Image processing system, information processing device, control method for information processing device, and program
The image processing system addresses the challenge of concentrated confidential information in documents by detecting, categorizing, and masking such information within the system, ensuring effective and secure identification and display.
Patent Information
- Application Number
- JP2023194405
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-15
- Publication Date
- 2025-05-27
AI Technical Summary
Existing methods for detecting confidential information in documents struggle when confidential information is concentrated within a single page, making it difficult to determine the correspondence between the outlined confidential information and masked character strings.
An image processing system that includes a detection unit for identifying confidential character strings, a determination unit for categorizing these strings, a mask processing unit for masking the strings in the document image, and a display control unit that adds category information to the masked areas, allowing for easier identification of confidential information without revealing its content.
The system enables effective identification and masking of confidential information, even when it is densely concentrated, ensuring that the outline of each piece of confidential information can be easily grasped without leaking the information itself.
Smart Images

Figure 2025080968000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a technique for masking images.
Background Art
[0002] There is a monitoring system that detects whether confidential information is included in document data when printing the document data and monitors whether the confidential information is leaked. In the monitoring system, in order to avoid detection omissions as much as possible, there is a possibility that document data that does not contain confidential information may be misdetected as document data that contains confidential information. Therefore, ultimately, it is necessary to visually determine whether the printed document data corresponds to a leakage of confidential information. For example, considering that the security department determines a huge amount of document data printed within the company, it is assumed that the person in charge of visual inspection does not necessarily have the right to view the confidential information described in the document data. In this case, there is a possibility that a leakage of confidential information may occur in the work of determining the leakage of confidential information. If the character area of the confidential information is masked to prevent the leakage of the confidential information, it becomes difficult to determine whether the content described in the document data corresponds to the leakage of the confidential information at all when visually inspecting the document data. In order to avoid such a situation, Patent Document 1 discloses a technique of inserting a message notifying an outline of the confidential information on the page before the page on which a character string corresponding to the confidential information (hereinafter referred to as "confidential character string") is masked.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the method of Patent Document 1, an outline of confidential information is notified in page units, but there may be cases where confidential character strings are grouped together within one page. In this case, the correspondence between the outline of the confidential information for the entire page and each masked character string becomes unclear, making it difficult to determine whether it is confidential information.
[0005] The present disclosure has been made in view of the above problems, and aims to easily grasp the outline of each piece of confidential information even when confidential information is concentrated in a document image.
Means for Solving the Problems
[0006] The image processing system according to the present disclosure includes a detection unit that detects a confidential character string corresponding to confidential information from among the recognized character strings obtained by performing OCR processing on a document image, a determination unit that determines the category of the detected confidential character string, a mask processing unit that masks the confidential character string included in the document image based on the recognized character string, and a display control unit that adds information indicating the category of the confidential character string to the target area of the mask and displays the masked document image on a display unit.
Effects of the Invention
[0007] According to the technology of the present disclosure, even when confidential information is concentrated in a document image, it is possible to easily grasp the outline of each piece of confidential information without leaking the confidential information.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Mode for Carrying Out the Invention
[0009] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. Note that the following embodiments do not limit the present disclosure, and not all combinations of features described in the embodiments are essential for the solution means of the present disclosure. For the same configuration, the same reference numerals will be used for explanation. Also, each step (step) in the flowchart is indicated by a symbol starting with "S".
[0010] [First Embodiment] [Overall Configuration] FIG. 1 is a diagram showing an example of the configuration of an image log display system in the present embodiment. The image log display system 100 (image processing system) includes an image forming apparatus 110, an image processing server 120, a user terminal 130, a monitor terminal 131, an administrator terminal 132, and a storage server 140. These devices and servers are interconnected by a network 150 and can communicate with each other.
[0011] The image forming apparatus 110 of this embodiment can request to transmit the document image scanned via the image processing server 120 to the storage server 140 or the like. Further, in this embodiment, the image forming apparatus 110 will be described by taking a multi-functional peripheral (MFP) having a scanning function, a printing function, a copying function, a FAX function, etc. as an example, but the present invention is not limited to the multi-functional peripheral. Any device having one or more of the above functions may be used. Here, the scanning function is a function of transmitting, to the outside, the image data generated by reading a document with a scanner provided in the image forming apparatus 110. The printing function is a function of printing the image data received from the user terminal 130 or the like. The copying function is a function of obtaining a copy of a document by printing the document image read by the scanner. The FAX function is a function of transmitting and receiving image data using a telephone line.
[0012] The image processing server 120 (image processing apparatus) is a server that performs a process of determining whether or not confidential information is described in a document image. The user terminal 130 has an application, a printer driver, etc., and is a terminal device to which a printing instruction of document data is input by the user. As an example, a general-purpose computer such as a personal computer, a portable terminal device such as a smartphone or a tablet terminal, etc. are applicable. When a printing instruction is input for the document data edited by the application in the user terminal 130, the document data is converted into print data such as PDL data interpretable by the printer 201 in the image forming apparatus 110 by the printer driver. Here, PDL stands for Page Description Language. The converted print data is transmitted to the printer 201 and printed. The print data includes, in addition to the document image, the following print attributes. The print attributes include the destination printer name, the print job name, the identification information (host name or IP address, etc.) of the user terminal 130 that is the print request source, the user name of the print request source, the timestamp, the print setting information (2in1, double-sided, enlargement, reduction, etc.), and the number of printed copies, etc.
[0013] The monitor terminal 131 and the administrator terminal 132 (information processing devices) are terminals operated by monitors and administrators for checking whether confidential information is described in a document image. The monitor terminal 131 and the administrator terminal 132 are applicable to general-purpose computers such as personal computers, and portable terminal devices such as smartphones and tablet terminals. The storage server 140 is a server that stores document images, processing results of the image processing server 120, and logs such as operation contents of the monitor terminal 131 and the administrator terminal 132.
