User information provision method, user information provision system, user information provision program and recording medium recording its program
Abstract
[Subject] There is the present invention, when the statistical information which a user's personal information or its personal information shows is offered, is a form where invasion of privacy can be prevented, and aims at realization of the new technology of enabling it to offer those User Information. [Solution means] The enciphering procedure which generates the mark which shows a seemingly different value which can be decoded to the same mark is used, The identifier which is visible to variable to a user each time is assigned, and it enables it to search User Information according to the character (character in which it can decode to a user's fixed identifier) which this variable identifier has. Thereby, when grasping a user's action history, a user's privacy can be protected by the ability of the situation where the fixed identifier used for a user's discernment and a user's action history are connected deeply to be prevented now. [Selection figure] Fig. 2
Term
Term ended
Projected expiry passed 4 June 2023, 3.3 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
10 claims: 4 independent, 6 dependent
- 1A user information providing method that provides personal information of a user or statistical information indicated by the personal information, and is used for identifying a user by using an encryption procedure that generates a code indicating an apparently different value that can be decrypted into the same code. From the fixed identifier used, the process of generating a variable identifier different from the previously created variable identifier and assigning it to the user, the process of obtaining the above variable identifier specified in the request for providing user information, and the process of obtaining the above obtained variable By decoding the identifier, the process of identifying the fixed identifier of the user who is requested to provide the user information, and the storage means for storing the user information in association with the fixed identifier of the user by using the specified fixed identifier as a key. A method for providing user information, which comprises a process of searching for user information pointed to by the specified fixed identifier by searching and providing the user information. ユーザの個人情報あるいはその個人情報が示す統計情報を提供するユーザ情報提供方法であって、同一の符号に復号できる見かけ上異なる値を示す符号を生成する暗号化手順を使って、ユーザの識別に用いる固定識別子から、前回作成した可変識別子とは異なる可変識別子を生成して、それをユーザに割り当てる過程と、ユーザ情報の提供要求で指定される上記可変識別子を入手する過程と、上記入手した可変識別子を復号することで、ユーザ情報の提供要求があるユーザの固定識別子を特定する過程と、上記特定した固定識別子をキーにして、ユーザの固定識別子に対応付けてユーザ情報を記憶する記憶手段を検索することで、上記特定した固定識別子の指すユーザ情報を検索して、それを提供する過程とを備えることを、特徴とするユーザ情報提供方法。
- 3A user information providing method that provides personal information of a user or statistical information indicated by the personal information, and is used for identifying a user by using an encryption procedure that generates a code indicating an apparently different value that can be decrypted into the same code. Decoding of the assigned variable identifier generated by generating a variable identifier from the fixed identifier to be used and assigning it to the user, and by converting from the above-assigned variable identifier specified in the user information provision request. The process of obtaining a variable identifier that decodes the same code as the code, the process of identifying the fixed identifier of the user who is requested to provide user information by decoding the obtained variable identifier, and the process of specifying the specified fixed identifier. By using a key to search for a storage means for storing user information in association with the fixed identifier of the user, the process of searching for the user information pointed to by the specified fixed identifier and providing the user information is provided. Characteristic user information provision method. ユーザの個人情報あるいはその個人情報が示す統計情報を提供するユーザ情報提供方法であって、同一の符号に復号できる見かけ上異なる値を示す符号を生成する暗号化手順を使って、ユーザの識別に用いる固定識別子から可変識別子を生成して、それをユーザに割り当てる過程と、ユーザ情報の提供要求で指定され、上記割り当てた可変識別子から変換されることで生成された、その割り当てた可変識別子の復号符号と同一の符号を復号する可変識別子を入手する過程と、上記入手した可変識別子を復号することで、ユーザ情報の提供要求があるユーザの固定識別子を特定する過程と、上記特定した固定識別子をキーにして、ユーザの固定識別子に対応付けてユーザ情報を記憶する記憶手段を検索することで、上記特定した固定識別子の指すユーザ情報を検索して、それを提供する過程とを備えることを、特徴とするユーザ情報提供方法。
