system

The system addresses inefficiencies in security checks by automating data collection and risk assessment, providing improvement proposals, and learning from user feedback to enhance accuracy and compliance with international standards.

JP2026100714APending Publication Date: 2026-06-19SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
SOFTBANK GROUP CORP
Filing Date
2024-12-09
Publication Date
2026-06-19

Smart Images

  • Figure 2026100714000001_ABST
    Figure 2026100714000001_ABST
Patent Text Reader

Abstract

We provide the system. [Solution] A means of collecting core data from an information processing device, Means for generating an information record sheet based on the aforementioned core data, A means for determining the degree of risk using the generated information record sheet, A means of presenting improvement proposals based on the results of the aforementioned risk assessment, A system that includes this.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology of this disclosure relates to a system.

Background Art

[0002] Patent Document 1 discloses a persona chatbot control method performed by at least one processor, including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] When a company newly introduces a system or service, the security check work required is extremely time - consuming and labor - intensive, and usually depends on specific personnel with certain experience. The inefficiency of this process and the variation in risk analysis due to relying on human factors have become problems. Also, in order to comply with international security standards, it is necessary to quickly adapt to market changes and regulatory updates, which is not easy either.

Means for Solving the Problems

[0005] This invention provides a system that directly collects data from an information processing device and automatically generates an information record sheet based on that data. The generated sheet can be used to evaluate risks, and based on the evaluation results, specific improvement proposals can be presented. Furthermore, this system has a function to adjust risk assessments based on multiple international security standards, and accordingly, it incorporates a mechanism to learn from user feedback and improve accuracy in subsequent assessments. In this way, it achieves increased efficiency and improved accuracy in security check operations.

[0006] An "information processing device" is a computer system used to collect and process data.

[0007] "Core data" refers to important data that supports the operation of the entire system and includes information necessary for security checks.

[0008] An "information record sheet" is a document generated based on collected data, and it includes security requirements and evaluation items.

[0009] "Risk level" is an evaluation index that indicates the degree of security risk or potential threat.

[0010] An "improvement proposal" is a specific action plan proposed based on a risk assessment to improve the security of a system or service.

[0011] "Multilateral security standards" refer to security standards and guidelines established by multiple countries or regions.

[0012] "Feedback" refers to suggestions for improvement and evaluations received from users, and contributes to improving the accuracy of the system.

[0013] A "learning method" is a mechanism in which a system accumulates and analyzes past data and feedback, and uses this information to improve accuracy in subsequent operations. [Brief explanation of the drawing]

[0014] [Figure 1] It is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] It is a conceptual diagram showing an example of the main functions of a data processing device and a smart device according to the first embodiment. [Figure 3] It is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] It is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] It is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] It is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] It is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] It is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] It shows an emotion map to which a plurality of emotions are mapped. [Figure 10] It shows an emotion map to which a plurality of emotions are mapped. [Figure 11] It is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] It is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] It is a sequence diagram showing the processing flow of the data processing system in Example 2 when an emotion engine is combined. [Figure 14] It is a sequence diagram showing the processing flow of the data processing system in Application Example 2 when an emotion engine is combined.

Embodiments for Carrying Out the Invention

[0015] Hereinafter, an example of an embodiment of a system according to the technology of the present disclosure will be described with reference to the accompanying drawings.

[0016] First, the terms used in the following description will be explained.

[0017] In the following embodiments, a numbered processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Also, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), and the like.

[0018] In the following embodiments, a numbered RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a work memory by the processor.

[0019] In the following embodiments, a numbered storage is one or more non-volatile storage devices that store various programs and various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes, and the like.

[0020] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).

[0021] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."

[0022] [First Embodiment]

[0023] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.

[0024] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0025] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0026] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.

[0027] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0028] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0029] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.

[0030] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0031] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0032] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0033] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0034] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".

[0035] This invention relates to an information processing system for efficiently and accurately performing security checks on new systems and services within a company. Embodiments of the present invention are described in detail below.

[0036] Information gathering and creation of record sheets

[0037] The server automatically collects core data from connected systems. In this process, the server extracts necessary information using API access and database queries. By also collecting user operation logs and security settings information from terminals, it achieves comprehensive data collection.

[0038] Based on the collected data, the AI ​​agent automatically generates an information record sheet. This sheet includes important security requirements and evaluation items, and compliance is confirmed by comparing each item with a benchmark value.

[0039] Risk assessment and improvement proposals

[0040] The AI ​​agent performs a risk assessment using an information record sheet. The server analyzes the assessment results in real time and performs a risk determination that is adjusted to comply with multiple international safety standards. In this process, the server utilizes machine learning algorithms to increase the rate at which problems are detected.

[0041] Based on the evaluation results, the AI ​​agent generates specific improvement suggestions and notifies the user. The device displays the recommended actions to the user and provides an interface that prompts them to make the necessary changes.

[0042] Learning and the use of feedback

[0043] Users can select and implement necessary actions based on improvement suggestions. The server collects feedback on each action and stores it as training data. This feedback information is used to improve the accuracy of evaluations in the future.

[0044] As a concrete example, when a company introduces a new cloud service, this system can be used to conduct a quick and accurate security check. Once the user enters basic information, the server collects relevant data, and an AI agent automatically generates a record sheet to complete a risk assessment in a short time, proposing optimal improvement measures. In this way, companies can smoothly implement new services while ensuring security.

[0045] In implementing this invention, the system automates and streamlines key steps in security check operations, thereby significantly reducing the workload on personnel.

[0046] The following describes the processing flow.

[0047] Step 1:

[0048] Users log in to the information processing system and enter basic information about the systems and services that need to be evaluated. This information includes details such as the service name, purpose, and planned implementation date.

[0049] Step 2:

[0050] Based on the information entered by the user, the server initiates a data collection process for the systems being evaluated, via APIs and other means. Core data such as relevant system configuration data, access logs, and security settings are collected.

[0051] Step 3:

[0052] The terminal monitors the operation of applications in the local environment and records security settings and operation history on the user's terminal.

[0053] Step 4:

[0054] The server analyzes the collected core data and automatically generates information record sheets for use by the AI ​​agent. These sheets comprehensively cover security requirements and evaluation targets.

[0055] Step 5:

[0056] The AI ​​agent conducts a risk assessment based on the generated information record sheet, in accordance with pre-defined multinational security standards. During this process, it uses machine learning algorithms to perform pattern recognition based on past cases.

[0057] Step 6:

[0058] The server aggregates the results of the risk assessment and identifies areas that need improvement if a certain level of risk exceeds a set threshold.

[0059] Step 7:

[0060] The AI ​​agent generates specific improvement suggestions based on the evaluation results and notifies the user's device. The user can review the suggested improvements and take necessary actions.

[0061] Step 8:

[0062] Users provide feedback to the system about the measures they have actually implemented. This feedback is used to improve the accuracy of future evaluations.

[0063] Step 9:

[0064] The server stores the collected feedback in a database, which the AI ​​agent uses for learning. Through this entire process, the efficiency and accuracy of the system's overall security check process continuously improve.

[0065] (Example 1)

[0066] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0067] Companies and organizations are required to efficiently and highly assess security risks for new information processing systems and services they implement, and to quickly propose necessary improvements. However, achieving this requires acquiring vast amounts of data and conducting accurate analysis and recommendations, which has been a challenge for traditional methods due to the significant time and effort required. Furthermore, effective risk management has been difficult because risk assessments that comply with international security standards and improvements that utilize user feedback have not been sufficiently implemented.

[0068] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0069] In this invention, the server includes means for acquiring data elements from an information processing system, means for creating a record based on the data elements, and means for evaluating risks using the generated record. This makes it possible to efficiently and quickly evaluate security risks and provide improvement suggestions in accordance with international standards. Furthermore, by accumulating user responses as data and utilizing them in subsequent evaluations, the accuracy of evaluations can also be improved.

[0070] An "information processing system" is a general term for computer devices and related technologies configured for the purpose of collecting, storing, analyzing, and processing diverse data into information.

[0071] A "data element" refers to a fragment or item of information that is treated as a basic unit in information processing.

[0072] A "record document" is a document-based record generated based on acquired data elements, and is used for organizing and evaluating various types of information.

[0073] "Risk assessment" is the process of identifying potential dangers and problems from data and operations in an information processing system, and analyzing their importance and impact.

[0074] An "improvement proposal" is a set of specific instructions or recommendations based on the results of a risk assessment, outlining how to achieve a better state by addressing identified problems.

[0075] "User responses" refer to the responses and actions that users exhibit in response to presented information and suggestions, and include those used as evaluation and learning data.

[0076] This invention relates to an information processing system that efficiently checks security and provides improvement suggestions when introducing new information processing systems and services in companies and organizations. Specifically, it includes a management server, user terminals, and an AI agent.

[0077] The server first automatically retrieves data elements from information processing systems installed within the company. In this process, the server efficiently collects necessary information, such as financial data and user access logs, using API endpoints and database queries. Examples of specific hardware and software used include database management systems (DBMS) and RESTful APIs.

[0078] The collected data is compiled into an organized record by an AI agent. The AI ​​agent uses a generative AI model to analyze each data element and generate a record that conforms to security standards and evaluation criteria. This record is then used in the subsequent risk assessment process.

[0079] The user terminal presents specific improvement suggestions to the user based on the generated records and risk assessment results. For example, the user can check recommended actions such as changing system settings or updating software through the terminal.

[0080] As a concrete example, if a company uses this system when introducing a new cloud service, the user will input service details as prompts. A possible prompt might be something like, "Please tell me how to perform security checks when introducing a new cloud service." The server immediately collects relevant data via API, and an AI agent creates a record and performs a risk assessment. By providing improvement suggestions to the user via the terminal, efficient and accurate security checks are achieved.

[0081] This system configuration allows companies to quickly assess security risks when introducing new information processing systems and implement corrective measures that comply with international standards. This process can be carried out in less time and with less effort than conventional methods, significantly reducing the workload of personnel.

[0082] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0083] Step 1:

[0084] The server connects to information processing systems to retrieve data elements. Inputs are specific API endpoints or database query parameters, and outputs are raw data collected from each system. For example, the server sends an API request to a financial system to retrieve relevant financial data. At this stage, accuracy in data retrieval is crucial.

[0085] Step 2:

[0086] The server sends the acquired raw data to the AI ​​agent. The input is the raw data acquired in step 1, and the output is a document that organizes the information. The AI ​​agent analyzes the data using a generative AI model and generates a document based on security standards and evaluation criteria. At this stage, multiple data elements are integrated and organized by important items.

[0087] Step 3:

[0088] The server assesses risk using records generated by the AI ​​agent. The input is the records received from the AI ​​agent, and the output is the risk assessment result. The server evaluates each element based on international safety standards and determines the presence and extent of risk. For example, risks related to data protection are assessed.

[0089] Step 4:

[0090] The terminal presents improvement suggestions to the user based on the risk assessment results generated by the server. The input is the risk assessment results, and the output is the improvement suggestions viewable by the user. The terminal displays the suggestions to the user through a visual interface and prompts specific actions. For example, strengthening encryption settings might be recommended.

[0091] Step 5:

[0092] The user selects and performs an action based on improvement suggestions presented through the terminal. The input is the details of the suggestion from the terminal, and the output is the result of the selected action. The user makes changes to settings, etc., and the system records these actions.

[0093] Step 6:

[0094] The server collects user feedback and the results of actions taken, storing them as training data for future evaluations. The input is user feedback, and the output is an updated evaluation model. This improves the accuracy of subsequent security evaluations. The feedback contributes to system improvement and helps deepen continuous risk assessment.

[0095] (Application Example 1)

[0096] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0097] In modern information systems, it is crucial to efficiently and quickly assess security risks and immediately propose countermeasures. However, existing systems require manual verification and analysis of a large amount of information, which is prone to delays and human errors. Furthermore, in environments where immediate on-site response is required, output via devices may not be properly performed.

[0098] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0099] In this invention, the server includes means for collecting core information from an information processing device, means for generating an information record document based on the core information, means for determining the degree of risk using the generated information record document, and means for visualizing the improvement suggestions on a smart wearable device and providing direct feedback to the user. This enables efficient evaluation of security risks and allows users to quickly understand and implement improvement suggestions on-site.

[0100] An "information processing device" is an electronic device used to collect core information and perform data analysis and processing.

[0101] "Core information" refers to fundamental and important data necessary for evaluating the security of a system.

[0102] An "information record document" is a document that is generated based on collected core information and outlines various evaluations and requirements.

[0103] "Means for determining the degree of risk" refers to a function for evaluating security risks using information records and documents.

[0104] "Means for presenting improvement suggestions" refers to a function that shows users specific improvement measures based on the results of the risk assessment.

[0105] A "smart wearable device" is a computer or communication device that a user can wear, capable of displaying information and providing feedback.

[0106] "Feedback" refers to information or notifications provided by a system to a user.

[0107] In this invention, an information processing system efficiently collects and analyzes core information to determine security risks and provide users with appropriate improvement suggestions. Specific embodiments are described below.

[0108] Program processing and operation

[0109] The server collects core information through information processing devices. This includes data retrieval using API access and database queries. The server then generates information record documents based on the collected information. This generation process involves formatting and analyzing the data using libraries such as Python's Pandas library.

[0110] Smart wearable devices (e.g., smart glasses) visualize and present risk assessments and improvement suggestions to users based on recorded information documents. In an environment where these wearable devices and servers can communicate bidirectionally, it is possible to notify users of changes and suggestions in real time.

[0111] Specific example

[0112] In a data center, a new device is about to connect to the network. At this moment, a server instantly collects security information about the device and displays the risk assessment results on smart glasses. The user sees the visualized results on the glasses and immediately implements the suggested security settings.

