Selective display of sensitive data

By generating a sensitive information dictionary, decision tree, and display matrix, sensitive data is dynamically detected and masked, solving the problem of sensitive information leakage in virtual meetings. It enables selective display or masking based on viewer characteristics, improving security and privacy protection.

CN114417949BActive Publication Date: 2025-11-25INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111185901.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-10-13
Filing Date
2021-10-12
Publication Date
2025-11-25
Estimated Expiration
2041-10-12

AI Technical Summary

Technical Problem

Existing virtual meeting systems cannot selectively display or mask sensitive information based on viewer characteristics, resulting in all participants having access to sensitive data, which may lead to the leakage of company secrets or personal privacy.

Method used

By generating a sensitive information dictionary, decision tree, and display matrix, sensitive data is dynamically detected and masked. Sensitive information is selectively displayed or masked based on the characteristics of the viewer, and automated processing is achieved using computer programs.

Benefits of technology

It enables the selective display or masking of sensitive information based on viewer characteristics, protecting company secrets and personal privacy, and improving the security and privacy protection of virtual meetings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114417949B_ABST
    Figure CN114417949B_ABST
Patent Text Reader

Abstract

Selectively demonstrating information by generating a lexicon including information classified as sensitive according to a characteristic of a participant, generating a display matrix including display rules according to the characteristic of the participant, detecting sensitive data in a presentation stream, determining display coordinates of the sensitive data, determining a demonstration state of the sensitive data according to the characteristic of the participant, the lexicon, a decision tree, and the display matrix, and masking the sensitive information according to the demonstration state and the display coordinates.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates generally to selective display of sensitive data. The present disclosure relates particularly to selectively displaying data according to viewer characteristics. BACKGROUND

[0002] Virtual meetings have grown exponentially over the past few years. Such meetings are used for a variety of purposes and also mitigate the distribution and separation of meeting attendees. Meetings typically include displaying a common set of information to all session participants during a session. Each user enjoys full access to all displayed content. SUMMARY

[0003] The following presents a summary to provide a basic understanding of one or more embodiments of the present disclosure. This summary is not intended to identify key or critical elements or to delineate any scope of certain embodiments or any scope of any claims. Its sole purpose is to present concepts in a simplified form as a prelude to the more detailed description that is presented later. In one or more embodiments described herein, a device, system, computer- implemented method, apparatus, and / or computer program product enables automatic selection and masking of presentation information according to presentation content and viewer characteristics.

[0004] Aspects of the invention disclose methods, systems, and computer-readable media associated with selectively presenting information by generating a lexicon comprising information classified as sensitive according to participant characteristics, generating a display matrix comprising display rules according to participant characteristics, detecting sensitive data in a presentation stream, determining display coordinates of the sensitive data, determining a presentation state of the sensitive data according to participant characteristics, the lexicon, a decision tree, and the display matrix, and masking presentation of the sensitive information according to the presentation state and the display coordinates. BRIEF DESCRIPTION OF DRAWINGS

[0005] The above and other objects, features and advantages of the present disclosure will become more apparent from the following detailed description when taken in conjunction with the accompanying drawings in which like reference characters indicate like components throughout the figures and in which:

[0006] Figure 1 A schematic diagram of a computing environment in accordance with embodiments of the present invention is provided.

[0007] Figure 2 A flow diagram depicting a sequence of operations in accordance with embodiments of the present invention is provided.

[0008] Figure 3 A participant decision tree in accordance with embodiments of the present invention is depicted.

[0009] Figure 4 A cloud computing environment in accordance with embodiments of the present invention is depicted.

[0010] Figure 5 An abstraction model layer is shown in accordance with embodiments of the application. DETAILED DESCRIPTION

[0011] Some embodiments will be described in greater detail with reference to the accompanying drawings, in which embodiments of the disclosure have been shown. The disclosure can be implemented in various ways, however, and therefore should not be construed as limited to the embodiments disclosed herein.

