所定の資格データなどを有するか否かを示す存否情報を含むユーザデータと、企業が所定の資格データなどを要求するか否かを示す要否情報を含む企業データとを照合し、ユーザと企業とのマッチング度合いを評価するサービスがある。
先行技術としては、例えば、撹乱用パラメータを算出し、取得したデータに対して、撹乱用パラメータを用いた不可逆変換を行うことにより、撹乱後のデータを生成するものがある。また、例えば、データベースに含まれる一部または全部の属性値のそれぞれについて、分散2σ^2のラプラス分布に従う値を加算する技術がある。
しかしながら、従来技術では、情報漏洩が生じることがある。例えば、企業データに含まれる要否情報が直接参照不能であっても、異なるユーザデータと、企業データとを照合した結果に基づいて、企業データに含まれる要否情報を推測可能である場合がある。
1つの側面では、本発明は、情報漏洩を防止し易くすることを目的とする。
1つの実施態様によれば、第1の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第1のデータと、第2の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報をそれぞれが含む複数の第2のデータとを取得し、取得した前記複数の第2のデータそれぞれに含まれる複数の要否情報に基づいて、前記第2の項目群に含まれる項目ごとに、当該項目に対応するデータを要求することを示す要否情報の総数を算出し、前記第2の項目群に含まれる複数の項目それぞれと、算出した前記要否情報の総数とに基づいて、データを要求することを示す要否情報の総数がいずれも基準数以上となるよう複数の項目を含む第3の項目群を生成し、前記第1のデータを、前記第3の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第3のデータに変換し、前記複数の第2のデータそれぞれを、前記第3の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報を含む第4のデータに変換し、変換した前記第3のデータと、変換した前記第4のデータそれぞれとを比較した結果に基づいて、前記第1のデータの提供元と、前記第2のデータの提供元とのマッチング状況を評価する評価方法、評価プログラム、および情報処理装置が提案される。
一態様によれば、情報漏洩を防止し易くすることが可能になる。
以下に、図面を参照して、本発明にかかる評価方法、評価プログラム、および情報処理装置の実施の形態を詳細に説明する。
(実施の形態にかかる評価方法の一実施例)
図1は、実施の形態にかかる評価方法の一実施例を示す説明図である。情報処理装置100は、異なる要素間のマッチング状況を評価するシステムにおいて、ある要素に関する情報漏洩を防止し易くすることができるコンピュータである。要素は、例えば、企業である。要素は、例えば、ユーザである。ユーザは、例えば、求職者である。
図1は、実施の形態にかかる評価方法の一実施例を示す説明図である。情報処理装置100は、異なる要素間のマッチング状況を評価するシステムにおいて、ある要素に関する情報漏洩を防止し易くすることができるコンピュータである。要素は、例えば、企業である。要素は、例えば、ユーザである。ユーザは、例えば、求職者である。
従来、ユーザと企業とをマッチングするサービスがある。このサービスでは、例えば、企業に、ユーザの個人情報を参照させる前段階として、ユーザが所定の資格データなどを有するか否かと、企業が所定の資格データなどを要求するか否かとに基づいて、ユーザと企業とを仮にマッチングすることが望まれる場合がある。例えば、ユーザが所定の資格データなどを有するか否かを示す存否情報を含むユーザデータと、企業が所定の資格データなどを要求するか否かを示す要否情報を含む企業データとを照合し、ユーザと企業とのマッチング度合いを評価することが望まれる。
しかしながら、従来では、情報漏洩が生じてしまうという問題がある。例えば、企業データに含まれる要否情報が直接参照不能であっても、異なるユーザデータと、企業データとを照合した結果に基づいて、企業データに含まれる要否情報を推測可能である場合がある。このため、企業の機密情報が漏洩するおそれがある。同様に、ユーザデータに含まれる存否情報が直接参照不能であっても、ユーザデータと、異なる企業データとを照合した結果に基づいて、ユーザデータに含まれる存否情報を推測可能である場合がある。このため、ユーザの個人情報が漏洩するおそれがある。企業の機密情報、または、ユーザの個人情報などのような、第三者から秘匿することが好ましい各種情報は、機微情報と呼ばれることがある。
これに対し、ユーザデータに含まれる存否情報、または、企業データに含まれる要否情報などに、ノイズを加算することにより、情報漏洩が生じるリスクを抑制しようとする手法が考えられるが、ユーザと企業とを精度よくマッチングすることが難しくなる。具体的には、存否情報が示す存否、または、要否情報が示す要否を反転する手法が考えられる。より具体的には、存否情報が1であれば0に反転し、存否情報が0であれば1に反転する手法が考えられる。また、より具体的には、要否情報が1であれば0に反転し、要否情報が0であれば1に反転する手法が考えられる。
そこで、本実施の形態では、存否情報または要否情報に関する項目群を変換することにより、機微情報の漏洩を防止し易くすることができる評価方法について説明する。
(1-1)情報処理装置100は、第1のデータ101を取得する。第1のデータ101は、第1の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む。第1のデータ101は、例えば、第1の要素に対応するデータである。第1の要素は、例えば、ユーザである。第1の項目群は、例えば、ユーザの能力的特徴または身体的特徴などに関する複数の項目を含む。能力的特徴に関する項目は、例えば、所定の資格に関する項目である。存否情報は、項目に対応するデータが存在するか否かを0または1で示すフラグ情報である。
情報処理装置100は、例えば、第1のデータ101を、ユーザが有する他のコンピュータから受信することにより取得する。図1の例では、情報処理装置100は、項目1と項目2と項目3と項目4とのそれぞれに対応するデータの存否を示す存否情報を含む第1のデータ101を、ユーザが有する他のコンピュータから受信することにより取得する。
(1-2)情報処理装置100は、複数の第2のデータ102を取得する。第2のデータ102は、第2の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報を含む。第2のデータ102は、例えば、第2の要素に対応するデータである。第2の要素は、例えば、企業である。第2の項目群は、例えば、企業が要求するユーザの能力的特徴または身体的特徴などに関する複数の項目を含む。能力的特徴に関する項目は、例えば、資格に関する項目である。第2の項目群は、例えば、第1の項目群と一部重複する。第2の項目群は、例えば、第1の項目群と同一である。要否情報は、項目に対応するデータを要求するか否かを0または1で示すフラグ情報である。
情報処理装置100は、例えば、複数の第2のデータ102を、企業が有する他のコンピュータから受信することにより取得する。図1の例では、情報処理装置100は、項目1と項目2と項目3と項目4とのそれぞれに対応するデータの要否を示す要否情報をそれぞれが含む複数の第2のデータ102を、企業が有する他のコンピュータから受信することにより取得する。
(1-3)情報処理装置100は、取得した複数の第2のデータ102それぞれに含まれる複数の要否情報に基づいて、第2の項目群に含まれる複数の項目それぞれに対応するデータを要求することを示す要否情報の総数を算出する。図1の例では、情報処理装置100は、表110に示す、項目1と項目2と項目3と項目4とのそれぞれに対応するデータを要求することを示す要否情報の総数を算出する。これにより、情報処理装置100は、第2の項目群のうち、要否情報が漏洩し易い項目を特定する指針となり、いずれの項目を変換することが好ましいかを判断する指針となる情報を得ることができる。
(1-4)情報処理装置100は、第3の項目群を生成する。第3の項目群は、例えば、ユーザの能力的特徴または身体的特徴などに関する複数の項目を含む。第3の項目群に含まれる項目は、例えば、第2の項目群に含まれる複数の項目それぞれに基づいて生成される。第3の項目群に含まれる項目は、具体的には、第2の項目群に含まれる2以上の項目を組み合わせた新たな項目である。第3の項目群に含まれる項目は、具体的には、第2の項目群に含まれる項目であってもよい。
情報処理装置100は、例えば、第2の項目群に含まれる複数の項目それぞれと、算出した要否情報の総数とに基づいて、第3の項目群を生成する。情報処理装置100は、具体的には、第3の項目群に含まれる複数の項目それぞれに対応するデータを要求することを示す要否情報の総数がいずれも基準数以上となるよう、第3の項目群を生成する。
情報処理装置100は、より具体的には、第2の項目群のうち、データを要求することを示す要否情報の総数が基準数未満である項目を選択した後、他の項目を選択する。そして、情報処理装置100は、より具体的には、選択した2つの項目を組み合わせたクラスタを新たな項目として、第3の項目群に追加する。また、情報処理装置100は、より具体的には、第2の項目群のうち、データを要求することを示す要否情報の総数が基準数以上であり、まだ選択していない項目を、そのまま第3の項目群に追加する。
図1の例では、情報処理装置100は、表120に示すように、データを要求することを示す要否情報の総数がいずれも基準数以上となるよう、項目3および項目4を組み合わせた項目3&4と項目1と項目2とを含む第3の項目群を生成する。
(1-5)情報処理装置100は、第1のデータ101を、第3の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第3のデータ103に変換する。図1の例では、情報処理装置100は、第1のデータ101のうち、項目3に対応するデータの存否を示す存否情報と、項目4に対応するデータの存否を示す存否情報とを組み合わせて、項目3&4に対応するデータの存否を示す存否情報を生成する。そして、情報処理装置100は、生成した存否情報と、項目1に対応するデータの存否を示す存否情報と、項目2に対応するデータの存否を示す存否情報とを含む、第3のデータ103を生成する。
(1-6)情報処理装置100は、複数の第2のデータ102それぞれを、第3の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報を含む第4のデータ104に変換する。図1の例では、情報処理装置100は、第2のデータ102のうち、項目3に対応するデータの要否を示す要否情報と、項目4に対応するデータの要否を示す要否情報とを組み合わせて、項目3&4に対応するデータの要否を示す要否情報を生成する。そして、情報処理装置100は、生成した要否情報と、項目1に対応するデータの要否を示す要否情報と、項目2に対応するデータの要否を示す要否情報とを含む、第4のデータ104を生成する。
(1-7)情報処理装置100は、変換した第3のデータ103と、変換した第4のデータ104それぞれとを比較した結果に基づいて、第1のデータ101の提供元と、第2のデータ102の提供元とのマッチング状況を評価する。情報処理装置100は、例えば、第4のデータ104に含まれる要否情報が要求することを示すデータが存在することを、第3のデータ103に含まれる存否情報が示すか否かを判定する。
情報処理装置100は、例えば、データが存在することを存否情報が示していれば、第3のデータ103の変換元の第1のデータ101の提供元と、第4のデータ104の変換元の第2のデータ102の提供元とがマッチングすると判定する。情報処理装置100は、例えば、データが存在することを存否情報が示していなければ、第3のデータ103の変換元の第1のデータ101の提供元と、第4のデータ104の変換元の第2のデータ102の提供元とがマッチングしないと判定する。
これにより、情報処理装置100は、機微情報の漏洩を防止し易くすることができる。情報処理装置100は、例えば、要否情報の漏洩を防止し易くしつつ、第1の要素と第2の要素とのマッチング状況を評価可能にすることができる。情報処理装置100は、具体的には、要否情報の漏洩を防止し易くしつつ、ユーザと企業とのマッチング状況を評価可能にすることができる。また、情報処理装置100は、存否情報または要否情報にノイズが含まれても、第1の要素と第2の要素とのマッチング状況を評価可能にすることができる。
