Real-time data viewing security

CN114175032BActive Publication Date: 2026-08-11SALESFORCE INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-13
Publication Date
2026-08-11

Smart Images

  • Figure CN114175032B_ABST
    Figure CN114175032B_ABST
Patent Text Reader

Abstract

This technology utilizes authentication processing to authenticate users viewing protected data and image detection processing to monitor the field of view of an image detection component. Authentication is activated when a user requests access to the protected data. After user authentication, the data can be displayed and image detection processing is activated, allowing the image detection component to monitor the field of view to determine if the user is actively viewing the data or if other people are present in the field of view. Upon detection of either event, the protected data is hidden from the user's device display.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-referencing

[0002] This patent application claims priority to U.S. Patent Application No. 16 / 834,376, filed March 30, 2020, entitled "Security of Real-Time Data Viewing," which has been assigned to the assignee of this application. Technical Field

[0003] The publicly available text generally deals with database systems and data processing, and more specifically, with the security of real-time data viewing. Background Technology

[0004] Many users can utilize cloud platforms (i.e., computing platforms for cloud computing) to store, manage, and process data using a shared network of remote servers. Users can develop applications on cloud platforms to handle the storage, management, and processing of data. In some cases, cloud platforms can leverage multi-tenant database systems. Users can access cloud platforms using a variety of user devices, such as desktop computers, laptops, smartphones, tablets, or other computing systems.

[0005] In one example, a cloud platform can support customer relationship management (CRM) solutions. This can include support for sales, service, marketing, community, analytics, applications, and the Internet of Things (IoT). Users can leverage the cloud platform to help manage their contacts. For example, managing a user's contacts can include analyzing data, storing and preparing communications, and tracking opportunities and sales.

[0006] In some cases, cloud platforms may support access to sensitive user or customer data. Privacy or sensitive data may be subject to privacy laws that require users to prevent the disclosure or access of such data. Viewing this data on a device in a public setting (such as a laptop or mobile device) may pose a risk of unintentional data disclosure. More specifically, a user may be viewing personal or security data on a device that could then be accessed by another user after the device has been left alone. In other cases, another person may be "spying" on personal or sensitive data. Attached Figure Description

[0007] Figure 1 Examples of systems for protecting the security of data that supports real-time data viewing are shown, based on various aspects of publicly available text.

[0008] Figure 2 This example illustrates a user device environment where security can be viewed in real-time based on various aspects of publicly available text.

[0009] Figure 3This illustrates an example of a computing system that allows for real-time security monitoring based on various aspects of publicly available text.

[0010] Figure 4 This example shows a flowchart illustrating the process of viewing security based on real-time data supporting various aspects of publicly available text.

[0011] Figure 5 A block diagram is shown illustrating a device that allows for real-time security monitoring based on various aspects of publicly available text.

[0012] Figure 6 This diagram illustrates a data management component that supports secure real-time data viewing based on various aspects of publicly available text.

[0013] Figure 7 The diagram illustrates a system including devices that support the security of real-time data viewing, based on various aspects of publicly available text.

[0014] Figures 8 to 10 The flowchart illustrates a method for viewing security based on real-time data supporting various aspects of publicly available text. Detailed Implementation

[0015] User devices, such as mobile devices or laptops, can be used to access various types of data. In some cases, devices may be used to access sensitive or security data, such as personally identifiable information, health data, financial data, etc. Such data may be subject to data protection laws, and accidental data breaches can be harmful to the data owner or the organization that supports access to the data. Due to the mobility of computing devices, data breaches are more common, and the use of these devices can lead to accidental data leaks. For example, a user may be viewing some personal or security data, and then the device may be accessed by another user after the device has been left alone. In other cases, another person may be "spying" on someone to view personal or sensitive data.

[0016] The techniques described herein provide data hiding at the device based on whether an authenticated user is actively viewing the data or whether another user is viewing the data. These techniques can utilize the device's image detection components (e.g., a camera) to authenticate the user and determine whether the user is actively viewing or to detect a "spy." When the device detects an event indicating that the user is not viewing protected data or indicating that at least one other person is in the field of view of the image detection component, the device can activate the data hiding process, making the data hidden and invisible or unreadable. When the user looks back at the display or when the spy leaves the field of view, the device can redisplay or unhide the data.

[0017] These technologies utilize authentication processing to authenticate users viewing the data and image detection processing to monitor the field of view of the image detection component. Authentication processing is activated when a user requests access to sensitive data. This processing determines whether the requesting user is authenticated and authorized to access the data. In some examples, authentication processing may determine whether the user is the "owner" of the device. Ownership determination may involve accessing the device's secure enclave (e.g., software or hardware-based encryption or secure key storage and management components). The device may determine whether a captured image of the user's face matching an image securely stored by the device owner.

[0018] After user authentication, data can be displayed and image detection processing can be activated. Image detection processing uses an image detection component to monitor the field of view to determine if the user is actively viewing the data. If the user's face leaves the field of view, or if the user's gaze is leaving the display, the image detection processing can detect an event that triggers data hiding. Additionally, if the image detection processing detects another person in the field of view, it also detects an event that triggers data hiding. When the user returns to view or another person leaves view, as detected by the image detection processing, the device can then redisplay the data or reactivate the authentication process based on the configured security level.

[0019] The various aspects of the published text are initially described in the context of an environment supporting on-demand database services. Further descriptions of these aspects are made regarding the environment illustrating real-time data viewing security, the computing system supporting real-time data viewing security, and processing flowcharts. The various aspects of the published text are further illustrated and described with reference to device diagrams, system diagrams, and flowcharts relating to real-time data viewing security.

[0020] Figure 1An example of a system 100 for supporting real-time data viewing security for cloud computing is shown, based on various aspects of publicly available text. System 100 includes a cloud client 105, a contact 110, a cloud platform 115, and a data center 120. Cloud platform 115 may be an example of a public or private cloud network. Cloud client 105 can access cloud platform 115 via network connection 135. This network may implement Transmission Control Protocol and Internet Protocol (TCP / IP), such as the Internet, or may implement other network protocols. Cloud client 105 may be an example of a user device, such as a server (e.g., cloud client 105-a), a smartphone (e.g., cloud client 105-b), or a laptop computer (e.g., cloud client 105-c). In other examples, cloud client 105 may be a desktop computer, tablet, sensor, or another computing device or system capable of generating, analyzing, sending, or receiving communications. In some examples, cloud client 105 may be operated by a user as part of a business, enterprise, non-profit organization, startup, or any other type of organization.