[0012] A teleconference for presenting information can include a project manager, software developers working on the project, and a financial analyst associated with the project. Portions of the presentation are shared with all participants. Project financial data, including developer compensation amounts, can be considered sensitive information. Disclosed embodiments enable selective presentation of information according to information content and viewer characteristics. For this example, disclosed embodiments enable sharing and discussion of financial data between the project manager and the financial analyst, while masking the data and discussion from the perspective of the developers. Disclosed embodiments dynamically detect and present sensitive data according to participant characteristics.

[0013] In one embodiment, one or more components of the system can employ hardware and / or software to address problems that are highly technical in nature (e.g., generating a lexicon including information classified as sensitive according to participant characteristics, generating a decision tree for communication channels according to participant behavior, generating a display matrix including display rules according to participant characteristics and the decision tree, detecting sensitive data in a presentation stream, determining display coordinates for sensitive data, determining a presentation state for sensitive data according to participant characteristics, the lexicon, the decision tree, and the display matrix, masking presentation of sensitive information according to the presentation state and the display coordinates, etc.). These solutions are not abstract and cannot be performed by a human as a set of mental acts due to, for example, the processing power required to facilitate selective content masking. Further, some of the processes performed can be performed by a special purpose computer for performing defined tasks related to presentation content. For example, a special purpose computer can be employed to perform tasks related to selectively masking or presenting sensitive content according to viewer characteristics, etc.

[0014] In one embodiment, the method generates and maintains a lexicon of sensitive terms. The method generates the lexicon using user-provided input that identifies sensitive terms. The input can be provided directly by the user or can be collected by the method from previous interactions with the user in which terms were identified as sensitive. The method updates the lexicon, adding sensitive information entries associated with terms identified by the presenter in content used to plan the presentation. The lexicon entries include terms and viewing permission restrictions related to company restrictions and position role restrictions. As an example, a lexicon entry for "cost" includes restrictions on viewing by "Company A" employees and restrictions on position roles of "Project Manager," "Manager," and "Financial Analyst."

[0015] In one embodiment, the method generates a decision tree for each participant. In this embodiment, each participant decision tree includes branches associated with different communication channels used by the participant. In this embodiment, each participant consents to, or "opts in" to, review and analysis of communications including emails, phone calls - using speech-to-text conversion algorithms, chat messages, and other communications. The decision tree review focuses on confirming the position role of the participant within the company. In one embodiment, the decision tree review also verifies the participant's access to different types of information.

[0016] In one embodiment, the method utilizes the lexicon entries and decision tree analysis output to generate a display matrix. The display matrix catalogs and cross-references individual participants in the effective position roles that have effective access to specific types of information designated as sensitive by the lexicon entries. The display matrix includes display rules for different types of information designated as sensitive according to the lexicon. The rules relate to which job types, or individuals, or company employees can view different types of sensitive information and which position roles, individuals in position roles, and company employees can not view each different type of sensitive information. In one embodiment, a matrix entry for a particular meeting includes the following fields: the source of information about the meeting, such as the meeting host, each participant, the meeting topic, the presentation area that includes sensitive information, the participant's company name, the participant's position role, and the results of the presentation area view.

[0017] In one embodiment, the method receives a scheduled presentation that includes sensitive information. The method scans the content of the presentation, such as a set of presentation slides. In this embodiment, the method divides each presentation slide into quadrants or regions, e.g., quadrants A, B, C, and D. The method then, for each quadrant of each slide, defines a positive angle that starts at 0 and ends at 359, the positive angle encompassing the entire quadrant. The method scans each quadrant for sensitive information text. The method tracks the quadrant and angle of any sensitive information text found. For example, the method identifies the word "cost" in quadrant or region C of slide 10 of the presentation slides, between 270 and 359 degrees, as being designated as sensitive in a dictionary. From the matrix entry for the associated meeting, the method determines a company-position role combination that lacks the necessary permissions to view the identified sensitive information. The method finds three participants that appear to match the identified company-position role combination. For each identified participant, the method generates or revisits a previously generated decision tree for the participant. The method reviews available emails, calls, and chats, including participant attestation company-position role trial indicators. For participants that are attested in terms of company-position role matching, the method determines that at least the portion of slide 10 related to "cost" must be masked from being seen by the particular participant lacking the necessary permissions. In this embodiment, the method masks at least 270-359 degrees of region C of slide 10 for the three identified participants during the presentation.