ここでは、情報処理装置100が、要否情報の漏洩を防止し易くなるよう、データを要求することを示す要否情報の総数がいずれも基準数以上となるよう、第3の項目群を生成する場合について説明したが、これに限らない。例えば、情報処理装置100が、存否情報の漏洩を防止し易くなるよう、データが存在することを示す存否情報の総数がいずれも基準数以上となるよう、第3の項目群を生成する場合があってもよい。この場合の具体例については、例えば、図19~図23を用いて後述する。
また、情報処理装置100が、存否情報および要否情報の漏洩を防止し易くなるよう、データが存在することを示す存否情報の総数と、データを要求することを示す要否情報の総数とがいずれも基準数以上となるよう、第3の項目群を生成する場合があってもよい。この場合の具体例については、例えば、図12~図16を用いて後述する。
(マッチングシステム200の一例)
次に、図2を用いて、図1に示した情報処理装置100を適用した、マッチングシステム200の一例について説明する。
次に、図2を用いて、図1に示した情報処理装置100を適用した、マッチングシステム200の一例について説明する。
図2は、マッチングシステム200の一例を示す説明図である。図2において、マッチングシステム200は、情報処理装置100と、1以上のユーザ側装置201と、1以上の企業側装置202とを含む。
マッチングシステム200において、情報処理装置100とユーザ側装置201とは、有線または無線のネットワーク210を介して接続される。ネットワーク210は、例えば、LAN(Local Area Network)、WAN(Wide Area Network)、インターネットなどである。また、情報処理装置100と企業側装置202とは、有線または無線のネットワーク210を介して接続される。
情報処理装置100は、マッチングサービスを提供するコンピュータである。情報処理装置100は、トラスト項目群のそれぞれのトラスト項目に対応するデータが存在するか否かを示す存否情報を含むトラストベクトルを複数取得する。情報処理装置100は、例えば、トラストベクトルを、それぞれのユーザ側装置201から受信する。トラストベクトルは、例えば、図1に示した第1のデータに対応する。トラストベクトルの一例は、具体的には、図5を用いて後述する。情報処理装置100は、例えば、取得したトラストベクトルを、図7に後述するトラストベクトル統計データ700に纏めて記憶する。
情報処理装置100は、トラスト項目群のそれぞれのトラスト項目に対応するデータを要求するか否かを示す要否情報を含むトラスト要件を複数取得する。情報処理装置100は、例えば、トラスト要件を、それぞれの企業側装置202から受信する。トラスト要件は、例えば、図1に示した第2のデータに対応する。トラスト要件の一例は、具体的には、図6を用いて後述する。情報処理装置100は、例えば、取得したトラスト要件を、図8に後述するトラスト要件統計データ800に纏めて記憶する。
情報処理装置100は、取得したトラストベクトルと、取得したトラスト要件との少なくともいずれかに基づいて、変換元となるトラスト項目群から、変換先となるトラスト項目群を生成する。情報処理装置100は、例えば、取得したトラストベクトルに基づいて、トラスト項目ごとに、データが存在することを示す存否情報の総数を算出する。情報処理装置100は、例えば、存否情報の総数を、図9に後述する統計化テーブル900に記憶する。
情報処理装置100は、例えば、取得したトラスト要件に基づいて、トラスト項目ごとに、データを要求することを示す要否情報の総数を算出する。情報処理装置100は、例えば、要否情報の総数を、図9に後述する統計化テーブル900に記憶する。情報処理装置100は、例えば、存否情報の総数と要否情報の総数とに基づいて、変換先となるトラスト項目群に含まれるトラスト項目ごとに、存否情報の総数と要否情報の総数とが基準数以上になるよう、変換先となるトラスト項目群を生成する。情報処理装置100は、変換先となるトラスト項目群を、図10に後述する匿名化テーブル1000に記憶する。
情報処理装置100は、生成したトラスト項目群に基づいて、トラストベクトルを変換する。情報処理装置100は、生成したトラスト項目群に基づいて、トラスト要件を変換する。情報処理装置100は、変換後のトラストベクトルと、変換後のトラスト要件とに基づいて、ユーザと企業とのマッチング状況を評価する。情報処理装置100は、例えば、サーバ、または、PC(Personal Computer)などである。
ユーザ側装置201は、ユーザが利用するコンピュータである。ユーザ側装置201は、ユーザの操作入力に基づき、トラストベクトルを生成して、情報処理装置100に送信する。ユーザ側装置201は、例えば、サーバ、PC、タブレット端末、または、スマートフォンなどである。
企業側装置202は、企業が利用するコンピュータである。企業側装置202は、企業の操作入力に基づき、トラスト要件を生成して、情報処理装置100に送信する。企業側装置202は、例えば、サーバ、PC、タブレット端末、または、スマートフォンなどである。
(マッチングシステム200の利用例)
次に、図3を用いて、マッチングシステム200の利用例について説明する。
次に、図3を用いて、マッチングシステム200の利用例について説明する。
図3は、マッチングシステム200の利用例を示す説明図である。図3において、企業側装置202は、企業従業員の操作入力に基づき、トラスト項目群に含まれるそれぞれのトラスト項目に対応するデータを要求するか否かを示す要否情報を含むトラスト要件302を生成し、情報処理装置100に送信する。
トラスト項目は、例えば、住所情報である。住所情報に対応するデータは、例えば、住民票である。トラスト項目は、例えば、健康情報である。健康情報に対応するデータは、例えば、健康上問題なしの診断結果である。トラスト項目は、例えば、語学情報である。語学情報に対応するデータは、例えば、規定点数以上のTOEFL受験結果である。これにより、企業は、企業とどのようなユーザとのマッチングを希望するのかを特定可能にすることができる。
情報処理装置100は、トラスト要件302を、企業側装置202から受信する。情報処理装置100は、トラストサービスによって真正性が保証された個人情報から作成されたトラストベクトル301を、ユーザ側装置201から受信する。情報処理装置100は、個人情報を受信し、個人情報に基づいてトラストベクトル301を生成する場合があってもよい。
情報処理装置100は、トラストベクトル301とトラスト要件302とに基づいて、ユーザと企業とのマッチング状況を評価する。情報処理装置100は、ユーザと企業とがマッチングすると評価すると、ユーザの個人情報を企業に提供する。情報処理装置100は、例えば、ユーザの個人情報を加工し、加工された個人情報を、企業側装置202に送信する。企業は、加工された個人情報に基づいて、ユーザの採用可否を判断する。
これにより、情報処理装置100は、ユーザの個人情報を企業に提供する前に、ユーザと企業とのマッチング状況を評価することができ、ユーザの個人情報を無作為に企業に提供することを防止することができる。このため、情報処理装置100は、セキュリティの向上を図ることができる。また、情報処理装置100は、マッチングの際、トラストベクトル301とトラスト要件302とを変換可能であるため、トラストベクトル301とトラスト要件302との漏洩を防止し易くすることができる。
(情報処理装置100のハードウェア構成例)
次に、図4を用いて、情報処理装置100のハードウェア構成例について説明する。
次に、図4を用いて、情報処理装置100のハードウェア構成例について説明する。
図4は、情報処理装置100のハードウェア構成例を示すブロック図である。図4において、情報処理装置100は、CPU(Central Processing Unit)401と、メモリ402と、ネットワークI/F(Interface)403と、記録媒体I/F404と、記録媒体405とを有する。また、各構成部は、バス400によってそれぞれ接続される。
ここで、CPU401は、情報処理装置100の全体の制御を司る。メモリ402は、例えば、ROM(Read Only Memory)、RAM(Random Access Memory)およびフラッシュROMなどを有する。具体的には、例えば、フラッシュROMやROMが各種プログラムを記憶し、RAMがCPU401のワークエリアとして使用される。メモリ402に記憶されるプログラムは、CPU401にロードされることにより、コーディングされている処理をCPU401に実行させる。
ネットワークI/F403は、通信回線を通じてネットワーク210に接続され、ネットワーク210を介して他のコンピュータに接続される。そして、ネットワークI/F403は、ネットワーク210と内部のインターフェースを司り、他のコンピュータからのデータの入出力を制御する。ネットワークI/F403は、例えば、モデムやLANアダプタなどである。
記録媒体I/F404は、CPU401の制御に従って記録媒体405に対するデータのリード/ライトを制御する。記録媒体I/F404は、例えば、ディスクドライブ、SSD(Solid State Drive)、USB(Universal Serial Bus)ポートなどである。記録媒体405は、記録媒体I/F404の制御で書き込まれたデータを記憶する不揮発メモリである。記録媒体405は、例えば、ディスク、半導体メモリ、USBメモリなどである。記録媒体405は、情報処理装置100から着脱可能であってもよい。
情報処理装置100は、上述した構成部の他、例えば、キーボード、マウス、ディスプレイ、プリンタ、スキャナ、マイク、スピーカーなどを有してもよい。また、情報処理装置100は、記録媒体I/F404や記録媒体405を複数有していてもよい。また、情報処理装置100は、記録媒体I/F404や記録媒体405を有していなくてもよい。
(トラストベクトル500の一例)
次に、図5を用いて、トラストベクトル500の一例について説明する。
次に、図5を用いて、トラストベクトル500の一例について説明する。
図5は、トラストベクトル500の一例を示す説明図である。図5に示すように、トラストベクトル500は、例えば、住所情報と健康情報と語学情報とのそれぞれのトラスト項目に対応するデータが存在するか否かを示す存否情報を含む。トラストベクトル500は、ノイズが加算されてもよい。例えば、健康情報に対応するデータが存在するか否かを示す存否情報に、ノイズが加算されていてもよい。
(トラスト要件600の一例)
次に、図6を用いて、トラスト要件600の一例について説明する。
次に、図6を用いて、トラスト要件600の一例について説明する。
図6は、トラスト要件600の一例を示す説明図である。図6に示すように、トラスト要件600は、例えば、住所情報と健康情報と語学情報とのそれぞれのトラスト項目に対応するデータを要求するか否かを示す要否情報を含む。トラスト要件600は、ノイズが加算されてもよい。
(トラストベクトル統計データ700の一例)
次に、図7を用いて、トラストベクトル統計データ700の一例について説明する。トラストベクトル統計データ700は、例えば、図4に示した情報処理装置100のメモリ402や記録媒体405などの記憶領域により実現される。
次に、図7を用いて、トラストベクトル統計データ700の一例について説明する。トラストベクトル統計データ700は、例えば、図4に示した情報処理装置100のメモリ402や記録媒体405などの記憶領域により実現される。
図7は、トラストベクトル統計データ700の一例を示す説明図である。図7に示すように、トラストベクトル統計データ700は、例えば、ユーザごとに、当該ユーザに対応するトラストベクトル500を、レコードとして含む。トラストベクトル統計データ700は、具体的には、ユーザと、それぞれのトラストベクトル500とのフィールドを有する。ユーザのフィールドには、ユーザを識別する識別情報が設定される。トラストベクトル500のフィールドには、トラストベクトル500に対応する存否情報が設定される。
(トラスト要件統計データ800の一例)
次に、図8を用いて、トラスト要件統計データ800の一例について説明する。トラスト要件統計データ800は、例えば、図4に示した情報処理装置100のメモリ402や記録媒体405などの記憶領域により実現される。
次に、図8を用いて、トラスト要件統計データ800の一例について説明する。トラスト要件統計データ800は、例えば、図4に示した情報処理装置100のメモリ402や記録媒体405などの記憶領域により実現される。
図8は、トラスト要件統計データ800の一例を示す説明図である。図8に示すように、トラスト要件統計データ800は、例えば、企業ごとに、当該企業に対応するトラスト要件600を、レコードとして含む。トラスト要件統計データ800は、具体的には、企業と、それぞれのトラスト要件600とのフィールドを有する。企業のフィールドには、企業を識別する識別情報が設定される。トラスト要件600のフィールドには、トラスト要件600に対応する要否情報が設定される。
