Access control for private messages
By recording the recipient's information on the sending terminal and sending private messages after activating access control on the recipient's terminal, combined with facial detection and biometric authentication, the problem of unauthorized access on the recipient's terminal is solved, thus achieving secure transmission of private messages and security for the sender.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-09-10
- Publication Date
- 2026-03-20
AI Technical Summary
In existing technologies, there is insufficient control over unauthorized access to private messages on the recipient's terminal, which makes it impossible to effectively guarantee the security of the sender.
By recording the recipient's information on the sending terminal, determining the recipient's terminal address, and only sending private messages after the recipient's terminal has activated access control, combined with facial detection and biometric authentication, the activation status of access control is ensured, restricting unauthorized access.
It improves the security of private messages, prevents unauthorized access, ensures that message transmission is only allowed when the recipient's terminal activates access control, and enhances the sender's security and privacy protection.
Smart Images

Figure CN114667714B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to a computer-implemented method for access control of a private message of a first end user to a second end user, and to corresponding computer program products for the first and second end. BACKGROUND
[0002] With regard to the exchange of private messages, solutions are known in many respects. For example, private messages between two participating terminals are usually transmitted in encrypted form ("end-to-end encryption"). It is therefore considerably difficult or practically impossible for third parties, for example intermediaries along the data connection, to read the data communication between the terminals in order to identify the content of the private messages. In any case, the terminals are usually secure with respect to third parties who primarily gain physical access to the respective terminal. To this end, the private messages are usually only saved in encrypted form on the two terminals. Decryption requires authentication of the user, for example based on biometrics such as fingerprint or facial recognition and / or based on an unlock code.
[0003] Another aspect is the reading of private messages by unauthorized third parties. In this case, the above-mentioned security mechanisms are overcome, since an authorized user of one of the two terminals reads the content of the private message and displays this same content on, for example, the screen of the terminal. In this case, the third party tries to gain visual access to the same screen and thus also reads the content of the private message. A similar situation arises if the authorized user voluntarily lets the third party access the terminal for other purposes and authenticates himself for this purpose. At the same time, he also wants to avoid that this legitimate access also extends to the content of the private message. WO 2018 / 229246 A1 proposes a continuous monitoring of the end users in order to avoid such access. In this case, access to private data can be restricted during an existing access to the terminal, for example if more than one user is detected.
[0004] The measures proposed in WO 2018 / 229246 A1 mainly help the users of the terminals concerned, i.e. these users want to restrict access to their private data saved on their terminals, which are independent of other data that can also be saved on their terminals, and they can want to allow third parties temporary access to the other data. That is, these measures mainly protect the recipients of private messages from third parties inadvertently gaining access to the private messages they received, or even from third parties discovering the existence of these messages.
[0005] US 2018 / 0083978 A1 shows a system and method for conditionally delivering electronic content, such as image or video stream content, over a communication network.
[0006] EP 2761 823 B1 shows a method and a device for authenticating electronic messages.
[0007] US 2013 / 0074195 A1 shows a method for accessing an email message from a control system. The method comprises requesting access to email message content of a user saved in the control system, determining whether the user is logged into the control system and activated by the control system, and authenticating the user when the user is logged into the control system and activated by the control system.
[0008] EP 1703431 A2 shows a display device and a corresponding control that will prevent information displayed on the display device from being snooped.
[0009] One aspect that is often neglected in known solutions is the interest of the sender of a private message that it cannot be read on the terminal of the recipient by an unauthorized third party. Encryption of the private message so that only the authorized recipient can decrypt it provides only limited protection in this respect. At least after the authorized recipient has decrypted the message, the protection of the message content depends on further precautions at the terminal of the recipient. The sender usually has no influence on these precautions with the methods described above. SUMMARY
[0010] It is an object of the present invention to improve the security of the sender of a private message against unwanted access on the terminal of the recipient.