[0018] Table 1 provides a view of representative matrix entries for a scheduled meeting / presentation.

[0019] Table 1:

[0020]

[0021] As shown in this table, three developer participants lack permission to view the sensitive cost information detected in quadrant C of slide 10.

[0022] For audio associated with sensitive information, the method uses a speech-to-text algorithm, and scans the converted text output for sensitive information. The method mutes the audio based on containing sensitive information after reviewing the relevant matrix entry, performs a decision tree analysis for the identified attention users, and attests that one or more users lack permission to listen to the sensitive audio portion of the presentation.

[0023] The method preserves the matrix entry for each meeting and references past meeting entries to determine rules associated with content viewing for future presentations of similar information types. For example, review of past entries indicates that viewing of source code information is prohibited for employees of company A. The method reviews the lexicon entries associated with source code and ensures that these entries accurately reflect the lack of viewing permission for employees of company A. For future meetings, the method scans the presentation information and annotates the source code related portions of the presentation according to the location - slide number, region, and region portion of the information. The method then generates a matrix entry for the future meeting that is relevant to the need to mask source code portions from viewing by employees of company A. The method looks at the company information for the participants scheduled for the future meeting. For any participants that appear to work for company A, the method scans available communications to verify employment with company A using a decision tree. The method then masks the information from being seen by employees of company A using a pixelation of the information, by removing quadrants of the slide entirely from view, or covering the relevant slide portions with a blur shading or blur effect.

[0024] In one embodiment, the method can change lexicon and matrix entries according to user input, for example, a meeting host making an exception for a particular job role or a particular company regarding viewing of sensitive information for a presentation of sensitive information.

[0025] In one embodiment, the web conferencing system starts a session, provides the session content of the user and the corresponding data that matches with the database or lexicon containing sensitive data for specific roles. The system loads the method / mechanism API (application program interface) containing the library and references to integrate the application sharing information. The method detects the specific shared application using known scripts (depending on the programming language), using the corresponding API and library to access the application elements such as TEXT, image, object, etc. The method initiates the matching data processing to detect the sensitive data on the shared application defined on the data matching DB or lexicon. As described above, the method determines the specific display coordinates of the sensitive data: the coordinates of the text, image, object, etc. within the presentation slide. The method then disables the presentation / masks / hides the sensitive information data on the specific application coordinates (e.g. XX, YY, ZZ) for specific viewers associated with defined companies and / or job roles.

[0026] In one embodiment, the method takes known steps to capture a recording of the presentation. For a recorded version of the presentation, the method performs the above analysis during the recording of the information of the participants identified by the conference moderator. The method then associates metadata with the recording. The metadata provides the details necessary to mask / present sensitive and non-sensitive portions depending on which participant is viewing the recording. In this embodiment, the method receives the profile information of the participant prior to playing back the recording and uses the metadata to appropriately mask sensitive data and audio to the participant during playback of the recording. For example, a conference restricts developer members from viewing financial information and the recording contains metadata indicating a common relationship between the sensitive financial information and the developer. When the method sends the recording to the developer, it associates the metadata with the profile of the developer to download the recording and injects the necessary rules so that in this case the financial information (text, images, speech, etc.) is hidden from the developer when reproduced / visualized.

[0027] Figure 1 A diagram of exemplary network resources associated with practicing the disclosed application is provided. The application can be implemented in a processor of any of the disclosed elements that process instruction streams. As shown, networked client devices 110 are wirelessly connected to server subsystem 102. Client device 104 is wirelessly connected to server subsystem 102 via network 114. Client devices 104 and 110 include a selective presentation program (not shown) and sufficient computing resources (processor, memory, network communication hardware) to execute the program. In one embodiment, client devices 104 and 110 represent presentation participant (conference support person or presentation viewer) devices. The moderator and viewers connect over the network to share presentation content under the watchful eye of the disclosed selective presentation program executing on the client devices and server subsystem computers.