[0021] Cloud client 105 can interact with multiple contacts 110. Interaction 130 can include communication, opportunities, purchases, sales, or any other interaction between cloud client 105 and contact 110. Data can be associated with interaction 130. Cloud client 105 can access cloud platform 115 to store, manage, and process data associated with interaction 130. In some cases, cloud client 105 may have associated security or permission levels. Cloud client 105 can access certain applications, data, and database information within cloud platform 115 based on associated security or permission levels, but cannot access other applications, data, and database information.

[0022] Contact 110 may interact with cloud client 105 in person or via telephone, email, web, text message, mail, or any other suitable form of interaction (e.g., interactions 130-a, 130-b, 130-c, and 130-d). Interaction 130 may be a business-to-business (B2B) interaction or a business-to-consumer (B2C) interaction. Contact 110 may also be referred to as a customer, prospect, lead, client, or some other suitable term. In some cases, Contact 110 may be an example of a user device, such as a server (e.g., Contact 110-a), a laptop computer (e.g., Contact 110-b), a smartphone (e.g., Contact 110-c), or a sensor (e.g., Contact 110-d). In other cases, Contact 110 may be another computing system. In some cases, Contact 110 may be operated by a user or a group of users. The user or group of users may be associated with a business, manufacturer, or any other suitable organization.

[0023] Cloud platform 115 can provide on-demand database services to cloud client 105. In some cases, cloud platform 115 can be an example of a multi-tenant database system. In this case, cloud platform 115 can serve multiple cloud clients 105 with a single software instance. However, other types of systems can be implemented, including but not limited to client-server systems, mobile device systems, and mobile network systems. In some cases, cloud platform 115 can support CRM solutions. This may include support for sales, service, marketing, community, analytics, applications, and the Internet of Things. Cloud platform 115 can receive data associated with contact interactions 130 from cloud client 105 via network connection 135, and can store and analyze this data. In some cases, cloud platform 115 can receive data directly from the interaction 130 between contact 110 and cloud client 105. In some cases, cloud client 105 can develop applications to run on cloud platform 115. Cloud platform 115 can be implemented using a remote server. In some cases, the remote server can be located at one or more data centers 120.

[0024] Data center 120 may include multiple servers. These servers can be used for data storage, management, and processing. Data center 120 may receive data from cloud platform 115 via connection 140, or directly from cloud client 105 or from interaction 130 between contact 110 and cloud client 105. Data center 120 may utilize multiple redundancies for security purposes. In some cases, data stored at data center 120 may be backed up by a copy of data at a different data center (not shown).

[0025] Subsystem 125 may include cloud client 105, cloud platform 115, and data center 120. In some cases, data processing may occur at any component of subsystem 125, or at a combination of these components. In some cases, a server may perform data processing. The server may be cloud client 105 or located in data center 120.

[0026] Cloud platform 115 can support access to sensitive user or customer data or other types of protected data. For example, cloud client 105 could be an organization that supports access (e.g., using an application) to the data of contact 110, which could be an example of a customer, user, etc. Viewing data on a device in a public setting (such as a laptop or mobile device) may pose a risk of unintentional data disclosure. More specifically, a user associated with client 105 may be viewing some personal or security data on the device, which may then be accessed by another person after the device has been left alone. In other cases, another person may be spying on you to view personal or sensitive data.

[0027] To prevent unintentional data disclosure, the techniques described herein support hiding data during real-time data viewing sessions. Hiding can be triggered based on events indicating a potential disclosure. Such events could include detecting that a user is not actively viewing the data or that another user may be viewing the data (e.g., peeping from behind). These techniques include detecting that a user is requesting access to protected data on a user's device (e.g., client 105's device), authenticating the user using an image detection component, displaying the data, monitoring the user using an image detection component, and hiding the data when a potential disclosure event is detected. The data can be redisplayed when the event is resolved (e.g., the user returns to actively viewing the data or another person leaves the image detection component's field of view). Therefore, these techniques support a real-time or near-real-time data disclosure / hiding process that allows access to protected data in public settings while reducing the likelihood of unintentional disclosure.

[0028] Those skilled in the art will understand that one or more aspects of the disclosed text can be implemented in system 100 to additionally or alternatively address other problems besides those described above. Furthermore, aspects of the disclosed text can provide technical improvements to "conventional" systems or processes as described herein. However, the description and figures only include exemplary technical improvements resulting from the implementation aspects of the disclosed text and therefore do not represent all technical improvements provided within the scope of the claims.

[0029] In one example use of the system, cloud client 105 could be an example of a health service provider, such as a home health device provider. Users such as sales managers, delivery personnel, etc., can access patient data on mobile devices such as smartphones or laptops using an application or web interface. Users can request access to specific patient data using a mobile device. The device, application, or web interface supports the technologies described herein. Upon receiving a request for patient data (e.g., protected data), the device can use its camera and authenticate the user according to an authentication process. The authentication process can verify that the requesting user is the "owner" of the device, or verify that the user is authenticated and able to use the device and / or access the data. When the user is authenticated, the patient data is displayed and image monitoring processing is activated. The image monitoring process actively monitors the real-time data feed from the device's camera and determines when a hidden event is detected. Detecting a hidden event triggers data hiding (e.g., blurring the screen, blocking data, sending an alarm). A hidden event can be detected when the user moves away from the display or is no longer in the camera's field of view. In another example, a hidden event can be detected when another user is detected in the field of view of the device's camera.

[0030] Figure 2An example of a user device environment 200 demonstrating real-time data viewing security is shown based on various aspects of publicly available text. User device environment 200 includes user device 205 and user 210. User device 205 may be... Figure 1 Example of a device with a cloud client 105. Figure 2 In this document, the user equipment is a smartphone, but the implementation described herein is applicable to other devices such as laptops, desktop computers, tablets, etc. User equipment 205 includes an image detection component that captures an image from its field of view 215. The image detection component may be an example of a camera and associated systems (e.g., image processing software and / or hardware).

