Attribute information provision method and attribute information provision system

US9946896B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9946896-B2
Application numberUS-201415024527-A
CountryUS
Kind codeB2
Filing dateOct 14, 2014
Priority dateOct 25, 2013
Publication dateApr 17, 2018
Grant dateApr 17, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A user attribute information provision system processes attribute information of users while preventing a leakage of attribute information. A provision apparatus: selects an apparatus group forming a communication path; generates information registration request in which information of a predetermined user is concealed in data recognizable only to a correspondent of the provision apparatus; and transmits the information registration request to an access destination solving apparatus via the apparatus groups. The access destination solving apparatus: stores the information of the user indicated by the information registration request and information of a correspondent provision apparatus; receives an inquiry request from an inquiry apparatus; and transfers the inquiry request by way of the correspondent provision apparatus as the user to the provision apparatus as the inquiry destination via the provision apparatuses in the communication path, thereby causing the provision apparatus to return the attribute information of the user to the inquiry apparatus.

First claim

Opening claim text (preview).

The invention claimed is: 1. An attribute information provision method, comprising: by a provision apparatus configured to provide attribute information on a user of a predetermined entity, selecting a plurality of provision apparatuses from other provision apparatuses on a network as an apparatus group forming a communication path of the attribute information by sequentially repeating data transfer through the provision apparatuses, and generating an information registration request in which information of a predetermined user is concealed in data recognizable only to a correspondent provision apparatus among the other provision apparatuses of the apparatus group; and transmitting the information registration request via the apparatus group to an access destination solving apparatus configured to manage a communication path between the provision apparatus and an inquiry apparatus that is to use the attribute information, and, by the access destination solving apparatus, receiving the information registration request, and storing the information of the user indicated by the information registration request and information of a provision apparatus in the apparatus group that has transmitted the information registration request directly to the access destination solving apparatus and that is a correspondent in a subsequent processing related to the information registration request, into a storage device; and receiving an inquiry request of a provision apparatus as an inquiry destination for attribute information of a predetermined user from the inquiry apparatus, and transferring the inquiry request by way of the correspondent provision apparatus registered for the user to the provision apparatus as the inquiry destination via the provision apparatuses in the communication path including the correspondent provision apparatus, thereby causing the provision apparatus as the inquiry destination to return the attribute information of the user to the inquiry apparatus via the provision apparatuses in the communication path. 2. The attribute information provision method according to claim 1 , wherein the access destination solving apparatus performs the processing of storing information in response to the information registration request by: generating an identifier unique to the information registration request; storing the identifier unique into the storage device while associating the identifier unique with the information of the user indicated by the information registration request and an identifier indicating the correspondent provision apparatus; and returning the identifier unique to the information registration request to the correspondent provision apparatus as a response to the information registration request, wherein each provision apparatus included in the apparatus group forming the communication path acquires the identifier unique to the information registration request from the response to the information registration request, stores, into a storage device, a combination of the unique identifier and the identifier of the correspondent provision apparatus in the communication path to which the provision apparatus belongs when transferring the information registration request, and transfers the response to the correspondent provision apparatus in the communication path, and upon receiving of the inquiry request from the inquire apparatus, the access destination solving apparatus performs processings of: searching the storage device for the unique identifier registered for the user and the identifier of the correspondent provision apparatus; and transmitting the unique identifier and the inquiry request to the correspondent provision apparatus to transfer the inquiry request by way of the correspondent provision apparatus to the provision apparatus as the inquiry destination via the provision apparatuses in the communication path corresponding to the unique identifier, thereby causing the provision apparatus as the inquiry destination to return the attribute information of the user to the inquiry apparatus via the provision apparatuses in the communication path. 3. The attribute information provision method according to claim 2 , wherein in the processing of storing information in response to the information registration request, the access destination solving apparatus stores the identifier unique to the information registration request, the information of the user indicated by the information registration request, the identifier indicating the correspondent provision apparatus, and data deletion information included in the information registration request into the storage device while associating them with each other; anyone of the provision apparatuses generates deletion request data including data deletion information and information of a deletion target user, newly selects an apparatus group forming a communication path, and transmits the deletion request data to the access destination solving apparatus via the selected apparatus group; the access destination solving apparatus receives the deletion request data, searches information held in the storage device to identify the information of the deletion target user indicated by the deletion request data, the identifier indicating a correspondent provision apparatus for the user, and the deletion information, and when the deletion information held in the storage device and the deletion information included in the deletion request data are identical with each other, deletes the information identified in the search from the storage device, and transmits the identifier unique to the information registration request and a deletion request to the correspondent provision apparatus identified in the search to transfer the deletion request data and the unique identifier to each provision apparatus in the communication path corresponding to the unique identifier; and each of the provision apparatuses having received the unique identifier and the deletion request data searches for the identifier indicating the correspondent provision apparatus, held in the provision apparatus, and associated with the unique identifier, transmits the unique identifier to the correspondent provision apparatus identified in the search, and then deletes the unique identifier and the identifier of the correspondent provision apparatus in the storage device thereof. 4. The attribute information provision method according to claim 1 , wherein when generating and transmitting the information registration request, a request-sender provision apparatus that generates and transmits the information registration request performs: a first processing of generating first data by encrypting the information of the predetermined user being a registration target indicated by the information registration request with a public key of the access destination solving apparatus; a processing of selecting, from the apparatus group, a first provision apparatus whose correspondent is the request-sender provision apparatus, and a second provision apparatus whose correspondent is the first provision apparatus in the apparatus group; and a second processing of generating the information registration request by encrypting the first data and identifiers of the second provision apparatus and the access destination solving apparatus, and transmits the generated information registration request to the first provision apparatus, wherein the first provision apparatus receives the information registration request from the request-sender provision apparatus, decodes the identifier of the second provision apparatus included in the second data by applying a private key of the first provision apparatus to the information registration request, and transmits the first data included in the information registration request to the provis

Assignees

Inventors

Classifications

  • Protecting personal data, e.g. for financial or medical purposes · CPC title

  • Replication, distribution or synchronisation of data between databases or within a distributed database system; Distributed database system architectures therefor · CPC title

  • User profiles · CPC title

  • Protecting access to data via a platform, e.g. using keys or access control rules · CPC title

  • wherein the identity of one or more communicating identities is hidden (cryptographic mechanisms or cryptographic arrangements for anonymous credentials or for identity based cryptographic systems H04L9/00) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9946896B2 cover?
A user attribute information provision system processes attribute information of users while preventing a leakage of attribute information. A provision apparatus: selects an apparatus group forming a communication path; generates information registration request in which information of a predetermined user is concealed in data recognizable only to a correspondent of the provision apparatus; and…
Who is the assignee on this patent?
Hitachi Ltd
What technology area does this patent fall under?
Primary CPC classification G06F21/6245. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 17 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).