[0028] As Figure 1 shown, server subsystem 102 includes server computer 150. Figure 1 A block diagram depicting components of server computer 150 within networked computer system 1000 according to an embodiment of the application is depicted. It should be appreciated that Figure 1 Only an example of one implementation is provided for illustrative purposes, but no implication is made that any limitation is implied regarding environments in which different embodiments can be implemented. Numerous modifications can be made to the described environments.

[0029] The server computer 150 can include a processor 154, a memory 158, a persistent storage 170, a communication unit 152, an input / output (I / O) interface 156, and a communication fiber 140. The communication fiber 140 provides communication between the cache 162, the memory 158, the persistent storage 170, the communication unit 152, and the input / output (I / O) interface 156. The communication fiber 140 can be implemented with any architecture designed for the communication of data and / or control information between processors (e.g., microprocessors, communication and network processors, etc.), system memory, peripheral devices, and any other hardware components within a system. For example, the communication fiber 140 can be implemented with one or more buses.

[0030] The memory 158 and the persistent storage 170 are computer readable storage media. In this embodiment, the memory 158 includes a random access memory (RAM) 160. Generally, the memory 158 can include any suitable volatile or non-volatile computer readable storage media. The cache 162 is a fast memory that enhances the performance of the processor 154 by

[0031] Program instructions and data used by the server computer 150 to practice embodiments of the present application, such as the selective presentation program 175, are stored in the persistent storage 170 for execution and / or access by one or more of the respective processors 154 via the cache 162. In this embodiment, the persistent storage 170 includes a magnetic hard disk drive. Alternatively, or in addition to the magnetic hard disk drive, the persistent storage 170 can include a solid-state hard drive, a semiconductor storage device, read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, or any other computer readable storage media that is capable of storing program instructions or digital information.

[0032] The media used by the persistent storage 170 can also be removable. For example, a removable hard drive can be used for the persistent storage 170. Other examples include optical and magnetic disks, thumb drives, and smart cards, which are inserted into a drive for transfer onto another computer readable storage medium, also a portion of the persistent storage 170.

[0033] In these examples, the communication units 152 provide communications with other data processing systems or devices that include resources of the client computing devices 104 and 110. In these examples, the communication units 152 include one or more network interface cards. The communication units 152 can provide communications through the use of either or both physical and wireless communications links. Software distributions, as well as other programs and data used in implementing the present application, can be downloaded to the permanent storage devices 170 of the server computer 150 through the communication unit 152.

[0034] The I / O interface 156 allows for input and output of data to other devices that can be connected to the server computer 150. For example, the I / O interface 156 can provide a connection to an external device 190 such as a keyboard, a keypad, a touch screen, a microphone, a digital camera, and / or some other suitable input device. The external device 190 can also include a portable computer- readable storage medium such as, for example, a thumb drive, a portable optical or magnetic disk, and a memory card. Software and data used in practicing embodiments of the present application, for example, the selective presentation program 175 on the server computer 150, can be stored on such portable computer- readable storage media, and can be loaded onto the permanent storage devices 170 via the I / O interface(s) 156. The I / O interface 156 is also connected to a display 180.

[0035] The display 180 provides a mechanism to display data to a user, and can be, for example, a computer monitor. The display 180 can also be used as a touch screen, such as the display of a tablet computer.

[0036] Figure 2 A flowchart 200 is provided that illustrates exemplary activities associated with the practice of the present disclosure. After a start, at block 210, a method of the selective presentation program 175 generates a lexicon of sensitive information. The lexicon includes sensitive terms and parameters associated with the terms that define sensitivity limits or define characteristics of viewers that can see the information and those that cannot. The sensitive information can be defined by a meeting host or by other user input. The user that defines the information as sensitive can further provide viewer characteristics that define the sensitivity limits. The lexicon of sensitive information is cumulative in nature. Over time, the method will add to the lexicon information that is designated as sensitive for any given presentation and viewer characteristics that define associated with that information. In one embodiment, the method receives presentation content data associated with a scheduled presentation and scans the data for sensitive data according to the lexicon entries.