[0011] The method according to the invention of the type mentioned in the opening part comprises the following steps:
[0012] - recording the private message and the recipient on the first terminal;
[0013] - determining the address of the second terminal on the basis of the recorded recipient;
[0014] - sending a query about the access control status from the first terminal to the second terminal;
[0015] - sending the private message from the first terminal to the second terminal only when the query is answered with a status message at the second terminal and according to the status message the access control is in the activated state at the second terminal.
[0016] Thus, if the recipient has not activated the access control desired by the sender on his terminal (herein referred to as the second terminal), the method provides that the private message from the sender is withheld (more precisely: by their terminal; herein referred to as the first terminal). In this way, the sender can ensure that the private message is only transmitted to the second terminal with activated access control, thus guaranteeing the security of the private message content and ultimately the security of the sender who expects or relies on the confidentiality of this content.
[0017] Optionally, it can be provided that the first terminal outputs an error message and deletes the message if, according to the status message, the access control on the second terminal is permanently deactivated. There is a permanently deactivated access control, for example, if the second terminal does not meet the technical requirements of the access control (e.g. missing software components and / or hardware components) or if the access control has been permanently deactivated on the second terminal (e.g. by a corresponding system configuration). In this case, it cannot be foreseen whether and when a private message can be transmitted without compromising security, which is the reason why the message can be deleted. In order to inform the user of the first terminal that the recipient has no access to the private message, an error message is output at the first terminal. This error message can expediently contain the reason, so that the sender has the opportunity to contact the recipient via a different channel, for example, to request activation of the access control.
[0018] Furthermore, it can also be provided, for example, that if according to the status message the access control is temporarily not activated at the second terminal, the first terminal starts a timer with a predefined duration and after the expiration of the timer the first terminal sends a new query to the second terminal about the status of the access control. Thus, during the period in which the access control is not activated and during which the private messages have a relatively high probability of being exposed to unauthorized access, it is ensured that the private messages do not reach the second terminal. The user of the second terminal can temporarily disable or switch off the access control. This can be used, for example, to allow an authorized third party to access private data on the second terminal. However, in this case the third party concerned has access to certain private data. Therefore, before allowing such access, the user of the second terminal will be sure which private data are saved on the second terminal and, if necessary, delete private data that the third party concerned should not have access to, before temporarily disabling the access control. If new private messages arrive at the second terminal during the access by the third party, the user of the second terminal will not be able to check these private messages in advance and possibly hide them from the third party, if necessary. Since the sender keeps the private messages during the period in which the access control is not activated, the above-mentioned variant of the method alleviates this problem. In this case, the first terminal attempts a re-delivery after a predefined duration, provided that the access control at the second terminal is in the activated state subsequently. The predefined duration can be, for example, 1 minute. The timer for monitoring the predefined duration is located at the first terminal, i.e. under the control of the sender of the private message. The first terminal does not output any error message as long as a new delivery attempt is made. The user of the first terminal can be informed by a suitable status indicator that the private message has not yet been delivered. As soon as the user of the second terminal reactivates the access control, they will therefore receive the private message as soon as possible without compromising the security of the private message.
[0019] The method can optionally involve some form of access control, which is required at the second terminal before the first terminal sends a private message. In particular, when the access control is in the activated state at the second terminal, access to the private message received from the first terminal can be restricted or not restricted on the second terminal, wherein in the case of unrestricted access the method comprises the following steps:
[0020] - recording an image signal using a camera of the second terminal;
[0021] - performing a face detection using the recorded image signal;
[0022] - continuously monitoring the number of faces determined in the recorded image signal by said face detection, wherein if the number of faces is greater than one, access is restricted.
[0023] Thus, as soon as only one person is detected in the field of view of the camera, i.e. the area recorded by the camera, unrestricted access is ensured. As soon as the face of a second person enters the field of view of the camera, the access is restricted, i.e. the second terminal is switched to restricted access. Then, the user of the second terminal has access to other data, which are not marked as private and which are saved on the second terminal. In this way, this makes it more difficult for third parties to spy on private data. For example, private contacts and all recommenders communicating with the private contacts can be kept secret from people other than the authorized user of the second terminal. The user can mark data as private and save this data on the second terminal. For example, the user can mark an existing contact as "private" or they create a new contact with a reference to "private". Then, the second terminal considers all data associated with this contact, e.g. previous calls, text messages, e-mails, chat messages, contact information itself, or images or videos associated with this contact, as private data. In any case, without interaction with the user, a private message received from the first terminal can be assigned to private data and the private message is not accessible in the case of restricted access.
