Collaborative office security system to prevent information leakage
By designing sensitive information identification and encryption protection modules in the collaborative office system, calculating file sensitivity index and encrypting, the information leakage problem caused by manual operation errors is solved, and the security and efficiency of collaborative office are improved.
Patent Information
- Application Number
- CN202411586325.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-08
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-11-08
AI Technical Summary
Due to manual operation errors in existing collaborative office systems, important or sensitive information files are not encrypted, causing the risk of information leakage.
A collaborative office security system that prevents information leakage is designed, including collaborative tool selection module, real-time collaboration module, sensitive information identification module and file management module. By calculating the file's sensitivity index, sensitive files greater than the threshold are identified and encrypted and protected, and encrypted files are managed to ensure information security.
It effectively avoids information leakage caused by manual errors, improves the efficiency and security of collaborative office work, and ensures that sensitive information is properly protected.
Smart Images

Figure CN119089507B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of collaborative office, and more specifically to a collaborative office security system for preventing information leakage. Background Art
[0002] A collaborative office system is a platform or tool that helps teams work together, share information, manage projects and improve work efficiency through the Internet and information technology support. It provides online document editing, file storage and sharing functions.
[0003] The existing collaborative office system requires administrators to manually encrypt important files, but this method may result in failure to encrypt important files or files containing sensitive information due to human errors, thereby causing information leakage.
[0004] In view of the above problems, the present invention proposes a solution. Summary of the invention
[0005] In order to overcome the above-mentioned defects of the prior art, the present invention provides a collaborative office security system for preventing information leakage to solve the problems existing in the above-mentioned background technology.
[0006] To achieve the above object, the present invention provides the following technical solutions:
[0007] The collaborative office security system for preventing information leakage includes a collaborative tool selection module, a real-time collaboration module, a sensitive information identification module, and a file management module. The modules are connected through signals. The steps of data processing between the modules are as follows:
[0008] The collaboration tool selection module is used to select collaboration tools based on the collaborative office project content and enterprise requirements so that team members can effectively share information, files and tasks;
[0009] The real-time collaboration module is used to conduct real-time collaboration using the collaboration tools selected by the collaboration tool selection module, ensuring that all team members can easily participate and contribute;
[0010] A sensitive information identification module is used to obtain a sensitivity index of a file by calculation, identify sensitive files with a sensitivity index greater than a threshold value, and encrypt and protect them;
[0011] The file management module is used to manage encrypted files by calculating the security risk index of encrypted files, ensuring that files and information are properly managed so that team members can access and update files.
[0012] Preferably, the step of selecting the collaborative tool is:
[0013] Define the functions and goals required by the organization or team, clarify what collaborative functions are needed, and understand the team's size, geographical distribution, and organizational structure;
[0014] Consider the working habits and preferences of team members. Some teams may be more comfortable with real-time communication and instant collaboration, while others may prefer to emphasize task and project management.
[0015] Evaluate the tool’s integration capabilities to ensure it can be integrated with other commonly used tools and applications, such as email, calendar, cloud storage, etc.
[0016] Ensure tools have adequate safety measures and check that they comply with applicable regulations and compliance standards;
[0017] Understand the reputation and security record of the collaboration tool vendor, and choose those that are certified and have a good reputation for customer service;
[0018] Determine the budget available to purchase and maintain collaboration tools, taking into account the initial purchase cost and the total cost of long-term use;
[0019] Regularly evaluate its effectiveness and adjust based on feedback to ensure the tool still meets the needs of your team and update or replace it as necessary.
[0020] Preferably, the steps for calculating the sensitivity index of the file are:
[0021] The administrator determines the keywords and phrases related to sensitive information based on the content of the collaborative office, and organizes the determined sensitive keywords into a list;
[0022] Use fuzzy matching algorithm to filter out sensitive words in the file. By traversing the text content of the file, each text segment is compared with the sensitive keyword list, and the number of times the keyword list is matched is counted and recorded as the sensitive word coefficient.