[0037] At block 220, the method of the selective presentation program 175 generates a decision tree for each presentation participant identified from the matrix of data entries associated with the presentation. The decision tree analyzes communications to and from potential presentation participants identified by the meeting host or otherwise present in the matrix entries. The method analyzes communication traffic on multiple communication channels, including email, telephone calls, VOIP calls, and chats, to validate participants according to their corporate affiliation, position role, and / or other participant characteristics. The decision tree analysis considers the text of emails and chats and the text transcription of any voice calls, where the call is converted to text using a speech-to-text algorithm.

[0038] At block 230, the method of the selective presentation program 175 generates a display matrix. The display matrix generation can start with entries provided by the meeting host. The initial entries can include the host's identification, the meeting topic, and participant characteristic information, such as the name, corporate affiliation, and position role of each participant. The entries can also include sensitive content information related to the planned presentation. The method builds on the initial matrix entries by adding participant characteristic validation data obtained from the participant decision tree analysis. The method builds the entries to include one or more rules related to the presentation of sensitive information and the characteristics of scheduled participants. These relationships can be defined by the host, the presentation of sensitive information, or derived from matrix entries associated with past meetings having similar topics, including similar sensitive information or similar participants.

[0039] After scanning the planned presentation content file from the view of the sensitive information lexicon for keywords, at block 240, the method of the selective presentation program 175 detects sensitive information in the content file for presentation.

[0040] At block 250, the method determines the display coordinates of the detected sensitive information. In one embodiment, the method divides the presentation slide into quadrants or regions. The method then defines a unit circle for each region and scans the region for sensitive information terms. The method locates sensitive information according to the relevant portion of the unit circle within the region. For example, the method detects the use of the sensitive term "cost" between 300 degrees and 360 degrees of the unit circle of region C of the presentation slide 10. The method adds the detected sensitive information and the associated display coordinates to the relevant display matrix entry. As an example, the method adds the presence of cost information between 300 degrees and 360 degrees of region C of slide 10 to the entry for the planned presentation and analyzes the permissions of the scheduled participants according to the lexicon entry for cost information. The method considers the characteristics of each participant and validates these characteristics using current and past decision tree analysis of participant communications.

[0041] At block 260, after validating the participant permissions according to the dictionary entries, decision tree analysis, and display matrix rules, the method determines the display status of the detected sensitive information. The method adds the determined display status to the scheduled participant's display matrix entry for the presentation of the plan. For example, the scheduled participant works for Company A as a developer. The method determines the display status to be "masked" for the participant and the cost information using the decision tree analysis of the participant's communications. The method validates the participant's company and position role. The method adds the display status "masked" to the entry associated with the presentation, cost data, and Company A developer.

[0042] At block 270, the method masks the sensitive data during the actual presentation. For this example, the method obscures or removes the data displayed between 300 degrees and 360 degrees in region C of slide 10 from the view of the content provided to the Company A developer, and from the view of any other participant as indicated by the entries of the display matrix. In one embodiment, the method obfuscates the sensitive data by changing the pixel resolution of the identified portion of the display, increasing the pixel size of the portion, and making the portion unreadable. In one embodiment, the method obscures the sensitive data portion by blurring all of the relevant pixels to a uniform color— such as gray, black, or other color, creating the appearance that the sensitive data has been edited out of the presentation, again rendering the sensitive data portion unreadable.