[0031] User 210 may request access to protected data 250 at user device 205. In one example, the user uses a mobile application or web interface associated with user 210's employer to request access to the data. In another case, the user requests access to a private group or domain of a social media website or application. In any example, the data or information is "protected" in some sense. That is, access to the data may require the user to have specified access permissions. Therefore, the techniques described herein can be utilized by various application types, such as web portals, social media applications / websites, organizational applications, etc. These implementations can be activated using toggles or other user interface components. For example, a user can create a private group on a social media website / application, an organization-specific website / application, etc., and toggle a switch to activate the data protection technology. Thus, the techniques described herein can be activated when a member of the group accesses the group.

[0032] When an application or device detects a user requesting access to protected data (e.g., a domain), authentication processing can be activated at user device 205. The authentication process can use image detection components to authenticate the user for access to the data. As shown in field of view 215, device 205 can determine that the user captured in field of view 215 is the owner of the device or that the user is authenticated and able to view the protected data. For example, the device can compare an image of the user's face in field of view 215-a with a stored image of the user's face. The stored image of the user's face can be stored in a security facility of user device 205. In some cases, the authentication process can be supported by the operating system of user device 205. For example, the authentication process can use an application programming interface (API) supported by the operating system of device 205 to activate the device's native facial recognition authentication process. Apple's Face ID TMThe system is an exemplary facial recognition authentication system that can be used to authenticate user 210. In another case, the authentication process can be specific to an application that supports access to secure data. Therefore, the authentication process can use facial recognition facilities to authenticate user 210 to view protected data 250.

[0033] When authenticating user 210 according to the authentication process, protected data 250 may be displayed as shown on display 220-a. Display 220 represents the visual display of device 205 (e.g., at the screen of device 205). Furthermore, image monitoring processing is activated when authenticating user 210. Image monitoring processing may actively monitor signals detected by the image monitoring components of device 205. For example, image monitoring processing may process each frame or frames captured by the image detection components to detect events that may indicate the protected data 250 should be hidden. For example, image monitoring processing may typically monitor the field of view 215-b to determine if there have been any changes since user 210 was authenticated. That is, image monitoring processing may determine that user 210 is within the field of view. If this state (e.g., user 210 is within the field of view) changes, image monitoring processing may activate a hiding process that hides the protected data 250 as shown on displays 220-b and 220-c.

[0034] As shown in field of view 215-b, because user 210 is no longer within field of view 215-b, the image monitoring process can determine that user 210 is no longer viewing data at the display. This could be the result of the user leaving the device, rotating the device, blocking the camera lens, or some other situation. In response to detecting this event, the image monitoring process of device 205 hides the protected data 250, as shown in display 220-b.

[0035] As shown in field of view 215-c, image detection processing can determine that another person 230 is in field of view 215-c. This could be an example of a peeping tom behind someone's back, or someone viewing device 205 without the knowledge of user 210. In response to detecting this event, image detection processing of device 205 hides protected data 250, as shown in display 220-c.

[0036] Hiding data can include generating a "blur" effect at the display, removing data, obscuring data with user interface components, alarms, etc. In some examples, hiding data can include generating visual and / or audio alarms. While data is hidden, image monitoring processing can continue to monitor field of view 215. Therefore, when the user returns to field of view 215, the protected data 250 can be redisplayed, as shown in display 220-a. However, in some cases, authentication processing can be reactivated before redisplaying the data, thereby re-authenticating the user 210 before redisplaying the protected data 250. This can be configured according to the application and associated with specific protected data 250. Re-authentication can be associated with a higher form of data protection compared to redisplaying data according to image monitoring processing. Therefore, re-authentication can be activated for a higher form of protection. In other cases, data can be redisplayed via image monitoring processing. Furthermore, the event that caused the data to be hidden can be used to determine how to re-access the protected data 250. For example, if the event that triggered the hiding is a spy behind the user, as shown in field of view 215-c, the user can be re-authenticated before displaying the protected data 250. However, if the event that triggers the hiding is when the user is out of the field of view (e.g., the user rotates the device or briefly leaves the device), the protected data 250 can be re-displayed when the user returns to the field of view 215. Alternatively, whether the user needs to re-authenticate may depend on the length of time the triggering event is active. Therefore, a timer can be activated when the triggering event occurs.

[0037] Figure 3 An example of a computing system 300 is shown that supports real-time data viewing security based on various aspects of publicly available text. The computing system 300 includes a user device 305 and a server 310. The user device 305 may be... Figure 2 User equipment 205 or Figure 1 Example of a cloud client 105 device. Server 310 can be... Figure 1 An example of a aspect of data center 120. Server 310 can support device 305's access to various data and facilities. That is, server 310 can support providing data services to executable application 340 on device 305 and access to data processing of application 340.

[0038] A user of device 305 can request access to data designated as protected. This data can be specified by a user, application 340, organization, etc. The request can be sent to server 310 for servicing the requested data. In some cases, the server responds with an authentication request at device 305, or application 340 triggers authentication. In some examples, the protected data being accessed can be stored at device 305, and device 305 can initiate authentication processing 320 without interacting with server 310. Authentication processing 320 can be activated in response to detecting a request to access protected data. Authentication processing 320 can use image detection component 315, which may include a lens, hardware, and / or software for capturing and processing image data. Authentication processing 320 can determine whether a user is authenticated and able to access the protected data. In some examples, authentication processing determines whether the user is the owner of the device. Determining whether a user is the owner may include comparing a captured image of the user with an image stored in the device's secure storage. Therefore, authentication processing 320 may use a facial recognition algorithm. Authentication process 320 may utilize the local authentication system of device 305 or an authentication application stored on device 305. For example, authentication process 320 may send an API request to the device's local authentication process. The local authentication process may respond to the request with authentication confirmation or negative confirmation.

[0039] If the user is not authenticated according to authentication process 320, then the user cannot access the protected data. If the user is authenticated, data control component 330 can display the protected data on display 335 and can activate image monitoring process 325. Image monitoring process 325 can monitor the output of image detection component 315 to identify events that may trigger data hiding at display 335. Image monitoring process 325 can analyze each frame or each image, or multiple images, within a specified time period to identify such events. This monitoring may include determining whether the state of the field of view has changed from when the user was in the field of view. For example, image monitoring process 325 can identify that the user has left the field of view or another person is in the field of view. Therefore, when the state of the field of view changes, image monitoring process 325 can trigger data hiding by data control component 330 at display 335.