[0023] Extract the identity information of the file creator and modifier, filter out high-privacy members, and calculate the member coefficient by the number of high-privacy members and the total number of parameter file members;
[0024] Extract the number of file modifications and filter out the number of times the file was modified during non-working hours. Calculate the modification coefficient by the total number of file modifications and the number of times the file was modified during non-working hours.
[0025] The sensitivity index is calculated by the sensitive word coefficient, member coefficient and modification coefficient.
[0026] Preferably, the step of using a fuzzy matching algorithm to filter out sensitive words in a file is:
[0027] Create a library of sensitive words using keywords or phrases related to sensitive information determined by the administrator;
[0028] Segment the text to be tested to obtain a list of words or phrases, which can be separated by spaces, punctuation marks, etc.
[0029] Use the cosine similarity algorithm to traverse each sensitive word in the sensitive word library and calculate the similarity between the phrase in the text and the sensitive word in the sensitive word library;
[0030] A similarity threshold is set. If the similarity is greater than the similarity threshold, the word is determined to be a sensitive word.
[0031] Preferably, the step of calculating the similarity between the phrases in the text and the sensitive words in the sensitive word library is:
[0032] Use word embedding models to represent two words as vectors;
[0033] Perform dot product operation on two word vectors;
[0034] The cosine similarity between word A and word B is calculated based on the dot product and the vector modulus, and the cosine similarity is recorded as the degree of similarity.
[0035] Preferably, the security risk index is calculated by taking a weighted sum of the total number of file modifications and a sensitivity coefficient.
[0036] Preferably, the step of managing the encrypted files is to set an initial security risk index threshold, compare the sensitivity index with the preset sensitivity index threshold, and if the sensitivity index is greater than the preset sensitivity index threshold, adjust the initial security risk index threshold according to the sensitivity coefficient to obtain the final security risk index threshold, and then manage the encrypted files according to the security risk index and the final security risk index threshold.
[0037] Technical effects and advantages of the present invention:
[0038] Collaboration tools are selected based on the project content of collaborative office and enterprise requirements. Real-time collaboration is carried out using the collaborative tools selected by the collaborative tool selection module. The sensitivity index of the file is calculated, and sensitive files greater than the threshold are identified through the sensitivity index of the file. These files are encrypted for protection. Encrypted files are managed based on the calculated security risk index of the encrypted files, which effectively avoids information leakage caused by human errors and improves the efficiency and security of collaborative office. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 The figure is a flow chart of sensitivity index calculation of the present invention. DETAILED DESCRIPTION
[0040] The technical solution of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the present invention. In addition, the forms of the various structures recorded in the following embodiments are merely illustrative, and the collaborative office security system for preventing information leakage involved in the present invention is not limited to the various structures recorded in the following embodiments. All other implementations obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0041] The present invention provides a collaborative office security system for preventing information leakage, including a collaborative tool selection module, a real-time collaboration module, a sensitive information identification module and a file management module. The modules are connected by signals, and the steps of data processing between the modules are as follows:
[0042] The collaboration tool selection module is used to select collaboration tools based on the collaborative office project content and enterprise requirements so that team members can effectively share information, files and tasks;
[0043] The real-time collaboration module is used to conduct real-time collaboration using the collaboration tools selected by the collaboration tool selection module, ensuring that all team members can easily participate and contribute;
[0044] A sensitive information identification module is used to obtain a sensitivity index of a file by calculation, identify sensitive files with a sensitivity index greater than a threshold value, and encrypt and protect them;
[0045] The file management module is used to manage encrypted files by calculating the security risk index of encrypted files, ensuring that files and information are properly managed so that team members can access and update files;
[0046] In this embodiment, it should be specifically explained that the collaborative tool is a type of software and platform used to promote team collaboration, information sharing, real-time communication, and collaborative task completion. These tools are designed to improve the communication efficiency between team members, simplify collaborative workflows, and enable teams to work together better. Collaborative tools can provide instant messaging and real-time chat functions, allowing team members to quickly exchange information, solve problems, and have real-time discussions, allowing team members to share, upload, download, and collaboratively edit files and documents to ensure that the team has access to the latest version of information, integrating calendar and time management tools so that team members can share schedules, schedule meetings, and collaboratively plan working time, and have security functions to ensure that sensitive information is protected, while providing flexible permission control to limit access to specific information.