[0043] Figure 3 A schematic diagram 300 of a participant decision tree according to an embodiment of the invention is provided. As shown, participant 310 has three communication channels, email, call, and chat, which are analyzed by the disclosed method. The method reviews the text of email 320 and chat 340, and the voice-to-text transcription of call 330. Each review of the analysis validates 322, 332, and 342, or invalidates 324, 334, and 344, the characteristics of participant 310. Validation includes detecting text in the communication that is similar or identical to the company name and / or position role associated with the participant's characteristics. The lack of such similar or identical terms in the communication stream invalidates the participant's characteristics. The decision tree analysis output is added to the participant's display matrix entry. For invalidated characteristics, the method generates a display matrix entry indicating the invalidation, and in one embodiment, flags all presentation content for masking for the participant with the invalidated characteristics.

[0044] It should be appreciated that, although the present disclosure includes detailed descriptions of cloud computing, implementation of the teachings presented herein are not limited to a cloud computing environment. Rather, embodiments of the present invention are capable of implementation in conjunction with any other type of computing environment now known or later developed.

[0045] Cloud computing is a model of service delivery for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g. networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with a provider of the service. This cloud model can be composed of at least five characteristics, at least three service models, and at least four deployment models.

[0046] The characteristics are as follows:

[0047] Broad network access: capabilities are available over a network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs).

[0048] Broad network access: capabilities are available over a network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs).

[0049] Resource pooling: the provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to demand. There is a sense of location independence in that the consumer generally has no control or knowledge over the exact location of the provided resources but can be able to specify location at a higher level of abstraction (e.g., country, state, or datacenter).

[0050] Rapid elasticity: capabilities can be rapidly and elastically provisioned, in some cases automatically, to quickly scale out and rapidly scale in. To the consumer, the provider's ability to provision capabilities on-demand and in near real-time, allows for rapidly adjusting to demand level, which translates to balancing of workloads.

[0051] Measured service: cloud systems automatically control and optimize resource use by leveraging utilization of resources in an efficient manner, such as in response to varying demand for the services. Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized service.

[0052] The service models are as follows:

[0053] Software as a Service (SaaS): the capability provided to the consumer is to use the provider's applications running on a cloud infrastructure. The applications are accessible from various client devices through a thin client interface such as a web browser (e.g., web-based e-mail). The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.

[0054] Platform as a Service (PaaS): the capability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including networks, servers, operating systems, or storage, but has control over the deployed applications and possibly application hosting environment configurations.

[0055] Infrastructure as a Service (laaS): the capability provided to the consumer is to provision processing, storage, networks, and other fundamental computing resources where the consumer is able to deploy and run arbitrary software, which can include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, deployed applications, and possibly limited control of select networking components (e.g., host firewalls).

[0056] Deployment models are as follows:

[0057] Private cloud: the cloud infrastructure is operated solely for an organization. It can be managed by the organization or a third party and can exist on-premises or off-premises.

[0058] Community cloud: the cloud infrastructure is shared by several organizations and supports mission-oriented business

[0059] Public cloud: the cloud infrastructure is made available to general public or a large industry group and is owned by an organization selling cloud services.

[0060] Hybrid cloud: the cloud infrastructure is a composition of two or more clouds (private, community, or public) that remain unique entities but are bound together, giving customers the benefit of combined computing power and data storage.

[0061] A cloud computing environment is service-oriented, with a focus on statelessness, loose coupling, modularity, and semantic interoperability. At the core of cloud computing is an infrastructure comprising a network of interconnected nodes.

[0062] Reference is now made to Figure 4The diagram illustrates an illustrative cloud computing environment 50. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 to which a local computing device used by a cloud consumer can communicate. This local computing device is, for example, a personal digital assistant (PDA) or cellular phone 54A, a desktop computer 54B, a laptop computer 54C, and / or an automotive computer system 54N. The nodes 10 can communicate with each other. They can be physically or virtually grouped (not shown) in one or more networks, such as private clouds, community clouds, public clouds, or hybrid clouds, or combinations thereof, as described above. This allows the cloud computing environment 50 to provide infrastructure, platform, and / or software as a service, without requiring the cloud consumer to maintain resources on their local computing device. It should be understood that... Figure 4 The types of computing devices 54A-N shown are for illustrative purposes only, and computing node 10 and cloud computing environment 50 can communicate with any type of computerized device via any type of network and / or network-addressable connection (e.g., using a web browser).