(統計化テーブル900の記憶内容)
次に、図9を用いて、統計化テーブル900の記憶内容の一例について説明する。統計化テーブル900は、例えば、図4に示した情報処理装置100のメモリ402や記録媒体405などの記憶領域により実現される。
次に、図9を用いて、統計化テーブル900の記憶内容の一例について説明する。統計化テーブル900は、例えば、図4に示した情報処理装置100のメモリ402や記録媒体405などの記憶領域により実現される。
図9は、統計化テーブル900の記憶内容の一例を示す説明図である。図9に示すように、統計化テーブル900は、トラスト項目と、トラストベクトル500と、トラスト要件600とのフィールドを有する。統計化テーブル900は、トラスト項目ごとに各フィールドに情報を設定することにより、統計化情報がレコードとして記憶される。
トラスト項目のフィールドには、トラスト項目が設定される。トラストベクトル500のフィールドには、トラストベクトル500集合のうち、上記トラスト項目に対応するデータが存在することを示す存否情報の総数が設定される。トラスト要件600のフィールドには、トラスト要件600集合のうち、上記トラスト項目に対応するデータを要求することを示す要否情報の総数が設定される。
(匿名化テーブル1000の記憶内容)
次に、図10を用いて、匿名化テーブル1000の記憶内容の一例について説明する。匿名化テーブル1000は、例えば、図4に示した情報処理装置100のメモリ402や記録媒体405などの記憶領域により実現される。
次に、図10を用いて、匿名化テーブル1000の記憶内容の一例について説明する。匿名化テーブル1000は、例えば、図4に示した情報処理装置100のメモリ402や記録媒体405などの記憶領域により実現される。
図10は、匿名化テーブル1000の記憶内容の一例を示す説明図である。図10に示すように、匿名化テーブル1000は、集合化情報と、トラストベクトル500と、トラスト要件600とのフィールドを有する。匿名化テーブル1000は、集合化情報ごとに各フィールドに情報を設定することにより、匿名化情報がレコードとして記憶される。
集合化情報のフィールドには、トラスト項目、または、トラスト項目を組み合わせた新たなトラスト項目となるクラスタが設定される。トラストベクトル500のフィールドには、トラストベクトル500集合のうち、上記トラスト項目に対応するデータが存在することを示す存否情報の総数が設定される。トラスト要件600のフィールドには、トラスト要件600集合のうち、上記トラスト項目に対応するデータを要求することを示す要否情報の総数が設定される。
(企業側装置202のハードウェア構成例)
企業側装置202のハードウェア構成例は、図4に示した情報処理装置100のハードウェア構成例と同様であるため、説明を省略する。
企業側装置202のハードウェア構成例は、図4に示した情報処理装置100のハードウェア構成例と同様であるため、説明を省略する。
(ユーザ側装置201のハードウェア構成例)
ユーザ側装置201のハードウェア構成例は、図4に示した情報処理装置100のハードウェア構成例と同様であるため、説明を省略する。
ユーザ側装置201のハードウェア構成例は、図4に示した情報処理装置100のハードウェア構成例と同様であるため、説明を省略する。
(情報処理装置100の機能的構成例)
次に、図11を用いて、情報処理装置100の機能的構成例について説明する。
次に、図11を用いて、情報処理装置100の機能的構成例について説明する。
図11は、情報処理装置100の機能的構成例を示すブロック図である。情報処理装置100は、記憶部1100と、取得部1101と、算出部1102と、変換部1103と、評価部1104と、出力部1105とを含む。
記憶部1100は、例えば、図4に示したメモリ402や記録媒体405などの記憶領域によって実現される。以下では、記憶部1100が、情報処理装置100に含まれる場合について説明するが、これに限らない。例えば、記憶部1100が、情報処理装置100とは異なる装置に含まれ、記憶部1100の記憶内容が情報処理装置100から参照可能である場合があってもよい。
取得部1101~出力部1105は、制御部の一例として機能する。取得部1101~出力部1105は、具体的には、例えば、図4に示したメモリ402や記録媒体405などの記憶領域に記憶されたプログラムをCPU401に実行させることにより、または、ネットワークI/F403により、その機能を実現する。各機能部の処理結果は、例えば、図4に示したメモリ402や記録媒体405などの記憶領域に記憶される。
記憶部1100は、各機能部の処理において参照され、または更新される各種情報を記憶する。記憶部1100は、第1の項目群を記憶する。第1の項目群は、例えば、ユーザの能力的特徴または身体的特徴などに関する複数の項目を含む。能力的特徴に関する項目は、例えば、所定の資格に関する項目である。第1の項目群に含まれる項目は、具体的には、トラスト項目である。
記憶部1100は、第1のデータを記憶する。記憶部1100は、例えば、第1のデータを複数記憶する。第1のデータは、第1の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む。第1のデータは、例えば、第1の要素に対応するデータである。第1のデータは、具体的には、トラストベクトル500である。第1の要素は、例えば、ユーザである。第1の要素は、具体的には、求職者となるユーザである。第1の要素は、具体的には、試験の受験者となるユーザであってもよい。第1の要素は、具体的には、ある性別のユーザであってもよい。存否情報は、項目に対応するデータが存在するか否かを0または1で示すフラグ情報である。第1のデータは、例えば、取得部1101によって取得される。記憶部1100は、具体的には、第1のデータとしてトラストベクトル500を、トラストベクトル統計データ700に記憶する。
記憶部1100は、第2の項目群を記憶する。第2の項目群は、例えば、企業が要求するユーザの能力的特徴または身体的特徴などに関する複数の項目を含む。能力的特徴に関する項目は、例えば、資格に関する項目である。第2の項目群に含まれる項目は、具体的には、トラスト項目である。第2の項目群は、例えば、第1の項目群と一部重複する。第2の項目群は、例えば、第1の項目群と同一である。
記憶部1100は、第2のデータを1以上記憶する。記憶部1100は、例えば、第2のデータを複数記憶する。第2のデータは、第2の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報含む。第2のデータは、例えば、第2の要素に対応するデータである。第2のデータは、具体的には、トラスト要件600である。第2の要素は、例えば、企業である。第2の要素は、具体的には、従業員を募集する企業である。第2の要素は、具体的には、試験を行う企業などの団体であってもよい。第2の要素は、具体的には、第1の要素とは別の性別のユーザであってもよい。要否情報は、項目に対応するデータを要求するか否かを0または1で示すフラグ情報である。第2のデータは、例えば、取得部1101によって取得される。記憶部1100は、具体的には、第2のデータとしてトラスト要件600を、トラスト要件統計データ800に記憶する。
記憶部1100は、第1の項目群に含まれる複数の項目それぞれに対応するデータが存在することを示す存否情報の総数を記憶する。存否情報の総数は、例えば、算出部1102によって算出される。記憶部1100は、具体的には、存否情報の総数を、統計化テーブル900に記憶する。
記憶部1100は、第2の項目群に含まれる複数の項目それぞれに対応するデータを要求することを示す要否情報の総数を記憶する。要否情報の総数は、例えば、算出部1102によって算出される。記憶部1100は、具体的には、要否情報の総数を、統計化テーブル900に記憶する。
記憶部1100は、第3の項目群を記憶する。第3の項目群は、例えば、ユーザの能力的特徴または身体的特徴などに関する複数の項目を含む。第3の項目群に含まれる項目は、例えば、第2の項目群に含まれる複数の項目それぞれに基づいて生成される。第3の項目群に含まれる項目は、具体的には、第2の項目群に含まれる2以上の項目を組み合わせた新たな項目である。第3の項目群に含まれる項目は、具体的には、第2の項目群に含まれる項目であってもよい。第3の項目群に含まれる項目は、例えば、トラスト項目、または、トラスト項目を組み合わせた新たなトラスト項目となるクラスタである。第3の項目群は、例えば、変換部1103によって生成される。記憶部1100は、具体的には、第3の項目群を、匿名化テーブル1000に記憶する。
記憶部1100は、第3のデータを記憶する。第3のデータは、第1のデータを変換した変換後のデータである。第3のデータは、例えば、変換部1103によって生成される。記憶部1100は、第4のデータを記憶する。第4のデータは、第2のデータを変換した変換後のデータである。第4のデータは、例えば、変換部1103によって生成される。
取得部1101は、各機能部の処理に用いられる各種情報を取得する。取得部1101は、取得した各種情報を、記憶部1100に記憶し、または、各機能部に出力する。また、取得部1101は、記憶部1100に記憶しておいた各種情報を、各機能部に出力してもよい。取得部1101は、例えば、サービス管理者の操作入力に基づき、各種情報を取得する。取得部1101は、例えば、情報処理装置100とは異なる装置から、各種情報を受信してもよい。
取得部1101は、第1のデータを取得する。取得部1101は、例えば、複数の第1のデータを取得する。取得部1101は、具体的には、第1のデータを、ユーザ側装置201から受信することにより取得する。取得部1101は、具体的には、サービス管理者の操作入力に基づいて、第1のデータの入力を受け付けることにより、第1のデータを取得してもよい。サービス管理者は、例えば、情報処理装置100の利用者である。取得部1101は、取得した第1のデータに含まれるいずれかの存否情報にノイズを付与する。これにより、取得部1101は、存否情報の漏洩を防止し易くすることができる。
取得部1101は、第2のデータを取得する。取得部1101は、例えば、複数の第2のデータを取得する。取得部1101は、具体的には、第2のデータを、企業側装置202から受信することにより取得する。取得部1101は、具体的には、サービス管理者の操作入力に基づいて、第2のデータの入力を受け付けることにより、第2のデータを取得してもよい。取得部1101は、取得した第2のデータに含まれるいずれかの要否情報にノイズを付与してもよい。これにより、取得部1101は、要否情報の漏洩を防止し易くすることができる。
取得部1101は、いずれかの機能部の処理を開始する開始トリガーを受け付けてもよい。開始トリガーは、例えば、サービス管理者による所定の操作入力があったことである。開始トリガーは、例えば、他のコンピュータから、所定の情報を受信したことであってもよい。開始トリガーは、例えば、いずれかの機能部が所定の情報を出力したことであってもよい。取得部1101は、具体的には、第1のデータと第2のデータとを取得したことを、算出部1102と変換部1103と評価部1104との処理を開始する開始トリガーとして受け付ける。
算出部1102は、取得した複数の第1のデータそれぞれに含まれる複数の存否情報に基づいて、第1の項目群に含まれる複数の項目それぞれに対応するデータが存在することを示す存否情報の総数を算出する。これにより、算出部1102は、第1の項目群のうち、存否情報が漏洩し易い項目を特定する指針となり、変換部1103でいずれの項目を変換対象とすることが好ましいかを判断する指針となる情報を得ることができる。
算出部1102は、取得した複数の第2のデータそれぞれに含まれる複数の要否情報に基づいて、第2の項目群に含まれる複数の項目それぞれに対応するデータを要求することを示す要否情報の総数を算出する。これにより、算出部1102は、第2の項目群のうち、要否情報が漏洩し易い項目を特定する指針となり、変換部1103でいずれの項目を変換対象とすることが好ましいかを判断する指針となる情報を得ることができる。
変換部1103は、第3の項目群を生成する。変換部1103は、例えば、第2の項目群に含まれる複数の項目それぞれと、算出した要否情報の総数とに基づいて、第3の項目群を生成する。変換部1103は、具体的には、第3の項目群に含まれる複数の項目それぞれに対応するデータを要求することを示す要否情報の総数がいずれも第1の基準数以上となるよう、第3の項目群を生成する。