[0014] Note that the image log display system of this embodiment is configured to include the image forming apparatus 110, the image processing server 120, the user terminal 130, the monitor terminal 131, the administrator terminal 132, and the storage server 140, but is not limited thereto. For example, the image forming apparatus 110 may also serve as the user terminal 130 or the image processing server 120. Further, the image processing server 120 may also serve as the storage server 140. The image processing server 120 or the storage server 140 may be arranged in a connection form on a server on a LAN instead of on the Internet. Further, the storage server 140 may be replaced with a mail server or the like, and the scanned image may be attached to and transmitted by mail. Further, a configuration in which there are a plurality of the image processing server 120, the user terminal 130, the monitor terminal 131, the administrator terminal 132, and the storage server 140 with respect to the image forming apparatus 110 may be acceptable.
[0015] FIG. 2 is a diagram showing an example of the hardware configuration of the image log display system according to this embodiment. The image forming apparatus 110 includes a printer 201, a scanner 202, an operation unit 203, a CPU 211, a RAM 212, an HDD 213, a network I / F 214, a printer I / F 215, a scanner I / F 216, an operation unit I / F 217, and an expansion I / F 218.
[0016] The CPU 211 can exchange data with the RAM 212, HDD 213, network I / F 214, printer I / F 215, scanner I / F 216, operation unit I / F 217, and expansion I / F 218. Also, the CPU 211 expands the instructions (computer programs) read from the HDD 213 into the RAM 212 and executes the instructions expanded in the RAM 212, thereby controlling the execution of each process described later. In the present embodiment, it is assumed that one CPU 211 executes each process shown in the flowchart below using one memory (RAM 212 or HDD 213), but it is not limited to this. For example, multiple CPUs, multiple RAMs, or HDDs may cooperate to execute each process.
[0017] The HDD 213 can store instructions executable by the CPU 211, setting values used in the image forming apparatus 110, data related to processes requested by the user, and the like. The RAM 212 is an area for temporarily storing the instructions read by the CPU 211 from the HDD 213. The RAM 212 can also store various types of data necessary for the execution of instructions. For example, in image processing, it is possible to perform processing by expanding the input image data into the RAM 212.
[0018] The network I / F 214 is an interface for performing network communication between the image forming apparatus 110 and the network. The network I / F 214 can transmit to the CPU 211 that data has been received, and can transmit the data on the RAM 212 to the network 150 according to an instruction from the CPU 211. The printer I / F 215 can transmit the image data to be printed to the printer 201 according to an instruction from the CPU 211, and can transmit the state of the printer received from the printer 201 to the CPU 211. The scanner I / F 216 transmits the image reading instruction instructed by the CPU 211 to the scanner 202, and transmits the image data received from the scanner 202 to the CPU 211. Also, the scanner I / F 216 can transmit the information on the state of the scanner received from the scanner 202 to the CPU 211.
[0019] The operation unit I / F 217 can transmit an instruction from the user to the CPU 211 via the operation unit 203 and display screen information for the user to operate on the operation unit 203. The expansion I / F 218 is an interface that enables an external device to be connected to the image forming apparatus 110. The expansion I / F 218 includes, for example, an interface in the USB (Universal Serial Bus) format. When an external storage device such as a USB memory is connected to the expansion I / F 218, the image forming apparatus 110 can read data stored in the external storage device and write data to the external storage device.
[0020] The printer 201 prints the image data received via the printer I / F 215 on a recording medium. The printer 201 can also transmit the status of its own device to the printer I / F 215. The scanner 202 can transmit a document image obtained by reading a document (sheet) placed on the scanner in accordance with an image reading instruction received via the scanner I / F 216 to the scanner I / F 216. The scanner 202 can also transmit the status of its own device to the scanner I / F 216. The operation unit 203 is an interface for giving various instructions to the image forming apparatus 110 based on the operations of the user. For example, the operation unit 203 includes a touch panel liquid crystal screen, displays an operation screen, and accepts operations from the user.
[0021] The image processing server 120 includes a CPU 221, a RAM 222, an HDD 223, and a network I / F 224. The CPU 221 can control the entire device and control the transfer of data among the RAM 222, the HDD 223, and the network I / F 224. Further, the CPU 221 expands and executes a control program (instructions) read from the HDD 223 in the RAM 222. The HDD 223 of the image processing server 120 is a large-capacity storage unit that stores document images, various programs, and data generated during image processing execution. In this embodiment, it is assumed that one CPU 221 executes each process shown in the flowchart below using one memory (RAM 222 or HDD 223), but it is not limited to this.
[0022] The user terminal 130 includes a CPU 231, a RAM 232, an HDD 233, a network I / F 234, an operation unit I / F 235, and an operation unit 236. The CPU 231 can control the entire device and control the transfer of data among the RAM 232, the HDD 233, the network I / F 234, the operation unit I / F 235, and the operation unit 236. Further, the CPU 231 expands and executes a control program (instructions) read from the HDD 233 in the RAM 232. The operation unit I / F 235 is an interface that transmits an instruction from the user input from the operation unit 236 to the CPU 231 and transmits information regarding the operation screen to be displayed to the operation unit 236 based on the display control by the CPU 231. In this embodiment, it is assumed that one CPU 231 executes each process shown in the flowchart below using one memory (RAM 232 or HDD 233), but it is not limited to this. The monitor terminal 131 and the administrator terminal 132 adopt the same configuration as the user terminal 130.
[0023] The storage server 140 includes a CPU 241, a RAM 242, an HDD 243, and a network I / F 244. The CPU 241 controls the entire device and is capable of controlling the transfer of data among the RAM 242, the HDD 243, and the network I / F 244. Also, the CPU 241 expands and executes a control program (instructions) read from the HDD 243 in the RAM 242. The HDD 243 of the storage server 140 can store the document images received from the image processing server 120. Note that in the present embodiment, it is assumed that one CPU 241 executes each process shown in the flowchart below using one memory (RAM 242 or HDD 243), but the present invention is not limited to this.
[0024] <Software Configuration of Image Log Display System> FIG. 3(a) is a diagram showing the software configuration of the image forming apparatus 110 according to the present embodiment. Each part constituting the software of the image forming apparatus 110 is stored in the HDD 213, transferred to the RAM 212, and executed by the CPU 211. In FIG. 3(a), the image printing unit 311 expands an image (document image) stored in the HDD 213 or an image received from another device on the network 150 via the network I / F 214 onto the RAM 212.