- 5A user information providing device that provides personal information of a user or statistical information indicated by the personal information, and is used for identifying a user by using an encryption procedure that generates a code indicating an apparently different value that can be decrypted into the same code. From the fixed identifier to be used, an allocation means for generating a variable identifier different from the previously created variable identifier and assigning it to the user, an acquisition means for obtaining the variable identifier specified in the request for providing user information, and the above acquisition A specific means for specifying a fixed identifier of a user who is requested to provide user information by decoding a variable identifier obtained by the means, a storage means for storing user information in association with the fixed identifier of the user, and the above-mentioned specific means. By searching for the storage means using the specified fixed identifier of the above-mentioned specific means as a key, the user information pointed to by the specified fixed identifier of the specific means is searched for, and a providing means for providing the user information is provided. User information providing device. ユーザの個人情報あるいはその個人情報が示す統計情報を提供するユーザ情報提供装置であって、同一の符号に復号できる見かけ上異なる値を示す符号を生成する暗号化手順を使って、ユーザの識別に用いる固定識別子から、前回作成した可変識別子とは異なる可変識別子を生成して、それをユーザに割り当てる割当手段と、ユーザ情報の提供要求で指定される上記可変識別子を入手する入手手段と、上記入手手段の入手した可変識別子を復号することで、ユーザ情報の提供要求があるユーザの固定識別子を特定する特定手段と、ユーザの固定識別子に対応付けてユーザ情報を記憶する記憶手段と、上記特定手段の特定した固定識別子をキーにして上記記憶手段を検索することで、上記特定手段の特定した固定識別子の指すユーザ情報を検索して、それを提供する提供手段とを備えることを、特徴とするユーザ情報提供装置。
- 7A user information providing device that provides personal information of a user or statistical information indicated by the personal information, and is used for identifying a user by using an encryption procedure that generates a code indicating an apparently different value that can be decrypted into the same code. An assignment means that generates a variable identifier from the fixed identifier to be used and assigns it to the user, and the assignment that is specified by the request for providing user information and is generated by converting from the variable identifier assigned by the allocation means. Identification to identify the fixed identifier of the user who is requested to provide user information by decoding the obtaining means for obtaining the variable identifier that decodes the same code as the decoding code of the variable identifier and the variable identifier obtained by the above-mentioned obtaining means. By searching the storage means using the means, the storage means for storing the user information in association with the fixed identifier of the user, and the fixed identifier specified by the specific means as a key, the fixed identifier specified by the specific means can be obtained. A user information providing device characterized in that it includes a providing means for searching for and providing the pointing user information. ユーザの個人情報あるいはその個人情報が示す統計情報を提供するユーザ情報提供装置であって、同一の符号に復号できる見かけ上異なる値を示す符号を生成する暗号化手順を使って、ユーザの識別に用いる固定識別子から可変識別子を生成して、それをユーザに割り当てる割当手段と、ユーザ情報の提供要求で指定され、上記割当手段の割り当てた可変識別子から変換されることで生成された、その割り当てた可変識別子の復号符号と同一の符号を復号する可変識別子を入手する入手手段と、上記入手手段の入手した可変識別子を復号することで、ユーザ情報の提供要求があるユーザの固定識別子を特定する特定手段と、ユーザの固定識別子に対応付けてユーザ情報を記憶する記憶手段と、上記特定手段の特定した固定識別子をキーにして上記記憶手段を検索することで、上記特定手段の特定した固定識別子の指すユーザ情報を検索して、それを提供する提供手段とを備えることを、特徴とするユーザ情報提供装置。
Independent claims4
209 paragraphs in 1 section, as filed
【0001】
[Technical field to which the invention belongs]
The present invention describes a user information providing method and its device for providing personal information of a user or statistical information indicated by the personal information, a user information providing program used for realizing the user information providing method, and a recording medium for recording the program. Regarding and.
【0002】
Specifically, the present invention is used in, for example, a system in which an ID and a consumer's behavior history are linked and used, and it is possible to prevent privacy infringement that may occur when the ID is used. It is about the technology to do.
【0003】
[Conventional technology]
Conventionally, when the store side records the purchase behavior history of a consumer in detail, the data of which product and when a consumer purchased is recorded by linking it with a fixed ID assigned to the individual. There is.
【0004】
Purchasing behavior history linked to consumer personal information in this way (what kind of sales floor you look at, what kind of products you take in order, what kind of products you actually bought at the cash register, etc. Information) has been used as marketing information in the subsequent commercial activities of sellers.
【0005】
Against this background, in recent years, research has been actively conducted to assign identifiers using RF tags (Radio Frequency Tag) instead of printing.
【0006】
An RF tag is a minute device generally composed of an antenna and an IC chip, and can exchange information with an external wireless device by wireless communication. As long as it is within the reach of the radio, an external wireless device can acquire a large amount of barcodes and product serial numbers stored in the RF tag at one time, so the RF tag can be attached to the article. By storing it in the article, it can be used for distribution of the article and management of inventory.