[0113] Examples of prompts for generative AI models

[0114] "Design a user interface on smart glasses that displays a risk assessment and improvement suggestions based on collected data for security checks when connecting new devices to a data network."

[0115] Thus, the present invention is designed to respond quickly and accurately to a variety of security risks in information systems environments, including data centers.

[0116] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0117] Step 1:

[0118] The server collects core information using API access and database queries. The input is security-related information from each device connected to the network, and the output is organized foundational data. The server uses Python and the Pandas library to format and parse this data.

[0119] Step 2:

[0120] The server generates information record documents based on the collected core information. The input is formatted base data, and the output is information record documents for risk assessment. The server uses a machine learning model to evaluate each element of the core information and visualize it in the document.

[0121] Step 3:

[0122] The server determines the level of risk using the generated information record documents. The input is the information record documents, and the output is the risk assessment result. The server uses machine learning algorithms such as Scikit-learn to perform risk assessments based on multiple international standards.

[0123] Step 4:

[0124] The terminal generates and displays improvement suggestions based on the risk assessment results. The input is the risk assessment results, and the output is the improvement suggestions presented to the user. The terminal uses visualization software to provide an interface for displaying improvement measures on a smart wearable device.

[0125] Step 5:

[0126] The user reviews improvement suggestions presented through a smart wearable device and selects the necessary actions. The input is the displayed improvement suggestions, and the output is the security action selected by the user. The user can adjust security settings according to the instructions.

[0127] Step 6:

[0128] The server collects feedback on user security actions and stores it as training data. The input is user feedback, and the output is training data to improve the accuracy of future evaluations. The server stores the feedback in a database to prepare for the next action.

[0129] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0130] This invention relates to a system that optimizes the security check process and provides more user-friendly improvement suggestions by combining an emotion engine that recognizes user emotions in an information processing system. Embodiments of this invention are described in detail below.

[0131] Information gathering and creation of record sheets

[0132] The server automatically collects core data from systems or services that require evaluation. This is done through API calls and log analysis, and necessary security information is collected. Additionally, it monitors user activity history and security settings on terminals to understand their operational status.

[0133] Based on the collected data, the AI ​​agent automatically generates an information record sheet. This sheet contains a checklist to ensure security requirements are met and is used as a basis for audits and evaluations.

[0134] Risk assessment and improvement suggestions

[0135] In the evaluation process, an AI agent uses an information recording sheet to determine the risk level of the system or service. The server generates improvement suggestions based on this and provides the user's device with the most suitable suggestions, taking into account the user's emotional state.

[0136] The emotion engine analyzes the user's facial expressions and voice data in real time during their interaction. This allows it to understand the user's emotions regarding the suggestions and adjust accordingly. For example, if the user is feeling anxious, the suggestion will be adjusted to be easier to understand and more approachable.

[0137] Feedback and Learning

[0138] When users accept improvement suggestions, they have choices based on emotional data collected by the emotion engine. The user's response is recorded on the server as feedback and reflected in future suggestions. This information is stored in the AI ​​agent as training data, contributing to future improvements in risk assessment and the accuracy of improvement suggestions.

[0139] For example, when a user tries to improve the security of a new business network system, this system can automatically determine the level of risk and suggest improvement measures based on sentiment. For instance, if feedback indicates that the system is complex, the suggestions will be adjusted to be simpler, helping the user implement the system smoothly.

[0140] This invention streamlines security checks and enables user-driven system improvements. By using this system, security personnel can perform their duties with confidence, leading to an overall improvement in security levels.

[0141] The following describes the processing flow.

[0142] Step 1:

[0143] Users input basic information about the systems and services requiring evaluation through the information processing system's interface. This information serves as a guide for identifying the targets for evaluation and for collecting appropriate data.

[0144] Step 2:

[0145] The server automatically collects core data from the target system based on information entered by the user. This collection includes direct access using APIs and acquisition of log data through network monitoring.

[0146] Step 3:

[0147] The device collects data locally related to user actions and settings. This includes security policy settings and user activity history.

[0148] Step 4:

[0149] The server integrates all the collected data, and an AI agent automatically generates an information record sheet. This sheet serves as a list of security requirements and evaluation points.

[0150] Step 5:

[0151] The AI ​​agent refers to the generated information record sheet and makes a risk assessment based on the established criteria. The server then uses this result to create specific improvement suggestions.

[0152] Step 6:

[0153] The emotion engine activates and acquires real-time emotional data from the user. It uses the device's camera and microphone to perform facial expression analysis and voice data analysis to understand the user's emotional state.

[0154] Step 7:

[0155] The server adjusts improvement suggestions based on the user's emotional state obtained from the emotion engine and presents them in the most appropriate and easily understandable format for the user. If the user expresses anxiety, measures such as adding more detailed explanations are taken.

[0156] Step 8:

[0157] Users review the proposed improvements and implement them as needed. They then provide feedback on their feelings and the results after implementing the suggestions.

[0158] Step 9:

[0159] The server collects user feedback and sentiment data and stores it in a database. This data is then analyzed using machine learning algorithms and used to improve the accuracy of evaluations and refine suggestions for future evaluations.

[0160] These steps enable the system to perform flexible and highly accurate security checks that take user emotions into consideration, and to provide adaptive improvement suggestions.

[0161] (Example 2)

[0162] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".

[0163] Traditional security check systems often failed to consider user emotions and feedback, potentially resulting in a poor user experience. Furthermore, they were unable to effectively utilize specific user feedback to improve the accuracy of risk assessments, limiting the accuracy of subsequent improvement suggestions. Additionally, they struggled to handle situations where security standards differed across countries.

[0164] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0165] In this invention, the server includes means for collecting basic information from information processing means, means for generating an information recording medium based on the basic information, means for determining risk using the generated information recording medium, means for analyzing user emotions and adjusting improvement suggestions, and means for recording user feedback and utilizing it for future evaluations. This enables improvement suggestions that take user emotions into account, improving the accuracy of security checks and the user experience. Furthermore, it facilitates compliance with multinational security standards and allows for continuous improvement of the accuracy of risk assessment.

[0166] "Information processing means" refers to devices and software for collecting, organizing, and analyzing data, and which have the function of acquiring basic system information.

[0167] "Basic information" refers to data necessary for evaluating the operation and security status of a system or service, and is considered core information.

[0168] An "information recording medium" refers to documents and digital files generated based on collected data, and includes checklists that indicate the evaluation criteria for the system.

[0169] "Risk assessment" refers to the process of analyzing and evaluating the degree of security risks associated with a system or service, and the act of identifying the need for improvement.

[0170] "Means of analyzing user emotions" refers to devices or software that analyze a user's facial expressions and voice data in real time to identify the user's emotional state.

[0171] "Means for recording feedback and using it for future evaluations" refers to a process or system for saving user responses and opinions in a database and using them to improve the system later.

[0172] This invention is a system that optimizes the security check process in an information processing system by utilizing an emotion engine to recognize user emotions. Specific embodiments of the invention are shown below.

[0173] The server first collects basic information from the system or service that needs to be evaluated. Data collection can be done using RESTful API calls or log analysis tools (e.g., Splunk). This allows for the efficient acquisition of security information and its storage in a database.

[0174] Next, an AI agent on the server generates an information storage medium based on the collected basic information. This process uses the Python pandas library to organize the data and output it to an Excel file in checklist format. This information storage medium is then used as a standard for audits and evaluations.

[0175] Furthermore, the AI ​​agent analyzes data from information storage media and performs risk assessment. Based on these results, the server generates improvement suggestions and delivers them to the user's terminal. In this process, the suggestions are customized using an emotion engine, taking into account the user's past responses. For example, if the user has expressed anxiety about a complex explanation, the suggestions will be adjusted to a simpler and easier-to-understand format.

[0176] The device uses its built-in camera and microphone to collect user facial expressions and voice data in real time, which are then analyzed by an emotion engine. When the user accepts a suggestion, they provide feedback, which is used to improve future suggestions.

[0177] For example, if a user aims to improve the security of a new business network system, this invention allows the system to automatically assess risks and propose improvement measures based on emotion. The user responds to on-screen dialogue such as "Do you accept this suggestion?", and the feedback is recorded and used for future evaluations.

[0178] An example of a prompt message could be a text format such as, "Use user sentiment data to assess the current state of network security and suggest improvements." This streamlines the security check process and improves the user experience.

[0179] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0180] Step 1:

[0181] The server collects basic information from the system or service requiring evaluation. Inputs include API endpoints and log files. The data is extracted using RESTful API calls and log analysis tools and stored in a database. The output is a dataset of security information.

[0182] Step 2:

[0183] The AI ​​agent on the server generates an information storage medium based on the basic information it collects. A series of structured data is used as input. The AI ​​agent organizes the data using the Python pandas library and outputs it to an Excel file in checklist format. The output is an information storage medium containing the system's evaluation criteria.

[0184] Step 3:

[0185] The AI ​​agent analyzes data from information storage media to determine risk. The input is collected system data. This process uses a machine learning model to perform risk scoring and identify areas with safety issues. The output is an assessment report indicating the system's risk level.

[0186] Step 4:

[0187] The server generates improvement suggestions based on the risk assessment results. Inputs include evaluation reports and past user response data. This allows the AI ​​agent to create optimal improvement plans for the user and fine-tune the suggestions using sentiment data. The output is a customized improvement suggestion based on the user's emotions.

[0188] Step 5:

[0189] The device uses its built-in camera and microphone to collect user facial expressions and voice data in real time, which is then analyzed by an emotion engine. Input consists of user voice and visual data. Output is data indicating the user's emotional state, which is used to adjust improvement suggestions.

[0190] Step 6:

[0191] The user reviews improvement suggestions displayed on their device and provides feedback. The input is the improvement suggestion displayed on the screen. The user chooses whether to accept or reject the suggestion, and this response is processed as input. The output is feedback data recording the user's selection.

[0192] Step 7:

[0193] The server records user feedback and uses it for future evaluations. The input is user feedback data. The server inputs this into its learning function to improve the accuracy of future risk assessments and improvement suggestions. The output is the improved evaluation and suggestion process.

[0194] (Application Example 2)

[0195] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as a "server" and the smart device 14 as a "terminal".

[0196] In modern information processing systems, the complex security check process is a significant challenge for users. In particular, determining the level of security risk, as well as how users respond, depends on individual emotions and circumstances, highlighting the need for improved user experience. Furthermore, traditional systems often fail to adequately utilize user feedback, hindering future evaluations.

[0197] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[0198] In this invention, the server includes means for collecting core data from an information processing device, means for generating an information record sheet based on the core data, means for determining the level of risk using the generated information record sheet, means for determining the emotional state using an emotion engine that analyzes the user's emotions and presenting optimal improvement suggestions according to those emotions, and means for presenting improvement suggestions based on the results of the risk level determination. This not only streamlines the assessment of security risks but also improves usability by providing improvement suggestions based on the user's emotions. Furthermore, feedback is accumulated as learning data, which helps improve the accuracy of evaluations, thus enabling continuous system improvement.

[0199] An "information processing device" is a device equipped with the functions of collecting, processing, storing, and analyzing data, and mainly refers to computers and servers.

[0200] "Core data" refers to the main data necessary for evaluating a system or service, and includes operation history and system configuration information.

[0201] An "information record sheet" is a document automatically generated based on core data, and it includes a list for checking security requirements.

[0202] "Risk assessment" is the process of evaluating and determining the risk level of a system or service based on an information record sheet.

[0203] An "emotion engine" is a technology that analyzes the user's facial expressions and voice data during operation to determine their emotional state in real time.

[0204] "Improvement suggestions" are proposals generated based on the results of risk assessments and the user's emotional state, and are aimed at improving security and usability.

[0205] "Feedback" refers to the user's reaction and opinion after receiving suggestions from the system, and this data is used to further improve the system.

[0206] "Learning methods" refer to the process of continuously collecting feedback and using it as data to improve the accuracy of future system evaluations and improvement suggestions.

[0207] The system for realizing this invention consists of an information processing device, an emotion engine, a data collection server, and a means for suggesting improvements. First, the server collects core data from the information processing device. This core data includes user operation history, security settings information, and terminal operating status. This data is automatically collected through appropriate API calls and log analysis. Based on the collected data, the server generates an information record sheet using an AI model (e.g., TENSORFLOW®) and uses this to determine the risk level of the system and service.

[0208] User emotion analysis is achieved by an emotion engine (e.g., Affectiva SDK) analyzing voice data and facial expressions. The analysis results are sent to the server in real time, and the server generates optimal improvement suggestions based on the user's emotional state. The improvement suggestions are presented in a friendly format that reduces user anxiety and improves understanding.

[0209] In the feedback process, the server collects user responses and stores them as training data. This data contributes to improving the accuracy of risk assessments and improvement suggestions for the next and future instances.

[0210] For example, when a user attempts to connect to public Wi-Fi, the server could assess the risk level of the connection, and if an emotion engine analyzes the user's anxiety, it might provide a guided suggestion on how to configure a VPN to alleviate that anxiety.

[0211] An example of a prompt to input into the AI ​​generation model would be, "The user feels uneasy when using public Wi-Fi. Please generate the best security improvement suggestions for this situation." This would allow the system to provide the user with specific and useful suggestions.

[0212] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0213] Step 1:

[0214] The server collects core data from the terminal. Specifically, it obtains user operation history and security settings information through API calls and log analysis. It receives terminal logs and operation information as input, extracts and processes the necessary security-related data, and prepares the materials for the information record sheet necessary for subsequent data analysis.

[0215] Step 2:

[0216] The server generates an information record sheet based on the core data it collects. Here, the collected data points are organized and applied to a template to create a security checklist. The input is core data, and the output is an information record sheet for assessment. This information record sheet is used later for risk assessment.