[0025] Then, the image printing unit 311 transfers the image data expanded in the RAM 212 to the printer 201 to execute image printing. The UI display unit 312 performs display of operation components such as buttons operated by the user and UI components for displaying information such as progress status. The input reception unit 313 receives an input to the UI components displayed by the UI display unit 312 and executes a process corresponding to the input. The image transmission unit 314 transmits an image (document image) and print attributes stored in the HDD 213 to another device on the network 150, for example, the image processing server 120 via the network I / F 214. That is, information such as the document image used for printing and print attributes is transmitted from the image transmission unit 314 to the image processing server 120.
[0026] FIG. 3(b) is a diagram showing the software configuration of the image processing server 120 according to the present embodiment. Each part constituting the software of the image processing server 120 is stored in the HDD 223, transferred to the RAM 222, and executed by the CPU 221. The application data generation unit 321 generates data that operates in the image log display application 350 of the monitor terminal 131 and the administrator terminal 132. In the present embodiment, the image log display application 350 is in the form of a web application. The web application is composed of page description data described in a web page description language such as HTML and script data described in a script language such as JavaScript (registered trademark). The page description data of the image log display application 350 includes the document image transmitted from the image transmission unit 314, the character recognition result detected by the confidential information detection module 330 for the document image, and the confidential information. Note that the page description data is not limited to HTML, and may be structured data such as XML or JSON that can be interpreted by the client side to operate the application.
[0027] When the leakage notification unit 322 detects confidential information in the confidential information detection module 330, it transmits notification information to a pre-set information processing terminal (the monitor terminal 131 in the present embodiment) by e-mail or the like. When the confidential information detection module 330 detects confidential information, or when it is determined whether or not confidential information has been leaked in the monitor terminal 131 and the administrator terminal 132 and the progress status is changed, the log generation unit 323 generates a log. The generated log includes, for example, a document image, the character recognition result and print attributes of the document image, the progress status, and the history of the date and time. Also, the format of the generated log may be a format that can be displayed by the image log display application 350 or a format that cannot be displayed. Here, the print attributes are acquired from the image transmission unit 314.
[0028] The log transmission unit 324 transmits the logs generated by the log generation unit 323 to the storage server 140, and the storage server 140 stores the logs. However, it is not necessary to transmit the logs every time, and they may be transmitted only when there is a transmission instruction. The keyword search unit 325 searches for any keyword from all the logs stored in the storage server 140 and obtains a list of logs that match the conditions.
[0029] The confidential information detection module 330 is a module that performs optical character recognition on the transmitted document image to obtain a character recognition result and detects confidential information from the character recognition result. The confidential information detection module 330 includes a character area detection unit 331, a character recognition execution unit 332, a confidential information detection unit 333, and a category determination unit 334.
[0030] The character area detection unit 331 is a unit that detects an area (character area) containing characters from a document image. In the present embodiment, a set of black pixel blocks and white pixel blocks in the document image is extracted, and the character area is detected by classifying them into characteristic areas such as characters, pictures, figures, tables, frames, and lines based on their shapes, sizes, and aggregation states. However, the method for detecting the character area is not particularly limited, and known techniques can be used. For example, a method of performing pixel-by-pixel labeling of whether it is a character pixel or not by applying semantic segmentation using deep learning and combining the surrounding character pixels into one area to detect the character area may also be used.
[0031] The character recognition execution unit 332 performs character recognition on the character region detected by the character region detection unit 331, and stores the result as character recognition information in the HDD 223. Here, the character recognition information includes the recognized character string and the position information of the recognized character string. The confidential information detection unit 333 detects confidential information from the character recognition information, and stores the result as detected confidential information in the HDD 223. In the present embodiment, keyword detection or entity extraction is performed on the character recognition information. Keyword detection searches for a character string that matches a character string previously set as confidential information from the recognized character string. Entity extraction extracts a character string classified into an entity (for example, a credit card number, etc.) previously set as confidential information from the recognized character string. Here, the method of entity extraction is not particularly limited, and known techniques can be used. For example, there are rule-based extraction such as extracting the character string closest to the key character string or machine learning using a large number of sentences and label data. The category determination unit 334 determines the category corresponding to the recognized character string from the categories set in advance in the case of keyword detection in the confidential information detection unit 333. In the case of entity extraction, it determines the category information corresponding to the extracted character string. The determined category information is stored in the HDD 223.
[0032] FIG. 3(c) is a diagram showing the software configuration of the user terminal 130 according to the present embodiment. Each part constituting the software of the user terminal 130 is stored in the HDD 233, transferred to the RAM 232, and executed by the CPU 231. The print image generation unit 341 receives a print command notified via the user interface, and generates print data according to various print settings. Here, the generated print data includes, in addition to the document image, a set of information such as user information, job name, etc., and output method information. The print image transmission unit 342 transmits the print data to the image forming apparatus 110 via the network 150.
[0033] FIG. 3(d) is a diagram showing the software configuration of the monitor terminal 131 and the administrator terminal 132 according to the present embodiment. The image log display application 350 of the monitor terminal 131 and the administrator terminal 132 is in the form of a web application. The image log display application 350 is a web application that is displayed on the operation unit 236 and enables confirmation of document images that may pose a risk of information leakage. The image log display application 350 transmits and receives data to and from the image processing server 120 via a web browser, and displays the information stored in the HDD 223 of the image processing server 120. Therefore, the image log display application 350 functions as a data transmission unit and a data reception unit.