[0024] If the second terminal has a screen for displaying private data and other data, the private data can be selectively completely hidden in the case of restricted access and only the other data is displayed. That is, the access to the private data is not only restricted by being covered, but also, in the case of restricted access, the access to the private data is restricted by not being able to see a representation of the existence of these data. In particular, an unauthorized third party should not be able to realize that they only have the right to restricted access.
[0025] For example, in this case, a visual indication of unrestricted access can additionally be prescribed to be displayed in the case of unrestricted access. Thus, in the case of unrestricted access, the user can realize that now other data and private data are displayed and thus he can freely access all data. The visual indication can be, for example, a green frame on the screen. Thus, without the visual indication, the authorized user can recognize restricted access; however, for an unauthorized user, restricted access cannot be recognized, since the user does not know or expect the visual indication.
[0026] According to another variant, events related to private data can be displayed on the screen in a restricted, e.g. censored, form during restricted access. This function should enable the user of the second terminal to be informed about events related to private data, e.g. messages from private contacts, even in the case of restricted access, e.g. without using the second terminal or without using the second terminal alone. For example, if the smartphone is lying on the table without being hidden, a call from a private contact can be displayed as "unknown number".
[0027] For starting the continuous monitoring, it would be advantageous if, in the case of an activated access control, an authentication of the user is performed for obtaining unrestricted access, before approving the unrestricted access, recording an image signal using the camera of the second terminal, performing a face detection using the recorded image signal and determining the number of faces in the recorded image signal, approving only if the number of faces is exactly one. Even in the case of a successful authentication, the unrestricted access is only approved if no observers and potential wanderers are detected.
[0028] Furthermore, it can optionally be provided that the authentication comprises a biometric authentication, in particular a face recognition and / or an iris recognition. In this case, the authentication and the determination of the number of faces can be performed on the basis of the same image data. Alternatively or additionally, other factors can of course also be used for the authentication, for example a password or a fingerprint.
[0029] In another variant of the method, the face recognition can be repeated periodically or randomly in parallel with the check of the number of faces. It can prove to be that an unauthorized user who appears in the camera field of view of the second terminal while an authorized user leaves the camera field of view obtains unrestricted access.
[0030] In the context of the present application, the method features related to the first terminal can for example be implemented as a computer program product which can be directly loadable into the internal memory of a digital computer and which comprises software code portions for performing the steps according to one or more of the described variants on the first terminal when the computer program is run on a computer.
[0031] In the context of the present application, the method features related to the second terminal can for example be implemented as a computer program product which can be directly loadable into the internal memory of a digital computer and which comprises software code portions for performing the steps according to one or more of the described variants on the second terminal when the computer program is run on a computer. BRIEF DESCRIPTION OF DRAWINGS
[0032] The application is explained below on the basis of particularly preferred exemplary embodiments and with reference to the drawings, to which, however, the application should not be restricted. In particular, in the drawings:
[0033] Figure 1 a data flow diagram of a private message from a sender to a recipient is schematically shown;
[0034] Figure 2 a sequence diagram of a method for access control of a private message from a first terminal user to a second terminal user is schematically shown;
[0035] Figure 3 A process illustrating access control on a second terminal is schematically shown;
[0036] Figure 4 A process illustrating an extended variant of the method according to Figure 3 is schematically shown;
[0037] Figure 5a A mobile terminal during blocked access is schematically shown;
[0038] Figure 5b A mobile terminal during unrestricted access is schematically shown;
[0039] Figure 5c A mobile terminal during restricted access is schematically shown;
[0040] Figure 6a A use case for a mobile terminal for unrestricted access is schematically shown; and