【0007】
However, with RF tags, this information is obtained by an arbitrary third party without the owner of the article noticing it, and as a result, the owner of the article is unknowingly undergoing some kind of monitoring. There is a risk of becoming.
【0008】
Regarding RF tags, under the presidency of the Massachusetts Institute of Technology (MIT) in the United States, various systems that embed RF tags in various objects, read RF tag information without human intervention, and make it available on the Internet. As one of them, a method of integrating EPC (Electronic Product Code) that identifies products and GTIN (Global Trade Item Number) that identifies products has been proposed (for example, non-integration). See Patent Document 1).
【0009】
[Non-Patent Document 1]
Integrating the Electronic Product Code (EPC) and the Global Trade Item Number (GTIN) [Searched April 11, 2003], Internet <URL: http://www.autoidcenter.org/pdfs/MIT-AUTOID-WH- 004.pdf> [0010]
[Problems to be Solved by the Invention]
However, if the method of recording the purchasing behavior history in a form linked to the consumer's fixed ID as in the conventional technology is used, once the consumer's fixed ID is known, the consumer's personal There was a problem that all the purchase behavior history was revealed.
【0011】
Furthermore, even for marketing purposes, it has been a problem in terms of privacy that a third party (in this case, the store side) directly grasps and uses the purchase behavior history of individual consumers that can be clearly identified. ..
【0012】
The present invention has been made in view of such circumstances, and when providing personal information of a user or statistical information indicated by the personal information, the user information is provided in a form capable of preventing privacy infringement. The purpose is to realize new technology that enables us to provide it.
【0013】
[Means for solving problems]
(B) First configuration In order to achieve the above object, the user information providing device of the present invention performs the process of providing the user's personal information or the statistical information indicated by the personal information. Using an encryption procedure that generates a code that shows an apparently different value that can be decrypted into the code of, a variable identifier that is different from the previously created variable identifier is generated from the fixed identifier used to identify the user, and it is given to the user. A user who has a request to provide user information by decoding the allocation means to be assigned, (2) the acquisition means for obtaining the variable identifier specified in the request for providing user information, and (3) the variable identifier obtained by the acquisition means. A specific means for specifying the fixed identifier of the specific means, (4) a storage means for storing user information in association with the fixed identifier of the user, and (5) searching for the storage means using the fixed identifier specified by the specific means as a key. Then, the user information pointed to by the specified fixed identifier of the specific means is searched, and the providing means for providing the user information is provided.
【0014】
When adopting this configuration, when the storage means stores the permission information for the disclosure of the user information, the providing means obtains permission for the disclosure of the user information pointed to by the fixed identifier specified by the specific means. Search for user information that has been provided and process it to provide it.
【0015】
Further, the obtaining means may obtain a variable identifier that decodes the same code as the decoding code of the assigned variable identifier, which is generated by converting from the variable identifier assigned by the assigning means.
【0016】
The user information providing method of the present invention realized by operating each of the above processing means can be realized by a computer program, and this computer program is recorded and provided on an appropriate recording medium such as a semiconductor memory. The present invention is realized by being provided or provided via a network, installed when carrying out the present invention, and operating on a control means such as a CPU.
【0017】
In the user information providing device of the present invention configured as described above, when it is necessary to assign an identifier to a user, an encryption procedure is used to generate a code indicating an apparently different value that can be decrypted to the same code. From the fixed identifier used to identify the user, a variable identifier different from the previously created variable identifier is generated and assigned to the user.
【0018】
In response to the assignment of this variable identifier, the user takes an action such as buying a product using a card or the like on which the assigned variable identifier is recorded. In order to investigate whether a user having user information has taken such an action, a variable identifier recorded on the card or the like is specified to request the user information providing device of the present invention to provide user information. Will be issued.
【0019】
From now on, in the user information providing apparatus of the present invention, when a request for providing user information is issued, the variable identifier specified in the request for providing the user information is obtained.
【0020】
The variable identifier obtained at this time may be rewritten to another variable identifier that decodes the same code as the decoded code of the assigned variable identifier by a variable identifier rewriting device installed in a store or the like. In such a case, the rewritten variable identifier will be obtained.
【0021】
Then, when the variable identifier specified in the user information provision request is obtained, the obtained variable identifier is decoded to specify the fixed identifier of the user who has the user information provision request, and the specified fixed identifier is used. By using a key to search for a storage means that stores user information in association with a fixed identifier of the user, the user information pointed to by the specified fixed identifier is searched and provided to a store or the like.
【0022】
At this time, when the storage means stores the permission information for the disclosure of the user information, the user information for which the permission has been obtained for the disclosure is searched for and provided among the user information pointed to by the specified fixed identifier. Will be done.