[0040] In some examples, the image detection process 325 performs facial recognition processing or algorithms that may differ from those used by the authentication process 320. This may be due to security restrictions configured for the device 305. In some examples, the facial recognition processing or algorithm may be inherent to the device 305 or supported by the device 305. That is, the image detection process 325 may send one or more API requests to a process supported by the device 305 to detect events that trigger data hiding. The request may be for the location of a face and / or how many faces are in a particular frame / image. In one example, the API may send a response indicating that the processing no longer detects faces (e.g., face detection is negative) or that a face is approaching the edge of a frame. Thus, data hiding can be triggered. Furthermore, the algorithm may be configured to detect multiple faces, such that the algorithm / API can respond with an indication that multiple faces have been detected. Data may be hidden accordingly. Since the algorithm can continuously or periodically feed frames captured by the image detection component 315, it can respond continuously or periodically with detection results.

[0041] In one example, image detection component 315 can capture multiple images per second (e.g., 60 images) and can send a request to a facial recognition algorithm for each image or for a group of images. In some cases, images are preprocessed so that they can be processed by the facial recognition algorithm. Preprocessing may include resizing, compression, etc. In some cases, image detection processing 325 can actively monitor eyes or gaze direction to determine whether a user is actively viewing data. Therefore, image detection processing 325 can utilize eye-tracking features of the facial recognition algorithm to detect events indicating that the user is not looking at the data / display 335. For example, if the algorithm detects that the user's gaze is leaving the screen while the user's face is still within the field of view, the data can be hidden until the user looks back at the screen / data. Eyes are an example of a facial feature that can be tracked to determine whether a user is viewing data. Other features may include the direction the nose is pointing, facial orientation, etc.

[0042] Therefore, authentication process 320 authenticates the user, and image detection process 325 is activated almost immediately after authentication. Thus, while image detection process 325 may not be certain that the actual user being authenticated is the detected face, the latency is minimal, and any "face switching" can be avoided. Furthermore, in some examples, image detection process 325 can detect that the detected face is the user / owner (e.g., the detected face is authenticated).

[0043] Data hiding may include obscuring the data, displaying an alert on the data, or otherwise blocking the data at the display 335. In some cases, data is hidden until the event is resolved. For example, if the image monitoring process 325 detects that the user has returned to the field of view or that another person has left the field of view, the data control component 330 may redisplay the protected data at the display 335. In other cases, after an event is detected and the data is hidden, it may be necessary to re-authenticate the user according to the authentication process 320. Whether re-authentication is required may depend on the required security level, application settings, etc.

[0044] Figure 4 An example of a process flowchart 400 supporting real-time data viewing security based on various aspects of publicly available text is shown. Process flowchart 400 includes user device 405 and server 410, which may be... Figures 1 to 3 Example of a corresponding device. At 415, user equipment 405 may send a data request to server 410. This request may indicate a set of protected data (e.g., private user data, security domains, etc.). At 420, in response to receiving a data request for protected data, the server sends an authentication request to device 405.

[0045] At 430, user equipment 405 can activate the image detection component of the user equipment to access protected data at the user equipment for authentication of the user according to the authentication process. In some examples, the image detection component is activated in response to an authentication request from server 410. In some examples, the image detection component is activated by an application executing on device 405 based on a received request to access protected data. That is, device 405 can activate the image detection component without input from server 410 and / or without sending a data request to server 410.

[0046] At 435, user equipment 405 sends an authentication confirmation to server 410 based on the result of the authentication process. In response, at 440, server 410 may send the requested protected data to equipment 405. In some examples, server 410 sends data in response to the initial request 415, but the data is not viewable until the user is authenticated. In other cases, the data is stored on the device and cannot be viewed until the user is authenticated.

[0047] At 445, user equipment 405 may display protected data at the user interface of the user equipment, at least in part, based on the result of the authentication process. At 450, the user equipment may detect, at least in part, an event indicating that the user is not viewing the protected data or that at least one other person is in the field of view of the image detection component, based at least in part on the execution of an image detection model and image monitoring processing using the image detection component. At 455, user equipment 405 may hide the protected data at the user interface, at least in part, based on the detection of the event.

[0048] Figure 5 A block diagram 500 illustrates a device 505 supporting secure real-time data viewing based on various aspects of publicly available text. Device 505 may include an input module 510, a data management component 515, and an output module 540. Device 505 may also include a processor. Each of these components may communicate with each other (e.g., via one or more buses). In some cases, device 505 may be an example of a user terminal, a database server, or a system comprising multiple computing devices.

[0049] Input module 510 can manage input signals of device 505. For example, input module 510 can identify input signals based on interaction with a modem, keyboard, mouse, touchscreen, or similar device. These input signals can be associated with user input or processing at other components or devices. In some cases, input module 510 can utilize, for example... Alternatively, another known operating system may be used to process the input signals. Input module 510 can send aspects of these input signals to other components of device 505 for processing. For example, input module 510 can send input signals to data management component 515 to support real-time data viewing security. In some cases, input module 510 may be as described in the reference... Figure 7 The components of the input / output (I / O) controller 715.

[0050] Data management component 515 may include authentication component 520, data display component 525, image monitoring component 530, and data hiding component 535. Data management component 515 may be a reference... Figure 6 and Figure 7 Examples of aspects of the described data management components 605 or 710.

[0051] At least some of the data management component 515 and / or its various subcomponents may be implemented in hardware, processor-executed software, firmware, or any combination thereof. If implemented in processor-executed software, the functionality of at least some of the data management component 515 and / or its various subcomponents may be performed by a general-purpose processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware component, or any combination thereof, designed to perform the functionality described in the disclosure. At least some of the data management component 515 and / or its various subcomponents may be physically located in various locations, including being distributed such that portions of the functionality are implemented by one or more physical devices in different physical locations. In some examples, according to various aspects of the disclosure, at least some of the data management component 515 and / or its various subcomponents may be separate and distinct components. In other examples, at least some of the data management component 515 and / or its various sub-components may be combined with one or more other hardware components, including but not limited to I / O components, transceivers, network servers, another computing device, one or more other components described in the disclosure, or combinations thereof according to various aspects of the disclosure.

[0052] The authentication component 520 can activate the image detection component of the user device according to the authentication process to authenticate the user to access the protected data on the user device.

[0053] The data display component 525 can display protected data on the user interface of the user device based on the result of the authentication process.