まず、変換部1103は、より具体的には、第3の項目群を空集合に設定する。次に、変換部1103は、より具体的には、第2の項目群に含まれ、要否情報の総数が第1の基準数未満である項目を選択し、さらに他の項目を選択する。そして、変換部1103は、より具体的には、選択した2つの項目を組み合わせた新たな項目となるクラスタを設定し、第3の項目群に追加する。また、変換部1103は、選択しなかった項目をそのまま第3の項目群に追加する。結果として、変換部1103は、第3の項目群を生成する。これにより、変換部1103は、要否情報の漏洩を防止し易くするために、第1のデータと第2のデータとを変換する指針を得ることができる。
変換部1103は、例えば、第1の項目群に含まれる複数の項目それぞれと、算出した存否情報の総数とに基づいて、第3の項目群を生成する。変換部1103は、具体的には、第3の項目群に含まれる複数の項目それぞれに対応するデータが存在することを示す存否情報の総数がいずれも第2の基準数以上となるよう、第3の項目群を生成する。
まず、変換部1103は、より具体的には、第3の項目群を空集合に設定する。次に、変換部1103は、より具体的には、第1の項目群に含まれ、存否情報の総数が第2の基準数未満である項目を選択し、さらに他の項目を選択する。そして、変換部1103は、より具体的には、選択した2つの項目を組み合わせた新たな項目となるクラスタを設定し、第3の項目群に追加する。また、変換部1103は、選択しなかった項目をそのまま第3の項目群に追加する。結果として、変換部1103は、第3の項目群を生成する。これにより、変換部1103は、存否情報の漏洩を防止し易くするために、第1のデータと第2のデータとを変換する指針を得ることができる。
変換部1103は、例えば、第1の項目群に含まれる複数の項目それぞれ、または第2の項目群に含まれる複数の項目それぞれと、算出した要否情報の総数と、算出した存否情報の総数とに基づいて、第3の項目群を生成する。変換部1103は、具体的には、第3の項目群に含まれる複数の項目それぞれについて、要否情報の総数がいずれも第1の基準数以上となり、かつ、存否情報の総数がいずれも第2の基準数以上となるよう、第3の項目群を生成する。
まず、変換部1103は、より具体的には、第3の項目群を空集合に設定する。次に、変換部1103は、より具体的には、第2の項目群に含まれ、要否情報の総数が第1の基準数未満である項目を選択し、さらに他の項目を選択する。そして、変換部1103は、より具体的には、選択した2つの項目を組み合わせた新たな項目となるクラスタを設定し、第3の項目群に追加する。また、変換部1103は、選択しなかった項目をそのまま第3の項目群に追加する。
さらに、変換部1103は、より具体的には、第3の項目群に含まれ、存否情報の総数が第2の基準数未満である項目を選択し、さらに他の項目を選択する。そして、変換部1103は、より具体的には、選択した2つの項目を組み合わせた新たな項目となるクラスタを設定し、第3の項目群に、選択した2つの項目の代わりに追加する。結果として、変換部1103は、第3の項目群を生成する。これにより、変換部1103は、存否情報および要否情報の漏洩を防止し易くするために、第1のデータと第2のデータとを変換する指針を得ることができる。
まず、変換部1103は、より具体的には、第3の項目群を空集合に設定する。次に、変換部1103は、より具体的には、第1の項目群に含まれ、存否情報の総数が第2の基準数未満である項目を選択し、さらに他の項目を選択する。そして、変換部1103は、より具体的には、選択した2つの項目を組み合わせた新たな項目となるクラスタを設定し、第3の項目群に追加する。また、変換部1103は、選択しなかった項目をそのまま第3の項目群に追加する。
さらに、変換部1103は、より具体的には、第3の項目群に含まれ、要否情報の総数が第1の基準数未満である項目を選択し、さらに他の項目を選択する。そして、変換部1103は、より具体的には、選択した2つの項目を組み合わせた新たな項目となるクラスタを設定し、第3の項目群に、選択した2つの項目の代わりに追加する。結果として、変換部1103は、第3の項目群を生成する。これにより、変換部1103は、存否情報および要否情報の漏洩を防止し易くするために、第1のデータと第2のデータとを変換する指針を得ることができる。
この際、変換部1103は、例えば、第1の項目群に含まれる項目間の意味的距離、または、第2の項目群に含まれる項目間の意味的距離に基づいて、第3の項目群を生成してもよい。変換部1103は、具体的には、第2の項目群に含まれる項目を選択するにあたり、第2の項目群に含まれ、要否情報の総数が第1の基準数未満である項目を選択し、さらに当該項目と意味的距離が比較的近しい他の項目を選択してもよい。これにより、変換部1103は、存否情報および要否情報の漏洩をさらに防止し易くすることを可能にすることができる。
また、変換部1103は、具体的には、第1の項目群に含まれる項目を選択するにあたり、第1の項目群に含まれ、存否情報の総数が第2の基準数未満である項目を選択し、さらに当該項目と意味的距離が近しい他の項目を選択してもよい。これにより、変換部1103は、存否情報および要否情報の漏洩をさらに防止し易くすることを可能にすることができる。
この際、変換部1103は、例えば、第3の項目群に含まれる複数の項目それぞれに対応するデータが存在することを示す存否情報の総数がいずれも基準数以上で取り得る最大数となるよう、第3の項目群を生成してもよい。総数が大きいほど、機微情報を秘匿し易くなると考えられる。具体的には、例えば、第1の項目群が、項目a、項目b、項目cを含むとする。項目aに対応するデータが存在することを示す存否情報の数1、項目bに対応するデータが存在することを示す存否情報の数2、項目cに対応するデータが存在することを示す存否情報の数3とする。この際、第3の項目群に含まれる項目を、項目aと項目bとの組み合わせにすると、当該組み合わせに対応するデータが存在することを示す存否情報の総数3になる。一方で、第3の項目群に含まれる項目を、項目aと項目cとの組み合わせにすると、当該組み合わせに対応するデータが存在することを示す存否情報の総数4になる。従って、変換部1103は、第3の項目群に含まれる項目を、項目aと項目cとの組み合わせにし、総数を相対的に大きくすることが好ましいと判断し、第3の項目群を生成する。これにより、変換部1103は、存否情報および要否情報の漏洩をさらに防止し易くすることを可能にすることができる。
この際、変換部1103は、例えば、第3の項目群に含まれる複数の項目それぞれに対応するデータを要求することを示す要否情報の総数がいずれも基準数以上で取り得る最大数となるよう、第3の項目群を生成してもよい。これにより、変換部1103は、存否情報および要否情報の漏洩をさらに防止し易くすることを可能にすることができる。
変換部1103は、第1のデータを、第3の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第3のデータに変換する。これにより、変換部1103は、存否情報または要否情報の漏洩を防止し易くしつつ、第1のデータの提供元と第2のデータの提供元とのマッチング状況を評価可能にすることができる。
変換部1103は、第2のデータを、第3の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報を含む第4のデータに変換する。これにより、変換部1103は、存否情報または要否情報の漏洩を防止し易くしつつ、第1のデータの提供元と第2のデータの提供元とのマッチング状況を評価可能にすることができる。
評価部1104は、変換した第3のデータと、変換した第4のデータそれぞれとを比較した結果に基づいて、第1のデータの提供元と、第2のデータの提供元とのマッチング状況を評価する。評価部1104は、例えば、第3のデータに含まれる存否情報によって存在することが示されたデータと、第4のデータのいずれかに含まれる要否情報によって要求することが示されたデータとが一致するか否かを判定する。
そして、評価部1104は、例えば、一致すれば、第1のデータの提供元と、第4のデータのいずれかに対応する第2のデータの提供元とがマッチングすると評価する。評価部1104は、具体的には、ユーザと企業とがマッチングすると評価する。これにより、評価部1104は、第1のデータの提供元と、第2のデータの提供元とのマッチング状況を評価することができる。
評価部1104は、変換した第3のデータと、変換した第4のデータそれぞれとを比較した結果に基づいて、第1のデータの提供元と、第2のデータの提供元とのマッチング度合いを算出してもよい。評価部1104は、例えば、第3のデータに含まれる存否情報によって存在することが示されたデータと、第4のデータのいずれかに含まれる要否情報によって要求することが示されたデータとが一致するか否かを判定する。
そして、評価部1104は、一致した数が多いほど、マッチング度合いが大きくなるよう、第1のデータの提供元と第2のデータの提供元とのマッチング度合いを算出する。評価部1104は、具体的には、ユーザと企業とのマッチング度合いを算出する。これにより、評価部1104は、第1のデータの提供元と、第2のデータの提供元とのマッチング状況を評価することができる。
出力部1105は、少なくともいずれかの機能部の処理結果を出力する。出力形式は、例えば、ディスプレイへの表示、プリンタへの印刷出力、ネットワークI/F403による外部装置への送信、または、メモリ402や記録媒体405などの記憶領域への記憶である。これにより、出力部1105は、少なくともいずれかの機能部の処理結果をサービス管理者に通知可能にし、情報処理装置100の利便性の向上を図ることができる。
出力部1105は、例えば、第1のデータの提供元と、第2のデータの提供元とのマッチング状況を評価した結果を出力する。出力部1105は、例えば、第1のデータの提供元と、第2のデータの提供元とのマッチング状況を評価した結果を、第2のデータの提供元が参照可能に出力する。出力部1105は、具体的には、第1のデータの提供元と、第2のデータの提供元とのマッチング度合いを算出した結果を、第2のデータの提供元が参照可能に出力してもよい。これにより、出力部1105は、マッチング状況を利用可能にすることができる。
(情報処理装置100の第1の動作例)
次に、図12および図13を用いて、情報処理装置100の第1の動作例について説明する。第1の動作例は、情報処理装置100が、データが存在することを示す存否情報の総数と、データを要求することを示す要否情報の総数とに基づいて、存否情報と要否情報との漏洩を防止し易くする場合における動作例である。
次に、図12および図13を用いて、情報処理装置100の第1の動作例について説明する。第1の動作例は、情報処理装置100が、データが存在することを示す存否情報の総数と、データを要求することを示す要否情報の総数とに基づいて、存否情報と要否情報との漏洩を防止し易くする場合における動作例である。
図12および図13は、情報処理装置100の第1の動作例を示す説明図である。図12において、情報処理装置100は、複数のトラストベクトル500と、複数のトラスト要件600とを取得する。情報処理装置100は、例えば、ユーザAとユーザBとユーザCとのトラストベクトル500などを取得する。情報処理装置100は、例えば、企業X社と企業Y社と企業Z社とのトラスト要件600などを取得する。
(12-1)情報処理装置100は、取得した複数のトラストベクトル500を、トラストベクトル統計データ700に纏めて記憶する。情報処理装置100は、トラストベクトル統計データ700に基づいて、トラスト項目ごとに、データが存在することを示す存否情報の出現数を算出し、統計化テーブル900に記憶する。
(12-2)情報処理装置100は、取得したトラスト要件600を、トラスト要件統計データ800に纏めて記憶する。情報処理装置100は、トラスト要件統計データ800に基づいて、トラスト項目ごとに、データを要求することを示す要否情報の出現数を算出し、統計化テーブル900に記憶する。
これにより、情報処理装置100は、漏洩の可能性が比較的高いトラスト項目を特定することができる。情報処理装置100は、例えば、算出したいずれかの出現数がk未満であるトラスト項目を、存否情報または要否情報の漏洩の可能性が比較的高いトラスト項目として特定する。kは、例えば、2である。
ここで、情報処理装置100は、統計化テーブル900を参照して、トラスト項目を結合してk-匿名化を行うことにより、存否情報または要否情報の漏洩の可能性の低減化を図ることにする。次に、図13の説明に移行する。
図13において、(13-1)情報処理装置100は、算出した出現数がk未満であるトラスト項目を選択した後、他のトラスト項目を選択し、選択した2つのトラスト項目を組み合わせて、新たなトラスト項目となるクラスタを生成する。情報処理装置100は、生成した新たなトラスト項目となるクラスタを、匿名化テーブル1000に記憶する。情報処理装置100は、選択しなかったトラスト項目があれば、当該トラスト項目をそのまま匿名化テーブル1000に記憶する。