[0047] In this embodiment, it should be specifically explained that the steps of selecting the collaborative tool are:
[0048] Define the functions and goals required by the organization or team, and clarify what collaborative functions are needed, such as real-time communication, file sharing, project management, etc., which will help determine the key features of the selected tool;
[0049] Understand the size, geographic distribution, and organizational structure of your team. Different tools may be suitable for teams of different sizes and types. If your team is working remotely, you may need to place more emphasis on remote collaboration features.
[0050] Consider the working habits and preferences of team members. Some teams may be more comfortable with real-time communication and instant collaboration, while others may prefer to emphasize task and project management.
[0051] Evaluate the tool’s integration capabilities to ensure it can be integrated with other commonly used tools and applications, such as email, calendar, cloud storage, etc., to help improve overall productivity;
[0052] Ensure that the tool has adequate security measures in place to protect sensitive information and check that the tool complies with applicable regulations and compliance standards;
[0053] Understand the reputation and security record of the collaboration tool vendor, and choose those that are certified and have a good reputation for customer service;
[0054] Determine the budget available to purchase and maintain the collaboration tool, taking into account not only the initial purchase cost but also the total cost of long-term use;
[0055] Once a collaboration tool is in use, regularly evaluate its effectiveness and make adjustments based on feedback to ensure that the tool still meets the needs of the team and to update or replace it if necessary.
[0056] Choosing the right collaborative tool can improve team efficiency, promote communication, simplify workflow, and improve overall work quality. The right collaborative tool can help team members work together more efficiently. Through functions such as real-time communication, file sharing, and collaborative editing, it reduces the delay in information transmission and speeds up the work process. Choosing a collaborative tool with strong integration can unify the team's work environment, which means that the team can access files, tasks, address books, etc. on one platform without frequently switching tools. Collaborative tools usually include task and project management functions, which help team members track the progress of tasks, assign work, set deadlines, etc., improving the manageability and visualization of the project. Tools with version control functions allow teams to track the modification history of files and projects, which is very important for avoiding misoperations, recovering data, and tracking changes.
[0057] In this embodiment, it should be specifically explained that the specific steps of using the collaborative tool to perform real-time collaboration are:
[0058] Create teams, projects or workspaces in collaborative tools and add relevant team members to the corresponding work areas;
[0059] Configure team member permissions and roles to ensure that each member can only access and edit the information they need;
[0060] Set up real-time communication channels in collaborative tools, such as chat rooms or channels, to facilitate real-time communication such as discussions, questions, and sharing of ideas;
[0061] Create folders or document libraries in collaborative tools to share files and documents needed by the team, and ensure that these files can be edited in real time to facilitate collaborative work among multiple people;
[0062] Use the real-time collaborative editing function provided by collaborative tools to allow multiple people to edit documents, spreadsheets or presentations at the same time, and ensure that the tools have version control to track modification history;
[0063] Use the task management function of collaborative tools to assign tasks to team members and set deadlines to help track task progress;
[0064] Configure reminder and notification functions of collaboration tools to ensure that team members receive important messages and task updates in a timely manner;
[0065] Recording important decisions, discussions, and meeting minutes in collaborative tools helps team members review and understand past work.