[0217] Step 3:

[0218] The server uses the generated information log sheet to determine the level of risk. An AI model (e.g., TensorFlow) is used to analyze the data in the information log sheet and evaluate the system's security risk. In this process, the information log sheet is used as input, and the security risk assessment is obtained as output.

[0219] Step 4:

[0220] The emotion engine analyzes the user's emotions in real time. The device sends voice and facial data to the emotion engine (e.g., Affectiva SDK) to identify the user's current emotional state. It receives voice and image data as input and generates an emotional state determination result as output.

[0221] Step 5:

[0222] The server generates optimal improvement suggestions based on the risk assessment results and sentiment analysis results, and presents them to the user's terminal. Specifically, it combines the risk assessment value with the user's emotional state to determine the content and format of the improvement suggestions. The input is the risk assessment and emotional state assessment results, and the output is the adjusted improvement suggestions.

[0223] Step 6:

[0224] The user reviews the suggested improvement and provides feedback. The device sends the user's response (whether they accept the suggestion, whether they request further improvements, etc.) to the server. The input is the user's opinion or response, and the output is feedback data reflecting that.

[0225] Step 7:

[0226] The server accumulates user feedback as training data and uses it to improve evaluation accuracy in the future. The server stores the feedback data in a database and uses it as training data for the AI ​​model. The input is the feedback data, and the output is the updated training dataset.

[0227] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0228] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0229] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may be performed by the smart device 14.

[0230] [Second Embodiment]

[0231] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.

[0232] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0233] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0234] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.

[0235] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0236] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0237] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0238] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0239] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0240] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0241] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0242] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0243] This invention relates to an information processing system for efficiently and accurately performing security checks on new systems and services within a company. Embodiments of the present invention are described in detail below.

[0244] Information gathering and creation of record sheets

[0245] The server automatically collects core data from connected systems. In this process, the server extracts necessary information using API access and database queries. By also collecting user operation logs and security settings information from terminals, it achieves comprehensive data collection.

[0246] Based on the collected data, the AI ​​agent automatically generates an information record sheet. This sheet includes important security requirements and evaluation items, and compliance is confirmed by comparing each item with a benchmark value.

[0247] Risk assessment and improvement proposals

[0248] The AI ​​agent performs a risk assessment using an information record sheet. The server analyzes the assessment results in real time and performs a risk determination that is adjusted to comply with multiple international safety standards. In this process, the server utilizes machine learning algorithms to increase the rate at which problems are detected.

[0249] Based on the evaluation results, the AI ​​agent generates specific improvement suggestions and notifies the user. The device displays the recommended actions to the user and provides an interface that prompts them to make the necessary changes.

[0250] Learning and the use of feedback

[0251] Users can select and implement necessary actions based on improvement suggestions. The server collects feedback on each action and stores it as training data. This feedback information is used to improve the accuracy of evaluations in the future.

[0252] As a concrete example, when a company introduces a new cloud service, this system can be used to conduct a quick and accurate security check. Once the user enters basic information, the server collects relevant data, and an AI agent automatically generates a record sheet to complete a risk assessment in a short time, proposing optimal improvement measures. In this way, companies can smoothly implement new services while ensuring security.

[0253] In implementing this invention, the system automates and streamlines key steps in security check operations, thereby significantly reducing the workload on personnel.

[0254] The following describes the processing flow.

[0255] Step 1:

[0256] Users log in to the information processing system and enter basic information about the systems and services that need to be evaluated. This information includes details such as the service name, purpose, and planned implementation date.

[0257] Step 2:

[0258] Based on the information entered by the user, the server initiates a data collection process for the systems being evaluated, via APIs and other means. Core data such as relevant system configuration data, access logs, and security settings are collected.

[0259] Step 3:

[0260] The terminal monitors the operation of applications in the local environment and records security settings and operation history on the user's terminal.

[0261] Step 4:

[0262] The server analyzes the collected core data and automatically generates information record sheets for use by the AI ​​agent. These sheets comprehensively cover security requirements and evaluation targets.

[0263] Step 5:

[0264] The AI ​​agent conducts a risk assessment based on the generated information record sheet, in accordance with pre-defined multinational security standards. During this process, it uses machine learning algorithms to perform pattern recognition based on past cases.

[0265] Step 6:

[0266] The server aggregates the results of the risk assessment and identifies areas that need improvement if a certain level of risk exceeds a set threshold.

[0267] Step 7:

[0268] The AI ​​agent generates specific improvement suggestions based on the evaluation results and notifies the user's device. The user can review the suggested improvements and take necessary actions.

[0269] Step 8:

[0270] Users provide feedback to the system about the measures they have actually implemented. This feedback is used to improve the accuracy of future evaluations.

[0271] Step 9:

[0272] The server stores the collected feedback in a database, which the AI ​​agent uses for learning. Through this entire process, the efficiency and accuracy of the system's overall security check process continuously improve.

[0273] (Example 1)

[0274] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0275] Companies and organizations are required to efficiently and highly assess security risks for new information processing systems and services they implement, and to quickly propose necessary improvements. However, achieving this requires acquiring vast amounts of data and conducting accurate analysis and recommendations, which has been a challenge for traditional methods due to the significant time and effort required. Furthermore, effective risk management has been difficult because risk assessments that comply with international security standards and improvements that utilize user feedback have not been sufficiently implemented.

[0276] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0277] In this invention, the server includes means for acquiring data elements from an information processing system, means for creating a record based on the data elements, and means for evaluating risks using the generated record. This makes it possible to efficiently and quickly evaluate security risks and provide improvement suggestions in accordance with international standards. Furthermore, by accumulating user responses as data and utilizing them in subsequent evaluations, the accuracy of evaluations can also be improved.

[0278] An "information processing system" is a general term for computer devices and related technologies configured for the purpose of collecting, storing, analyzing, and processing diverse data into information.

[0279] A "data element" refers to a fragment or item of information that is treated as a basic unit in information processing.

[0280] A "record document" is a document-based record generated based on acquired data elements, and is used for organizing and evaluating various types of information.

[0281] "Risk assessment" is the process of identifying potential dangers and problems from data and operations in an information processing system, and analyzing their importance and impact.

[0282] An "improvement proposal" is based on the results of risk assessment and presents specific instructions and recommendations for achieving a better state for identified problems.

[0283] "User reaction" refers to the responses and actions shown by users to the presented information and proposals, including those used as data for evaluation and learning.

[0284] This invention relates to an information processing system that efficiently checks the security when introducing a new information processing system or service in an enterprise or organization and makes improvement proposals. Specifically, it includes a management server, user terminals, and an AI agent.

[0285] The server first automatically acquires data elements from the information processing system installed within the enterprise. At this time, the server uses API endpoints and database queries to efficiently collect necessary information such as financial data and user access logs. Examples of specific hardware and software used include a database management system (DBMS) and a RESTful API.

[0286] The collected data is created by the AI agent as a record book that organizes the information. The AI agent uses a generative AI model to analyze each data element and generate a record book according to security criteria and evaluation target items. This record book is used in the subsequent risk assessment process.

[0287] Based on the generated record book and the results of the risk assessment, the user terminal presents specific improvement proposals to the user. For example, the user can confirm recommended actions such as system setting changes and software updates through the terminal.

[0288] As a concrete example, if a company uses this system when introducing a new cloud service, the user will input service details as prompts. A possible prompt might be something like, "Please tell me how to perform security checks when introducing a new cloud service." The server immediately collects relevant data via API, and an AI agent creates a record and performs a risk assessment. By providing improvement suggestions to the user via the terminal, efficient and accurate security checks are achieved.

[0289] This system configuration allows companies to quickly assess security risks when introducing new information processing systems and implement corrective measures that comply with international standards. This process can be carried out in less time and with less effort than conventional methods, significantly reducing the workload of personnel.

[0290] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0291] Step 1:

[0292] The server connects to information processing systems to retrieve data elements. Inputs are specific API endpoints or database query parameters, and outputs are raw data collected from each system. For example, the server sends an API request to a financial system to retrieve relevant financial data. At this stage, accuracy in data retrieval is crucial.

[0293] Step 2:

[0294] The server sends the acquired raw data to the AI ​​agent. The input is the raw data acquired in step 1, and the output is a document that organizes the information. The AI ​​agent analyzes the data using a generative AI model and generates a document based on security standards and evaluation criteria. At this stage, multiple data elements are integrated and organized by important items.

[0295] Step 3:

[0296] The server assesses risk using records generated by the AI ​​agent. The input is the records received from the AI ​​agent, and the output is the risk assessment result. The server evaluates each element based on international safety standards and determines the presence and extent of risk. For example, risks related to data protection are assessed.

[0297] Step 4:

[0298] The terminal presents improvement suggestions to the user based on the risk assessment results generated by the server. The input is the risk assessment results, and the output is the improvement suggestions viewable by the user. The terminal displays the suggestions to the user through a visual interface and prompts specific actions. For example, strengthening encryption settings might be recommended.

[0299] Step 5:

[0300] The user selects and performs an action based on improvement suggestions presented through the terminal. The input is the details of the suggestion from the terminal, and the output is the result of the selected action. The user makes changes to settings, etc., and the system records these actions.

[0301] Step 6:

[0302] The server collects user feedback and the results of actions taken, storing them as training data for future evaluations. The input is user feedback, and the output is an updated evaluation model. This improves the accuracy of subsequent security evaluations. The feedback contributes to system improvement and helps deepen continuous risk assessment.

[0303] (Application Example 1)

[0304] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0305] In modern information systems, it is important to efficiently and quickly evaluate security risks and immediately present countermeasures. However, in existing systems, a large amount of information needs to be manually checked and analyzed, which easily leads to work delays and human errors. In addition, in an environment where immediate response at the scene is required, output via a device may not be properly performed.

[0306] The specific processing by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following respective means.

[0307] In this invention, the server includes means for collecting core information from an information processing device, means for generating an information recording document based on the core information, means for determining a risk level using the generated information recording document, and means for visualizing the improvement proposal in a smart wearable device and providing direct feedback to the user. Thereby, it becomes possible to efficiently evaluate security risks and enable the user to quickly understand and execute improvement proposals on-site.

[0308] The "information processing device" is an electronic device for collecting core information and performing data analysis and processing.

[0309] The "core information" is basic and important data necessary for the security evaluation of the system.

[0310] The "information recording document" is a document indicating various evaluations and requirements, generated based on the collected core information.

[0311] The "means for determining the risk level" is a function for evaluating security risks using the information recording document.

[0312] The "means for presenting an improvement proposal" is a function for showing specific improvement measures to the user based on the result of the risk level determination.

[0313] A "smart wearable device" is a computer or communication device that a user can wear, capable of displaying information and providing feedback.

[0314] "Feedback" refers to information or notifications provided by a system to a user.

[0315] In this invention, an information processing system efficiently collects and analyzes core information to determine security risks and provide users with appropriate improvement suggestions. Specific embodiments are described below.

[0316] Program processing and operation

[0317] The server collects core information through information processing devices. This includes data retrieval using API access and database queries. The server then generates information record documents based on the collected information. This generation process involves formatting and analyzing the data using libraries such as Python's Pandas library.

[0318] Smart wearable devices (e.g., smart glasses) visualize and present risk assessments and improvement suggestions to users based on recorded information documents. In an environment where these wearable devices and servers can communicate bidirectionally, it is possible to notify users of changes and suggestions in real time.

[0319] Specific example

[0320] In a data center, a new device is about to connect to the network. At this moment, a server instantly collects security information about the device and displays the risk assessment results on smart glasses. The user sees the visualized results on the glasses and immediately implements the suggested security settings.

[0321] Examples of prompts for generative AI models

[0322] "Design a user interface on smart glasses that displays a risk assessment and improvement suggestions based on collected data for security checks when connecting new devices to a data network."

[0323] Thus, the present invention is designed to respond quickly and accurately to a variety of security risks in information systems environments, including data centers.

[0324] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0325] Step 1:

[0326] The server collects core information using API access and database queries. The input is security-related information from each device connected to the network, and the output is organized foundational data. The server uses Python and the Pandas library to format and parse this data.

[0327] Step 2:

[0328] The server generates information record documents based on the collected core information. The input is formatted base data, and the output is information record documents for risk assessment. The server uses a machine learning model to evaluate each element of the core information and visualize it in the document.

[0329] Step 3:

[0330] The server determines the level of risk using the generated information record documents. The input is the information record documents, and the output is the risk assessment result. The server uses machine learning algorithms such as Scikit-learn to perform risk assessments based on multiple international standards.

[0331] Step 4:

[0332] The terminal generates and displays improvement suggestions based on the risk assessment results. The input is the risk assessment results, and the output is the improvement suggestions presented to the user. The terminal uses visualization software to provide an interface for displaying improvement measures on a smart wearable device.

[0333] Step 5:

[0334] The user reviews improvement suggestions presented through a smart wearable device and selects the necessary actions. The input is the displayed improvement suggestions, and the output is the security action selected by the user. The user can adjust security settings according to the instructions.

[0335] Step 6:

[0336] The server collects feedback on user security actions and stores it as training data. The input is user feedback, and the output is training data to improve the accuracy of future evaluations. The server stores the feedback in a database to prepare for the next action.

[0337] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0338] This invention relates to a system that optimizes the security check process and provides more user-friendly improvement suggestions by combining an emotion engine that recognizes user emotions in an information processing system. Embodiments of this invention are described in detail below.

[0339] Information gathering and creation of record sheets

[0340] The server automatically collects core data from systems or services that require evaluation. This is done through API calls and log analysis, and necessary security information is collected. Additionally, it monitors user activity history and security settings on terminals to understand their operational status.