図13の例では、情報処理装置100は、存否情報の出現数がk未満である健康情報を選択し、健康情報と意味的距離が比較的近しい住所情報を選択し、健康情報と住所情報とを組み合わせた新たなトラスト項目となるクラスタを生成する。また、情報処理装置100は、要否情報の出現数がk未満である語学情報2を選択し、語学情報2と意味的距離が比較的近しい語学情報1を選択し、語学情報1と語学情報2とを組み合わせた新たなトラスト項目となるクラスタを生成する。
そして、情報処理装置100は、新たなトラスト項目となるクラスタを、匿名化テーブル1000に記憶する。匿名化テーブル1000に示すように、新たなトラスト項目となるクラスタに対応する存否情報の出現数および要否情報の出現数は、共にk以上である。このため、情報処理装置100は、k-匿名化を行うことができ、存否情報および要否情報の漏洩を防止し易くすることができる。また、情報処理装置100は、存否情報にノイズが加算されていても、ユーザと企業とをマッチング可能にすることができる。マッチングの具体例については、例えば、図14~図16を用いて後述する。
ここでは、情報処理装置100が、選択したトラスト項目と意味的距離が比較的近しい他のトラスト項目を選択する場合について説明したが、これに限らない。例えば、情報処理装置100が、選択したトラスト項目と出現数が比較的近しい他のトラスト項目を選択する場合があってもよい。
(動作例1におけるマッチングの具体例)
次に、図14~図16を用いて、動作例1におけるマッチングの具体例について説明する。
次に、図14~図16を用いて、動作例1におけるマッチングの具体例について説明する。
図14~図16は、動作例1におけるマッチングの具体例を示す説明図である。図14において、(14-1)情報処理装置100は、匿名化テーブル1000に基づいて、ユーザA氏のトラストベクトル500と、ユーザB氏のトラストベクトル500とを、匿名化ベクトル1401に変換する。
情報処理装置100は、具体的には、匿名化テーブル1000に基づいて、ユーザA氏のトラストベクトル500に含まれる住所情報の存否情報と健康情報の存否情報とを結合して、住所情報と健康情報とのクラスタの存否情報に変換する。情報処理装置100は、具体的には、匿名化テーブル1000に基づいて、ユーザA氏のトラストベクトル500に含まれる語学情報1の存否情報と語学情報2の存否情報とを結合して、語学情報1と語学情報2とのクラスタの存否情報に変換する。
情報処理装置100は、具体的には、ユーザA氏のトラストベクトル500に、語学情報1の存否情報と語学情報2の存否情報とのいずれかのみが含まれる場合、語学情報1の存否情報と語学情報2の存否情報とのいずれかを、クラスタの存否情報として扱う。このように、情報処理装置100は、ユーザA氏のトラストベクトル500を、ユーザA氏の匿名化ベクトル1401に変換する。
(14-2)情報処理装置100は、匿名化テーブル1000に基づいて、企業X社のトラスト要件600と、企業Y社のトラスト要件600とを、匿名化要件1402に変換する。
情報処理装置100は、具体的には、匿名化テーブル1000に基づいて、企業X社のトラスト要件600に含まれる住所情報の要否情報と健康情報の要否情報とを結合して、住所情報と健康情報とのクラスタの要否情報に変換する。情報処理装置100は、具体的には、匿名化テーブル1000に基づいて、企業X社のトラスト要件600に含まれる語学情報1の要否情報と語学情報2の要否情報とを結合して、語学情報1と語学情報2とのクラスタの要否情報に変換する。
情報処理装置100は、具体的には、企業X社のトラスト要件600に、語学情報1の要否情報と語学情報2の要否情報とのいずれかのみが含まれる場合、語学情報1の要否情報と語学情報2の要否情報とのいずれかを、クラスタの要否情報として扱う。このように、情報処理装置100は、企業X社のトラスト要件600を、企業X社の匿名化要件1402に変換する。次に、図15の説明に移行する。
図15において、トラストベクトル500とトラスト要件600とを直接参照して、ユーザと企業とをマッチングする場合について説明する。例えば、企業のトラスト要件600に含まれる要否情報が、データを要求することを示すトラスト項目のすべてについて、ユーザのトラストベクトル500に含まれる存否情報が、データが存在することを示していれば、企業とユーザとがマッチングされる。
この場合、企業X社は、要求するデータの種類が比較的多いため、表1500に示すように、企業X社とマッチングするユーザが少なくなるという課題がある。ユーザA氏が、健康情報を秘匿することを望み、健康情報の存否情報にノイズを付与した場合、表1500に示すように、企業X社とユーザA氏とがマッチングしないことになるという課題がある。
企業Y社は、語学情報2に対応する独語検定を要求するが、表1500に示すように、企業Y社とユーザB氏のみとがマッチングすることにより、独語検定を要求するという機微情報が漏洩し易くなるという課題がある。ユーザB氏は、健康情報に比較的些末な問題を有するだけで、表1500に示すように、企業X社とマッチングしないことになるという課題がある。次に、図16の説明に移行する。
図16において、匿名化ベクトルと匿名化要件とに基づいて、ユーザと企業とをマッチングする場合について説明する。情報処理装置100は、例えば、企業の要件に含まれる要否情報が、データを要求することを示すトラスト項目のすべてについて、ユーザの匿名化ベクトルに含まれる存否情報が、データが存在することを示しているか否かを判定する。情報処理装置100は、トラスト項目のすべてについて、データが存在することを示していれば、企業とユーザとがマッチングすると評価する。
この場合、図15の例とは異なり、企業X社は、表1600に示すように、比較的多くのユーザとマッチング可能である。図15の例とは異なり、ユーザA氏が、健康情報を秘匿することを望み、健康情報の存否情報にノイズを付与していても、表1600に示すように、企業X社とユーザA氏とはマッチング可能である。
図15の例とは異なり、表1600に示すように、企業Y社とユーザB氏以外ともマッチングするため、企業Y社が、独語検定を要求するという機微情報が漏洩することを防止し易くなる。図15の例とは異なり、ユーザB氏は、健康情報に比較的些末な問題を有していても、表1600に示すように、企業X社とマッチング可能である。このように、情報処理装置100は、機微情報の漏洩を防止し易くしつつ、ユーザと企業とを効果的にマッチング可能にすることができる。
(両変換処理手順)
次に、図17および図18を用いて、情報処理装置100が実行する、両変換処理手順の一例について説明する。両変換処理は、例えば、図4に示したCPU401と、メモリ402や記録媒体405などの記憶領域と、ネットワークI/F403とによって実現される。
次に、図17および図18を用いて、情報処理装置100が実行する、両変換処理手順の一例について説明する。両変換処理は、例えば、図4に示したCPU401と、メモリ402や記録媒体405などの記憶領域と、ネットワークI/F403とによって実現される。
図17および図18は、両変換処理手順の一例を示すフローチャートである。図17において、情報処理装置100は、トラスト要件統計データ800を取得する(ステップS1701)。
次に、情報処理装置100は、取得したトラスト要件統計データ800に基づいて、トラスト項目群のうち、まだ選択していない、トラスト要件600集合における出現数<kであるトラスト項目を1つ選択する(ステップS1702)。そして、情報処理装置100は、トラスト項目群のうち、選択したトラスト項目と出現数または性質が比較的近しい別のトラスト項目を抽出する(ステップS1703)。
次に、情報処理装置100は、抽出したトラスト項目のうち、トラストベクトル500集合における出現数が最も大きくなるトラスト項目を選択する(ステップS1704)。そして、情報処理装置100は、選択したトラスト項目を、選択したトラスト項目を組み合わせたクラスタに変換し、トラスト項目群を更新する(ステップS1705)。
次に、情報処理装置100は、トラスト項目群のうち、まだ選択していない出現数<kであるトラスト項目が存在するか否かを判定する(ステップS1706)。ここで、まだ選択していない出現数<kであるトラスト項目が存在する場合(ステップS1706:Yes)、情報処理装置100は、ステップS1702の処理に戻る。一方で、選択していない出現数<kであるトラスト項目が存在しない場合(ステップS1706:No)、情報処理装置100は、図18のステップS1801の処理に移行する。
図18において、情報処理装置100は、トラストベクトル統計データ700を取得する(ステップS1801)。
次に、情報処理装置100は、取得したトラストベクトル統計データ700に基づいて、トラスト項目群のうち、まだ選択していない、トラストベクトル500集合における出現数<kであるトラスト項目を1つ選択する(ステップS1802)。そして、情報処理装置100は、トラスト項目群のうち、選択したトラスト項目と出現数または性質が比較的近しい別のトラスト項目を抽出する(ステップS1803)。
次に、情報処理装置100は、抽出したトラスト項目のうち、トラスト要件600集合における出現数が最も大きくなるトラスト項目を選択する(ステップS1804)。そして、情報処理装置100は、選択したトラスト項目を、選択したトラスト項目を組み合わせたクラスタに変換し、トラスト項目群を更新する(ステップS1805)。
次に、情報処理装置100は、トラスト項目群のうち、まだ選択していない出現数<kであるトラスト項目が存在するか否かを判定する(ステップS1806)。ここで、まだ選択していない出現数<kであるトラスト項目が存在する場合(ステップS1806:Yes)、情報処理装置100は、ステップS1802の処理に戻る。一方で、選択していない出現数<kであるトラスト項目が存在しない場合(ステップS1806:No)、情報処理装置100は、ステップS1807の処理に移行する。
ステップS1807では、情報処理装置100は、トラスト項目群に基づいて、匿名化テーブル1000を生成する(ステップS1807)。そして、情報処理装置100は、両変換処理を終了する。これにより、情報処理装置100は、機微情報の漏洩を防止し易くすることができる。
(情報処理装置100の第2の動作例)
次に、図19を用いて、情報処理装置100の第2の動作例について説明する。第2の動作例は、情報処理装置100が、データが存在することを示す存否情報の総数と、データを要求することを示す要否情報の総数とのいずれかに基づいて、存否情報と要否情報とのいずれかの漏洩を防止し易くする場合における動作例である。
次に、図19を用いて、情報処理装置100の第2の動作例について説明する。第2の動作例は、情報処理装置100が、データが存在することを示す存否情報の総数と、データを要求することを示す要否情報の総数とのいずれかに基づいて、存否情報と要否情報とのいずれかの漏洩を防止し易くする場合における動作例である。
図19は、情報処理装置100の第2の動作例を示す説明図である。図19において、情報処理装置100は、複数のトラストベクトル500と、複数のトラスト要件600とを取得する。情報処理装置100は、例えば、ユーザAとユーザBとユーザCとのトラストベクトル500などを取得する。情報処理装置100は、例えば、企業X社と企業Y社と企業Z社とのトラスト要件600などを取得する。
(19-1)情報処理装置100は、取得した複数のトラストベクトル500を、トラストベクトル統計データ700に纏めて記憶する。情報処理装置100は、トラストベクトル統計データ700に基づいて、トラスト項目ごとに、データが存在することを示す存否情報の出現数を算出し、統計化テーブル900に記憶する。
(19-2)情報処理装置100は、取得したトラスト要件600を、トラスト要件統計データ800に纏めて記憶する。情報処理装置100は、トラスト要件統計データ800に基づいて、トラスト項目ごとに、データを要求することを示す要否情報の出現数を算出し、統計化テーブル900に記憶する。これにより、情報処理装置100は、漏洩の可能性が比較的高いトラスト項目を特定することができる。
ここで、トラストベクトル500に含まれる存否情報と、トラスト要件600に含まれる要否情報とのうち、トラストベクトル500に含まれる存否情報の漏洩を防止し易くすることが望まれる第1の状況が考えられる。一方で、トラストベクトル500に含まれる存否情報と、トラスト要件600に含まれる要否情報とのうち、トラスト要件600に含まれる要否情報の漏洩を防止し易くすることが望まれる第2の状況が考えられる。