【0023】
(B) Second configuration Further, in order to achieve the above object, the user information providing device of the present invention performs a process of providing the user's personal information or the statistical information indicated by the personal information (1). ) An assignment means that generates a variable identifier from a fixed identifier used to identify a user and assigns it to the user, using an encryption procedure that produces codes that appear to have different values that can be decrypted to the same code, and (2) ) As an acquisition means for obtaining a variable identifier that decodes the same code as the decoding code of the assigned variable identifier, which is specified in the request for providing user information and is generated by converting from the variable identifier assigned by the assigning means. , (3) By decrypting the variable identifier obtained by the acquisition means, the specific means for specifying the fixed identifier of the user who is requested to provide the user information, and (4) the user information is stored in association with the fixed identifier of the user. And (5) By searching the storage means using the fixed identifier specified by the specific means as a key, the user information pointed to by the fixed identifier specified by the specific means is searched and the providing means that provides it. It is configured to include.
【0024】
When adopting this configuration, when the storage means stores the permission information for the disclosure of the user information, the providing means obtains permission for the disclosure of the user information pointed to by the fixed identifier specified by the specific means. Search for user information that has been provided and process it to provide it.
【0025】
The user information providing method of the present invention realized by operating each of the above processing means can be realized by a computer program, and this computer program is recorded and provided on an appropriate recording medium such as a semiconductor memory. The present invention is realized by being provided or provided via a network, installed when carrying out the present invention, and operating on a control means such as a CPU.
【0026】
In the user information providing device of the present invention configured as described above, when it is necessary to assign an identifier to a user, an encryption procedure is used to generate a code indicating an apparently different value that can be decrypted to the same code. A variable identifier is generated from a fixed identifier used to identify a user, and the variable identifier is assigned to the user.
【0027】
The variable identifier assigned to the user in this way is rewritten to another variable identifier that decodes the same code as the decoding code of the variable identifier by a variable identifier rewriting device installed in a store or the like. Become.
【0028】
Since the user takes an action such as buying a product using a card or the like on which the rewritten variable identifier is recorded, the user who has what kind of user information is such an action at the store or the like that receives the action. In order to check whether or not an action has been taken, a variable identifier recorded on the card or the like is specified, and a request for providing user information is issued to the user information providing device of the present invention.
【0029】
From now on, when a request for providing user information is issued, the user information providing device of the present invention obtains a variable identifier specified in the request for providing the user information.
【0030】
Then, when the variable identifier specified in the user information provision request is obtained, the obtained variable identifier is decoded to specify the fixed identifier of the user who has the user information provision request, and the specified fixed identifier is used. By using a key to search for a storage means that stores user information in association with a fixed identifier of the user, the user information pointed to by the specified fixed identifier is searched and provided to a store or the like.
【0031】
At this time, when the storage means stores the permission information for the disclosure of the user information, the user information for which the permission has been obtained for the disclosure is searched for and provided among the user information pointed to by the specified fixed identifier. Will be done.
【0032】
Thus, in the present invention, an identifier that appears variable each time is assigned to the user using an encryption procedure that produces codes that appear to be different values that can be decrypted into the same code. Since user information can be searched according to the property (the property of being able to decrypt to the user's fixed identifier), the fixed identifier used to identify the user and the user's behavior history when grasping the user's behavior history It will be possible to prevent the situation where the information is deeply connected, and this will protect the user's privacy.
【0033】
Then, in the present invention, a variable identifier is assigned to the user by using an encryption procedure for generating codes indicating apparently different values that can be decrypted to the same code, and this variable identifier is changed to another variable identifier at any time. When making it look variable by being done, user information can be searched according to the property of this variable identifier (the property of being able to decode to the user's fixed identifier), so that the user's action history can be grasped. In such a case, it becomes possible to prevent a situation in which the fixed identifier used for identifying the user and the action history of the user are deeply linked, thereby protecting the privacy of the user.
【0034】
Moreover, by preparing the user information providing device of the present invention, the store side or the like does not directly grasp the user's action history, but in the end, a reliable management organization grasps it. It becomes possible to prevent the side and the like from directly grasping the user's information in detail.
【0035】
BEST MODE FOR CARRYING OUT THE INVENTION
Hereinafter, the present invention will be described in detail according to embodiments.
【0036】
FIG. 1 illustrates an example of a store 1 to which the present invention is applied.