[0034] In addition, the image log display application 350 includes each part 351 to 357 implemented by page description data and script data. The UI display part 351 displays operation parts such as buttons operated by the user and UI parts for displaying information such as progress status. The image display part 352 displays a document image. The mask processing part 353 performs mask processing on a specified area in the document image displayed by the image display part 352. The category display part 354 displays a category in the area masked by the mask processing part 353 (mask target area). Since the category display part 354 displays a category in the masked area and also controls the display of the image display part 352, the category display part 354 also functions as a display control part. The transfer part 355 changes the person in charge of making a leakage determination to the person at the transfer destination and sends notification information to the transfer destination by e-mail or the like. At this time, comments from the previous person in charge can also be attached. The user authentication part 356 displays a login screen for inputting authentication information when starting the image log display application 350, and requests the user for an ID and a password. When it is confirmed that the ID and the password match those registered by sending them to the image processing server 120, an access token is acquired. Thereafter, the image log display application 350 can access the information stored in the HDD 223 of the image processing server 120. Note that the user authentication method is generally performed using a publicly known method (such as Basic authentication, Digest authentication, authorization using OAuth). The input reception part 357 receives input to the UI parts displayed by the UI display part 351, the image display part 352, and the category display part 354, and executes processing corresponding to the input.
[0035] <Overall processing flow> FIG. 4 is a sequence diagram showing the processing flow from when printing is started on the user terminal 130 until the image log is saved. Here, the communication between each device will be mainly described. Note that in this embodiment, a flow triggered by the processing of the printing function will be described. The flow after a trigger occurs is the same for processing triggered by other functions.
[0036] In this embodiment, there are an employee who uses the user terminal 130, a monitor who uses the monitor terminal 131, and an administrator who uses the administrator terminal 132. It is assumed that the employee is prohibited from taking out information within the department outside the department to which he / she belongs. The monitor is assumed to belong to, for example, the security department and does not have special viewing privileges. The administrator is assumed to be, for example, a management position in each department and has the authority to view information within the department. It is assumed that there is only one security department within the company. If there is a possibility of information leakage, a detailed investigation is requested to be conducted by a management position with higher authority.
[0037] The user terminal 130 receives a print instruction from the user via an application and activates the printer driver. At that time, it reads the initial values of various settings such as print settings and image processing settings stored in the HDD 233. It displays the user interface screen of the printer driver on the operation unit 236 and receives a selection operation for changing various settings such as print settings and image processing settings from the user. Then, when the "Print" button is pressed on the user interface screen, the processing shown in the sequence of FIG. 4 is performed.
[0038] In S401, in the user terminal 130, the print image generation unit 341 generates the above-described print data according to various print settings, and the process proceeds to S402. In S402, the print image transmission unit 342 of the user terminal 130 transmits the print data generated in S401 to the image forming apparatus 110, and the process proceeds to S403.
[0039] In S403, the image printing unit 311 of the image forming apparatus 110 prints the print data using the printer 101 according to various print settings of the print job for which printing is instructed. When the print data is printed, the process proceeds to S404. Note that the user may execute the printing of the print data by selecting the print data waiting to be printed in the print job list displayed by the UI display unit 312. In S404, the image transmission unit 314 of the image forming apparatus 110 transmits the print data including the document image generated in S401 to the image processing server 120, and the process proceeds to S405.
[0040] In S405, the confidential information detection module 330 of the image processing server 120 performs confidential information detection on the print data including the document image received in S404, and the process proceeds to S406. Details of the confidential information detection will be described later with reference to FIG. 5. In S406, the CPU 221 of the image processing server 120 generates a log including the document image from the result output in S405 via the log generation unit 323, and the process proceeds to S407. In S407, the CPU 221 of the image processing server 120 transmits the log generated in S406 to the storage server 140 via the log transmission unit 324, and the storage server 140 stores the log. When the log is transmitted to the storage server 140, the process proceeds to S408.
[0041] In S408, the application data generation unit 321 of the image processing server 120 determines whether confidential information was detected in S405. If no confidential information was detected, the processing flow shown in FIG. 4 ends. If confidential information was detected, the process proceeds to S409. In S409, the application data generation unit 321 of the image processing server 120 generates data that operates on the image log display application 350 of the monitor terminal 131 and the administrator terminal 132 from the result output in S405. When the data is generated, the process proceeds to S410. In S410, the leakage notification unit 322 of the image processing server 120 transmits a notification stating that confidential information has been detected to the monitor terminal 131, and the process proceeds to S411.
[0042] In S411, the CPU 231 of the monitor terminal 131 receives an instruction from the user to execute an application, executes the image log display application 350, and the process proceeds to S412. Details of the application execution process will be described later. In S412, the CPU 231 of the monitor terminal 131 determines whether it has received a transfer instruction from the user via the input reception unit 357. A transfer instruction is issued when there is a suspicion of information leakage and a request is made to the administrator to conduct a detailed investigation. If a transfer instruction is received from the user, the process proceeds to S413. If a transfer instruction is not received from the user, the process proceeds to S415. In S413, the CPU 231 of the monitor terminal 131 transmits a notification stating that confidential information has been detected to the administrator terminal 132 via the transfer unit 355, and the process proceeds to S414.
[0043] In S414, the CPU 231 of the administrator terminal 132 receives an instruction from the user to execute an application, executes the image log display application 350, and the process proceeds to S415. Details of the application execution process will be described later. In S415, the CPU 221 of the image processing server 120 generates a log from the progress status that has changed in the monitor terminal 131 and the administrator terminal 132 via the log generation unit 323. When the log is generated, the process proceeds to S416. In S416, the CPU 221 of the image processing server 120 transmits the log generated in S415 to the storage server 140 via the log transmission unit 324, and the storage server 140 stores the log. When the log is transmitted to the storage server 140, the processing flow shown in FIG. 4 ends.
[0044] <Details of Confidential Information Detection (S405)> The process (confidential information detection process) performed by the confidential information detection module 330 executed in S405 of FIG. 4 will be described in detail. The confidential information detection process performs optical character recognition on the document image included in the print data transmitted from the image forming apparatus 110, and detects confidential information from the recognized character string. In the application execution process (S411, S414) executed after the confidential information detection process, in order to mask the character string indicating the confidential information and simultaneously display the category information, the confidential information detection process also determines the category information.
[0045] FIG. 5 is a flowchart showing the content of the process (confidential information detection process) executed by the confidential information detection module 330. The confidential information detection module 330 is realized by the CPU 221 of the image processing server 120 executing a predetermined program corresponding to the flowchart of FIG. 5. The flow of FIG. 5 starts when the document image is received in S404.