[0066] Configuring the permissions and roles of team members is a key step in ensuring the effective operation of real-time collaboration in collaborative tools. It can ensure that each member can only access and edit the information they need while protecting sensitive data. In collaborative tools, different tools may have different permissions and role models. Determine the role of each member based on the responsibilities and needs of team members, configure the access level of team members, and practice the principle of least privilege, that is, give users the minimum permissions required to complete their work, which helps reduce potential risks and data leaks. For example, administrators may have the right to create and delete teams and manage member permissions, while general members may only be able to edit specific projects or documents, and there can be multiple administrators.
[0067] In this embodiment, it should be specifically explained that Figure 1 As shown, the steps for calculating the sensitivity index of the file are:
[0068] Based on the content of the collaborative work, the administrator determines keywords and phrases related to sensitive information, which may include social security numbers, credit card numbers, passwords, confidential project names, proprietary technical terms, etc.;
[0069] Organize the determined sensitive keywords into a list, which will be used as input for the matching algorithm;
[0070] Use fuzzy matching algorithm to filter out sensitive words in the file. By traversing the text content of the file, each text segment is compared with the sensitive keyword list, and the number of times the keyword list is matched is counted and recorded as the sensitive word coefficient.
[0071] The fuzzy matching algorithm is an algorithm for finding items similar to a target pattern in a text or string. These algorithms take into account the differences between the input and the target, can tolerate spelling errors, homophones, vocabulary variations, etc., and find the closest match as possible.
[0072] The steps of using the fuzzy matching algorithm to filter out sensitive words in the file are as follows:
[0073] Create a library of sensitive words using keywords or phrases related to sensitive information determined by the administrator;
[0074] Segment the text to be tested to obtain a list of words or phrases, which can be separated by spaces, punctuation marks, etc.
[0075] Use the cosine similarity algorithm to traverse each sensitive word in the sensitive word library and calculate the similarity between the phrase in the text and the sensitive word in the sensitive word library. The steps are as follows:
[0076] Use the word embedding model to represent two words as vectors. For example, convert word A and word B into word vectors: ,The word embedding model is a technique for mapping words to a continuous vector space, which can capture the semantic relationship between words;
[0077] Perform a dot product operation on the two word vectors. The dot product is calculated by multiplying the elements at corresponding positions of the two vectors and then adding all the products. The calculation formula is: , for example, do a dot product operation on word A and word B ;
[0078] Calculate the modulus of word A and B vectors respectively, and the calculation formula is , ;
[0079] The cosine similarity between word A and word B is calculated based on the dot product and vector modulus. The calculation formula is: , where CS AB Expressed as the cosine similarity between word A and word B, DP AB Represented as the dot product of word A and word B, M A 、M B Represented as the modulus of word A and B vectors.
[0080] The cosine similarity is a measurement method for measuring the similarity of two vector directions, and is usually used in the calculation of text similarity. Two words are regarded as two vectors, and each dimension of the vector corresponds to a word in the vocabulary. The closer the cosine similarity is to 1, the more similar the two vectors are.
[0081] A similarity threshold is set. If the similarity is greater than the similarity threshold, the word is determined to be a sensitive word.
[0082] The identity information of the file creator and editor is extracted to screen out high privacy members. The member coefficient is calculated by the number of high privacy members and the total number of parameter file members. The high privacy member is the administrator, and its calculation formula is: , where MB represents the membership coefficient, M 高 Expressed as the number of high privacy members, M 总 Expressed as the total number of parameter file members;
[0083] Extract the number of file modifications and filter out the number of times the file was modified during non-working hours. Calculate the modification coefficient by the total number of file modifications and the number of times the file was modified during non-working hours. The calculation formula is: , where RI is the modification coefficient, R 非 It is expressed as the number of times the modification time is during non-working hours, R 总 Represented as the total number of modifications to the file;
[0084] The sensitivity index is calculated by the sensitive word coefficient, member coefficient and modification coefficient. The calculation formula is: , where ST represents the sensitivity index, NUM CS It is expressed as the sensitive word coefficient. The higher the sensitive word coefficient, the more sensitive words there are in the file, the more the file needs to be encrypted, and the higher the sensitivity coefficient will be. MB is expressed as the member coefficient. The higher the member coefficient, the more highly sensitive members there are in the modified file, the more the file needs to be encrypted, and the higher the sensitivity coefficient will be. RI is expressed as the modification coefficient. The higher the modification coefficient, the more times the file is modified during non-working hours, the more important the file is, and the higher the sensitivity coefficient will be. a1, a2, and a3 are expressed as the sensitive word coefficient NUM CS , member coefficient MB and weight coefficient of modification coefficient RI. This embodiment does not perform specific calculations on the specific values of a1, a2 and a3.