[0341] Based on the collected data, the AI ​​agent automatically generates an information record sheet. This sheet contains a checklist to ensure security requirements are met and is used as a basis for audits and evaluations.

[0342] Risk assessment and improvement suggestions

[0343] In the evaluation process, an AI agent uses an information recording sheet to determine the risk level of the system or service. The server generates improvement suggestions based on this and provides the user's device with the most suitable suggestions, taking into account the user's emotional state.

[0344] The emotion engine analyzes the user's facial expressions and voice data in real time during their interaction. This allows it to understand the user's emotions regarding the suggestions and adjust accordingly. For example, if the user is feeling anxious, the suggestion will be adjusted to be easier to understand and more approachable.

[0345] Feedback and Learning

[0346] When users accept improvement suggestions, they have choices based on emotional data collected by the emotion engine. The user's response is recorded on the server as feedback and reflected in future suggestions. This information is stored in the AI ​​agent as training data, contributing to future improvements in risk assessment and the accuracy of improvement suggestions.

[0347] For example, when a user tries to improve the security of a new business network system, this system can automatically determine the level of risk and suggest improvement measures based on sentiment. For instance, if feedback indicates that the system is complex, the suggestions will be adjusted to be simpler, helping the user implement the system smoothly.

[0348] This invention streamlines security checks and enables user-driven system improvements. By using this system, security personnel can perform their duties with confidence, leading to an overall improvement in security levels.

[0349] The following describes the processing flow.

[0350] Step 1:

[0351] Users input basic information about the systems and services requiring evaluation through the information processing system's interface. This information serves as a guide for identifying the targets for evaluation and for collecting appropriate data.

[0352] Step 2:

[0353] The server automatically collects core data from the target system based on information entered by the user. This collection includes direct access using APIs and acquisition of log data through network monitoring.

[0354] Step 3:

[0355] The device collects data locally related to user actions and settings. This includes security policy settings and user activity history.

[0356] Step 4:

[0357] The server integrates all the collected data, and an AI agent automatically generates an information record sheet. This sheet serves as a list of security requirements and evaluation points.

[0358] Step 5:

[0359] The AI ​​agent refers to the generated information record sheet and makes a risk assessment based on the established criteria. The server then uses this result to create specific improvement suggestions.

[0360] Step 6:

[0361] The emotion engine activates and acquires real-time emotional data from the user. It uses the device's camera and microphone to perform facial expression analysis and voice data analysis to understand the user's emotional state.

[0362] Step 7:

[0363] The server adjusts improvement suggestions based on the user's emotional state obtained from the emotion engine and presents them in the most appropriate and easily understandable format for the user. If the user expresses anxiety, measures such as adding more detailed explanations are taken.

[0364] Step 8:

[0365] Users review the proposed improvements and implement them as needed. They then provide feedback on their feelings and the results after implementing the suggestions.

[0366] Step 9:

[0367] The server collects user feedback and sentiment data and stores it in a database. This data is then analyzed using machine learning algorithms and used to improve the accuracy of evaluations and refine suggestions for future evaluations.

[0368] These steps enable the system to perform flexible and highly accurate security checks that take user emotions into consideration, and to provide adaptive improvement suggestions.

[0369] (Example 2)

[0370] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0371] Traditional security check systems often failed to consider user emotions and feedback, potentially resulting in a poor user experience. Furthermore, they were unable to effectively utilize specific user feedback to improve the accuracy of risk assessments, limiting the accuracy of subsequent improvement suggestions. Additionally, they struggled to handle situations where security standards differed across countries.

[0372] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0373] In this invention, the server includes means for collecting basic information from information processing means, means for generating an information recording medium based on the basic information, means for determining risk using the generated information recording medium, means for analyzing user emotions and adjusting improvement suggestions, and means for recording user feedback and utilizing it for future evaluations. This enables improvement suggestions that take user emotions into account, improving the accuracy of security checks and the user experience. Furthermore, it facilitates compliance with multinational security standards and allows for continuous improvement of the accuracy of risk assessment.

[0374] "Information processing means" refers to devices and software for collecting, organizing, and analyzing data, and which have the function of acquiring basic system information.

[0375] "Basic information" refers to data necessary for evaluating the operation and security status of a system or service, and is considered core information.

[0376] An "information recording medium" refers to documents and digital files generated based on collected data, and includes checklists that indicate the evaluation criteria for the system.

[0377] "Risk assessment" refers to the process of analyzing and evaluating the degree of security risks associated with a system or service, and the act of identifying the need for improvement.

[0378] "Means of analyzing user emotions" refers to devices or software that analyze a user's facial expressions and voice data in real time to identify the user's emotional state.

[0379] "Means for recording feedback and using it for future evaluations" refers to a process or system for saving user responses and opinions in a database and using them to improve the system later.

[0380] This invention is a system that optimizes the security check process in an information processing system by utilizing an emotion engine to recognize user emotions. Specific embodiments of the invention are shown below.

[0381] The server first collects basic information from the system or service that needs to be evaluated. Data collection can be done using RESTful API calls or log analysis tools (e.g., Splunk). This allows for the efficient acquisition of security information and its storage in a database.

[0382] Next, an AI agent on the server generates an information storage medium based on the collected basic information. This process uses the Python pandas library to organize the data and output it to an Excel file in checklist format. This information storage medium is then used as a standard for audits and evaluations.

[0383] Furthermore, the AI ​​agent analyzes data from information storage media and performs risk assessment. Based on these results, the server generates improvement suggestions and delivers them to the user's terminal. In this process, the suggestions are customized using an emotion engine, taking into account the user's past responses. For example, if the user has expressed anxiety about a complex explanation, the suggestions will be adjusted to a simpler and easier-to-understand format.

[0384] The device uses its built-in camera and microphone to collect user facial expressions and voice data in real time, which are then analyzed by an emotion engine. When the user accepts a suggestion, they provide feedback, which is used to improve future suggestions.

[0385] For example, if a user aims to improve the security of a new business network system, this invention allows the system to automatically assess risks and propose improvement measures based on emotion. The user responds to on-screen dialogue such as "Do you accept this suggestion?", and the feedback is recorded and used for future evaluations.

[0386] An example of a prompt message could be a text format such as, "Use user sentiment data to assess the current state of network security and suggest improvements." This streamlines the security check process and improves the user experience.

[0387] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0388] Step 1:

[0389] The server collects basic information from the system or service requiring evaluation. Inputs include API endpoints and log files. The data is extracted using RESTful API calls and log analysis tools and stored in a database. The output is a dataset of security information.

[0390] Step 2:

[0391] The AI ​​agent on the server generates an information storage medium based on the basic information it collects. A series of structured data is used as input. The AI ​​agent organizes the data using the Python pandas library and outputs it to an Excel file in checklist format. The output is an information storage medium containing the system's evaluation criteria.

[0392] Step 3:

[0393] The AI ​​agent analyzes data from information storage media to determine risk. The input is collected system data. This process uses a machine learning model to perform risk scoring and identify areas with safety issues. The output is an assessment report indicating the system's risk level.

[0394] Step 4:

[0395] The server generates improvement suggestions based on the risk assessment results. Inputs include evaluation reports and past user response data. This allows the AI ​​agent to create optimal improvement plans for the user and fine-tune the suggestions using sentiment data. The output is a customized improvement suggestion based on the user's emotions.

[0396] Step 5:

[0397] The device uses its built-in camera and microphone to collect user facial expressions and voice data in real time, which is then analyzed by an emotion engine. Input consists of user voice and visual data. Output is data indicating the user's emotional state, which is used to adjust improvement suggestions.

[0398] Step 6:

[0399] The user reviews improvement suggestions displayed on their device and provides feedback. The input is the improvement suggestion displayed on the screen. The user chooses whether to accept or reject the suggestion, and this response is processed as input. The output is feedback data recording the user's selection.

[0400] Step 7:

[0401] The server records user feedback and uses it for future evaluations. The input is user feedback data. The server inputs this into its learning function to improve the accuracy of future risk assessments and improvement suggestions. The output is the improved evaluation and suggestion process.

[0402] (Application Example 2)

[0403] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0404] In modern information processing systems, the complex security check process is a significant challenge for users. In particular, determining the level of security risk, as well as how users respond, depends on individual emotions and circumstances, highlighting the need for improved user experience. Furthermore, traditional systems often fail to adequately utilize user feedback, hindering future evaluations.

[0405] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[0406] In this invention, the server includes means for collecting core data from an information processing device, means for generating an information record sheet based on the core data, means for determining the level of risk using the generated information record sheet, means for determining the emotional state using an emotion engine that analyzes the user's emotions and presenting optimal improvement suggestions according to those emotions, and means for presenting improvement suggestions based on the results of the risk level determination. This not only streamlines the assessment of security risks but also improves usability by providing improvement suggestions based on the user's emotions. Furthermore, feedback is accumulated as learning data, which helps improve the accuracy of evaluations, thus enabling continuous system improvement.

[0407] An "information processing device" is a device equipped with the functions of collecting, processing, storing, and analyzing data, and mainly refers to computers and servers.

[0408] "Core data" refers to the main data necessary for evaluating a system or service, and includes operation history and system configuration information.

[0409] An "information record sheet" is a document automatically generated based on core data, and it includes a list for checking security requirements.

[0410] "Risk assessment" is the process of evaluating and determining the risk level of a system or service based on an information record sheet.

[0411] An "emotion engine" is a technology that analyzes the user's facial expressions and voice data during operation to determine their emotional state in real time.

[0412] "Improvement suggestions" are proposals generated based on the results of risk assessments and the user's emotional state, and are aimed at improving security and usability.

[0413] "Feedback" refers to the user's reaction and opinion after receiving suggestions from the system, and this data is used to further improve the system.

[0414] "Learning methods" refer to the process of continuously collecting feedback and using it as data to improve the accuracy of future system evaluations and improvement suggestions.

[0415] The system for realizing this invention consists of an information processing device, an emotion engine, a data collection server, and a means for suggesting improvements. First, the server collects core data from the information processing device. This core data includes user operation history, security settings information, and terminal operating status. This data is automatically collected through appropriate API calls and log analysis. Based on the collected data, the server generates an information record sheet using an AI model (e.g., TensorFlow), and uses this to determine the risk level of the system and service.

[0416] User emotion analysis is achieved by an emotion engine (e.g., Affectiva SDK) analyzing voice data and facial expressions. The analysis results are sent to the server in real time, and the server generates optimal improvement suggestions based on the user's emotional state. The improvement suggestions are presented in a friendly format that reduces user anxiety and improves understanding.

[0417] In the feedback process, the server collects user responses and stores them as training data. This data contributes to improving the accuracy of risk assessments and improvement suggestions for the next and future instances.

[0418] For example, when a user attempts to connect to public Wi-Fi, the server could assess the risk level of the connection, and if an emotion engine analyzes the user's anxiety, it might provide a guided suggestion on how to configure a VPN to alleviate that anxiety.

[0419] An example of a prompt to input into the AI ​​generation model would be, "The user feels uneasy when using public Wi-Fi. Please generate the best security improvement suggestions for this situation." This would allow the system to provide the user with specific and useful suggestions.

[0420] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0421] Step 1:

[0422] The server collects core data from the terminal. Specifically, it obtains user operation history and security settings information through API calls and log analysis. It receives terminal logs and operation information as input, extracts and processes the necessary security-related data, and prepares the materials for the information record sheet necessary for subsequent data analysis.

[0423] Step 2:

[0424] The server generates an information record sheet based on the core data it collects. Here, the collected data points are organized and applied to a template to create a security checklist. The input is core data, and the output is an information record sheet for assessment. This information record sheet is used later for risk assessment.

[0425] Step 3:

[0426] The server uses the generated information log sheet to determine the level of risk. An AI model (e.g., TensorFlow) is used to analyze the data in the information log sheet and evaluate the system's security risk. In this process, the information log sheet is used as input, and the security risk assessment is obtained as output.

[0427] Step 4:

[0428] The emotion engine analyzes the user's emotions in real time. The device sends voice and facial data to the emotion engine (e.g., Affectiva SDK) to identify the user's current emotional state. It receives voice and image data as input and generates an emotional state determination result as output.

[0429] Step 5:

[0430] The server generates optimal improvement suggestions based on the risk assessment results and sentiment analysis results, and presents them to the user's terminal. Specifically, it combines the risk assessment value with the user's emotional state to determine the content and format of the improvement suggestions. The input is the risk assessment and emotional state assessment results, and the output is the adjusted improvement suggestions.

[0431] Step 6:

[0432] The user reviews the suggested improvement and provides feedback. The device sends the user's response (whether they accept the suggestion, whether they request further improvements, etc.) to the server. The input is the user's opinion or response, and the output is feedback data reflecting that.

[0433] Step 7:

[0434] The server accumulates user feedback as training data and uses it to improve evaluation accuracy in the future. The server stores the feedback data in a database and uses it as training data for the AI ​​model. The input is the feedback data, and the output is the updated training dataset.

[0435] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0436] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0437] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.

[0438] [Third Embodiment]

[0439] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.

[0440] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0441] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0442] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.

[0443] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0444] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0445] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0446] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0447] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0448] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0449] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0450] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".

[0451] This invention relates to an information processing system for efficiently and accurately performing security checks on new systems and services within a company. Embodiments of the present invention are described in detail below.

[0452] Information gathering and creation of record sheets

[0453] The server automatically collects core data from connected systems. In this process, the server extracts necessary information using API access and database queries. By also collecting user operation logs and security settings information from terminals, it achieves comprehensive data collection.

[0454] Based on the collected data, the AI ​​agent automatically generates an information record sheet. This sheet includes important security requirements and evaluation items, and compliance is confirmed by comparing each item with a benchmark value.