[0054] The image detection component 530 can detect events that indicate that a user is not viewing protected data or that at least one other person is in the field of view of the image detection component, based on the execution of an image detection model and the image detection processing of the image detection component.

[0055] The data hiding component 535 can hide protected data at the user interface based on the detection of an event.

[0056] Output module 540 can manage the output signals of device 505. For example, output module 540 can receive signals from other components of device 505 (e.g., data management component 515) and can send these signals to other components or devices. In some specific examples, output module 540 can send output signals for display in a user interface, for storage in a database or data storage, for further processing at a server or server cluster, or for any other processing at any number of devices or systems. In some cases, as referenced... Figure 7 The output module 540 may be a component of the I / O controller 715.

[0057] Figure 6 A block diagram 600 of a data management component 605 supporting real-time data viewing security, based on aspects of publicly available text, is shown. Data management component 605 may be an example of aspects of data management component 515 or data management component 710 described herein. Data management component 605 may include authentication component 610, data display component 615, image detection component 620, data hiding component 625, image recognition component 630, image matching component 635, facial recognition component 640, activation component 645, and data access component 650. Each of these modules may communicate with each other directly or indirectly (e.g., via one or more buses).

[0058] The authentication component 610 can activate the image detection component of the user device according to the authentication process to authenticate the user to access the protected data on the user device.

[0059] In some examples, authentication component 610 can determine that the user is the owner of the user device based on the authentication process, wherein, based on the determination that the user is the owner of the user device, the user is authenticated and able to access protected data.

[0060] The data display component 615 can display protected data on the user interface of the user device based on the result of the authentication process.

[0061] In some examples, the data display component 615 can redisplay protected data based on the detection of a second event.

[0062] The image detection component 620 can detect events that indicate that a user is not viewing protected data or that at least one other person is in the field of view of the image detection component, based on the execution of an image detection model and the image detection processing of the image detection component.

[0063] In some examples, the image monitoring component 620 can process users in the monitoring field of view based on image monitoring, wherein events are detected based on the monitoring.

[0064] In some examples, the image detection component 620 can detect a second event that indicates a user is viewing protected data or that at least one other person is not in the field of view of the image detection component, based on image detection processing.

[0065] The data hiding component 625 can hide protected data at the user interface based on the detection of the event.

[0066] In some examples, the data hiding component 625 can obscure protected data at the user interface, display an alert at the user interface, or a combination thereof.

[0067] The image recognition component 630 can recognize faces in the field of view of the image detection component.

[0068] Image matching component 635 can match faces with images of the user device owner stored in a secure compartment of the user device.

[0069] The facial recognition component 640 can detect one or more facial features that indicate whether a user is looking at the display of a user device.

[0070] In some examples, the facial recognition component 640 can determine that the user's eyes are indicating that the user's gaze is leaving the display of the user's device, and the event is detected based on this determination.

[0071] Activation component 645 can reactivate the authentication process based on the detection of this event.

[0072] In some examples, the activation component 645 can activate the image monitoring process in response to authenticating a user based on the authentication process.

[0073] The data access component 650 can detect that a user is requesting access to protected data, and performs authentication processing in response to detecting that a user is requesting access.

[0074] Figure 7 A diagram illustrates a system 700 including a device 705 supporting real-time data viewing security, based on various aspects of the disclosed text. Device 705 may be an example of a user equipment or a component of device 505 as described herein, or may include components of a user equipment or device 505. Device 705 may include components for bidirectional data communication, including components for sending and receiving communications, such as a data management component 710, an I / O controller 715, a database controller 720, a memory 725, a processor 730, and a database 735. These components may communicate electronically via one or more buses (e.g., bus 740).

[0075] Data management component 710 can be an example of data management component 515 or 605 as described herein. For example, data management component 710 can perform the functions described in the above reference. Figure 5 and Figure 6 Any method or process described. In some cases, the data management component 710 may be implemented in hardware, software executed by a processor, firmware, or any combination thereof.

[0076] The I / O controller 715 can manage the input signals 745 and output signals 750 of the device 705. The I / O controller 715 can also manage peripheral devices not integrated into the device 705. In some cases, the I / O controller 715 can represent a physical connection or port to an external peripheral device. In some cases, the input module 510 can utilize, for example... The I / O controller 715 processes input signals using its own operating system or another known operating system. In other cases, the I / O controller 715 may represent or interact with a modem, keyboard, mouse, touchscreen, or similar device. In some cases, the I / O controller 715 may be implemented as part of a processor. In some cases, a user may interact with the device 705 via the I / O controller 715 or via hardware components controlled by the I / O controller 715.

[0077] Database controller 720 manages data storage and processing within database 735. In some cases, users can interact with database controller 720. In other cases, database controller 720 can operate automatically without user interaction. Database 735 can be an example of a single database, a distributed database, multiple distributed databases, a data store, a data lake, or an emergency backup database.

[0078] Memory 725 may include random access memory (RAM) and read-only memory (ROM). Memory 725 may store computer-readable, computer-executable software, which includes instructions that, when executed, cause the processor to perform the various functions described herein. In some cases, memory 725 may contain a basic input / output system (BIOS), etc., which controls basic hardware or software operations such as interaction with peripheral components or devices.

[0079] Processor 730 may include intelligent hardware devices (e.g., general-purpose processors, DSPs, central processing units (CPUs), microcontrollers, ASICs, FPGAs, programmable logic devices, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some cases, processor 730 may be configured to operate a memory array using a memory controller. In other cases, the memory controller may be integrated into processor 730. Processor 730 may be configured to execute computer-readable instructions stored in memory 725 to perform various functions (e.g., functions or tasks supporting real-time data viewing security).

[0080] Figure 8A flowchart illustrating method 800 for real-time data security based on various aspects of publicly available text is provided. Operation of method 800 can be implemented by the user device or its components described herein. For example, operation of method 800 can be achieved by referring to... Figures 5 to 7 The data management component described herein performs the functions. In some examples, the user equipment may execute a set of instructions to control the functional elements of the user equipment to perform the functions described below. Additionally or alternatively, the user equipment may use dedicated hardware to perform various aspects of the functions described below.

[0081] In 805, the user equipment can activate its image detection component to access protected data at the user equipment location by authenticating the user according to the authentication process. The operation of 805 can be performed according to the methods described herein. In some examples, aspects of the operation of 805 can be referenced... Figures 5 to 7 The authentication component is executed.