(19-3)第1の状況では、情報処理装置100は、算出した存否情報の出現数がk未満であるトラスト項目を選択した後、他のトラスト項目を選択し、選択した2つのトラスト項目を組み合わせて、新たなトラスト項目となるクラスタを生成する。そして、情報処理装置100は、生成した新たなトラスト項目となるクラスタを、匿名化テーブル1000-1に記憶する。情報処理装置100は、選択しなかったトラスト項目があれば、当該トラスト項目をそのまま匿名化テーブル1000-1に記憶する。
図19の例では、情報処理装置100は、存否情報の出現数がk未満である健康情報を選択し、健康情報と意味的距離が比較的近しい住所情報を選択し、健康情報と住所情報とを組み合わせた新たなトラスト項目となるクラスタを生成する。そして、情報処理装置100は、選択しなかった語学情報1および語学情報2と、生成した新たなトラスト項目となるクラスタとを、匿名化テーブル1000-1に記憶する。
匿名化テーブル1000-1に示すように、新たなトラスト項目となるクラスタに対応する存否情報の出現数は、k以上である。このため、情報処理装置100は、k-匿名化を行うことができ、存否情報の漏洩を防止し易くすることができる。また、情報処理装置100は、存否情報にノイズが加算されていても、ユーザと企業とをマッチング可能にすることができる。マッチングの具体例については、例えば、図22および図23を用いて後述する。
(19-4)第2の状況では、情報処理装置100は、算出した要否情報の出現数がk未満であるトラスト項目を選択した後、他のトラスト項目を選択し、選択した2つのトラスト項目を組み合わせて、新たなトラスト項目となるクラスタを生成する。そして、情報処理装置100は、生成した新たなトラスト項目となるクラスタを、匿名化テーブル1000-2に記憶する。情報処理装置100は、選択しなかったトラスト項目があれば、当該トラスト項目をそのまま匿名化テーブル1000-2に記憶する。
図19の例では、情報処理装置100は、要否情報の出現数がk未満である語学情報2を選択し、語学情報2と意味的距離が比較的近しい語学情報1を選択し、健康情報と住所情報とを組み合わせた新たなトラスト項目となるクラスタを生成する。そして、情報処理装置100は、選択しなかった住所情報および健康情報と、生成した新たなトラスト項目となるクラスタとを、匿名化テーブル1000-2に記憶する。
匿名化テーブル1000-2に示すように、新たなトラスト項目となるクラスタに対応する要否情報の出現数は、k以上である。このため、情報処理装置100は、k-匿名化を行うことができ、要否情報の漏洩を防止し易くすることができる。また、情報処理装置100は、要否情報にノイズが加算されていても、ユーザと企業とをマッチング可能にすることができる。マッチングの具体例については、例えば、図20および図21を用いて後述する。
ここでは、情報処理装置100が、トラスト項目ごとに、データが存在することを示す存否情報の出現数と、データを要求することを示す要否情報の出現数とを算出し、統計化テーブル900に記憶する場合について説明したが、これに限らない。例えば、存否情報の漏洩を防止し易くする際、情報処理装置100は、データを要求することを示す要否情報の出現数を算出しなくてもよい。例えば、要否情報の漏洩を防止し易くする際、情報処理装置100は、データが存在することを示す存否情報の出現数を算出しなくてもよい。
(動作例2におけるマッチングの具体例)
次に、図20~図23を用いて、動作例2におけるマッチングの具体例について説明する。まず、例えば、図20および図21を用いて、要否情報の漏洩を防止し易くする場合のマッチングの具体例について説明する。
次に、図20~図23を用いて、動作例2におけるマッチングの具体例について説明する。まず、例えば、図20および図21を用いて、要否情報の漏洩を防止し易くする場合のマッチングの具体例について説明する。
図20および図21は、要否情報の漏洩を防止し易くする場合のマッチングの具体例を示す説明図である。図20において、トラストベクトル500とトラスト要件600とを直接参照して、ユーザと企業とをマッチングする場合について説明する。
例えば、企業のトラスト要件600に含まれる要否情報が、データを要求することを示すトラスト項目のすべてについて、ユーザのトラストベクトル500に含まれる存否情報が、データが存在することを示していれば、企業とユーザとがマッチングされる。
この場合、語学情報2に対応する要否情報の出現数が1であるため、表2000に示すように、企業Y社とユーザB氏のみとがマッチングすることにより、企業Y社が独語検定を要求するという機微情報が漏洩し易くなるという課題がある。次に、図21の説明に移行する。
図21において、(21-1)情報処理装置100は、匿名化テーブル1000に基づいて、ユーザA氏のトラストベクトル500と、ユーザB氏のトラストベクトル500とを、匿名化ベクトル2101に変換する。情報処理装置100は、具体的には、匿名化テーブル1000に基づいて、ユーザA氏のトラストベクトル500に含まれる語学情報1の存否情報と語学情報2の存否情報とを結合して、語学情報1と語学情報2とのクラスタの存否情報に変換する。このように、情報処理装置100は、ユーザA氏のトラストベクトル500を、ユーザA氏の匿名化ベクトル2101に変換する。
(21-2)情報処理装置100は、匿名化テーブル1000に基づいて、企業X社のトラスト要件600と、企業Y社のトラスト要件600とを、匿名化要件2102に変換する。情報処理装置100は、具体的には、匿名化テーブル1000に基づいて、企業X社のトラスト要件600に含まれる語学情報1の要否情報と語学情報2の要否情報とを結合して、語学情報1と語学情報2とのクラスタの要否情報に変換する。このように、情報処理装置100は、企業X社のトラスト要件600を、企業X社の匿名化要件2102に変換する。
(21-3)情報処理装置100は、企業の匿名化要件に含まれる要否情報が、データを要求することを示すトラスト項目のすべてについて、ユーザの匿名化ベクトルに含まれる存否情報が、データが存在することを示しているか否かを判定する。情報処理装置100は、トラスト項目のすべてについて、データが存在することを示していれば、企業とユーザとがマッチングすると評価する。
図21の例では、図20の例とは異なり、表2100に示すように、企業Y社とユーザB氏以外ともマッチングするため、企業Y社が独語検定を要求するという機微情報が漏洩することを防止し易くなる。このように、情報処理装置100は、機微情報の漏洩を防止し易くしつつ、ユーザと企業とを効果的にマッチング可能にすることができる。また、情報処理装置100は、存否情報に関してトラスト項目を結合しないため、処理量の低減化を図ることができる。また、情報処理装置100は、存否情報に関してトラスト項目を結合しないため、マッチング精度の低下を抑制することができる。
次に、例えば、図22および図23を用いて、存否情報の漏洩を防止し易くする場合のマッチングの具体例について説明する。
図22および図23は、存否情報の漏洩を防止し易くする場合のマッチングの具体例を示す説明図である。図22において、トラストベクトル500とトラスト要件600とを直接参照して、ユーザと企業とをマッチングする場合について説明する。
例えば、企業のトラスト要件600に含まれる存否情報が、データを要求することを示すトラスト項目のすべてについて、ユーザのトラストベクトル500に含まれる存否情報が、データが存在することを示していれば、企業とユーザとがマッチングされる。
この場合、健康情報に対応する存否情報の出現数が1であるため、表2200に示すように、ユーザB氏が企業Y社とのみマッチングすることにより、ユーザB氏が健康情報に比較的些末な問題を有するという機微情報が漏洩し易くなるという課題がある。次に、図23の説明に移行する。
図23において、(23-1)情報処理装置100は、匿名化テーブル1000に基づいて、ユーザA氏のトラストベクトル500と、ユーザB氏のトラストベクトル500とを、匿名化ベクトル2301に変換する。情報処理装置100は、具体的には、匿名化テーブル1000に基づいて、ユーザA氏のトラストベクトル500に含まれる住所情報の存否情報と健康情報の存否情報とを結合して、住所情報と健康情報とのクラスタの存否情報に変換する。このように、情報処理装置100は、ユーザA氏のトラストベクトル500を、ユーザA氏の匿名化ベクトル2301に変換する。
(23-2)情報処理装置100は、匿名化テーブル1000に基づいて、企業X社のトラスト要件600と、企業Y社のトラスト要件600とを、匿名化要件2302に変換する。情報処理装置100は、具体的には、テーブル1000に基づいて、企業X社のトラスト要件600に含まれる住所情報の要否情報と健康情報の要否情報とを結合して、住所情報と健康情報とのクラスタの要否情報に変換する。このように、情報処理装置100は、企業X社のトラスト要件600を、企業X社の匿名化要件2302に変換する。
(23-3)情報処理装置100は、企業の匿名化要件に含まれる要否情報が、データを要求することを示すトラスト項目のすべてについて、ユーザの匿名化ベクトルに含まれる存否情報が、データが存在することを示しているか否かを判定する。情報処理装置100は、トラスト項目のすべてについて、データが存在することを示していれば、企業とユーザとがマッチングすると評価する。
図23の例では、図22の例とは異なり、表2300に示すように、企業Y社がユーザB氏以外ともマッチングすることにより、ユーザB氏が健康情報に比較的些末な問題を有するという機微情報が漏洩することを防止し易くなる。このように、情報処理装置100は、機微情報の漏洩を防止し易くしつつ、ユーザと企業とを効果的にマッチング可能にすることができる。また、情報処理装置100は、要否情報に関してトラスト項目を結合しないため、処理量の低減化を図ることができる。また、情報処理装置100は、要否情報に関してトラスト項目を結合しないため、マッチング精度の低下を抑制することができる。
(第1の片変換処理手順)
次に、図24を用いて、情報処理装置100が実行する、第1の片変換処理手順の一例について説明する。第1の片変換処理は、例えば、図4に示したCPU401と、メモリ402や記録媒体405などの記憶領域と、ネットワークI/F403とによって実現される。第1の片変換処理は、要否情報の漏洩を防止し易くする場合に対応する。
次に、図24を用いて、情報処理装置100が実行する、第1の片変換処理手順の一例について説明する。第1の片変換処理は、例えば、図4に示したCPU401と、メモリ402や記録媒体405などの記憶領域と、ネットワークI/F403とによって実現される。第1の片変換処理は、要否情報の漏洩を防止し易くする場合に対応する。
図24は、第1の片変換処理手順の一例を示すフローチャートである。図24において、情報処理装置100は、トラスト要件統計データ800を取得する(ステップS2401)。
次に、情報処理装置100は、取得したトラスト要件統計データ800に基づいて、トラスト項目群のうち、まだ選択していない、トラスト要件600集合における出現数<kであるトラスト項目を1つ選択する(ステップS2402)。そして、情報処理装置100は、トラスト項目群のうち、選択したトラスト項目と出現数または性質が比較的近しい別のトラスト項目を抽出する(ステップS2403)。
次に、情報処理装置100は、抽出したトラスト項目のうち、トラストベクトル500集合における出現数が最も大きくなるトラスト項目を選択する(ステップS2404)。そして、情報処理装置100は、選択したトラスト項目を、選択したトラスト項目を組み合わせたクラスタに変換し、トラスト項目群を更新する(ステップS2405)。
次に、情報処理装置100は、トラスト項目群のうち、まだ選択していない出現数<kであるトラスト項目が存在するか否かを判定する(ステップS2406)。ここで、まだ選択していない出現数<kであるトラスト項目が存在する場合(ステップS2406:Yes)、情報処理装置100は、ステップS2402の処理に戻る。一方で、まだ選択していない出現数<kであるトラスト項目が存在しない場合(ステップS2406:No)、情報処理装置100は、ステップS2407の処理に移行する。
ステップS2407では、情報処理装置100は、トラスト項目群に基づいて、匿名化テーブル1000を生成する(ステップS2407)。そして、情報処理装置100は、第1の片変換処理を終了する。これにより、情報処理装置100は、機微情報の漏洩を防止し易くするために、トラストベクトル500とトラスト要件600とを変換する際の指針となる情報を生成することができる。
(第2の片変換処理手順)