[0046] In S501, character region detection (block selection) is performed on the document image received in S404 by the character region detection unit 331. The character region detection process is a process of extracting character regions (character blocks) for each rectangle circumscribing a block of character strings from various objects such as characters, pictures, figures, tables, frames, and lines in the document image. Character recognition processing (OCR processing) is performed on the character regions detected in the character region detection process. The character region detection result is given in JSON format as a list of circumscribing rectangles representing individual character regions. The circumscribing rectangle of the character region is represented by four values: the x-axis coordinate and y-axis coordinate of the upper left vertex, and the height and width of the circumscribing rectangle. Note that the character region detection result is not limited to the above format. For example, the character region detection result may be in XML format. Also, the circumscribing rectangle of the character region may be represented by the coordinate values of the upper left vertex and the lower right vertex. When the character region is extracted from the document image, the process proceeds to S502.
[0047] In S502, character recognition processing (OCR processing) using an OCR engine is performed on the character region detected in S501. This processing is carried out by the character recognition execution unit 332. The character recognition result is associated with the document image and stored in the HDD 223. Note that the character recognition result includes the recognized character string and the position information of the recognized character string. When the character recognition result is stored in association with the document image, the process proceeds to S503.
[0048] In S503, confidential information is detected by the confidential information detection unit 333 from the character recognition result obtained in S502. When the confidential information detection process is completed, the process proceeds to S504. In the present embodiment, the confidential information detection process is performed by performing keyword detection or entity extraction on the character recognition result. The details of the keyword detection and entity extraction processes are described below.
[0049] The image processing server 120 has a database in which search keywords and categories corresponding to the search keywords are stored in association with each other. In keyword detection, a character string that matches the search keyword in the database is searched for from the character recognition result, and it is determined whether the search keyword is included in the character recognition result. Note that the administrator performs the setting of the database using the image log display application 350. The setting method will be described later.
[0050] Entity extraction involves, for example, storing existing addresses in a database if the entity is an address, and extracting all strings that match the addresses in the database from the character recognition results. If the entity is a credit card number, strings that match the logic for determining a high likelihood of being a credit card number are extracted from the character recognition results using that logic. The logic is that if the string consists of 16 digits and is an identification number with the first 6 digits present, the 16-digit string is subject to entity extraction. Specific examples of entities to be extracted include personal names, addresses, credit card numbers, company names, telephone numbers, and the like. The strings corresponding to the keyword-detected confidential information or entity-extracted confidential information are associated with the character recognition results recognized in S502 and stored in HDD223.
[0051] In S504, the category information of the keyword-detected confidential information or entity-extracted confidential information in S503 is determined by the category determination unit 334. In the case of keyword detection, the image processing server 120 has a database of search keywords and the categories corresponding to the search keywords. Therefore, for the string that hits with the search keyword, the category information corresponding to the search keyword is applied. In the case of entity extraction, the category information associated with the database corresponding to the extracted string or the category information corresponding to the determination logic as described above (e.g., credit card number) is applied to the extracted string. The obtained category information is associated with the corresponding confidential information and stored in HDD223. When the category information is determined, the processing flow shown in FIG. 5 ends.
[0052] The information obtained through the above series of processes is ultimately stored in the HDD 223 as the following information. This information includes the document image that is the target of confidential information detection, the character recognition result of the document image, the confidential character strings detected or extracted using the character recognition result, and the category information of the confidential character strings. Here, the document image, the character recognition result, the confidential character strings, and the category information of the confidential character strings are linked. Specifically, the detected or extracted confidential character strings, the position information of the confidential character strings, and the category information of the confidential character strings are linked as a list of confidential information. An example of the list of confidential information stored in the HDD 223 is shown in Table 1. The position information of the confidential character strings is indicated by the x-axis coordinate and y-axis coordinate of the upper left vertex of the circumscribed rectangle of the confidential character strings, and the height and width of the circumscribed rectangle, a total of four values. Also, the information shown in the list of confidential information is used for the display of the image log display application 350.
[0053]
Table 1
[0054] In S601, the user authentication unit 356 of the image processing server 120 displays a login screen for the user and requests the user for an ID and a password. When the user authentication is successful, the authenticated user can access the information stored in the HDD 223 of the image processing server 120 and the storage server 140. The HDD 223 stores browsing information composed of the user's name, affiliation, and browsing level, and the access range to confidential information changes according to the affiliation and the browsing level. An example registered in the HDD 223 is shown in Table 2.
[0055]
Table 2
[0056] FIG. 7(a) is a diagram showing an example of a screen displaying a list of detection settings. The image log display application 350 of the image processing server 120 displays a detection setting list 701 on the UI display unit 351. In the detection setting list 701, the detection setting list items 702 include items such as detection keywords, display categories, disclosure ranges (disclosure levels, affiliations), the presence or absence of mask processing, and other mask area settings (detection keywords, display categories).
[0057] The "detection keyword" is any keyword detected in S503. The "display category" is the character string displayed during the category display process of S605 described later. The "disclosure range" is divided into items of disclosure level and affiliation, and is used as a threshold when determining whether there is a viewing authority for S603 described later. Also, multiple "disclosure ranges" can be set. The "presence or absence of masking process" is a flag indicating whether the detected or extracted character string itself is the target of the masking process. When it is "valid", the masking process is performed. When it is "invalid", the masking process is not performed.
[0058] The "other mask area setting" is an item for setting a character string other than the detected or extracted character string as the masking target when a keyword is detected or an entity is extracted. Multiple masking targets can be set for one detected or extracted character string. For example, only when "▲▲ product" is detected, the character string representing the amount associated with "▲▲ product" and set as the masking target is also set as the masking target. When "▲▲ product" is not detected, the character string representing the amount is not masked. Regarding the items of "disclosure range" and "presence or absence of masking process" of the character string set here, they take the same values as the parent setting. The detection switch button 703 can switch between valid and invalid. The valid setting is detected in S503.