[0085] The sensitivity index is compared with the preset threshold. If the sensitivity index is less than the preset threshold, the file is determined to be not a sensitive file and the file is not encrypted. If the sensitivity index is greater than the preset threshold, the file is determined to be a sensitive file and the file is encrypted.
[0086] For encrypted files, the access personnel must pass the administrator's identification and authentication, and then the system will randomly generate an access password, which will be distributed by the administrator to the access personnel who have passed the identification and authentication.
[0087] Encrypted files can effectively protect data from unauthorized access. Even if the file is stolen or leaked, unauthorized personnel cannot decrypt and access the file content. Managing encrypted files can effectively prevent data leakage, especially in the case of storage device loss, cloud service provider vulnerabilities, or risks during data transmission. Managing encrypted files ensures security during file transmission. Even when transmitting in an insecure network environment, encryption can effectively prevent man-in-the-middle attacks and eavesdropping. Managing encrypted files also involves encrypting backup files. This ensures that backup data remains confidential in the event of data corruption or catastrophic events.
[0088] In this embodiment, it should be specifically explained that the security risk index is obtained by analyzing the sensitivity index. If the file sensitivity index is too large, it means that the file is more important and the security risk caused by untimely backup may increase. The calculation formula is: , where SH is the safety hazard index, R 总 It is expressed as the total number of file modifications. The greater the total number of file modifications, the greater the risk of file leakage and the higher the security risk. SP is expressed as the file sensitivity coefficient, which is the ratio of the sensitivity index to the preset threshold. Its calculation formula is: , where ST is the sensitivity index, ST 0 It is represented as the preset threshold. The higher the file sensitivity coefficient, the higher the sensitivity index, the more important the file is, and the higher the security risk is. b1 and b2 represent the total number of file modifications R 总 The weight coefficient of the file sensitivity coefficient SP, and this embodiment does not specifically calculate the specific values of b1 and b2.
[0089] Set an initial safety hazard index threshold SH 0 The security risk index threshold varies with the sensitivity index. The larger the sensitivity index, the more sensitive information the file contains. The smaller the sensitivity index, the less sensitive information the file contains. To ensure the security of the file, when the sensitivity index is greater than the sensitivity index threshold, the security risk index threshold is lowered. The final security risk index threshold is calculated by the file sensitivity coefficient, and its calculation formula is: ,in Expressed as the final safety hazard index threshold, Expressed as the initial safety hazard index threshold, Expressed as file sensitivity coefficient.
[0090] The security risk index is compared with the final security risk index threshold. If the security risk index is less than the final security risk index threshold, it is determined that the current file does not have a security risk and the file will not be backed up. If the security risk index is greater than the final security risk index threshold, it is determined that the current file has a security risk, the administrator will be notified and the file will be backed up.