[0455] Risk assessment and improvement proposals

[0456] The AI ​​agent performs a risk assessment using an information record sheet. The server analyzes the assessment results in real time and performs a risk determination that is adjusted to comply with multiple international safety standards. In this process, the server utilizes machine learning algorithms to increase the rate at which problems are detected.

[0457] Based on the evaluation results, the AI ​​agent generates specific improvement suggestions and notifies the user. The device displays the recommended actions to the user and provides an interface that prompts them to make the necessary changes.

[0458] Learning and the use of feedback

[0459] Users can select and implement necessary actions based on improvement suggestions. The server collects feedback on each action and stores it as training data. This feedback information is used to improve the accuracy of evaluations in the future.

[0460] As a concrete example, when a company introduces a new cloud service, this system can be used to conduct a quick and accurate security check. Once the user enters basic information, the server collects relevant data, and an AI agent automatically generates a record sheet to complete a risk assessment in a short time, proposing optimal improvement measures. In this way, companies can smoothly implement new services while ensuring security.

[0461] In implementing this invention, the system automates and streamlines key steps in security check operations, thereby significantly reducing the workload on personnel.

[0462] The following describes the processing flow.

[0463] Step 1:

[0464] Users log in to the information processing system and enter basic information about the systems and services that need to be evaluated. This information includes details such as the service name, purpose, and planned implementation date.

[0465] Step 2:

[0466] Based on the information entered by the user, the server initiates a data collection process for the systems being evaluated, via APIs and other means. Core data such as relevant system configuration data, access logs, and security settings are collected.

[0467] Step 3:

[0468] The terminal monitors the operation of applications in the local environment and records security settings and operation history on the user's terminal.

[0469] Step 4:

[0470] The server analyzes the collected core data and automatically generates information record sheets for use by the AI ​​agent. These sheets comprehensively cover security requirements and evaluation targets.

[0471] Step 5:

[0472] The AI ​​agent conducts a risk assessment based on the generated information record sheet, in accordance with pre-defined multinational security standards. During this process, it uses machine learning algorithms to perform pattern recognition based on past cases.

[0473] Step 6:

[0474] The server aggregates the results of the risk assessment and identifies areas that need improvement if a certain level of risk exceeds a set threshold.

[0475] Step 7:

[0476] The AI ​​agent generates specific improvement suggestions based on the evaluation results and notifies the user's device. The user can review the suggested improvements and take necessary actions.

[0477] Step 8:

[0478] Users provide feedback to the system about the measures they have actually implemented. This feedback is used to improve the accuracy of future evaluations.

[0479] Step 9:

[0480] The server stores the collected feedback in a database, which the AI ​​agent uses for learning. Through this entire process, the efficiency and accuracy of the system's overall security check process continuously improve.

[0481] (Example 1)

[0482] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[0483] Companies and organizations are required to efficiently and highly assess security risks for new information processing systems and services they implement, and to quickly propose necessary improvements. However, achieving this requires acquiring vast amounts of data and conducting accurate analysis and recommendations, which has been a challenge for traditional methods due to the significant time and effort required. Furthermore, effective risk management has been difficult because risk assessments that comply with international security standards and improvements that utilize user feedback have not been sufficiently implemented.

[0484] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0485] In this invention, the server includes means for acquiring data elements from an information processing system, means for creating a record based on the data elements, and means for evaluating risks using the generated record. This makes it possible to efficiently and quickly evaluate security risks and provide improvement suggestions in accordance with international standards. Furthermore, by accumulating user responses as data and utilizing them in subsequent evaluations, the accuracy of evaluations can also be improved.

[0486] An "information processing system" is a general term for computer devices and related technologies configured for the purpose of collecting, storing, analyzing, and processing diverse data into information.

[0487] A "data element" refers to a fragment or item of information that is treated as a basic unit in information processing.

[0488] A "record document" is a document-based record generated based on acquired data elements, and is used for organizing and evaluating various types of information.

[0489] "Risk assessment" is the process of identifying potential dangers and problems from data and operations in an information processing system, and analyzing their importance and impact.

[0490] An "improvement proposal" is a set of specific instructions or recommendations based on the results of a risk assessment, outlining how to achieve a better state by addressing identified problems.

[0491] "User responses" refer to the responses and actions that users exhibit in response to presented information and suggestions, and include those used as evaluation and learning data.

[0492] This invention relates to an information processing system that efficiently checks security and provides improvement suggestions when introducing new information processing systems and services in companies and organizations. Specifically, it includes a management server, user terminals, and an AI agent.

[0493] The server first automatically retrieves data elements from information processing systems installed within the company. In this process, the server efficiently collects necessary information, such as financial data and user access logs, using API endpoints and database queries. Examples of specific hardware and software used include database management systems (DBMS) and RESTful APIs.

[0494] The collected data is compiled into an organized record by an AI agent. The AI ​​agent uses a generative AI model to analyze each data element and generate a record that conforms to security standards and evaluation criteria. This record is then used in the subsequent risk assessment process.

[0495] The user terminal presents specific improvement suggestions to the user based on the generated records and risk assessment results. For example, the user can check recommended actions such as changing system settings or updating software through the terminal.

[0496] As a concrete example, if a company uses this system when introducing a new cloud service, the user will input service details as prompts. A possible prompt might be something like, "Please tell me how to perform security checks when introducing a new cloud service." The server immediately collects relevant data via API, and an AI agent creates a record and performs a risk assessment. By providing improvement suggestions to the user via the terminal, efficient and accurate security checks are achieved.

[0497] This system configuration allows companies to quickly assess security risks when introducing new information processing systems and implement corrective measures that comply with international standards. This process can be carried out in less time and with less effort than conventional methods, significantly reducing the workload of personnel.

[0498] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0499] Step 1:

[0500] The server connects to information processing systems to retrieve data elements. Inputs are specific API endpoints or database query parameters, and outputs are raw data collected from each system. For example, the server sends an API request to a financial system to retrieve relevant financial data. At this stage, accuracy in data retrieval is crucial.

[0501] Step 2:

[0502] The server sends the acquired raw data to the AI ​​agent. The input is the raw data acquired in step 1, and the output is a document that organizes the information. The AI ​​agent analyzes the data using a generative AI model and generates a document based on security standards and evaluation criteria. At this stage, multiple data elements are integrated and organized by important items.

[0503] Step 3:

[0504] The server assesses risk using records generated by the AI ​​agent. The input is the records received from the AI ​​agent, and the output is the risk assessment result. The server evaluates each element based on international safety standards and determines the presence and extent of risk. For example, risks related to data protection are assessed.

[0505] Step 4:

[0506] The terminal presents improvement suggestions to the user based on the risk assessment results generated by the server. The input is the risk assessment results, and the output is the improvement suggestions viewable by the user. The terminal displays the suggestions to the user through a visual interface and prompts specific actions. For example, strengthening encryption settings might be recommended.

[0507] Step 5:

[0508] The user selects and performs an action based on improvement suggestions presented through the terminal. The input is the details of the suggestion from the terminal, and the output is the result of the selected action. The user makes changes to settings, etc., and the system records these actions.

[0509] Step 6:

[0510] The server collects user feedback and the results of actions taken, storing them as training data for future evaluations. The input is user feedback, and the output is an updated evaluation model. This improves the accuracy of subsequent security evaluations. The feedback contributes to system improvement and helps deepen continuous risk assessment.

[0511] (Application Example 1)

[0512] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[0513] In modern information systems, it is crucial to efficiently and quickly assess security risks and immediately propose countermeasures. However, existing systems require manual verification and analysis of a large amount of information, which is prone to delays and human errors. Furthermore, in environments where immediate on-site response is required, output via devices may not be properly performed.

[0514] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0515] In this invention, the server includes means for collecting core information from an information processing device, means for generating an information record document based on the core information, means for determining the degree of risk using the generated information record document, and means for visualizing the improvement suggestions on a smart wearable device and providing direct feedback to the user. This enables efficient evaluation of security risks and allows users to quickly understand and implement improvement suggestions on-site.

[0516] An "information processing device" is an electronic device used to collect core information and perform data analysis and processing.

[0517] "Core information" refers to fundamental and important data necessary for evaluating the security of a system.

[0518] An "information record document" is a document that is generated based on collected core information and outlines various evaluations and requirements.

[0519] "Means for determining the degree of risk" refers to a function for evaluating security risks using information records and documents.

[0520] "Means for presenting improvement suggestions" refers to a function that shows users specific improvement measures based on the results of the risk assessment.

[0521] A "smart wearable device" is a computer or communication device that a user can wear, capable of displaying information and providing feedback.

[0522] "Feedback" refers to information or notifications provided by a system to a user.

[0523] In this invention, an information processing system efficiently collects and analyzes core information to determine security risks and provide users with appropriate improvement suggestions. Specific embodiments are described below.

[0524] Program processing and operation

[0525] The server collects core information through information processing devices. This includes data retrieval using API access and database queries. The server then generates information record documents based on the collected information. This generation process involves formatting and analyzing the data using libraries such as Python's Pandas library.

[0526] Smart wearable devices (e.g., smart glasses) visualize and present risk assessments and improvement suggestions to users based on recorded information documents. In an environment where these wearable devices and servers can communicate bidirectionally, it is possible to notify users of changes and suggestions in real time.

[0527] Specific example

[0528] In a data center, a new device is about to connect to the network. At this moment, a server instantly collects security information about the device and displays the risk assessment results on smart glasses. The user sees the visualized results on the glasses and immediately implements the suggested security settings.

[0529] Examples of prompts for generative AI models

[0530] "Design a user interface on smart glasses that displays a risk assessment and improvement suggestions based on collected data for security checks when connecting new devices to a data network."

[0531] Thus, the present invention is designed to respond quickly and accurately to a variety of security risks in information systems environments, including data centers.

[0532] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0533] Step 1:

[0534] The server collects core information using API access and database queries. The input is security-related information from each device connected to the network, and the output is organized foundational data. The server uses Python and the Pandas library to format and parse this data.

[0535] Step 2:

[0536] The server generates information record documents based on the collected core information. The input is formatted base data, and the output is information record documents for risk assessment. The server uses a machine learning model to evaluate each element of the core information and visualize it in the document.

[0537] Step 3:

[0538] The server determines the level of risk using the generated information record documents. The input is the information record documents, and the output is the risk assessment result. The server uses machine learning algorithms such as Scikit-learn to perform risk assessments based on multiple international standards.

[0539] Step 4:

[0540] The terminal generates and displays improvement suggestions based on the risk assessment results. The input is the risk assessment results, and the output is the improvement suggestions presented to the user. The terminal uses visualization software to provide an interface for displaying improvement measures on a smart wearable device.

[0541] Step 5:

[0542] The user reviews improvement suggestions presented through a smart wearable device and selects the necessary actions. The input is the displayed improvement suggestions, and the output is the security action selected by the user. The user can adjust security settings according to the instructions.

[0543] Step 6:

[0544] The server collects feedback on user security actions and stores it as training data. The input is user feedback, and the output is training data to improve the accuracy of future evaluations. The server stores the feedback in a database to prepare for the next action.

[0545] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0546] This invention relates to a system that optimizes the security check process and provides more user-friendly improvement suggestions by combining an emotion engine that recognizes user emotions in an information processing system. Embodiments of this invention are described in detail below.

[0547] Information gathering and creation of record sheets

[0548] The server automatically collects core data from systems or services that require evaluation. This is done through API calls and log analysis, and necessary security information is collected. Additionally, it monitors user activity history and security settings on terminals to understand their operational status.

[0549] Based on the collected data, the AI ​​agent automatically generates an information record sheet. This sheet contains a checklist to ensure security requirements are met and is used as a basis for audits and evaluations.

[0550] Risk assessment and improvement suggestions

[0551] In the evaluation process, an AI agent uses an information recording sheet to determine the risk level of the system or service. The server generates improvement suggestions based on this and provides the user's device with the most suitable suggestions, taking into account the user's emotional state.

[0552] The emotion engine analyzes the user's facial expressions and voice data in real time during their interaction. This allows it to understand the user's emotions regarding the suggestions and adjust accordingly. For example, if the user is feeling anxious, the suggestion will be adjusted to be easier to understand and more approachable.

[0553] Feedback and Learning

[0554] When users accept improvement suggestions, they have choices based on emotional data collected by the emotion engine. The user's response is recorded on the server as feedback and reflected in future suggestions. This information is stored in the AI ​​agent as training data, contributing to future improvements in risk assessment and the accuracy of improvement suggestions.

[0555] For example, when a user tries to improve the security of a new business network system, this system can automatically determine the level of risk and suggest improvement measures based on sentiment. For instance, if feedback indicates that the system is complex, the suggestions will be adjusted to be simpler, helping the user implement the system smoothly.

[0556] This invention streamlines security checks and enables user-driven system improvements. By using this system, security personnel can perform their duties with confidence, leading to an overall improvement in security levels.

[0557] The following describes the processing flow.

[0558] Step 1:

[0559] Users input basic information about the systems and services requiring evaluation through the information processing system's interface. This information serves as a guide for identifying the targets for evaluation and for collecting appropriate data.

[0560] Step 2:

[0561] The server automatically collects core data from the target system based on information entered by the user. This collection includes direct access using APIs and acquisition of log data through network monitoring.

[0562] Step 3:

[0563] The device collects data locally related to user actions and settings. This includes security policy settings and user activity history.

[0564] Step 4:

[0565] The server integrates all the collected data, and an AI agent automatically generates an information record sheet. This sheet serves as a list of security requirements and evaluation points.

[0566] Step 5:

[0567] The AI ​​agent refers to the generated information record sheet and makes a risk assessment based on the established criteria. The server then uses this result to create specific improvement suggestions.