[0082] In 810, the user equipment can display protected data at the user interface based on the result of the authentication process. The operation of 810 can be performed according to the methods described herein. In some examples, aspects of the operation of 810 can be derived from references... Figures 5 to 7 The data display component is executed.

[0083] In 815, the user equipment can detect events indicating that the user is not viewing protected data or indicating that at least one other person is in the field of view of the image detection component, based on the execution of an image detection model and image monitoring processing using the image detection component. The operation of 815 can be performed according to the methods described herein. In some examples, aspects of the operation of 815 can be derived from references... Figures 5 to 7 The image monitoring component is executed.

[0084] In 820, the user equipment can hide protected data at the user interface based on the detection of an event. The operation of 820 can be performed according to the methods described herein. In some examples, aspects of the operation of 820 can be referenced... Figures 5 to 7 The data hiding component is executed.

[0085] Figure 9 A flowchart illustrating method 900 for viewing security in real-time based on various aspects of publicly available text is provided. Operation of method 900 can be implemented by the user device or its components described herein. For example, operation of method 900 can be achieved by referring to... Figures 5 to 7 The data management component described herein performs the functions. In some examples, the user equipment may execute a set of instructions to control the functional elements of the user equipment to perform the functions described below. Additionally or alternatively, the user equipment may use dedicated hardware to perform various aspects of the functions described below.

[0086] In 905, a user equipment can detect that a user is requesting access to protected data, and in response to detecting that a user is requesting access, authentication processing is performed. The operation of 905 can be performed according to the methods described herein. In some examples, aspects of the operation of 905 can be referenced... Figures 5 to 7 The data access component is executed.

[0087] In 910, the user equipment can activate its image detection component to access protected data at the user equipment location by authenticating the user according to the authentication process. The operation of 910 can be performed according to the method described herein. In some examples, aspects of the operation of 910 can be referenced... Figures 5 to 7 The authentication component is executed.

[0088] In 915, a user equipment (UE) can determine, through authentication processing, that a user is the owner of the UE. Based on this determination, the user is authenticated and granted access to protected data. The operation of 915 can be performed according to the methods described herein. In some examples, aspects of the operation of 915 can be referenced... Figures 5 to 7 The authentication component is executed.

[0089] In 920, the user equipment can identify faces within the field of view of the image detection component. The operation of 920 can be performed according to the method described herein. In some examples, aspects of the operation of 920 can be derived from references... Figures 5 to 7 The image recognition component is executed.

[0090] In 925, the user equipment can match a face with an image of the user equipment owner stored in the secure enclave of the user equipment. The operation of 925 can be performed according to the method described herein. In some examples, aspects of the operation of 925 can be referenced... Figures 5 to 7 The image matching component is executed.

[0091] In 930, the user equipment can display protected data at the user interface based on the result of the authentication process. The operation of 930 can be performed according to the methods described herein. In some examples, aspects of the operation of 930 can be referenced... Figures 5 to 7 The data display component is executed.

[0092] In 935, the user equipment can detect events indicating that a user is not viewing protected data or indicating that at least one other person is in the field of view of the image detection component, based on the execution of an image detection model and image monitoring processing using the image detection component. The operation of 935 can be performed according to the methods described herein. In some examples, aspects of the operation of 935 can be derived from references... Figures 5 to 7 The image monitoring component is executed.

[0093] In 940, the user equipment can hide protected data at the user interface based on the detection of an event. The operation of 940 can be performed according to the methods described herein. In some examples, aspects of the operation of 940 can be referenced... Figures 5 to 7 The data hiding component is executed.

[0094] Figure 10 A flowchart illustrating a method 1000 for viewing security in real-time based on various aspects of publicly available text is provided. The operation of method 1000 can be implemented by a user device or its components described herein. For example, the operation of method 1000 can be implemented by referring to... Figures 5 to 7 The data management component described herein performs the functions. In some examples, the user equipment may execute a set of instructions to control the functional elements of the user equipment to perform the functions described below. Additionally or alternatively, the user equipment may use dedicated hardware to perform various aspects of the functions described below.

[0095] In 1005, the user equipment can detect that a user is requesting access to protected data, and in response to detecting that a user is requesting access, authentication processing is performed. The operation of 1005 can be performed according to the methods described herein. In some examples, aspects of the operation of 1005 can be referenced... Figures 5 to 7 The data access component is executed.

[0096] In 1010, the user equipment can activate its image detection component to access protected data at the user equipment location by authenticating the user according to the authentication process. The operation of 1010 can be performed according to the method described herein. In some examples, aspects of the operation of 1010 can be referenced... Figures 5 to 7 The authentication component is executed.

[0097] In 1015, the user equipment can display protected data at the user interface based on the result of the authentication process. The operation of 1015 can be performed according to the methods described herein. In some examples, aspects of the operation of 1015 can be referenced... Figures 5 to 7 The data display component is executed.

[0098] In 1020, the user equipment can process the user in the monitored field of view based on image monitoring, wherein events are detected based on the monitoring. The operation of 1020 can be performed according to the methods described herein. In some examples, aspects of the operation of 1020 can be derived from references... Figures 5 to 7 The image monitoring component described above is used to perform this task.

[0099] In 1025, the user equipment can detect events indicating that the user is not viewing protected data or indicating that at least one other person is in the field of view of the image detection component, based on the execution of an image detection model and image monitoring processing using the image detection component. The operation of 1025 can be performed according to the methods described herein. In some examples, aspects of the operation of 1025 can be derived from references... Figures 5 to 7 The image monitoring component is executed.

[0100] In 1030, the user equipment can hide protected data at the user interface based on the detection of an event. The operation of 1030 can be performed according to the methods described herein. In some examples, aspects of the operation of 1030 can be referenced... Figures 5 to 7 The data hiding component is executed.

[0101] A method for protecting data at a user device is described. The method may include activating an image detection component of the user device to access protected data at the user device by authenticating a user according to an authentication process; displaying the protected data at a user interface of the user device based on the result of the authentication process; detecting events indicating that the user is not viewing the protected data or indicating that at least one other person is in the field of view of the image detection component, based on image monitoring processing using an image detection model and the image detection component; and hiding the protected data at the user interface based on the detected events.