[0059] The entity extraction setting 704 is the setting of the entity to be extracted in S503. Basically, all entities that can be extracted are set with default values. Since it is not searching for a unique character string, the item of the detection keyword is empty, and the range that the user can change is the "disclosure range", the "presence or absence of masking process", and the "other mask area setting". The keyword detection setting 705 is the setting of the keyword to be detected in S503. Different from the entity extraction setting 704, the keyword detection setting 705 is a setting that the user can arbitrarily add.
[0060] FIG. 7(b) is a diagram showing an example of a detection keyword setting screen. The image log display application 350 of the image processing server 120 displays a detection keyword setting screen 706 on the UI display unit 351. In the detection keyword setting screen 706, the detection keyword setting item 707 is an item for setting the "detection keyword" in the detection setting list item 702. The user can input any character string in the detection keyword setting item 707. Alternatively, all extractable entities can be selected from the pull-down menu. When an entity is selected in the detection keyword setting item 707, the automatically selected entity is also input in the display category setting item 709. At this time, the "detection keyword" in the detection setting list item 702 becomes empty.
[0061] When an arbitrary character string is input in the detection keyword setting item 707, an arbitrary character string can also be input in the display category setting item 709. The mask target switching button 708 is a button for setting whether the detection keyword itself is masked. This button is empty by default. When checked, the "presence / absence of mask processing" in the detection setting list item 702 is set to invalid.
[0062] The display category setting item 709 is an item for setting the "display category" in the detection setting list item 702. The disclosure range item 710 is an item for setting the "disclosure range" in the detection setting list item 702, and multiple settings are possible. The add button 711 is a button for adding items. The mask target pluralization button 712 is a button that permits entry in the "other mask area setting" in the detection setting list item 702. When the mask target pluralization button 712 is checked, the additional detection setting item 713 is enabled.
[0063] The additional detection setting item 713 is an item for setting the "Other Mask Area Setting" in the detection setting list item 702, and multiple settings can be made. The "Detection Keyword" and "Display Category" in the additional detection setting item 713 are the same as those in the detection keyword setting item 707 and the display category setting item 709 respectively. There are no items for "Disclosure Range", "Existence of Mask Processing", and "Other Mask Area Setting", and they cannot be set. The same value as the parent setting is applied to the "Disclosure Range". The "Existence of Mask Processing" is set internally as "Effective", and the "Other Mask Area Setting" is set as empty. Also, the settings of the "Detection Keyword" and the "Display Category" set here are independent, and even if the same character string is entered in different settings, it does not matter.
[0064] It is recommended that the above detection settings be performed by a person with a high viewing authority. This is because in the case of an environment where a monitor using the monitor terminal 131 can set, the monitor can grasp the detection keywords of the areas to be masked. When the above settings are made, the process proceeds to S602.
[0065] In S602, the CPU 221 of the image processing server 120 accesses the extraction information and detection settings stored in the HDD 223 via the image log display application 350 to obtain all the character strings to be masked. When all the character strings to be masked are obtained, the processes from S603 to S607 are performed for each of the obtained character strings.
[0066] In S603, the image log display application 350 of the image processing server 120 accesses the viewing information and detection settings stored in the HDD 223. That is, the image log display application 350 of the image processing server 120 obtains the viewing level and affiliation of the logged-in user and the disclosure range of the character strings to be masked. When the image log display application 350 of the image processing server 120 obtains the information of the character strings to be masked, the process proceeds to S604.
[0067] In S604, the CPU 221 of the image processing server 120 determines whether the logged-in user has the viewing permission. If the viewing level is equal to or higher than the disclosure level and the affiliation meets the conditions, the logged-in user can view. If the CPU 221 of the image processing server 120 determines that the logged-in user has the viewing permission, the processes of S605 and S606 are skipped. If it is determined that the logged-in user does not have the viewing permission, the process proceeds to S605.
[0068] In S605, the mask processing unit 353 of the image processing server 120 masks the string to be masked on the document image. The position of the area to be masked is described in the extraction information stored in the HDD 223. In this embodiment, the mask processing is performed by blotting out, but any method may be used if the content of the string cannot be grasped. After masking the string to be masked, the process proceeds to S606.
[0069] In S606, the category display unit 354 of the image processing server 120 describes a string representing the category in a recognizable state such as white text in the area masked in S605 on the document image. The category information is described in the extraction information stored in the HDD 223 of the image processing server 120. Note that as long as the category is in a recognizable state, it may be in a format such that when the cursor on the UI screen is aligned with the masked area, a string indicating the category pops up. Also, the category information is not limited to characters. For example, if it is an amount, it may be in a format displayed as an emoji such as a coin mark. When the display process of the category information is completed, the process proceeds to S607.
[0070] In S607, when the CPU 221 of the image processing server 120 has performed the above-described processing on all the acquired character strings, the process proceeds to S608. When the CPU 221 of the image processing server 120 has not performed the above-described processing on all the acquired character strings, the process returns to S603. In S608, the CPU 221 of the image processing server 120 displays the document image masked in S603 to S607 on the UI screen. When the masked document image is displayed on the UI screen, the processing flow shown in FIG. 6 ends.
[0071] FIG. 8(a) is an example of a document image before mask processing. The report 801 includes confidential information such as company name, project name, product name, and amount. FIG. 8(b) is an example of a document image after mask processing and category display. In the report 802, the character strings representing the confidential information are masked, and the character strings indicating the category are described in the same area. The mask area 803 is an area where the character strings representing the company name, project name, product name, and amount are detected and masked. The category name is described in the masked area. FIG. 8(c) is an example in which the category is indicated by an emoji representing the category instead of the category name. The company name is represented by a building representing the company, the project name is represented by a document representing the project, the product name is represented by a display representing an example of the product, and the amount is represented by a coin representing an example of the amount as an emoji. The illustrated emojis are merely examples, and other emojis may be used.
[0072] FIG. 9 is a diagram showing an example of a screen displayed on the UI screen of the image log display application 350 in S608. The UI display unit 351 of the image processing server 120 displays a screen 901, a job-in-approval display unit 902, a completed job display unit 903, and an all-job display unit 904. In the job-in-approval display unit 902, the jobs for which the logged-in user is the person in charge are displayed in a list.