次に、図25を用いて、情報処理装置100が実行する、第2の片変換処理手順の一例について説明する。第2の片変換処理は、例えば、図4に示したCPU401と、メモリ402や記録媒体405などの記憶領域と、ネットワークI/F403とによって実現される。第2の片変換処理は、存否情報の漏洩を防止し易くする場合に対応する。
次に、図25を用いて、情報処理装置100が実行する、第2の片変換処理手順の一例について説明する。第2の片変換処理は、例えば、図4に示したCPU401と、メモリ402や記録媒体405などの記憶領域と、ネットワークI/F403とによって実現される。第2の片変換処理は、存否情報の漏洩を防止し易くする場合に対応する。
図25は、第2の片変換処理手順の一例を示すフローチャートである。図25において、情報処理装置100は、トラストベクトル統計データ700を取得する(ステップS2501)。
次に、情報処理装置100は、取得したトラストベクトル統計データ700に基づいて、トラスト項目群のうち、まだ選択していない、トラストベクトル500集合における出現数<kであるトラスト項目を1つ選択する(ステップS2502)。そして、情報処理装置100は、トラスト項目群のうち、選択したトラスト項目と出現数または性質が比較的近しい別のトラスト項目を抽出する(ステップS2503)。
次に、情報処理装置100は、抽出したトラスト項目のうち、トラスト要件600集合における出現数が最も大きくなるトラスト項目を選択する(ステップS2504)。そして、情報処理装置100は、選択したトラスト項目を、選択したトラスト項目を組み合わせたクラスタに変換し、トラスト項目群を更新する(ステップS2505)。
次に、情報処理装置100は、トラスト項目群のうち、まだ選択していない出現数<kであるトラスト項目が存在するか否かを判定する(ステップS2506)。ここで、まだ選択していない出現数<kであるトラスト項目が存在する場合(ステップS2506:Yes)、情報処理装置100は、ステップS2502の処理に戻る。一方で、まだ選択していない出現数<kであるトラスト項目が存在しない場合(ステップS2506:No)、情報処理装置100は、ステップS2507の処理に移行する。
ステップS2507では、情報処理装置100は、トラスト項目群に基づいて、匿名化テーブル1000を生成する(ステップS2507)。そして、情報処理装置100は、第2の片変換処理を終了する。これにより、情報処理装置100は、機微情報の漏洩を防止し易くするために、トラストベクトル500とトラスト要件600とを変換する際の指針となる情報を生成することができる。
以上説明したように、情報処理装置100によれば、第1の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第1のデータを取得することができる。情報処理装置100によれば、第2の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報をそれぞれが含む複数の第2のデータを取得することができる。情報処理装置100によれば、取得した複数の第2のデータそれぞれに含まれる複数の要否情報に基づいて、第2の項目群に含まれる複数の項目それぞれに対応するデータを要求することを示す要否情報の総数を算出することができる。情報処理装置100によれば、算出した要否情報の総数に基づいて、第3の項目群に含まれる複数の項目それぞれに対応するデータを要求することを示す要否情報の総数がいずれも基準数以上となるよう、第3の項目群を生成することができる。情報処理装置100によれば、第1のデータを、第3の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第3のデータに変換することができる。情報処理装置100によれば、複数の第2のデータそれぞれを、第3の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報を含む第4のデータに変換することができる。情報処理装置100によれば、変換した第3のデータと、変換した第4のデータそれぞれとを比較した結果に基づいて、第1のデータの提供元と、第2のデータの提供元とのマッチング状況を評価することができる。これにより、情報処理装置100は、機微情報となる要否情報の漏洩を防止し易くしつつ、第1のデータの提供元と第2のデータの提供元とをマッチング可能にすることができる。
情報処理装置100によれば、第1の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報をそれぞれが含む複数の第1のデータと、複数の第2のデータとを取得することができる。情報処理装置100によれば、さらに、取得した複数の第1のデータそれぞれに含まれる複数の存否情報に基づいて、第1の項目群に含まれる複数の項目それぞれに対応するデータが存在することを示す存否情報の総数を算出することができる。情報処理装置100によれば、算出した要否情報の総数と、算出した存否情報の総数とに基づいて、要否情報の総数がいずれも第1の基準数以上となり、かつ、存否情報の総数がいずれも第2の基準数以上となるよう、第3の項目群を生成することができる。これにより、情報処理装置100は、機微情報となる要否情報および存否情報の漏洩を防止し易くすることができる。
情報処理装置100によれば、算出した存否情報の総数に基づいて、第3の項目群に含まれる複数の項目それぞれに対応するデータが存在することを示す存否情報の総数がいずれも第2の基準数以上となるよう、第3の項目群を生成することができる。これにより、情報処理装置100は、機微情報となる存否情報の漏洩を防止し易くすることができる。
情報処理装置100によれば、第2の項目群に含まれる項目間の意味的距離に基づいて、第3の項目群を生成することができる。これにより、情報処理装置100は、機微情報の漏洩を防止し易くしつつ、マッチング精度の低下を抑制することができる。
情報処理装置100によれば、第3のデータに含まれる存否情報によって存在することが示されたデータと、第4のデータのいずれかに含まれる要否情報によって要求することが示されたデータとが一致するか否かを判定することができる。情報処理装置100によれば、一致すれば、第1のデータの提供元と、第4のデータのいずれかに対応する第2のデータの提供元とがマッチングすると評価することができる。これにより、情報処理装置100は、マッチングを正しく評価することができる。
情報処理装置100によれば、算出した要否情報の総数に基づいて、第3の項目群に含まれる複数の項目それぞれに対応するデータを要求することを示す要否情報の総数がいずれも基準数以上で取り得る最大数となるよう、第3の項目群を生成することができる。これにより、情報処理装置100は、機微情報の漏洩をさらに防止し易くすることができる。
情報処理装置100によれば、取得した第1のデータに含まれるいずれかの存否情報にノイズを付与することができる。これにより、情報処理装置100は、機微情報の漏洩を防止し易くすることができる。
なお、本実施の形態で説明した評価方法は、予め用意されたプログラムをPCやワークステーションなどのコンピュータで実行することにより実現することができる。本実施の形態で説明した評価プログラムは、コンピュータで読み取り可能な記録媒体に記録され、コンピュータによって記録媒体から読み出されることによって実行される。記録媒体は、ハードディスク、フレキシブルディスク、CD(Compact Disc)-ROM、MO(Magneto Optical disc)、DVD(Digital Versatile Disc)などである。また、本実施の形態で説明した評価プログラムは、インターネットなどのネットワークを介して配布してもよい。
100 情報処理装置
101 第1のデータ
102 第2のデータ
103 第3のデータ
104 第4のデータ
110,120,1500,1600,2000,2100,2200,2300 表
200 マッチングシステム
201 ユーザ側装置
202 企業側装置
210 ネットワーク
400 バス
401 CPU
402 メモリ
403 ネットワークI/F
404 記録媒体I/F
405 記録媒体
500 トラストベクトル
600 トラスト要件
700 トラストベクトル統計データ
800 トラスト要件統計データ
900 統計化テーブル
1000 匿名化テーブル
1100 記憶部
1101 取得部
1102 算出部
1103 変換部
1104 評価部
1105 出力部
1401,2101,2301 匿名化ベクトル
1402,2102,2302 匿名化要件
101 第1のデータ
102 第2のデータ
103 第3のデータ
104 第4のデータ
110,120,1500,1600,2000,2100,2200,2300 表
200 マッチングシステム
201 ユーザ側装置
202 企業側装置
210 ネットワーク
400 バス
401 CPU
402 メモリ
403 ネットワークI/F
404 記録媒体I/F
405 記録媒体
500 トラストベクトル
600 トラスト要件
700 トラストベクトル統計データ
800 トラスト要件統計データ
900 統計化テーブル
1000 匿名化テーブル
1100 記憶部
1101 取得部
1102 算出部
1103 変換部
1104 評価部
1105 出力部
1401,2101,2301 匿名化ベクトル
1402,2102,2302 匿名化要件
Claims (10)
- 第1の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第1のデータと、第2の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報をそれぞれが含む複数の第2のデータとを取得し、
取得した前記複数の第2のデータそれぞれに含まれる複数の要否情報に基づいて、前記第2の項目群に含まれる項目ごとに、当該項目に対応するデータを要求することを示す要否情報の総数を算出し、
前記第2の項目群に含まれる複数の項目それぞれと、算出した前記要否情報の総数とに基づいて、データを要求することを示す要否情報の総数がいずれも基準数以上となるよう複数の項目を含む第3の項目群を生成し、
前記第1のデータを、前記第3の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第3のデータに変換し、
前記複数の第2のデータそれぞれを、前記第3の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報を含む第4のデータに変換し、
変換した前記第3のデータと、変換した前記第4のデータそれぞれとを比較した結果に基づいて、前記第1のデータの提供元と、前記第2のデータの提供元とのマッチング状況を評価する、
処理をコンピュータが実行することを特徴とする評価方法。 - 前記取得する処理は、
前記第1の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報をそれぞれが含む複数の第1のデータと、前記複数の第2のデータとを取得し、
前記算出する処理は、
さらに、取得した前記複数の第1のデータそれぞれに含まれる複数の存否情報に基づいて、前記第1の項目群に含まれる複数の項目それぞれに対応するデータが存在することを示す存否情報の総数を算出し、
前記生成する処理は、
前記第2の項目群に含まれる複数の項目それぞれと、算出した前記要否情報の総数と、算出した前記存否情報の総数とに基づいて、データを要求することを示す要否情報の総数がいずれも第1の基準数以上となり、かつ、データが存在することを示す存否情報の総数がいずれも第2の基準数以上となるよう、前記第3の項目群を生成する、ことを特徴とする請求項1に記載の評価方法。 - 前記生成する処理は、
前記第1の項目群に含まれる複数の項目それぞれと、算出した前記存否情報の総数とに基づいて、データが存在することを示す存否情報の総数がいずれも前記第2の基準数以上となるよう、前記第3の項目群を生成する、ことを特徴とする請求項2に記載の評価方法。 - 前記生成する処理は、
前記第2の項目群に含まれる項目間の意味的距離に基づいて、前記第3の項目群を生成する、ことを特徴とする請求項1~3のいずれか一つに記載の評価方法。 - 前記評価する処理は、
前記第3のデータに含まれる存否情報によって存在することが示されたデータと、前記第4のデータのいずれかに含まれる要否情報によって要求することが示されたデータとが一致すれば、前記第1のデータの提供元と、前記第4のデータのいずれかに対応する前記第2のデータの提供元とがマッチングすると評価する、ことを特徴とする請求項1~4のいずれか一つに記載の評価方法。 - 前記生成する処理は、