[0568] Step 6:

[0569] The emotion engine activates and acquires real-time emotional data from the user. It uses the device's camera and microphone to perform facial expression analysis and voice data analysis to understand the user's emotional state.

[0570] Step 7:

[0571] The server adjusts improvement suggestions based on the user's emotional state obtained from the emotion engine and presents them in the most appropriate and easily understandable format for the user. If the user expresses anxiety, measures such as adding more detailed explanations are taken.

[0572] Step 8:

[0573] Users review the proposed improvements and implement them as needed. They then provide feedback on their feelings and the results after implementing the suggestions.

[0574] Step 9:

[0575] The server collects user feedback and sentiment data and stores it in a database. This data is then analyzed using machine learning algorithms and used to improve the accuracy of evaluations and refine suggestions for future evaluations.

[0576] These steps enable the system to perform flexible and highly accurate security checks that take user emotions into consideration, and to provide adaptive improvement suggestions.

[0577] (Example 2)

[0578] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[0579] Traditional security check systems often failed to consider user emotions and feedback, potentially resulting in a poor user experience. Furthermore, they were unable to effectively utilize specific user feedback to improve the accuracy of risk assessments, limiting the accuracy of subsequent improvement suggestions. Additionally, they struggled to handle situations where security standards differed across countries.

[0580] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0581] In this invention, the server includes means for collecting basic information from information processing means, means for generating an information recording medium based on the basic information, means for determining risk using the generated information recording medium, means for analyzing user emotions and adjusting improvement suggestions, and means for recording user feedback and utilizing it for future evaluations. This enables improvement suggestions that take user emotions into account, improving the accuracy of security checks and the user experience. Furthermore, it facilitates compliance with multinational security standards and allows for continuous improvement of the accuracy of risk assessment.

[0582] "Information processing means" refers to devices and software for collecting, organizing, and analyzing data, and which have the function of acquiring basic system information.

[0583] "Basic information" refers to data necessary for evaluating the operation and security status of a system or service, and is considered core information.

[0584] An "information recording medium" refers to documents and digital files generated based on collected data, and includes checklists that indicate the evaluation criteria for the system.

[0585] "Risk assessment" refers to the process of analyzing and evaluating the degree of security risks associated with a system or service, and the act of identifying the need for improvement.

[0586] "Means of analyzing user emotions" refers to devices or software that analyze a user's facial expressions and voice data in real time to identify the user's emotional state.

[0587] "Means for recording feedback and using it for future evaluations" refers to a process or system for saving user responses and opinions in a database and using them to improve the system later.

[0588] This invention is a system that optimizes the security check process in an information processing system by utilizing an emotion engine to recognize user emotions. Specific embodiments of the invention are shown below.

[0589] The server first collects basic information from the system or service that needs to be evaluated. Data collection can be done using RESTful API calls or log analysis tools (e.g., Splunk). This allows for the efficient acquisition of security information and its storage in a database.

[0590] Next, an AI agent on the server generates an information storage medium based on the collected basic information. This process uses the Python pandas library to organize the data and output it to an Excel file in checklist format. This information storage medium is then used as a standard for audits and evaluations.

[0591] Furthermore, the AI ​​agent analyzes data from information storage media and performs risk assessment. Based on these results, the server generates improvement suggestions and delivers them to the user's terminal. In this process, the suggestions are customized using an emotion engine, taking into account the user's past responses. For example, if the user has expressed anxiety about a complex explanation, the suggestions will be adjusted to a simpler and easier-to-understand format.

[0592] The device uses its built-in camera and microphone to collect user facial expressions and voice data in real time, which are then analyzed by an emotion engine. When the user accepts a suggestion, they provide feedback, which is used to improve future suggestions.

[0593] For example, if a user aims to improve the security of a new business network system, this invention allows the system to automatically assess risks and propose improvement measures based on emotion. The user responds to on-screen dialogue such as "Do you accept this suggestion?", and the feedback is recorded and used for future evaluations.

[0594] An example of a prompt message could be a text format such as, "Use user sentiment data to assess the current state of network security and suggest improvements." This streamlines the security check process and improves the user experience.

[0595] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0596] Step 1:

[0597] The server collects basic information from the system or service requiring evaluation. Inputs include API endpoints and log files. The data is extracted using RESTful API calls and log analysis tools and stored in a database. The output is a dataset of security information.

[0598] Step 2:

[0599] The AI ​​agent on the server generates an information storage medium based on the basic information it collects. A series of structured data is used as input. The AI ​​agent organizes the data using the Python pandas library and outputs it to an Excel file in checklist format. The output is an information storage medium containing the system's evaluation criteria.

[0600] Step 3:

[0601] The AI ​​agent analyzes data from information storage media to determine risk. The input is collected system data. This process uses a machine learning model to perform risk scoring and identify areas with safety issues. The output is an assessment report indicating the system's risk level.

[0602] Step 4:

[0603] The server generates improvement suggestions based on the risk assessment results. Inputs include evaluation reports and past user response data. This allows the AI ​​agent to create optimal improvement plans for the user and fine-tune the suggestions using sentiment data. The output is a customized improvement suggestion based on the user's emotions.

[0604] Step 5:

[0605] The device uses its built-in camera and microphone to collect user facial expressions and voice data in real time, which is then analyzed by an emotion engine. Input consists of user voice and visual data. Output is data indicating the user's emotional state, which is used to adjust improvement suggestions.

[0606] Step 6:

[0607] The user reviews improvement suggestions displayed on their device and provides feedback. The input is the improvement suggestion displayed on the screen. The user chooses whether to accept or reject the suggestion, and this response is processed as input. The output is feedback data recording the user's selection.

[0608] Step 7:

[0609] The server records user feedback and uses it for future evaluations. The input is user feedback data. The server inputs this into its learning function to improve the accuracy of future risk assessments and improvement suggestions. The output is the improved evaluation and suggestion process.

[0610] (Application Example 2)

[0611] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[0612] In modern information processing systems, the complex security check process is a significant challenge for users. In particular, determining the level of security risk, as well as how users respond, depends on individual emotions and circumstances, highlighting the need for improved user experience. Furthermore, traditional systems often fail to adequately utilize user feedback, hindering future evaluations.

[0613] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[0614] In this invention, the server includes means for collecting core data from an information processing device, means for generating an information record sheet based on the core data, means for determining the level of risk using the generated information record sheet, means for determining the emotional state using an emotion engine that analyzes the user's emotions and presenting optimal improvement suggestions according to those emotions, and means for presenting improvement suggestions based on the results of the risk level determination. This not only streamlines the assessment of security risks but also improves usability by providing improvement suggestions based on the user's emotions. Furthermore, feedback is accumulated as learning data, which helps improve the accuracy of evaluations, thus enabling continuous system improvement.

[0615] An "information processing device" is a device equipped with the functions of collecting, processing, storing, and analyzing data, and mainly refers to computers and servers.

[0616] "Core data" refers to the main data necessary for evaluating a system or service, and includes operation history and system configuration information.

[0617] An "information record sheet" is a document automatically generated based on core data, and it includes a list for checking security requirements.

[0618] "Risk assessment" is the process of evaluating and determining the risk level of a system or service based on an information record sheet.

[0619] An "emotion engine" is a technology that analyzes the user's facial expressions and voice data during operation to determine their emotional state in real time.

[0620] "Improvement suggestions" are proposals generated based on the results of risk assessments and the user's emotional state, and are aimed at improving security and usability.

[0621] "Feedback" refers to the user's reaction and opinion after receiving suggestions from the system, and this data is used to further improve the system.

[0622] "Learning methods" refer to the process of continuously collecting feedback and using it as data to improve the accuracy of future system evaluations and improvement suggestions.

[0623] The system for realizing this invention consists of an information processing device, an emotion engine, a data collection server, and a means for suggesting improvements. First, the server collects core data from the information processing device. This core data includes user operation history, security settings information, and terminal operating status. This data is automatically collected through appropriate API calls and log analysis. Based on the collected data, the server generates an information record sheet using an AI model (e.g., TensorFlow), and uses this to determine the risk level of the system and service.

[0624] User emotion analysis is achieved by an emotion engine (e.g., Affectiva SDK) analyzing voice data and facial expressions. The analysis results are sent to the server in real time, and the server generates optimal improvement suggestions based on the user's emotional state. The improvement suggestions are presented in a friendly format that reduces user anxiety and improves understanding.

[0625] In the feedback process, the server collects user responses and stores them as training data. This data contributes to improving the accuracy of risk assessments and improvement suggestions for the next and future instances.

[0626] For example, when a user attempts to connect to public Wi-Fi, the server could assess the risk level of the connection, and if an emotion engine analyzes the user's anxiety, it might provide a guided suggestion on how to configure a VPN to alleviate that anxiety.

[0627] An example of a prompt to input into the AI ​​generation model would be, "The user feels uneasy when using public Wi-Fi. Please generate the best security improvement suggestions for this situation." This would allow the system to provide the user with specific and useful suggestions.

[0628] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0629] Step 1:

[0630] The server collects core data from the terminal. Specifically, it obtains user operation history and security settings information through API calls and log analysis. It receives terminal logs and operation information as input, extracts and processes the necessary security-related data, and prepares the materials for the information record sheet necessary for subsequent data analysis.

[0631] Step 2:

[0632] The server generates an information record sheet based on the core data it collects. Here, the collected data points are organized and applied to a template to create a security checklist. The input is core data, and the output is an information record sheet for assessment. This information record sheet is used later for risk assessment.

[0633] Step 3:

[0634] The server uses the generated information log sheet to determine the level of risk. An AI model (e.g., TensorFlow) is used to analyze the data in the information log sheet and evaluate the system's security risk. In this process, the information log sheet is used as input, and the security risk assessment is obtained as output.

[0635] Step 4:

[0636] The emotion engine analyzes the user's emotions in real time. The device sends voice and facial data to the emotion engine (e.g., Affectiva SDK) to identify the user's current emotional state. It receives voice and image data as input and generates an emotional state determination result as output.

[0637] Step 5:

[0638] The server generates optimal improvement suggestions based on the risk assessment results and sentiment analysis results, and presents them to the user's terminal. Specifically, it combines the risk assessment value with the user's emotional state to determine the content and format of the improvement suggestions. The input is the risk assessment and emotional state assessment results, and the output is the adjusted improvement suggestions.

[0639] Step 6:

[0640] The user reviews the suggested improvement and provides feedback. The device sends the user's response (whether they accept the suggestion, whether they request further improvements, etc.) to the server. The input is the user's opinion or response, and the output is feedback data reflecting that.

[0641] Step 7:

[0642] The server accumulates user feedback as training data and uses it to improve evaluation accuracy in the future. The server stores the feedback data in a database and uses it as training data for the AI ​​model. The input is the feedback data, and the output is the updated training dataset.

[0643] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0644] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0645] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.

[0646] [Fourth Embodiment]

[0647] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.

[0648] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[0649] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0650] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.

[0651] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0652] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0653] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0654] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.

[0655] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0656] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0657] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0658] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0659] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[0660] This invention relates to an information processing system for efficiently and accurately performing security checks on new systems and services within a company. Embodiments of the present invention are described in detail below.

[0661] Information gathering and creation of record sheets

[0662] The server automatically collects core data from connected systems. In this process, the server extracts necessary information using API access and database queries. By also collecting user operation logs and security settings information from terminals, it achieves comprehensive data collection.

[0663] Based on the collected data, the AI ​​agent automatically generates an information record sheet. This sheet includes important security requirements and evaluation items, and compliance is confirmed by comparing each item with a benchmark value.

[0664] Risk assessment and improvement proposals

[0665] The AI ​​agent performs a risk assessment using an information record sheet. The server analyzes the assessment results in real time and performs a risk determination that is adjusted to comply with multiple international safety standards. In this process, the server utilizes machine learning algorithms to increase the rate at which problems are detected.

[0666] Based on the evaluation results, the AI ​​agent generates specific improvement suggestions and notifies the user. The device displays the recommended actions to the user and provides an interface that prompts them to make the necessary changes.

[0667] Learning and the use of feedback

[0668] Users can select and implement necessary actions based on improvement suggestions. The server collects feedback on each action and stores it as training data. This feedback information is used to improve the accuracy of evaluations in the future.

[0669] As a concrete example, when a company introduces a new cloud service, this system can be used to conduct a quick and accurate security check. Once the user enters basic information, the server collects relevant data, and an AI agent automatically generates a record sheet to complete a risk assessment in a short time, proposing optimal improvement measures. In this way, companies can smoothly implement new services while ensuring security.

[0670] In implementing this invention, the system automates and streamlines key steps in security check operations, thereby significantly reducing the workload on personnel.

[0671] The following describes the processing flow.

[0672] Step 1:

[0673] Users log in to the information processing system and enter basic information about the systems and services that need to be evaluated. This information includes details such as the service name, purpose, and planned implementation date.

[0674] Step 2:

[0675] Based on the information entered by the user, the server initiates a data collection process for the systems being evaluated, via APIs and other means. Core data such as relevant system configuration data, access logs, and security settings are collected.

[0676] Step 3:

[0677] The terminal monitors the operation of applications in the local environment and records security settings and operation history on the user's terminal.

[0678] Step 4:

[0679] The server analyzes the collected core data and automatically generates information record sheets for use by the AI ​​agent. These sheets comprehensively cover security requirements and evaluation targets.

[0680] Step 5:

[0681] The AI ​​agent conducts a risk assessment based on the generated information record sheet, in accordance with pre-defined multinational security standards. During this process, it uses machine learning algorithms to perform pattern recognition based on past cases.

[0682] Step 6:

[0683] The server aggregates the results of the risk assessment and identifies areas that need improvement if a certain level of risk exceeds a set threshold.