[0102] A device for protecting data at a user equipment is described. The device may include a processor, memory coupled to the processor, and instructions stored in the memory. The instructions, executable by the processor, cause the device to activate an image detection component of the user equipment to access protected data at the user equipment by authenticating the user according to an authentication process; display the protected data at a user interface of the user equipment based on the result of the authentication process; detect an event indicating that the user has not viewed the protected data or indicating that at least one other person is in the field of view of the image detection component, based on image monitoring processing that executes an image detection model and uses the image detection component; and hide the protected data at the user interface based on the detected event.

[0103] Another device for protecting data at a user equipment is described. The device may include: activating an image detection component of the user equipment to authenticate a user and access protected data at the user equipment according to an authentication process; displaying the protected data at a user interface of the user equipment based on the result of the authentication process; detecting events indicating that the user is not viewing the protected data or indicating that at least one other person is in the field of view of the image detection component, based on image monitoring processing that performs an image detection model and uses the image detection component; and means for hiding the protected data at the user interface based on the detected events.

[0104] A non-transitory computer-readable medium is described, storing code for protecting data at a user device. The code may include instructions executable by a processor to: activate an image detection component of the user device to access protected data at the user device by authenticating a user according to an authentication process; display the protected data at a user interface of the user device based on the result of the authentication process; detect an event indicating that the user is not viewing the protected data or indicating that at least one other person is in the field of view of the image detection component, based on image monitoring processing that executes an image detection model and uses the image detection component; and hide the protected data at the user interface based on the detected event.

[0105] Some examples of the methods, apparatuses, and non-transitory computer-readable media described herein may further include operations, features, means, or instructions for determining, based on authentication processing, that a user may be the owner of a user device, wherein based on the determination that a user may be the owner of a user device, the user can be authenticated and enabled to access protected data.

[0106] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, determining that a user may be an owner may include operations, features, means, or instructions for recognizing a face in the field of view of an image detection component and matching that face with an image of the owner of the user device stored in a secure compartment of the user device.

[0107] Some examples of the methods, apparatuses, and non-transitory computer-readable media described herein may further include operations, features, devices, or instructions of a user in a monitored field of view for processing based on image monitoring, wherein events may be detected based on monitoring.

[0108] In some examples of the methods, apparatuses, and nontransient computer-readable media described herein, monitoring a user may include operations, features, devices, or instructions for monitoring one or more facial features that indicate whether the user is looking at the display of the user's device.

[0109] Some examples of the methods, apparatuses, and non-transient computer-readable media described herein may further include operations, features, devices, or instructions for determining that a user's eye indicates that the user's gaze may be leaving the display of a user's device, wherein an event may be detected based on such determination.

[0110] Some examples of the methods, apparatuses, and non-transitory computer-readable media described herein may further include operations, features, means, or instructions for reactivating authentication processing based on the detection of an event.

[0111] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may further include operations, features, means, or instructions for detecting, in accordance with image monitoring processing, a second event indicating that a user may be viewing protected data or that at least one other person may not be in the field of view of the image detection component, and for re-displaying the protected data based on the detection of the second event.

[0112] In some examples of the methods, devices, and nontransient computer-readable media described herein, hiding protected data may include operations, features, means, or instructions for obscuring protected data at a user interface, displaying an alert at a user interface, or a combination thereof.

[0113] Some examples of the methods, apparatuses, and non-transitory computer-readable media described herein may further include operations, features, means, or instructions for detecting that a user may be requesting access to protected data, wherein authentication processing may be performed in response to detecting that a user may be requesting access.

[0114] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may further include operations, features, devices, or instructions that activate image monitoring processing in response to authenticating a user according to authentication processing.

[0115] It should be noted that the methods described above describe possible implementations, and the operations and steps can be rearranged or otherwise modified, and other implementations are possible. Furthermore, aspects from two or more methods can be combined.

[0116] The description set forth herein in conjunction with the accompanying drawings describes an exemplary configuration and does not represent all examples that can be implemented or that are within the scope of the claims. The term "exemplary" as used herein means "serving as an example, instance, or illustration," and not "preferred" or "superior to other examples." The detailed description includes specific details used to provide an understanding of the described techniques. However, these techniques can be practiced without these specific details. In some instances, well-known structures and devices are shown in block diagram form to avoid obscuring the concept of the described examples.

[0117] In the accompanying figures, similar components or features may have the same reference label. Furthermore, various components of the same type can be distinguished by a dash following the reference label and a second label used to differentiate between similar components. If only the first reference label is used in the specification, the description applies to any similar part having the same first reference label, regardless of the second reference label.

[0118] The information and signals described herein can be represented using any of a variety of different techniques and technologies. For example, data, instructions, commands, information, signals, bits, symbols, and chips referenced in the foregoing description can be represented by voltage, current, electromagnetic waves, magnetic fields or particles, light fields or particles, or any combination thereof.

[0119] The various illustrative blocks and modules described in connection with the disclosure herein may be implemented or executed using a general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic, discrete hardware component, or any combination thereof, and are designed to perform the functions described herein. The general-purpose processor may be a microprocessor, but alternatively, it may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration).

[0120] The functions described herein can be implemented by hardware, software executed by a processor, firmware, or any combination thereof. If implemented in software executed by a processor, the functions can be stored on or transmitted on a computer-readable medium as one or more instructions or code. Other examples and implementations are within the scope of the disclosure and the appended claims. For example, due to the nature of software, the functions described above can be implemented using software executed by a processor, hardware, firmware, hardwired, or any combination thereof. Features implementing the functions can also be physically located in various locations, including distributed such that parts of the functions are implemented in different physical locations. Furthermore, as used herein, including in the claims, the use of “or” in the list of items (e.g., a list of items beginning with phrases such as “at least one” or “one or more”) indicates a list of included items, such that a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Furthermore, as used herein, the phrase “based on” should not be construed as a reference to a closed set of conditions. For example, an exemplary step described as “based on condition A” can be based on both condition A and condition B without departing from the scope of the disclosure. In other words, as used in this article, the phrase “based on” should be interpreted in the same way as the phrase “at least partially based on”.