前記第2の項目群に含まれる複数の項目それぞれと、算出した前記要否情報の総数とに基づいて、データを要求することを示す要否情報の総数がいずれも基準数以上で取り得る最大数となるよう、前記第3の項目群を生成する、ことを特徴とする請求項1~5のいずれか一つに記載の評価方法。 - 取得した前記第1のデータに含まれるいずれかの存否情報にノイズを付与する、
処理を前記コンピュータが実行することを特徴とする請求項1~6のいずれか一つに記載の評価方法。 - 第1の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第1のデータと、第2の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報をそれぞれが含む複数の第2のデータとを取得し、
取得した前記複数の第2のデータそれぞれに含まれる複数の要否情報に基づいて、前記第2の項目群に含まれる項目ごとに、当該項目に対応するデータを要求することを示す要否情報の総数を算出し、
前記第2の項目群に含まれる複数の項目それぞれと、算出した前記要否情報の総数とに基づいて、データを要求することを示す要否情報の総数がいずれも基準数以上となるよう複数の項目を含む第3の項目群を生成し、
前記第1のデータを、前記第3の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第3のデータに変換し、
前記複数の第2のデータそれぞれを、前記第3の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報を含む第4のデータに変換し、
変換した前記第3のデータと、変換した前記第4のデータそれぞれとを比較した結果に基づいて、前記第1のデータの提供元と、前記第2のデータの提供元とのマッチング状況を評価する、
処理をコンピュータに実行させることを特徴とする評価プログラム。 - 第1の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第1のデータと、第2の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報をそれぞれが含む複数の第2のデータとを取得し、
取得した前記複数の第2のデータそれぞれに含まれる複数の要否情報に基づいて、前記第2の項目群に含まれる項目ごとに、当該項目に対応するデータを要求することを示す要否情報の総数を算出し、
前記第2の項目群に含まれる複数の項目それぞれと、算出した前記要否情報の総数とに基づいて、データを要求することを示す要否情報の総数がいずれも基準数以上となるよう複数の項目を含む第3の項目群を生成し、
前記第1のデータを、前記第3の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第3のデータに変換し、
前記複数の第2のデータそれぞれを、前記第3の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報を含む第4のデータに変換し、
変換した前記第3のデータと、変換した前記第4のデータそれぞれとを比較した結果に基づいて、前記第1のデータの提供元と、前記第2のデータの提供元とのマッチング状況を評価する、
制御部を有することを特徴とする情報処理装置。 - 第1の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報をそれぞれが含む複数の第1のデータと、第2の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報を含む第2のデータとを取得し、
取得した前記複数の第1のデータそれぞれに含まれる複数の存否情報に基づいて、前記第1の項目群に含まれる項目ごとに、当該項目に対応するデータが存在することを示す存否情報の総数を算出し、
前記第1の項目群に含まれる複数の項目それぞれと、算出した前記存否情報の総数とに基づいて、データが存在することを示す存否情報の総数がいずれも基準数以上となるよう複数の項目を含む前記第3の項目群を生成し、
前記複数の第1のデータそれぞれを、前記第3の項目群に含まれる複数の項目それぞれに対応するデータの存否を示す存否情報を含む第3のデータに変換し、
前記第2のデータを、前記第3の項目群に含まれる複数の項目それぞれに対応するデータの要否を示す要否情報を含む第4のデータに変換し、
変換した前記第3のデータのそれぞれと、変換した前記第4のデータとを比較した結果に基づいて、前記第1のデータの提供元と、前記第2のデータの提供元とのマッチング度合いを評価する、
処理をコンピュータが実行することを特徴とする評価方法。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2023523739A JPWO2022249258A1 (ja) | 2021-05-24 | 2021-05-24 | |
| PCT/JP2021/019686 WO2022249258A1 (ja) | 2021-05-24 | 2021-05-24 | 評価方法、評価プログラム、および情報処理装置 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2021/019686 WO2022249258A1 (ja) | 2021-05-24 | 2021-05-24 | 評価方法、評価プログラム、および情報処理装置 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022249258A1 true WO2022249258A1 (ja) | 2022-12-01 |
Family
ID=84229734
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2021/019686 Ceased WO2022249258A1 (ja) | 2021-05-24 | 2021-05-24 | 評価方法、評価プログラム、および情報処理装置 |
Country Status (2)
| Country | Link |
|---|---|
| JP (1) | JPWO2022249258A1 (ja) |
| WO (1) | WO2022249258A1 (ja) |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2020235014A1 (ja) * | 2019-05-21 | 2020-11-26 | 日本電信電話株式会社 | 情報処理装置、情報処理方法及びプログラム |
-
2021
- 2021-05-24 WO PCT/JP2021/019686 patent/WO2022249258A1/ja not_active Ceased
- 2021-05-24 JP JP2023523739A patent/JPWO2022249258A1/ja not_active Withdrawn
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2020235014A1 (ja) * | 2019-05-21 | 2020-11-26 | 日本電信電話株式会社 | 情報処理装置、情報処理方法及びプログラム |
Non-Patent Citations (1)
| Title |
|---|
| YASUNORI SAGAWA, TSUNENORI MINE: "Reciprocal Recommendation for Job Matching - an Evaluation", IEICE TECHNICAL REPORT, vol. 113, no. 332 (AI2013-25), 21 November 2013 (2013-11-21), JP, pages 35 - 40, XP009542169 * |
Also Published As
| Publication number | Publication date |
|---|---|
| JPWO2022249258A1 (ja) | 2022-12-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12388875B2 (en) | Method, apparatus, and computer-readable medium for data protection simulation and optimization in a computer network | |
| JP6744854B2 (ja) | データ記憶方法、データ照会方法、およびそれらの装置 | |
| US11409911B2 (en) | Methods and systems for obfuscating sensitive information in computer systems | |
| US20090055382A1 (en) | Automatic Peer Group Formation for Benchmarking | |
| AU2022254512A1 (en) | System and method for privacy-preserving analytics on disparate data sets | |
| JP2017091515A (ja) | 匿名化のために属性を自動的に識別するコンピュータ実装システムおよび方法 | |
| CN115087967A (zh) | 电子多租户数据管理系统 | |
| AU2022261181B2 (en) | Electronic multi-tenant data management systems and clean rooms | |
| CN107203705A (zh) | 可追踪式数据稽核装置及方法 | |
| US20180137149A1 (en) | De-identification data generation apparatus, method, and non-transitory computer readable storage medium thereof | |
| WO2017203672A1 (ja) | アイテム推奨方法、アイテム推奨プログラムおよびアイテム推奨装置 | |
| WO2020004139A1 (ja) | 個人情報分析システム、及び個人情報分析方法 | |
| WO2022249258A1 (ja) | 評価方法、評価プログラム、および情報処理装置 | |
| CN115603958A (zh) | 登陆数据处理方法、装置、计算机设备和存储介质 | |
| JP2014011503A (ja) | 秘匿化装置、秘匿化プログラムおよび秘匿化方法 | |
| US11711203B2 (en) | Systems and methods for gated offer eligibility verification | |
| CN113608949A (zh) | 压力测试方法和装置、以及存储介质和电子设备 | |
| JPWO2022249258A5 (ja) | ||
| JP6549076B2 (ja) | 匿名化テーブル生成装置、匿名化テーブル生成方法、プログラム | |
| JP5998184B2 (ja) | コンテンツ配信システム、方法、およびプログラム | |
| JP2013083801A (ja) | データベース撹乱装置、システム、方法及びプログラム | |
| US20210110450A1 (en) | Systems and methods for gated offer eligibility verification | |
| CN114004456A (zh) | 数据标签的计算方法、装置、计算机设备和存储介质 | |
| US20120179586A1 (en) | Computer based system for spend analysis solution through strategies for mining spend information | |
| JP2021140502A (ja) | 情報処理プログラム、情報処理方法、および情報処理装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21942915 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2023523739 Country of ref document: JP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21942915 Country of ref document: EP Kind code of ref document: A1 |