[0684] Step 7:

[0685] The AI ​​agent generates specific improvement suggestions based on the evaluation results and notifies the user's device. The user can review the suggested improvements and take necessary actions.

[0686] Step 8:

[0687] Users provide feedback to the system about the measures they have actually implemented. This feedback is used to improve the accuracy of future evaluations.

[0688] Step 9:

[0689] The server stores the collected feedback in a database, which the AI ​​agent uses for learning. Through this entire process, the efficiency and accuracy of the system's overall security check process continuously improve.

[0690] (Example 1)

[0691] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[0692] Companies and organizations are required to efficiently and highly assess security risks for new information processing systems and services they implement, and to quickly propose necessary improvements. However, achieving this requires acquiring vast amounts of data and conducting accurate analysis and recommendations, which has been a challenge for traditional methods due to the significant time and effort required. Furthermore, effective risk management has been difficult because risk assessments that comply with international security standards and improvements that utilize user feedback have not been sufficiently implemented.

[0693] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0694] In this invention, the server includes means for acquiring data elements from an information processing system, means for creating a record based on the data elements, and means for evaluating risks using the generated record. This makes it possible to efficiently and quickly evaluate security risks and provide improvement suggestions in accordance with international standards. Furthermore, by accumulating user responses as data and utilizing them in subsequent evaluations, the accuracy of evaluations can also be improved.

[0695] An "information processing system" is a general term for computer devices and related technologies configured for the purpose of collecting, storing, analyzing, and processing diverse data into information.

[0696] A "data element" refers to a fragment or item of information that is treated as a basic unit in information processing.

[0697] A "record document" is a document-based record generated based on acquired data elements, and is used for organizing and evaluating various types of information.

[0698] "Risk assessment" is the process of identifying potential dangers and problems from data and operations in an information processing system, and analyzing their importance and impact.

[0699] An "improvement proposal" is a set of specific instructions or recommendations based on the results of a risk assessment, outlining how to achieve a better state by addressing identified problems.

[0700] "User responses" refer to the responses and actions that users exhibit in response to presented information and suggestions, and include those used as evaluation and learning data.

[0701] This invention relates to an information processing system that efficiently checks security and provides improvement suggestions when introducing new information processing systems and services in companies and organizations. Specifically, it includes a management server, user terminals, and an AI agent.

[0702] The server first automatically retrieves data elements from information processing systems installed within the company. In this process, the server efficiently collects necessary information, such as financial data and user access logs, using API endpoints and database queries. Examples of specific hardware and software used include database management systems (DBMS) and RESTful APIs.

[0703] The collected data is compiled into an organized record by an AI agent. The AI ​​agent uses a generative AI model to analyze each data element and generate a record that conforms to security standards and evaluation criteria. This record is then used in the subsequent risk assessment process.

[0704] The user terminal presents specific improvement suggestions to the user based on the generated records and risk assessment results. For example, the user can check recommended actions such as changing system settings or updating software through the terminal.

[0705] As a concrete example, if a company uses this system when introducing a new cloud service, the user will input service details as prompts. A possible prompt might be something like, "Please tell me how to perform security checks when introducing a new cloud service." The server immediately collects relevant data via API, and an AI agent creates a record and performs a risk assessment. By providing improvement suggestions to the user via the terminal, efficient and accurate security checks are achieved.

[0706] This system configuration allows companies to quickly assess security risks when introducing new information processing systems and implement corrective measures that comply with international standards. This process can be carried out in less time and with less effort than conventional methods, significantly reducing the workload of personnel.

[0707] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0708] Step 1:

[0709] The server connects to information processing systems to retrieve data elements. Inputs are specific API endpoints or database query parameters, and outputs are raw data collected from each system. For example, the server sends an API request to a financial system to retrieve relevant financial data. At this stage, accuracy in data retrieval is crucial.

[0710] Step 2:

[0711] The server sends the acquired raw data to the AI ​​agent. The input is the raw data acquired in step 1, and the output is a document that organizes the information. The AI ​​agent analyzes the data using a generative AI model and generates a document based on security standards and evaluation criteria. At this stage, multiple data elements are integrated and organized by important items.

[0712] Step 3:

[0713] The server assesses risk using records generated by the AI ​​agent. The input is the records received from the AI ​​agent, and the output is the risk assessment result. The server evaluates each element based on international safety standards and determines the presence and extent of risk. For example, risks related to data protection are assessed.

[0714] Step 4:

[0715] The terminal presents improvement suggestions to the user based on the risk assessment results generated by the server. The input is the risk assessment results, and the output is the improvement suggestions viewable by the user. The terminal displays the suggestions to the user through a visual interface and prompts specific actions. For example, strengthening encryption settings might be recommended.

[0716] Step 5:

[0717] The user selects and performs an action based on improvement suggestions presented through the terminal. The input is the details of the suggestion from the terminal, and the output is the result of the selected action. The user makes changes to settings, etc., and the system records these actions.

[0718] Step 6:

[0719] The server collects user feedback and the results of actions taken, storing them as training data for future evaluations. The input is user feedback, and the output is an updated evaluation model. This improves the accuracy of subsequent security evaluations. The feedback contributes to system improvement and helps deepen continuous risk assessment.

[0720] (Application Example 1)

[0721] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[0722] In modern information systems, it is crucial to efficiently and quickly assess security risks and immediately propose countermeasures. However, existing systems require manual verification and analysis of a large amount of information, which is prone to delays and human errors. Furthermore, in environments where immediate on-site response is required, output via devices may not be properly performed.

[0723] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0724] In this invention, the server includes means for collecting core information from an information processing device, means for generating an information record document based on the core information, means for determining the degree of risk using the generated information record document, and means for visualizing the improvement suggestions on a smart wearable device and providing direct feedback to the user. This enables efficient evaluation of security risks and allows users to quickly understand and implement improvement suggestions on-site.

[0725] An "information processing device" is an electronic device used to collect core information and perform data analysis and processing.

[0726] "Core information" refers to fundamental and important data necessary for evaluating the security of a system.

[0727] An "information record document" is a document that is generated based on collected core information and outlines various evaluations and requirements.

[0728] "Means for determining the degree of risk" refers to a function for evaluating security risks using information records and documents.

[0729] "Means for presenting improvement suggestions" refers to a function that shows users specific improvement measures based on the results of the risk assessment.

[0730] A "smart wearable device" is a computer or communication device that a user can wear, capable of displaying information and providing feedback.

[0731] "Feedback" refers to information or notifications provided by a system to a user.

[0732] In this invention, an information processing system efficiently collects and analyzes core information to determine security risks and provide users with appropriate improvement suggestions. Specific embodiments are described below.

[0733] Program processing and operation

[0734] The server collects core information through information processing devices. This includes data retrieval using API access and database queries. The server then generates information record documents based on the collected information. This generation process involves formatting and analyzing the data using libraries such as Python's Pandas library.

[0735] Smart wearable devices (e.g., smart glasses) visualize and present risk assessments and improvement suggestions to users based on recorded information documents. In an environment where these wearable devices and servers can communicate bidirectionally, it is possible to notify users of changes and suggestions in real time.

[0736] Specific example

[0737] In a data center, a new device is about to connect to the network. At this moment, a server instantly collects security information about the device and displays the risk assessment results on smart glasses. The user sees the visualized results on the glasses and immediately implements the suggested security settings.

[0738] Examples of prompts for generative AI models

[0739] "Design a user interface on smart glasses that displays a risk assessment and improvement suggestions based on collected data for security checks when connecting new devices to a data network."

[0740] Thus, the present invention is designed to respond quickly and accurately to a variety of security risks in information systems environments, including data centers.

[0741] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0742] Step 1:

[0743] The server collects core information using API access and database queries. The input is security-related information from each device connected to the network, and the output is organized foundational data. The server uses Python and the Pandas library to format and parse this data.

[0744] Step 2:

[0745] The server generates information record documents based on the collected core information. The input is formatted base data, and the output is information record documents for risk assessment. The server uses a machine learning model to evaluate each element of the core information and visualize it in the document.

[0746] Step 3:

[0747] The server determines the level of risk using the generated information record documents. The input is the information record documents, and the output is the risk assessment result. The server uses machine learning algorithms such as Scikit-learn to perform risk assessments based on multiple international standards.

[0748] Step 4:

[0749] The terminal generates and displays improvement suggestions based on the risk assessment results. The input is the risk assessment results, and the output is the improvement suggestions presented to the user. The terminal uses visualization software to provide an interface for displaying improvement measures on a smart wearable device.

[0750] Step 5:

[0751] The user reviews improvement suggestions presented through a smart wearable device and selects the necessary actions. The input is the displayed improvement suggestions, and the output is the security action selected by the user. The user can adjust security settings according to the instructions.

[0752] Step 6:

[0753] The server collects feedback on user security actions and stores it as training data. The input is user feedback, and the output is training data to improve the accuracy of future evaluations. The server stores the feedback in a database to prepare for the next action.

[0754] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0755] This invention relates to a system that optimizes the security check process and provides more user-friendly improvement suggestions by combining an emotion engine that recognizes user emotions in an information processing system. Embodiments of this invention are described in detail below.

[0756] Information gathering and creation of record sheets

[0757] The server automatically collects core data from systems or services that require evaluation. This is done through API calls and log analysis, and necessary security information is collected. Additionally, it monitors user activity history and security settings on terminals to understand their operational status.

[0758] Based on the collected data, the AI ​​agent automatically generates an information record sheet. This sheet contains a checklist to ensure security requirements are met and is used as a basis for audits and evaluations.

[0759] Risk assessment and improvement suggestions

[0760] In the evaluation process, an AI agent uses an information recording sheet to determine the risk level of the system or service. The server generates improvement suggestions based on this and provides the user's device with the most suitable suggestions, taking into account the user's emotional state.

[0761] The emotion engine analyzes the user's facial expressions and voice data in real time during their interaction. This allows it to understand the user's emotions regarding the suggestions and adjust accordingly. For example, if the user is feeling anxious, the suggestion will be adjusted to be easier to understand and more approachable.

[0762] Feedback and Learning

[0763] When users accept improvement suggestions, they have choices based on emotional data collected by the emotion engine. The user's response is recorded on the server as feedback and reflected in future suggestions. This information is stored in the AI ​​agent as training data, contributing to future improvements in risk assessment and the accuracy of improvement suggestions.

[0764] For example, when a user tries to improve the security of a new business network system, this system can automatically determine the level of risk and suggest improvement measures based on sentiment. For instance, if feedback indicates that the system is complex, the suggestions will be adjusted to be simpler, helping the user implement the system smoothly.

[0765] This invention streamlines security checks and enables user-driven system improvements. By using this system, security personnel can perform their duties with confidence, leading to an overall improvement in security levels.

[0766] The following describes the processing flow.

[0767] Step 1:

[0768] Users input basic information about the systems and services requiring evaluation through the information processing system's interface. This information serves as a guide for identifying the targets for evaluation and for collecting appropriate data.

[0769] Step 2:

[0770] The server automatically collects core data from the target system based on information entered by the user. This collection includes direct access using APIs and acquisition of log data through network monitoring.

[0771] Step 3:

[0772] The device collects data locally related to user actions and settings. This includes security policy settings and user activity history.

[0773] Step 4:

[0774] The server integrates all the collected data, and an AI agent automatically generates an information record sheet. This sheet serves as a list of security requirements and evaluation points.

[0775] Step 5:

[0776] The AI ​​agent refers to the generated information record sheet and makes a risk assessment based on the established criteria. The server then uses this result to create specific improvement suggestions.

[0777] Step 6:

[0778] The emotion engine activates and acquires real-time emotional data from the user. It uses the device's camera and microphone to perform facial expression analysis and voice data analysis to understand the user's emotional state.

[0779] Step 7:

[0780] The server adjusts improvement suggestions based on the user's emotional state obtained from the emotion engine and presents them in the most appropriate and easily understandable format for the user. If the user expresses anxiety, measures such as adding more detailed explanations are taken.

[0781] Step 8:

[0782] Users review the proposed improvements and implement them as needed. They then provide feedback on their feelings and the results after implementing the suggestions.

[0783] Step 9:

[0784] The server collects user feedback and sentiment data and stores it in a database. This data is then analyzed using machine learning algorithms and used to improve the accuracy of evaluations and refine suggestions for future evaluations.

[0785] These steps enable the system to perform flexible and highly accurate security checks that take user emotions into consideration, and to provide adaptive improvement suggestions.

[0786] (Example 2)

[0787] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[0788] Traditional security check systems often failed to consider user emotions and feedback, potentially resulting in a poor user experience. Furthermore, they were unable to effectively utilize specific user feedback to improve the accuracy of risk assessments, limiting the accuracy of subsequent improvement suggestions. Additionally, they struggled to handle situations where security standards differed across countries.

[0789] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0790] In this invention, the server includes means for collecting basic information from information processing means, means for generating an information recording medium based on the basic information, means for determining risk using the generated information recording medium, means for analyzing user emotions and adjusting improvement suggestions, and means for recording user feedback and utilizing it for future evaluations. This enables improvement suggestions that take user emotions into account, improving the accuracy of security checks and the user experience. Furthermore, it facilitates compliance with multinational security standards and allows for continuous improvement of the accuracy of risk assessment.

[0791] "Information processing means" refers to devices and software for collecting, organizing, and analyzing data, and which have the function of acquiring basic system information.

[0792] "Basic information" refers to data necessary for evaluating the operation and security status of a system or service, and is considered core information.

[0793] An "information recording medium" refers to documents and digital files generated based on collected data, and includes checklists that indicate the evaluation criteria for the system.