[0091] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
[0092] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A collaborative office security system to prevent information leakage, characterized in that: It includes collaborative tool selection module, real-time collaboration module, sensitive information identification module and file management module. The modules are connected through signals. The steps of data processing between modules are as follows: The collaboration tool selection module is used to select collaboration tools based on the collaborative office project content and enterprise requirements so that team members can effectively share information, files and tasks; The real-time collaboration module is used to conduct real-time collaboration using the collaboration tools selected by the collaboration tool selection module, ensuring that all team members can easily participate and contribute; A sensitive information identification module is used to obtain a sensitivity index of a file by calculation, identify sensitive files with a sensitivity index greater than a threshold value, and encrypt and protect them; The file management module is used to manage encrypted files by calculating the security risk index of encrypted files, ensuring that files and information are properly managed so that team members can access and update files; The steps for calculating the sensitivity index of the file are as follows: The administrator determines the keywords and phrases related to sensitive information based on the content of the collaborative office, and organizes the determined sensitive keywords into a list; Use fuzzy matching algorithm to filter out sensitive words in the file. By traversing the text content of the file, each text segment is compared with the sensitive keyword list, and the number of times the keyword list is matched is counted and recorded as the sensitive word coefficient. Extract the identity information of the file creator and modifier, filter out high-privacy members, and calculate the member coefficient by the number of high-privacy members and the total number of parameter file members; Extract the number of file modifications and filter out the number of times the file was modified during non-working hours. Calculate the modification coefficient by the total number of file modifications and the number of times the file was modified during non-working hours. The sensitivity index is calculated by using the sensitive word coefficient, member coefficient and modification coefficient; The security risk index is calculated by weighted summing the total number of file modifications and the sensitivity coefficient.
2. The collaborative office security system for preventing information leakage according to claim 1 is characterized in that: The steps for selecting the collaborative tool are: Define the functions and goals required by the organization or team, clarify what collaborative functions are needed, and understand the team's size, geographical distribution, and organizational structure; Consider the working habits and preferences of team members. Some teams may be more comfortable with real-time communication and instant collaboration, while others may prefer to emphasize task and project management. Evaluate the tool's integration capabilities to ensure it can be integrated with other commonly used tools and applications; Ensure tools have adequate safety measures and check that they comply with applicable regulations and compliance standards; Understand the reputation and security record of the collaboration tool vendor, and choose those that are certified and have a good reputation for customer service; Determine the budget available to purchase and maintain collaboration tools, taking into account the initial purchase cost and the total cost of long-term use; Regularly evaluate its effectiveness and adjust based on feedback to ensure the tool still meets the needs of your team and update or replace it as necessary.
3. The collaborative office security system for preventing information leakage according to claim 1 is characterized in that: The steps of using the fuzzy matching algorithm to filter out sensitive words in the file are as follows: Create a library of sensitive words using keywords or phrases related to sensitive information determined by the administrator; Segment the text to be tested to obtain a list of words or phrases separated by spaces or punctuation marks; Use the cosine similarity algorithm to traverse each sensitive word in the sensitive word library and calculate the similarity between the phrase in the text and the sensitive word in the sensitive word library; A similarity threshold is set. If the similarity of phrases in the text is greater than the similarity threshold, the phrase in the text is determined to be a sensitive word.
4. The collaborative office security system for preventing information leakage according to claim 3 is characterized in that: The steps of calculating the similarity between the phrases in the text and the sensitive words in the sensitive word library are as follows: Use word embedding models to represent two words as vectors; Perform dot product operation on two word vectors; The cosine similarity between word A and word B is calculated based on the dot product and the vector modulus, and the cosine similarity is recorded as the degree of similarity.
5. The collaborative office security system for preventing information leakage according to claim 1 is characterized in that: The steps for managing encrypted files are: setting an initial security risk index threshold, comparing the sensitivity index with the preset sensitivity index threshold, if the sensitivity index is greater than the preset sensitivity index threshold, adjusting the initial security risk index threshold according to the sensitivity coefficient to obtain the final security risk index threshold, and then managing the encrypted files according to the security risk index and the final security risk index threshold.
Citation Information
Patent Citations
Railway construction service digital collaborative management method and collaborative management system
CN117557239A
Collaborative office intelligent management platform and method
CN118211939A
Cited By
Safety management method and system for data management and storage medium
CN120896742A
Security management method, system and storage medium for data governance
CN120896742B