[0041] Figure 6b A use case for a mobile terminal for restricted access is schematically shown. DETAILED DESCRIPTION
[0042] Figure 1 A data flow of a private message 1 between a sender 2 and a recipient 3 is shown. The sender 2 is a user of a first terminal 4. The recipient 3 is a user of a second terminal 5. The private message 1 is transmitted from the first terminal 4 to the second terminal 5 in one or more encrypted data packets 6, e.g. over the internet. Before transmitting the private message 1, the present method provides a plurality of steps, based on the example procedure shown in Figure 2 These steps are explained in more detail based on the example procedure shown in
[0043] Figure 2The sequence diagram in Fig. 1 shows the steps of an exemplary execution of the method according to the present application in more detail. The sequence diagram involves the exchange of a private message 1 between a sender 2 and a recipient 3 using terminals 4, 5. First, the private message 1 is recorded 7 at the first terminal 4 together with the identification of the recipient 3. In this case, the sender 2 represents the intention to transmit the private message 1. In addition, the sender 2 can optionally determine the parameters required for the access control on the recipient 3 side. Usually, the sender 2 at the first terminal 4 also activates the corresponding access control. Therefore, the sender 2 will first authenticate himself to the first terminal 4 before starting the recording of the private message. The recipient 3 can be identified, for example, by selecting from a list of contacts or an address book. The parameters of the access control can be determined specifically for the private message 1 or for all private messages. These parameters can include, for example, a time limit for the access or storage on the recipient 3 side. In addition, this type of parameter can also be used to determine whether the recipient 3 can forward the private message 1 or whether the access control can fundamentally prevent such a forwarding at the second terminal 5. The private message 1 and the associated parameters of the access control can be stored in a secure, in particular encrypted, cache of the first terminal 4 until the method is completed.
[0044] During or after the recording 8 of the private message 1 and the identification of the recipient 3, at the earliest when the identification of at least one recipient has been recorded, the first terminal determines 9 the address of the second terminal 5 on the basis of the recorded identification of the recipient 3. For this purpose, for example, a query 10 is sent to an address database 11. The address database 11 can exist locally on the first terminal 4 or be provided by a connection service on a remote server. In response to the query 10, the address database 11 transmits the sought address 12 of the second terminal 5 to the first terminal 4.
[0045] With the now existing address 12, the first terminal 4 sends a query 13 about the access control status to the second terminal 5. The query 13 optionally also contains the parameters of the access control desired by the sender 2. As Figure 2As shown in the example, during the first query 13, access control on the second terminal 5 is temporarily inactive. The second terminal 5 sends a corresponding status message 14 to the first terminal 4. According to status message 14, access control on the second terminal 5 is temporarily inactive. The first terminal 4 then starts a timer 15 for a predetermined duration of 1 minute. After timer 15 expires, the first terminal 4 sends a new query 16 regarding the access control status to the second terminal 5. Simultaneously, the receiver 3 has activated access control 17 on the second terminal 5. As a second status message 19 sent from the second terminal 5 to the first terminal 4 in response to the second query 16, it is thus proven that access control 17 on the second terminal 5 is active. If the sender 2 has defined the access control parameters, the second terminal 5 also checks the implementation of these parameters and, if appropriate, confirms or rejects each parameter in status message 19.
[0046] Therefore, since the second query 16 is answered with status message 19, and according to status message 19, access control 17 on the second terminal 5 is active (and—if present—all parameters of the access control are implemented as requested), the first terminal 4 sends private message 1 to the second terminal 5. The second terminal 5 notifies the receiver 3 of the received private message 1 21. Thus, the receiver 3 can access 22 and read private message 1 on the second terminal 5 with active access control 17 and a corresponding protected environment. Once the second terminal 5 registers the access, it can send a read notification 23 to the first terminal 4. The read notification 23 may include the time of access 22. The first terminal 4 can then notify the sender 24 that private message 1 from the receiver 3 has been received. At this point, for example, private message 1 can be deleted by the first terminal 4. Alternatively, it can be specified that the sender 2 can also delete private message 1 on the second terminal 5 via remote control.