[0794] "Risk assessment" refers to the process of analyzing and evaluating the degree of security risks associated with a system or service, and the act of identifying the need for improvement.

[0795] "Means of analyzing user emotions" refers to devices or software that analyze a user's facial expressions and voice data in real time to identify the user's emotional state.

[0796] "Means for recording feedback and using it for future evaluations" refers to a process or system for saving user responses and opinions in a database and using them to improve the system later.

[0797] This invention is a system that optimizes the security check process in an information processing system by utilizing an emotion engine to recognize user emotions. Specific embodiments of the invention are shown below.

[0798] The server first collects basic information from the system or service that needs to be evaluated. Data collection can be done using RESTful API calls or log analysis tools (e.g., Splunk). This allows for the efficient acquisition of security information and its storage in a database.

[0799] Next, an AI agent on the server generates an information storage medium based on the collected basic information. This process uses the Python pandas library to organize the data and output it to an Excel file in checklist format. This information storage medium is then used as a standard for audits and evaluations.

[0800] Furthermore, the AI ​​agent analyzes data from information storage media and performs risk assessment. Based on these results, the server generates improvement suggestions and delivers them to the user's terminal. In this process, the suggestions are customized using an emotion engine, taking into account the user's past responses. For example, if the user has expressed anxiety about a complex explanation, the suggestions will be adjusted to a simpler and easier-to-understand format.

[0801] The device uses its built-in camera and microphone to collect user facial expressions and voice data in real time, which are then analyzed by an emotion engine. When the user accepts a suggestion, they provide feedback, which is used to improve future suggestions.

[0802] For example, if a user aims to improve the security of a new business network system, this invention allows the system to automatically assess risks and propose improvement measures based on emotion. The user responds to on-screen dialogue such as "Do you accept this suggestion?", and the feedback is recorded and used for future evaluations.

[0803] An example of a prompt message could be a text format such as, "Use user sentiment data to assess the current state of network security and suggest improvements." This streamlines the security check process and improves the user experience.

[0804] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0805] Step 1:

[0806] The server collects basic information from the system or service requiring evaluation. Inputs include API endpoints and log files. The data is extracted using RESTful API calls and log analysis tools and stored in a database. The output is a dataset of security information.

[0807] Step 2:

[0808] The AI ​​agent on the server generates an information storage medium based on the basic information it collects. A series of structured data is used as input. The AI ​​agent organizes the data using the Python pandas library and outputs it to an Excel file in checklist format. The output is an information storage medium containing the system's evaluation criteria.

[0809] Step 3:

[0810] The AI ​​agent analyzes data from information storage media to determine risk. The input is collected system data. This process uses a machine learning model to perform risk scoring and identify areas with safety issues. The output is an assessment report indicating the system's risk level.

[0811] Step 4:

[0812] The server generates improvement suggestions based on the risk assessment results. Inputs include evaluation reports and past user response data. This allows the AI ​​agent to create optimal improvement plans for the user and fine-tune the suggestions using sentiment data. The output is a customized improvement suggestion based on the user's emotions.

[0813] Step 5:

[0814] The device uses its built-in camera and microphone to collect user facial expressions and voice data in real time, which is then analyzed by an emotion engine. Input consists of user voice and visual data. Output is data indicating the user's emotional state, which is used to adjust improvement suggestions.

[0815] Step 6:

[0816] The user reviews improvement suggestions displayed on their device and provides feedback. The input is the improvement suggestion displayed on the screen. The user chooses whether to accept or reject the suggestion, and this response is processed as input. The output is feedback data recording the user's selection.

[0817] Step 7:

[0818] The server records user feedback and uses it for future evaluations. The input is user feedback data. The server inputs this into its learning function to improve the accuracy of future risk assessments and improvement suggestions. The output is the improved evaluation and suggestion process.

[0819] (Application Example 2)

[0820] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[0821] In modern information processing systems, the complex security check process is a significant challenge for users. In particular, determining the level of security risk, as well as how users respond, depends on individual emotions and circumstances, highlighting the need for improved user experience. Furthermore, traditional systems often fail to adequately utilize user feedback, hindering future evaluations.

[0822] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[0823] In this invention, the server includes means for collecting core data from an information processing device, means for generating an information record sheet based on the core data, means for determining the level of risk using the generated information record sheet, means for determining the emotional state using an emotion engine that analyzes the user's emotions and presenting optimal improvement suggestions according to those emotions, and means for presenting improvement suggestions based on the results of the risk level determination. This not only streamlines the assessment of security risks but also improves usability by providing improvement suggestions based on the user's emotions. Furthermore, feedback is accumulated as learning data, which helps improve the accuracy of evaluations, thus enabling continuous system improvement.

[0824] An "information processing device" is a device equipped with the functions of collecting, processing, storing, and analyzing data, and mainly refers to computers and servers.

[0825] "Core data" refers to the main data necessary for evaluating a system or service, and includes operation history and system configuration information.

[0826] An "information record sheet" is a document automatically generated based on core data, and it includes a list for checking security requirements.

[0827] "Risk assessment" is the process of evaluating and determining the risk level of a system or service based on an information record sheet.

[0828] An "emotion engine" is a technology that analyzes the user's facial expressions and voice data during operation to determine their emotional state in real time.

[0829] "Improvement suggestions" are proposals generated based on the results of risk assessments and the user's emotional state, and are aimed at improving security and usability.

[0830] "Feedback" refers to the user's reaction and opinion after receiving suggestions from the system, and this data is used to further improve the system.

[0831] "Learning methods" refer to the process of continuously collecting feedback and using it as data to improve the accuracy of future system evaluations and improvement suggestions.

[0832] The system for realizing this invention consists of an information processing device, an emotion engine, a data collection server, and a means for suggesting improvements. First, the server collects core data from the information processing device. This core data includes user operation history, security settings information, and terminal operating status. This data is automatically collected through appropriate API calls and log analysis. Based on the collected data, the server generates an information record sheet using an AI model (e.g., TensorFlow), and uses this to determine the risk level of the system and service.

[0833] User emotion analysis is achieved by an emotion engine (e.g., Affectiva SDK) analyzing voice data and facial expressions. The analysis results are sent to the server in real time, and the server generates optimal improvement suggestions based on the user's emotional state. The improvement suggestions are presented in a friendly format that reduces user anxiety and improves understanding.

[0834] In the feedback process, the server collects user responses and stores them as training data. This data contributes to improving the accuracy of risk assessments and improvement suggestions for the next and future instances.

[0835] For example, when a user attempts to connect to public Wi-Fi, the server could assess the risk level of the connection, and if an emotion engine analyzes the user's anxiety, it might provide a guided suggestion on how to configure a VPN to alleviate that anxiety.

[0836] An example of a prompt to input into the AI ​​generation model would be, "The user feels uneasy when using public Wi-Fi. Please generate the best security improvement suggestions for this situation." This would allow the system to provide the user with specific and useful suggestions.

[0837] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0838] Step 1:

[0839] The server collects core data from the terminal. Specifically, it obtains user operation history and security settings information through API calls and log analysis. It receives terminal logs and operation information as input, extracts and processes the necessary security-related data, and prepares the materials for the information record sheet necessary for subsequent data analysis.

[0840] Step 2:

[0841] The server generates an information record sheet based on the core data it collects. Here, the collected data points are organized and applied to a template to create a security checklist. The input is core data, and the output is an information record sheet for assessment. This information record sheet is used later for risk assessment.

[0842] Step 3:

[0843] The server uses the generated information log sheet to determine the level of risk. An AI model (e.g., TensorFlow) is used to analyze the data in the information log sheet and evaluate the system's security risk. In this process, the information log sheet is used as input, and the security risk assessment is obtained as output.

[0844] Step 4:

[0845] The emotion engine analyzes the user's emotions in real time. The device sends voice and facial data to the emotion engine (e.g., Affectiva SDK) to identify the user's current emotional state. It receives voice and image data as input and generates an emotional state determination result as output.

[0846] Step 5:

[0847] The server generates optimal improvement suggestions based on the risk assessment results and sentiment analysis results, and presents them to the user's terminal. Specifically, it combines the risk assessment value with the user's emotional state to determine the content and format of the improvement suggestions. The input is the risk assessment and emotional state assessment results, and the output is the adjusted improvement suggestions.

[0848] Step 6:

[0849] The user reviews the suggested improvement and provides feedback. The device sends the user's response (whether they accept the suggestion, whether they request further improvements, etc.) to the server. The input is the user's opinion or response, and the output is feedback data reflecting that.

[0850] Step 7:

[0851] The server accumulates user feedback as training data and uses it to improve evaluation accuracy in the future. The server stores the feedback data in a database and uses it as training data for the AI ​​model. The input is the feedback data, and the output is the updated training dataset.

[0852] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0853] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0854] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.

[0855] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[0856] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.

[0857] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.

[0858] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.

[0859] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.

[0860] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."

[0861] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values ​​representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.

[0862] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.

[0863] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.

[0864] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.

[0865] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[0866] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.

[0867] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using this memory.

[0868] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.

[0869] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.

[0870] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.

[0871] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.

[0872] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.

[0873] The following is further disclosed regarding the embodiments described above.

[0874] (Claim 1)

[0875] A means of collecting core data from an information processing device,

[0876] Means for generating an information record sheet based on the aforementioned core data,

[0877] A means for determining the degree of risk using the generated information record sheet,

[0878] A means of presenting improvement proposals based on the results of the aforementioned risk assessment,

[0879] A system that includes this.

[0880] (Claim 2)

[0881] The system according to claim 1, characterized in that it includes means for making adjustments in the risk assessment to correspond to multinational safety standards.

[0882] (Claim 3)

[0883] The system according to claim 1, characterized in that it includes a learning means that stores the results of the risk assessment and feedback on improvement suggestions as learning data, and improves the accuracy in the next evaluation.

[0884] "Example 1"

[0885] (Claim 1)

[0886] Means for obtaining data elements from an information processing system,

[0887] A means for creating a record based on the aforementioned data elements,

[0888] A means for evaluating the risk using the generated record,

[0889] A means of making suggestions for improvement based on the results of the aforementioned risk assessment,

[0890] A means of presenting the aforementioned improvement proposal to the user via a terminal,

[0891] A means of accumulating user feedback as data and using it for subsequent evaluations,

[0892] A system that includes this.

[0893] (Claim 2)

[0894] The system according to claim 1, characterized in that it includes means for making adjustments based on international standards in the risk assessment.

[0895] (Claim 3)

[0896] The system according to claim 1, further comprising a function to learn the response to operations selected and performed by the user based on the aforementioned improvement proposals, and to improve the accuracy of the evaluation method.

[0897] "Application Example 1"

[0898] (Claim 1)

[0899] A means of collecting core information from an information processing device,

[0900] Means for generating an information record document based on the aforementioned core information,

[0901] A means for determining the degree of risk using the generated information record document,

[0902] A means of presenting improvement proposals based on the results of the aforementioned risk assessment,

[0903] A means for visualizing the aforementioned improvement suggestions in a smart wearable device and providing direct feedback to the user,

[0904] A system that includes this.

[0905] (Claim 2)

[0906] The system according to claim 1, characterized in that it includes means for making adjustments in the risk assessment to correspond to multinational safety standards.

[0907] (Claim 3)

[0908] The system according to claim 1, characterized in that it includes a learning means that stores the results of the risk assessment and feedback on improvement suggestions as learning data, and improves the accuracy in the next evaluation.

[0909] "Example 2 of combining an emotion engine"

[0910] (Claim 1)

[0911] Means for collecting basic information from information processing means,

[0912] Means for generating an information recording medium based on the aforementioned basic information,

[0913] A means for determining risk using the generated information recording medium,

[0914] A means of presenting improvement proposals based on the results of the aforementioned risk assessment,

[0915] A means for analyzing user emotions and adjusting the aforementioned improvement suggestions,

[0916] A means of recording the aforementioned user feedback and using it for the next evaluation,

[0917] A system that includes this.

[0918] (Claim 2)

[0919] The system according to claim 1, characterized in that adjustments are made in the risk assessment to correspond to international safety standards.

[0920] (Claim 3)

[0921] The system according to claim 1, characterized in that it has a function to retain the feedback on the risk assessment and improvement proposals as learning information and to improve the accuracy in the next evaluation.

[0922] "Application example 2 when combining with an emotional engine"

[0923] (Claim 1)

[0924] A means of collecting core data from an information processing device,

[0925] Means for generating an information record sheet based on the aforementioned core data,

[0926] A means for determining the degree of risk using the generated information record sheet,

[0927] A means of determining the emotional state using an emotion engine that analyzes the user's emotions and presenting optimal improvement suggestions according to those emotions,

[0928] A means of presenting improvement proposals based on the results of the aforementioned risk assessment,

[0929] A system that includes this.

[0930] (Claim 2)

[0931] The system according to claim 1, characterized in that the optimal improvement proposal based on the risk assessment and sentiment analysis includes means for making adjustments to correspond to multilateral safety standards.

[0932] (Claim 3)

[0933] The system according to claim 1, characterized in that it includes a learning means that stores the results of the risk assessment and feedback on improvement suggestions using sentiment analysis as learning data, and improves the accuracy in the next evaluation. [Explanation of Symbols]

[0934] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>

Claims

1. A means of collecting core data from an information processing device, Means for generating an information record sheet based on the aforementioned core data, A means for determining the degree of risk using the generated information record sheet, A means of presenting improvement proposals based on the results of the aforementioned risk assessment, A system that includes this.

2. The system according to claim 1, characterized in that it includes means for making adjustments in the risk assessment to correspond to multinational safety standards.

3. The system according to claim 1, characterized in that it includes a learning means that stores the results of the risk assessment and feedback on improvement suggestions as learning data, and improves the accuracy in the next evaluation.