【0037】
In the store 1 shown in this figure, when the user 2 holds a mobile card 20 such as a point card and shop in the store, it is for a wireless tag installed on the product display shelf 10-i (i = 1 to n). The reader 11-i (i = 1 to n) reads the user ID transmitted by the wireless tag (wireless tag 200 shown in FIG. 2) of the mobile card 20, and the read user ID and the own reader are installed. By sending the ID of the product display shelf to the store host computer 12, it is possible to grasp what kind of product the user 2 who entered the store was interested in shopping.
【0038】
The reason why the user 2 holds the mobile card 20 and shop in the store is that the store 1 provides services such as points and discounts to the user 2 as a consideration for collecting marketing information.
【0039】
FIG. 2 illustrates an example of an embodiment of the user information providing device 3 of the present invention used to realize such grasping of the purchasing behavior history of the user 2.
【0040】
As shown in this figure, the user information providing device 3 of the present invention provides the personal information database 30 that manages the personal information of the user 2, the variable ID issuing unit 31 that assigns a variable ID to the user 2, and the user 2. On the other hand, the work memory 32 for recording the variable ID assigned last time and the personal information providing unit 33 for providing the user's personal information to the store host computer 12 are provided.
【0041】
This personal information database 30 manages personal information (name, age, gender, address, etc.) of each user 2 in association with a fixed ID (hereinafter referred to as a fixed ID) possessed by the user 2. As for whether or not user 2 permits the disclosure of personal information, as shown in Fig. 3 (a), personal information is managed as an integrated unit, or as shown in Fig. 3 (b). In addition, we manage which personal information is permitted to be disclosed and which personal information is not permitted to be disclosed.
【0042】
FIG. 4 illustrates an example of the processing flow executed by the variable ID issuing unit 31, and FIG. 5 illustrates an example of the processing flow executed by the personal information providing unit 33.
【0043】
Next, the processing executed by the user information providing device 3 of the present invention will be described in detail according to these processing flows.
【0044】
When the user 2 holding the mobile card 20 requests the issuance of an ID, the variable ID issuing unit 31 first obtains a user name from the user 2 in step 10, as shown in the processing flow of FIG. receive.
【0045】
Subsequently, in step 11, the fixed ID pointed to by the received user name is acquired by referring to the personal information database 30. That is, the fixed ID possessed by the user is acquired.
【0046】
Subsequently, in step 12, the previously issued variable ID recorded in association with the acquired fixed ID is read from the working memory 32. Subsequently, in step 13, a random number is generated, and in the following step 14, the variable ID is configured by padding the acquired fixed ID with this random number.
【0047】
For example, as shown in Fig. 6 (a), a sufficiently large random number is padded before and after the acquired fixed ID, or as shown in Fig. 6 (b), the part before the acquired fixed ID. Padding a sufficiently large random number, as shown in Fig. 6 (c), padding a sufficiently large random number in the part after the acquired fixed ID, as shown in Fig. 6 (d). For example, a variable ID is constructed by adding data indicating the position of the fixed ID to the first "α" part and padding a sufficiently large random number in the parts before and after the acquired fixed ID. ..
【0048】
Then, in step 15, it is determined whether or not the variable ID configured by padding the random number matches the previously issued variable ID (variable ID read from the working memory 32), and it is determined that they match. When doing so, the process returns to step 13 to generate a variable ID that does not match.
【0049】
On the other hand, in step 15, when it is determined that the variable ID configured by padding the random numbers does not match the previously issued variable ID, the process proceeds to step 16 and the variable ID configured by padding the random numbers is used for work. Record in memory 32.
【0050】
Then, in step 17, the variable ID configured by padding the random numbers is encrypted using the public key, and in the following step 18, the encrypted variable ID is issued to the user 2 who issues the ID request. End the process.
【0051】
Upon receiving the issuance of this encrypted variable ID, the variable ID issued by the user information providing device 3 is registered in the wireless tag 200 of the mobile card 20 held by the user 2.
【0052】
The encrypted variable ID registered in the wireless tag 200 in this way looks as if it is a different ID each time.
【0053】
As described above, the user 2 holds the mobile card 20 having the wireless tag 200 in which the encrypted variable ID is registered and enters the store 1, and in response to this, the user 2 adjusts to the movement of the user 2. Then, the store host computer 12 collects the encrypted variable ID read by the wireless tag reader 11-i and the product display shelf ID on which the wireless tag reader 11-i is installed.
【0054】
When the store host computer 12 collects the purchase behavior history of the user 2 in this way, the user information providing device 3 of the present invention knows what kind of personal information the store host computer 12 has in the purchase behavior history of the user 2. In response to this, a request for provision of personal information is issued by designating the encryption variable ID read by the wireless tag reader 11-i.