[0121] Computer-readable media includes non-transitory computer storage media and communication media, including any media that facilitates the transfer of a computer program from one place to another. Non-transitory storage media can be any available medium accessible by a general-purpose or special-purpose computer. By way of example, and not limitation, non-transitory computer-readable media can include RAM, ROM, electrically erasable programmable read-only memory (EEPROM), optical disc (CD) ROM or other optical disc storage, disk storage or other magnetic storage devices, or any other means of carrying or storing desired program code in the form of instructions or data structures, accessible by a general-purpose or special-purpose computer, or a general-purpose or special-purpose processor. Furthermore, any connection is appropriately referred to as computer-readable media. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of media. The disks and optical discs used in this article include CDs, laser discs, optical discs, DVDs, floppy disks, and Blu-ray discs. Disks typically reproduce data magnetically, while optical discs reproduce data optically using lasers. Combinations of these are also included within the scope of computer-readable media.

[0122] The description provided herein is intended to enable those skilled in the art to make or use the disclosed text. Various modifications to the disclosed text will be apparent to those skilled in the art, and the general principles defined herein may be applied to other variations without departing from the scope of the disclosed text. Therefore, the disclosed text is not limited to the examples and designs described herein, but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for protecting data at a user equipment, comprising: Activate the image detection component of the user equipment to access protected data at the user equipment by authenticating the user according to the authentication process; The authentication process determines that the user is the owner of the user device, wherein the authentication process identifies the owner in the field of view of the image detection component, and wherein the user is authenticated to access the protected data based at least in part on the determination that the user is the owner of the user device; Based at least in part on the result of the authentication process, the protected data is displayed at the user interface of the user equipment and image monitoring processing is activated. The image monitoring process, which is at least partially based on the execution of an image detection model and the use of the image detection component, detects events indicating that the user is not currently viewing the protected data or indicating that at least one other person is in the field of view of the image detection component, wherein the image monitoring process includes monitoring multiple frames captured in the field of view while the protected data is displayed at the user interface and detecting the event based at least partially on the monitoring to determine whether the state of the field of view has changed; and The protected data is hidden in the user interface, at least in part based on the detection of the event.

2. The method of claim 1, wherein determining that the user is the owner comprises: Identify faces within the field of view of the image detection component; and The face is matched with an image of the user device's owner stored in the secure compartment of the user device.

3. The method according to claim 1, further comprising: According to the image monitoring process, the plurality of frames are processed to monitor whether the user is in the field of view, wherein the event is detected based on the processing of the plurality of frames.

4. The method according to claim 3, further comprising: The monitoring indicates whether the user is looking at one or more facial features on the display of the user device.

5. The method according to claim 4, further comprising: The determination that the user's eyes indicate that the user's gaze is leaving the display of the user's device is detected based on the determination.

6. The method according to claim 1, further comprising: The authentication process is reactivated, at least in part, based on the detection of the event.

7. The method according to claim 1, further comprising: Based on the image monitoring process, a second event is detected indicating that the user is viewing the protected data or that at least one other person is not in the field of view of the image detection component; and The protected data is redisplayed, at least in part based on the detection of the second event.

8. The method of claim 1, wherein hiding the protected data comprises: The protected data may be obscured at the user interface, an alarm may be displayed at the user interface, or a combination of both may be used.

9. The method according to claim 1, further comprising: The system detects that the user is requesting access to the protected data, and performs the authentication process in response to detecting that the user is requesting access.

10. An apparatus for protecting data at a user equipment, comprising: processor; A memory coupled to the processor; and Instructions, which are stored in the memory and can be executed by the processor to cause the device to: Activate the image detection component of the user equipment to access protected data at the user equipment by authenticating the user according to the authentication process; The authentication process determines that the user is the owner of the user device, wherein the authentication process identifies the owner in the field of view of the image detection component, and wherein the user is authenticated to access the protected data based at least in part on the determination that the user is the owner of the user device; Based at least in part on the result of the authentication process, the protected data is displayed at the user interface of the user equipment and image monitoring processing is activated. The image detection process, at least in part based on the execution of an image detection model and the use of the image detection component, detects an event indicating that the user is not currently viewing the protected data or at least one other person in the field of view of the image detection component, wherein the image detection process includes monitoring multiple frames captured in the field of view while the protected data is displayed at the user interface and detecting the event based at least in part on the monitoring to determine whether the state of the field of view has changed; And, at least in part based on the detection of the event, hide the protected data at the user interface.

11. The device of claim 10, wherein the instruction for determining that the user is the owner is executable by the processor to cause the device to: Identify faces in the field of view of the image detection component; and The face is matched with an image of the user device's owner stored in the secure compartment of the user device.

12. The device of claim 10, wherein the instructions are further executable by the processor to cause the device to: According to the image monitoring process, the plurality of frames are processed to monitor whether the user is in the field of view, wherein the event is detected based on the processing of the plurality of frames.

13. The device of claim 12, wherein the instructions are further executable by the processor to cause the device to: The monitoring indicates whether the user is looking at one or more facial features on the display of the user device.

14. A non-transitory computer-readable medium storing code for protecting data at a user equipment, said code comprising instructions executable by a processor to perform the following operations: Activate the image detection component of the user equipment to access protected data at the user equipment by authenticating the user according to the authentication process; The authentication process determines that the user is the owner of the user device, wherein the authentication process identifies the owner in the field of view of the image detection component, and wherein the user is authenticated to access the protected data based at least in part on the determination that the user is the owner of the user device; Based at least in part on the result of the authentication process, the protected data is displayed at the user interface of the user equipment and image monitoring processing is activated. The image detection process, at least in part based on the execution of an image detection model and the use of the image detection component, detects an event indicating that the user is not currently viewing the protected data or at least one other person in the field of view of the image detection component, wherein the image detection process includes monitoring multiple frames captured in the field of view while the protected data is displayed at the user interface and detecting the event based at least in part on the monitoring to determine whether the state of the field of view has changed; and The protected data is hidden in the user interface, at least in part based on the detection of the event.

15. The non-transitory computer-readable medium of claim 14, wherein the instruction for determining that the user is the owner is executable to: Identify faces in the field of view of the image detection component; and The face is matched with an image of the user device's owner stored in the secure compartment of the user device.

16. The non-transitory computer-readable medium of claim 14, wherein the instructions are further capable of performing: According to the image monitoring process, the plurality of frames are processed to monitor whether the user is in the field of view, wherein the event is detected based on the processing of the plurality of frames.

Citation Information

Patent Citations

  • Continuous digital content protection

    CN105378741A

  • Data protecting method and device

    CN107437012A