[0073] In the completed job display section 903, the jobs determined by the user whether there is information leakage are displayed in a list. In the all jobs display section 904, all printed jobs are displayed in a list. The displayed jobs are generated based on the logs generated by the log generation section 323 stored in the storage server 140. The in - approval job display section 902, the completed job display section 903, and the all jobs display section 904 display the pressed screen in the front according to the user input received by the input reception section 357. The image log items 905 include items such as job name, date and time, source, user, person in charge, detection category, and number of detections. The "job name" is the job name indicating the printed matter generated by the print image generation section 341. The "date and time" is the printed date and time. The "source" is the identification ID of the device where printing was executed. The "user name" is the user name logged in when printing was executed. The "person in charge" is the person in charge of checking the document in which confidential information was detected. The "detection category" is the category group of the detected confidential information. The "number of detections" is the number of detected confidential information.
[0074] The job details 906 represent the details of the printed job. When the area of the job details 906 is pressed by the user input received by the input reception section 357, a document image may be displayed on the image display section 910. The selection box 907 indicates the selected job details 906. Each time the area of the selection box 907 is pressed by the user input received by the input reception section 357, it toggles between valid and invalid. Also, multiple printed jobs can be selected. The transfer button 908 is a button for changing the person in charge of the job details 906 for which the selection box 907 is valid.
[0075] When the area of the transfer button 908 is pressed due to the user input received by the input reception unit 357, a screen for selecting the person in charge of the transfer destination is displayed, and the data with the changed person in charge is transmitted. The log is updated by the log generation unit 323, and the person in charge is changed. At the same time, a notification such as an email is sent to the person in charge of the transfer destination. The completion button 909 is a button for moving the job details 906 for which the selection box 907 displayed in the approval-in-progress job display unit 902 is valid to the completed job display unit 903. It is pressed when the user determines whether there is information leakage. When the area of the completion button 909 is pressed due to the user input received by the input reception unit 357, a screen for entering a comment is displayed. When the entry of the comment is completed, the log generation unit 323 updates the log and the job moves to the completed job display unit 903. At this time, the comment is also saved in the log. At the same time, the completion notification is sent to the destination set by email or the like. The document image processed in S411 is displayed on the image display unit 910. The page forward button 911 is a button for changing the page. The page number display unit 912 displays the page number of the document image displayed on the image display unit 910 and the total number of pages of the document image.
[0076] In the description of the above flowchart, it is determined whether or not to perform the masking process according to the viewing authority, but it is not limited to this. The viewing authority levels of the users who have received user authentication can be divided into multiple levels, and the masking process according to the viewing authority level may be performed. For example, the masking process levels may be set from viewing authority level 1 to viewing authority level 5. Thereby, it becomes possible to display on the UI screen a document image subjected to the masking process according to the viewing authority level of the user who views the document image.
[0077] In the present embodiment, the image processing server 120 and the monitor terminal 131 or the administrator terminal 132 are described as separate devices, but it is not limited to this. The functions of the monitor terminal 131 and the administrator terminal 132 may be added to the image processing server 120 to integrate the above three devices. Alternatively, the function of the monitor terminal 131 may be added to the image processing server 120 to integrate the two devices.
[0078] In this embodiment, through a series of processes via the image log display application 350, a monitor without viewing authority can instantly determine from the category information displayed in the masked area whether the printed document image is at risk of information leakage. Therefore, even when confidential information is concentrated in the document image, it is possible to easily grasp the outline of individual confidential information without leaking the confidential information.
[0079] [Second Embodiment] In the first embodiment, the document image to be displayed on the UI screen using the image log display application 350 was determined and displayed from the detailed information of the job. Consider the case of processing documents in the same category continuously for efficiency. There are cases where it is effective to narrow down the jobs by the keywords described in the document image, such as when an undetected incident occurs and the target job has to be found from all jobs. However, since the viewing authority varies depending on the user, it is necessary to avoid the masked area from being searched by keywords. For example, a monitor belonging to the security department without special viewing authority can know the existence of confidential information that is usually masked by searching with appropriate keywords.
[0080] In this embodiment, in order to prevent the above situation from occurring, the process of making the character string in the masked area not searchable according to the viewing authority when searching for jobs with the character string in the document image will be described. This makes it possible to search for jobs with the character string in the document image while suppressing the leakage of confidential information. In the description of this embodiment, the description of the parts where the configuration and processing procedures are the same as those in the first embodiment will be omitted, and only the different parts will be described.
[0081] [Overall Process Flow] FIG. 10 is a sequence diagram showing the processing flow from when the search is started by the administrator terminal 132 until the search results are displayed on the image log display application 350. In the present embodiment, the processing of the user who uses the administrator terminal 132 to search is described, but the processing flow is the same even when the user who uses the monitor terminal 131 searches.
[0082] The administrator terminal 132 receives a search instruction from the user via the image log display application 350. When the "Search" button on the UI screen is pressed, the processing shown in the sequence diagram of FIG. 10 starts. In S1001, the CPU 231 of the administrator terminal 132 acquires the search keyword input on the search screen displayed on the UI display unit 351 via the input reception unit 357, and transmits the search keyword to the image processing server 120.
[0083] In S1002, the keyword search unit 325 of the image processing server 120 searches for the search keyword transmitted in S1001 from the extraction information of all the logs stored in the storage server 140. The CPU 221 of the image processing server 120 acquires a list of logs that meet the conditions based on the search keyword.
[0084] Specifically, the log extraction information includes the extraction character string of the entire document image and the position information of the extraction character string, and the CPU 221 of the image processing server 120 searches for the search keyword from the extraction character string. When there is an extraction character string that matches the search keyword, the CPU 221 of the image processing server 120 determines whether the position information of the extraction character string matches the position information of the detected or extracted confidential information as shown in the confidential information list. When there is confidential information with matching position information, the CPU 221 of the image processing server 120 acquires the viewing level and affiliation of the logged-in user and the disclosure range of the string to be masked, and determines whether the logged-in user has the viewing authority.