[0047] Figures 3 to 6b A detailed illustration shows an example of access control 17 on the second terminal 5:
[0048] Figure 3 A program illustrating a computer implementation method for access control of the second terminal 5 (see...) Figures 5a-5c Private data and other data are stored on Terminal 5. Access to private data can be restricted or unrestricted.
[0049] Based on unrestricted access 31 (see also) Figure 5b ), Figure 3 The method shown includes the following steps, illustrated as functional blocks. First, the image signal is recorded 32 using the camera of the second terminal 5 (see [link to documentation]). Figures 6a-6b). Then, face detection is performed 33 using the recorded image signal. After completion of the face detection, it is checked 34 whether the number of faces determined by the face detection in the recorded image signal is greater than one (see Figure 6b ), access is restricted 35 (see Figure 5c ). Otherwise 36, the next image signal is recorded in order to continuously monitor 37 the number of faces in the camera view during unrestricted access. Monitoring can be stopped as soon as access is restricted.
[0050] If the second terminal 5 has a screen for displaying private data and other data, the private data is completely hidden and only the other data is displayed in case of restricted access. In case of unrestricted access, a visual indication of the unrestricted access is displayed on the screen in the form of a colored (e.g. green) frame. If an event related to the private data occurs during restricted access, the event is displayed on the screen in a restricted form.
[0051] Figure 4 An extended variant of the access control 17 on the second terminal 5 is shown. In this case, face recognition 38 is additionally performed during the monitoring 37. This is followed by a check 39 of the authorization of the user (i.e. the recipient). If the user is not authorized, access is restricted 35. Figure 4 The illustration in
[0052] According to another variant of the access control 17 on the second terminal 5, biometric authentication of the user can be performed using face recognition and optionally iris recognition for obtaining unrestricted access. In this case, an image signal is recorded using the camera of the second terminal 5, face detection is performed using the recorded image signal and the number of faces in the recorded image signal is determined before unrestricted access is granted. Afterwards, unrestricted access is granted only if the number of faces is exactly one.
[0053] In Figures 5a-5c , different states of the second terminal 5 are illustrated, which can be employed in the context of the application of the present method. In this example, the second terminal 5 is a smartphone with a screen 41. In Figure 5aIn the middle, the second terminal 5 is illustrated with access blocked. On the screen 41 a general symbol is displayed which indicates that access is blocked and makes this access block identifiable. In this state, access to the data saved on the second terminal 5 is generally not allowed; in particular, the personal data of the user of the second terminal 5 are not displayed. If necessary, only technical data (e.g. time, signal, network information, etc.) can be displayed. If an authorized user authenticates himself, e.g. by proving his identity, and is successfully authenticated, the second terminal 5 changes directly to the state of unrestricted access to all data saved on the second terminal 5 in the usual way. This state is illustrated in Figure 5b In this state, the messages from the four contacts, i.e. the first message 42 from the contact "Anthony", the second message 43 from the contact "Beatrice", the third message 44 from the contact "Chris" and the fourth message 45 from the contact "David", are displayed on the screen 41 of the second terminal 5. The contact "Chris" is marked as a private contact. The third message 44 is therefore displayed with the visual indication 46 "private"; because of the indication 46, the user of the second terminal 5 can identify the authorized unrestricted access.
[0054] In the context of the active execution of the access control 17 on the second terminal 5, as soon as more than one face is identified in the image signal of the camera, the second terminal 5 changes to the restricted access state. This state is illustrated in Figure 5c In this state, the first message 42, the second message 43 and the fourth message 45 are displayed. The third message 44 from the contact "Chris" marked as private is therefore also marked as private and thus belongs to the private data. The private messages transmitted according to the method are only transmitted to the second terminal 5 under the condition that the access control 17 is activated and the private message is in any case considered private and thus belongs to the private data. In Figure 5c In the illustrated restricted access, no indication of the content or the existence of the private third message 44 is displayed. An observer who observes the screen 41 together with the user therefore does not discover the existence of the third message 44. After the visual indication 46 is also hidden, the observer cannot identify the current restricted access either.