【0055】
Upon receiving this request for providing personal information, the personal information providing unit 33 first receives the encrypted variable ID specified in step 20 as shown in the processing flow of FIG.
【0056】
Subsequently, in step 21, the variable ID is specified by decrypting the received encrypted variable ID using the private key associated with the above-mentioned public key, and is included in the specified variable ID in the following step 22. Extract the fixed ID of user 2 by removing the random number part.
【0057】
For example, as shown in FIGS. 6 (a) to 6 (c), when a rule for padding random numbers is provided, the random number part included in the specified variable ID is set according to the rule. By removing it, the fixed ID of user 2 will be extracted. On the other hand, as shown in FIG. 6 (d), for example, when padding a random number while adding data indicating the position of a fixed ID to the leading α part, the specified variable is specified according to the data indicating the position. By removing the random number part included in the ID, the fixed ID of user 2 will be extracted.
【0058】
After extracting the fixed ID of user 2, in step 23, the personal information pointed to by the extracted fixed ID is acquired by referring to the personal information database 30, and in the following step 24, among the acquired personal information. , Identifies the personal information for which disclosure permission has been obtained, provides it to the store host computer 12, and ends the process.
【0059】
In this way, in the present invention, it is processed as follows.
【0060】
(1) Before entering the store, consumer A informs the "reliable ID management organization (the organization that operates the user information providing device 3 of the present invention)" of his / her personal information Info.<sub>A </sub>And its "trusted ID management agency" is Info<sub>A </sub>ID that is a variable ID from<sub>A1</sub>To generate. Consumer A has that ID<sub>A1</sub>Receives the issuance of wireless tags and IC cards that store.
【0061】
(2) Consumer A goes to the store A to purchase the product with the wireless tag or IC card.
【0062】
(3) Store A is ID<sub>A1</sub>Collect the history of purchasing behavior in the store (information such as what kind of sales floor you look at, what kind of products you take in order, and what kind of products you actually bought at the cash register).
【0063】
(4) Store A will be a variable ID at a later date due to marketing research.<sub>A1</sub>I want to know the personal information of the person who corresponds to<sub>A1</sub>Request the provision of personal information.
【0064】
(5) The "trusted ID management organization" is the "table of permission policy management information (corresponding to personal information database 30)" that is registered for the permission & non-permission information of the person regarding each item of personal information at the time of disclosure. Match with the contents of.
【0065】
(6) ID in the contents of "Table of licensed policy management information"<sub>A1</sub>For example, it is assumed that "Name not allowed, Age allowed, Gender allowed, Place of residence not allowed ... (Omitted)" was posted by the person corresponding to.
【0066】
(7) As a result, the "trusted ID management organization" will give the store A the ID.<sub>A1</sub>Only the age and gender of the person will be disclosed, and other items that were prohibited will not be disclosed.
【0067】
(8) Before Consumer A re-enters the store A, the same personal information Info for Consumer A<sub>A </sub>ID which is another ID from<sub>A2</sub>Is generated and issued.
【0068】
In this way, according to the present invention, even for the same consumer A, an ID that is a different ID each time the store is visited.<sub>An</sub>Will be issued.
【0069】
With the above flow, the store side has an ID<sub>A1</sub>Although it is possible to obtain the purchasing behavior history of<sub>A1</sub>Info corresponding to<sub>A </sub>I can't know about this personal information unless I get permission. Also, ID<sub>A1</sub>And ID<sub>A2</sub>It is not possible to know that and are the same person unless permission is obtained. This protects Consumer A's privacy.
【0070】
Here, in the present invention, the store 1 dares to use the "trusted ID management organization" without collecting the personal information of the user 2 by itself, for the following reason.
【0071】
In other words, recently, the handling of personal information has become a responsibility to be strictly managed due to laws and regulations, and it is difficult for only store 1 to handle it. Therefore, the store 1 contracts with a "reliable ID management institution" to manage the customer's information, and although it costs money, the customer is told that "the store uses a reliable ID management institution". Because we manage customer information safely, you can shop with peace of mind. "
【0072】
FIG. 7 illustrates another example of store 1 to which the present invention is applied. Unlike the store 1 shown in FIG. 1, the store 1 shown in this figure has a configuration in which the variable ID rewriting device 13 is provided.
【0073】
When the mobile card 20 held by the user 2 is inserted, the variable ID rewriting device 13 rewrites the encrypted variable ID registered in the wireless tag 200 of the mobile card 20 to another encrypted variable ID. I do.