[0063] Now for reference Figure 5 This demonstrates a cloud computing environment of 50 ( Figure 4 This provides a set of functional abstractions. It should be understood beforehand that... Figure 5 The components, layers, and functions shown are for illustrative purposes only, and embodiments of the invention are not limited thereto. As depicted, the following layers and corresponding functions are provided:

[0064] The hardware and software layer 60 includes hardware and software components. Examples of hardware components include: a host 61; a server 62 based on a RISC (Reduced Instruction Set Computer) architecture; a server 63; a blade server 64; a storage device 65; and a network and network components 66. In some embodiments, software components include network application server software 67 and database software 68.

[0065] The virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual server 71; virtual storage 72; virtual network 73, including virtual private network; virtual application and operating system 74; and virtual client 75.

[0066] In one example, management layer 80 can provide the functions described below. Resource provisioning 81 provides dynamic procurement of computing resources and other resources that are utilized to perform tasks within the cloud computing environment. Metering and Pricing 82 provide cost tracking as resources are utilized within the cloud computing environment, and billing or invoicing for consumption of these resources. In one example, these resources can include application software licenses. Security provides identity verification for cloud consumers and tasks, as well as protection for data and other resources. User portal 83 provides access to the cloud computing environment for consumers and system administrators. Service level management 84 provides cloud computing resource allocation and management such that required service levels are met. Service Level Agreement (SLA) planning and fulfillment 85 provide pre-arrangement for, and procurement of, cloud computing resources according to demand that is anticipated in accordance with the SLA.

[0067] Workloads layer 90 provides examples of functionality for which the cloud computing environment can be utilized. Examples of workloads and functions which can be provided from this layer include: mapping and navigation 91; software development and lifecycle management 92; virtual classroom education delivery 93; data analysis processing 94; transaction processing 95; and selective demonstration program 175.

[0068] The present application can be a system, a method, and / or a computer program product at any possible technical detail level of integration. The present application can advantageously implement in any system that processes instruction streams, singularly or in parallel. The computer program product can include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to carry out aspects of the present application.

[0069] The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer readable storage medium includes the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch-cards or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.

[0070] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adaptation card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions to storage media within the respective computing / processing device for execution.

[0071] Computer readable program instructions for carrying out operations of the present application can be assembly instructions, instruction-set-architecture (ISA) instructions, machine- related instructions, microcode, firmware instructions, state-setting data, configuration data for an integrated circuit, or source code or object code written in any combination of one or more programming languages, including an object oriented programming language such as Smalltalk, C++ or the like, and a procedural programming language such as the "C" programming language or similar programming languages. The computer readable program instructions can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGA), or programmable logic arrays (PLA) can execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present application.

[0072] Aspects of the present application are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions.

[0073] These computer readable program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions can also be stored in a computer readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer readable storage medium having instructions for causing an apparatus to implement aspects of the functions / acts specified in the flowchart and / or block diagram block or blocks is produced. The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0074] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0075] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0076] Reference throughout this specification to "an embodiment", "example embodiment", or the like, means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. The appearances of the phrase "in

[0077] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the present application. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0078] The description of the various embodiments of the present application has been presented for purposes of illustration, but is not intended to be exhaustive or limited to the embodiments disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the present application. The terminology used herein was chosen to best explain the principles of the embodiments, the practical application or technical improvement over technologies found in the marketplace, or to enable others skilled in the art to understand the embodiments disclosed herein.

Claims

1. A computer-implemented method for selectively presenting information, the method comprising: A dictionary is generated by one or more computer processors, the dictionary including information categorized as sensitive based on the characteristics of the participants; The one or more computer processors generate a decision tree for the communication channel based on the behavior of the participants, wherein the decision tree includes communications from the communication channel; The one or more computer processors generate a display matrix including display rules based on the characteristics of the participants; The one or more computer processors detect sensitive data in the presentation stream based on the dictionary; The coordinates for displaying the sensitive data are determined by the one or more computer processors. The presentation status of the sensitive data is determined by the one or more computer processors based on the characteristics of the participants, the dictionary, the decision tree, and the display matrix; The presentation of the sensitive data is masked by the one or more computer processors based on the presentation state and the display coordinates; and The one or more computer processors may mask audio content associated with the sensitive data based on the presentation state.