[0055] Figure 6a and Figure 6b use cases corresponding to the states according to Figure 5b and Figure 5c are shown. Figure 6aA first use case is shown in which the authorized user 47, i.e. user 3, uses the second terminal 5. The second terminal 5 has been unlocked and is in an unrestricted access state to private data 48 and other data 49. The front camera 50 (arranged on the same side of the screen 41) of the second terminal 5 repeatedly records images and detects the number of faces in the recorded images (see Figure 3 ). In this first use case, only the authorized user 47 is located in the field of view of the front camera 50, so only one face is detected during each check, keeping the unrestricted access.
[0056] Figure 6b A second use case is shown. In this case, the observer 51 walks to the side of the authorized user 47 and enters the field of view of the front camera 50. The check immediately recognizes that the number of recognized faces is greater than one and switches the second terminal 5 to a restricted access state (see Figure 5c ). Only the other data 49 is displayed on the screen. All private data 48 is hidden from the display, so the presence and content of the private data 48 is hidden from the observer 51.
Claims
1. A computer-implemented method for access control of private messages from a second terminal user to a first terminal user, the method comprising the following steps: - Record the private messages and recipients on the first terminal; - Determine the address of the second terminal based on the recorded receiver; - Send a query about the access control status from the first terminal to the second terminal; - Private messages are sent from the first terminal to the second terminal only when the second terminal answers the query using a status message and activates the access control at the second terminal based on the status message.
2. The method according to claim 1, characterized in that, If, according to the status message, the access control on the second terminal is permanently inactive, the first terminal outputs an error message and deletes the private message.
3. The method according to claim 1, characterized in that, If, according to the status message, the access control is temporarily not activated at the second terminal, the first terminal starts a timer for a predefined duration, and after the timer expires, the first terminal sends a new query about the access control status to the second terminal.
4. The method according to claim 1, wherein, When the access control is activated at the second terminal, access to private messages received from the first terminal is either restricted or unrestricted on the second terminal. In the case of unrestricted access, the following steps are included: - Use the camera of the second terminal to record image signals; - Perform face detection using the recorded image signals; - The number of faces determined in the recorded image signal is continuously monitored by the face detection, wherein access is restricted if the number of faces is greater than 1.
5. The method according to claim 4, wherein, The second terminal has a screen for displaying the private messages, which are completely hidden under restricted access conditions.
6. The method according to claim 5, characterized in that, When there is no restricted access, display a visual indication of unrestricted access.
7. The method according to claim 5, characterized in that, During restricted access, events related to private messages are displayed on the screen in a restricted manner.
8. The method according to claim 4, characterized in that, When access control is activated, user authentication is performed to obtain unrestricted access. Before granting unrestricted access, image signals are recorded using the camera of the second terminal. Face detection is performed using the recorded image signals, and the number of faces in the recorded image signals is determined. Approval occurs only when the number of faces is exactly 1.
9. The method according to claim 8, characterized in that, The authentication includes biometric authentication.
10. The method according to claim 9, characterized in that, The biometric authentication is facial recognition and / or iris recognition.
11. A computer program product for access control of private messages of a first terminal user, the computer program product being directly loaded into the internal memory of a digital computer, and the computer program product including a software code portion that, when the computer program is run on the computer, uses the software code portion to perform the steps according to any one of claims 1 to 10 on the first terminal.
12. A computer program product for access control of private messages of a second terminal user, the computer program product being directly loaded into the internal memory of a digital computer, and the computer program product including a software code portion that, when the computer program is run on the computer, uses the software code portion to perform the steps according to any one of claims 1 to 10 on the second terminal.
Citation Information
Patent Citations
Display device, control method thereof, electronic device including display device, display device control program, and recording medium on which display device control program is recorded
EP1703431A2
Methods and systems for increasing the security of electronic messages
US20130074195A1
Conditional Delivery of Content Over a Communication Network Including Social Sharing and Video Conference Applications Using Facial Recognition
US20180083978A1
Computer-implemented method and computer program product for the access control of a terminal
WO2018229246A1
Displaying private information on personal devices
CN106575344A