【0074】
FIG. 8 illustrates an example of the processing flow executed by the variable ID issuing unit 31 when the variable ID rewriting device 13 is prepared, and FIG. 9 illustrates an example of the processing flow executed by the variable ID rewriting device 13. To do.
【0075】
Next, according to these processing flows, the processing executed by the user information providing device 3 of the present invention when the variable ID rewriting device 13 is prepared will be described in detail.
【0076】
When the user 2 holding the mobile card 20 requests the issuance of an ID, the variable ID issuing unit 31 first obtains a user name from the user 2 in step 30, as shown in the processing flow of FIG. receive.
【0077】
Subsequently, in step 31, the fixed ID pointed to by the received user name is acquired by referring to the personal information database 30. That is, the fixed ID possessed by the user is acquired.
【0078】
Then, in step 32, a random number is generated, and in the following step 33, the variable ID is configured by padding the acquired fixed ID with this random number. As explained with reference to FIG. 6, a variable ID is constructed by padding this random number to the acquired fixed ID.
【0079】
Then, in step 34, the variable ID configured by padding the random numbers is encrypted using the public key, and in the following step 35, the encrypted variable ID is issued to the user 2 who issues the ID request. End the process.
【0080】
In this way, when the variable ID rewriting device 13 is prepared, the variable ID issuing unit 31 acquires the fixed ID possessed by the user when the user 2 requests the issuance of the ID, and outputs a random number to the fixed ID. By padding, a variable ID is generated, and it is encrypted using a public key and issued.
【0081】
Upon receiving the issuance of this encrypted variable ID, the variable ID issued by the user information providing device 3 is registered in the wireless tag 200 of the mobile card 20 held by the user 2.
【0082】
On the other hand, when the user 2 enters the store 1, the mobile card 20 in which the variable ID is registered in this way is inserted into the variable ID rewriting device 13.
【0083】
In response to the insertion of the mobile card 20, the variable ID rewriting device 13 is first registered in the wireless tag 200 of the inserted mobile card 20 in step 40, as shown in the processing flow of FIG. Read the encrypted variable ID to be rewritten.
【0084】
Subsequently, in step 41, the variable ID is specified by decrypting the received encrypted variable ID using the private key, and in the following step 42, the user 2 is removed by removing the random number portion included in the specified variable ID. Extract the fixed ID of. As explained with reference to FIG. 6, the fixed ID of user 2 is extracted by removing the random number part included in the specified variable ID.
【0085】
Subsequently, in step 43, a random number is generated, and in the following step 44, the variable ID is configured by padding the extracted fixed ID with this random number. As explained with reference to FIG. 6, a variable ID is constructed by padding this random number to the extracted fixed ID.
【0086】
Subsequently, in step 45, when it is determined whether or not the variable ID configured in step 44 matches the variable ID to be rewritten (the variable ID specified in step 41) and it is determined that they match, step 43 By returning to, it processes to generate a variable ID that does not match.
【0087】
On the other hand, in step 45, when it is determined that the variable ID configured by padding the random number does not match the variable ID to be rewritten, the process proceeds to step 46 and the variable ID configured by padding the random number is used as the public key. In the following step 47, the encrypted variable ID registered in the wireless tag 200 of the inserted mobile card 20 is rewritten according to the encrypted variable ID, and the process ends.
【0088】
The personal information providing unit 33 can also extract the fixed ID of the encrypted variable ID rewritten in this way according to the processing of step 21 / step 22 of the processing flow of FIG. In response to the request for providing personal information that specifies the rewritten encrypted variable ID, the personal information can be provided to the store host computer 12 according to the processing flow of FIG.
【0089】
In this way, when the variable ID rewriting device 13 is prepared, the user 2 does not have to issue the variable ID from the user information providing device 3 of the present invention each time before entering the store 1. You will be able to do it.
【0090】
Here, even if the variable ID issuing unit 31 issues a variable ID each time according to the processing flow of FIG. 4, the user 2 uses the variable ID rewriting device 13 before entering the store 1. The variable ID may be rewritten.
【0091】
Also, instead of preparing the variable ID rewriting device 13, the encrypted variable ID registered in the wireless tag 200 of the mobile card 20 is automatically rewritten to another encrypted variable ID at the entrance of the store 1. A gate for processing may be provided, or the wireless tag 200 may automatically rewrite the registered encryption variable ID to another encryption variable ID at a certain time interval. ..