2. The computer-implemented method according to claim 1, wherein, The characteristics of the participants include their job titles and roles.

3. The computer-implemented method according to claim 1 further includes: A display matrix, including display rules, is generated based on the characteristics of the participants and the decision tree.

4. The computer-implemented method according to claim 1, wherein, Sensitive information detection includes scanning files for keywords.

5. The computer-implemented method according to claim 1, further comprising: The presentation is recorded by one or more computer processors, wherein the recorded presentation includes presentation status metadata of the participants.

6. The computer-implemented method according to claim 1, wherein, The characteristics of the participants include past presentation status of sensitive information.

7. A computer program product for selectively displaying information, the computer program product comprising one or more computer-readable storage devices and program instructions commonly stored on the one or more computer-readable storage devices, the stored program instructions comprising: Program instructions for generating a dictionary, which includes information categorized as sensitive based on the characteristics of the participants; Program instructions for generating a decision tree for communication channels based on the behavior of participants, wherein the decision tree includes communications from each of a plurality of communication channels; Program instructions used to generate a display matrix including display rules based on the characteristics of the participants; Program instructions for detecting sensitive data in the presentation stream based on the dictionary; Program instructions used to determine the display coordinates of the sensitive data; Program instructions for determining the presentation status of the sensitive data based on the characteristics of the participants, the dictionary, the decision tree, and the display matrix; Program instructions for masking the presentation of sensitive data based on the presentation state and the display coordinates; and Program instructions for masking audio content associated with the sensitive data based on the presentation state.

8. The computer program product according to claim 7, wherein, The characteristics of the participants include their job titles and roles.

9. The computer program product according to claim 7, wherein the stored program instructions further include: Program instructions for generating a display matrix including display rules based on the characteristics of the participants and the decision tree.

10. The computer program product according to claim 7, wherein, Sensitive information detection includes scanning files for keywords.

11. The computer program product according to claim 7, wherein the stored program instructions further include: Program instructions for capturing recordings of presentations, wherein the recorded presentations include metadata about the participants' presentation status.

12. The computer program product according to claim 7, wherein, The characteristics of the participants include past presentation status of sensitive information.

13. A computer system for selectively displaying information, the computer system comprising: One or more computer processors; One or more computer-readable storage devices; as well as Program instructions stored in the one or more computer-readable storage devices, for execution by the one or more computer processors, the stored program instructions including: Program instructions for generating a dictionary, which includes information categorized as sensitive based on the characteristics of the participants; Program instructions for generating a decision tree for communication channels based on the behavior of participants, wherein the decision tree includes communications from each of a plurality of communication channels; Program instructions used to generate a display matrix including display rules based on the characteristics of the participants; Program instructions for detecting sensitive data in the presentation stream based on the dictionary; Program instructions used to determine the display coordinates of the sensitive data; Program instructions for determining the presentation status of the sensitive data based on the characteristics of the participants, the dictionary, the decision tree, and the display matrix; Program instructions for masking the sensitive data in the presentation based on the presentation state and the display coordinates; and Program instructions for masking audio content associated with the sensitive data based on the presentation state.

14. The computer system according to claim 13, wherein, The characteristics of the participants include their job titles and roles.

15. The computer system according to claim 13, wherein the stored program instructions further include: Program instructions for generating a display matrix including display rules based on the characteristics of the participants and the decision tree.

16. The computer system according to claim 13, wherein, Sensitive information detection includes scanning files for keywords.

17. The computer system according to claim 13, wherein the stored program instructions further include: Program instructions for capturing recordings of presentations, wherein the recorded presentations include metadata about the participants' presentation status.

Citation Information

Patent Citations

  • Operation authentication relay device, method, and program

    WO2019106849A1