【0092】
In the embodiment described above, the user information providing device 3 of the present invention provides the personal information of the user 2 to the store host computer 12, but for example, the user is provided in the personal information database 30. According to 2, for example, if it is registered that "Personal information items cannot be disclosed and can only be used for statistical use", the personal information of that user 2 will not be disclosed at all, and other users 2 will not be disclosed. It will provide information and comprehensive statistical data (such as marketing data that shows purchasing behavior by age group and gender group, purchased product information, etc. in graphs, etc.).
【0093】
Further, in the embodiment example, as a method of generating a variable ID from a fixed ID, a method of padding a random number has been described, but another method such as using a probability encryption may be used.
【0094】
[Effect of the invention]
As described above, in the present invention, an identifier that looks variable each time is assigned to the user by using an encryption procedure that generates a code that shows apparently different values that can be decrypted into the same code, and this variable identifier. Since user information can be searched according to the property of (the property of being able to decrypt to the user's fixed identifier), the fixed identifier used to identify the user and the user's behavior history when grasping the user's behavior history. It will be possible to prevent the situation where the information is deeply linked with, and this will protect the user's privacy.
【0095】
Then, in the present invention, a variable identifier is assigned to the user by using an encryption procedure for generating codes indicating apparently different values that can be decrypted to the same code, and this variable identifier is changed to another variable identifier at any time. When making it look variable by being done, user information can be searched according to the property of this variable identifier (the property of being able to decode to the user's fixed identifier), so that the user's action history can be grasped. In such a case, it becomes possible to prevent a situation in which the fixed identifier used for identifying the user and the action history of the user are deeply linked, thereby protecting the privacy of the user.
【0096】
Moreover, by preparing the user information providing device of the present invention, the store side or the like does not directly grasp the user's action history, but in the end, a reliable management organization grasps it. It becomes possible to prevent the side and the like from directly grasping the user's information in detail.
[Simple explanation of drawings]
FIG. 1 is a diagram showing an example of a store to which the present invention is applied.
FIG. 2 is an example of an embodiment of the user information providing device of the present invention.
FIG. 3 is a diagram showing an example of management data of a personal information database.
FIG. 4 is an example of a processing flow executed by a variable ID issuing unit.
FIG. 5 is an example of a processing flow executed by the personal information providing unit.
FIG. 6 is a diagram showing an example of a method of configuring a variable ID.
FIG. 7 is a diagram showing an example of a store to which the present invention is applied.
FIG. 8 is an example of a processing flow executed by a variable ID issuing unit.
FIG. 9 is an example of a processing flow executed by a variable ID rewriting device.
[Explanation of symbols]
1 Store 2 User 10 Product display shelf 11 Wireless tag reader 12 Store host computer 13 Variable ID rewriting device 20 Mobile card 30 Personal information database 31 Variable ID issuer 32 Work memory 33 Personal information provider 200 Wireless tag
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2015115380A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2012244284A | Cited by | Japan | Search report |
| US11483160B2 | Cited by | United States of America | Applicant |
| JP2006134101A | Cited by | Japan | Search report |
| JP2024027626A | Cited by | Japan | Search report |
| US10778440B2 | Cited by | United States of America | Applicant |
| US11792016B2 | Cited by | United States of America | Applicant |
| US10063378B2 | Cited by | United States of America | Applicant |
| JP2015226265A | Cited by | Japan | Search report |
| JP2018173986A | Cited by | Japan | Search report |
| WO2024038695A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10305685B2 | Cited by | United States of America | Applicant |
| US11870912B2 | Cited by | United States of America | Applicant |
| JP2016149143A | Cited by | Japan | Search report |
| JP2012244284A | Cited by | Japan | Search report |
| US9912482B2 | Cited by | United States of America | Applicant |
| JP2016149143A | Cited by | Japan | Search report |
| WO2022185542A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP6079905B2 | Cited by | Japan | Examiner |
| JP2021108217A | Cited by | Japan | Search report |
| JP2006134115A | Cited by | Japan | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2003158939 | Japan | A | |
| JP20030158939 | – | – | – |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalA02 | A02 | |
| Notification of reasons for refusalA131 | A131 | |
| Report on retrievalA977 | A977 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2004362201
- Publication, DOCDB
- 2004362201
- Publication, EPODOC
- JP2004362201
- Application
- 158939
- Application, DOCDB
- 2003158939
- Application, EPODOC
- JP20030158939
Titles2
- Japanese
- ユーザ情報提供方法、ユーザ情報提供装置、ユーザ情報提供プログラム及びそのプログラムを記録した記録媒体
- English
- User information providing method, user information providing device, user information providing program, and recording medium on which the program is recorded.
Classification
- IPC, 4
- G06Q30 02
- G06Q10 00
- G06Q50 00
- H04L9 32