[0085] When the logged-in user has viewing privileges, the CPU 221 of the image processing server 120 determines that the log meets the conditions based on the search keyword. When the logged-in user does not have viewing privileges, the CPU 221 of the image processing server 120 determines that the log does not meet the conditions based on the search keyword. Here, a specific explanation will be given using an example of an image that partially includes the search keyword shown in FIG. 11.
[0086] The report 1101 contains confidential information such as company name, project name, product name, and amount. The project name 1102 is confidential information. The character string 1103 is not confidential information. Here, consider a user who does not have viewing privileges for confidential information searching for "project". The latter part of the project name 1102 partially matches, and the entire text of the character string 1103 matches. At this time, since the project name 1102 is confidential information, it cannot be displayed. By determining whether the position information of the detected character string exists within the position information of the confidential information, the CPU 221 of the image processing server 120 can distinguish between the project name 1102 and the character string 1103. As another method, an ID is assigned to all characters in the image (for example, the number of characters from the beginning), and the CPU 221 of the image processing server 120 can also determine whether it is confidential information based on whether the detected character string matches the ID.
[0087] In S1003, the application data generation unit 321 of the image processing server 120 generates a search job list to be displayed on the image log display application 350 based on the list of logs obtained in S1002. The generated search job list is transmitted from the image processing server 120 to the administrator terminal 132. In S1004, the image log display application 350 of the administrator terminal 132 displays the search job list generated in S1003 on the UI screen by the UI display unit 351. When the search job list is displayed on the UI screen, the processing flow of the sequence diagram shown in FIG. 10 ends.
[0088] FIG. 12(a) is a diagram showing an example of a screen before a search. Screen 1201 is a screen in which the entire job display section 904 of FIG. 9 is displayed in the frontmost position. A search keyword is input by the user into the search keyword input section 1202. The search button 1203 is a button for starting a search. When the search button 1203 is pressed by the user input received by the input reception section 357, the processing flow of the sequence diagram shown in FIG. 10 is started. The confidential document A1204 is a confidential document containing the character strings "xxx joint project" and "project". The confidential document B1205 is a confidential document containing the character string "xxx joint project". The general document A1206 is a general document containing the character string "project". The general document B1207 is a general document not containing the character string "project".
[0089] FIG. 12(b) is a diagram showing an example of a screen in which a monitor inputs "project" into the search keyword input section 1202 and performs a search. Since the monitor does not have the viewing authority for "xxx joint project", when searching for "project", the confidential document A1204 and the general document A1206 are displayed as search results. At this time, the confidential document A1204 is because the character string "project" was searched, and it is not the case that "xxx joint project" was searched with a partial match. Therefore, when the document image is displayed, a masking process is performed on the entire "xxx joint project". Therefore, the monitor does not know whether the character string "project" is described in "xxx joint project".
[0090] FIG. 12(c) is a diagram showing an example of a screen in which an administrator inputs "project" into the search keyword input section 1202 and performs a search. Since the administrator has the viewing authority for "xxx joint project", when searching for "project", the confidential document A1204, the confidential document B1205, and the general document A1206 are displayed as search results. Since the administrator has the viewing authority, there is no character string that is masked when the document image is displayed.
[0091] In this embodiment, through a series of processes via the image log display application 350, it becomes possible to search for jobs by the character strings in the document image without leaking confidential information to the monitor by making it impossible to search for confidential information without viewing permission. An administrator with viewing permission can search for jobs using the character strings in the document image without being restricted.
[0092] [Third Embodiment] In the second embodiment, when the keyword searched by a monitor without viewing permission is included in the masked portion, it is not displayed in the search results. However, for character strings that can be easily imagined to be included in the masked portion from the category information, they may be displayed in the search results without being masked. For example, this applies when the string "project" is displayed above the portion where the category "project name" is masked. In this embodiment, a process will be described in which when a specific character string included in the confidential information is searched, it is displayed in the search results and the character string used in the search is not masked. As a result, it becomes possible to perform a display that allows the user to easily grasp the situation by displaying the specific character string without being masked. In the description of this embodiment, the description of the parts having the same configuration and processing procedure as those of the first embodiment and the second embodiment will be omitted, and only the different parts will be described.
[0093] FIG. 13 is a diagram showing an example of a screen in which a monitor inputs "project" into the search keyword input section 1202 and conducts a search in this embodiment. As a difference from FIG. 12(b), the confidential document B1205 is displayed as a search result. The confidential information 1301 is confidential information named "xxx joint project". The masked portion 1302 is a character area described as "xxx joint" and cannot be viewed by a monitor who does not have the viewing permission. At this time, the category information may not be described above the masked portion. The search keyword 1303 within the confidential information is a character area that is usually masked when viewed by a monitor who does not have the viewing permission. In this embodiment, when a character string that can be easily imagined to be included in the masked portion is searched as a search keyword from the category information, it will be displayed. Therefore, only the search keyword 1303 "project" within the confidential information shown in FIG. 13 is displayed. For example, when a character string included in the character string representing the category is searched, only that character string is displayed. Specifically, it corresponds to character strings such as "project" when the category is displayed as "project name" and "product" when the category is displayed as "product name".
[0094] In this embodiment, through a series of processes via the image log display application 350, when conducting a search, a specific character string is displayed without being masked, enabling the user to perform a display that makes it easier to grasp the situation.
[0095] [Other Embodiments] The present disclosure can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (for example, ASIC) that realizes one or more functions.
[0096] The disclosure of the above-described embodiments includes the following configurations.
[0097] An image processing system, comprising: a detection means for detecting a confidential character string corresponding to confidential information from among recognized character strings obtained by performing OCR processing on a character region in a document image; a determination means for determining a category of the detected confidential character string; a mask processing means for masking a character region corresponding to the confidential character string among the character regions in the document image; and a display control means for causing a display means to display the document image with information indicating the category of the confidential character string determined by the determination means added to the character region masked by the mask processing means.
[0098] The image processing system according to Configuration 1, wherein the mask by the mask processing means is performed on a part of the confidential character string.
[0099] The image processing system according to Configuration 1, wherein the detection means also detects a confidential character string regarding confidential information related to the confidential character string.
[0100] The image processing system according to Configuration 1, further comprising an authentication means for performing user authentication on a logged-in user, wherein the mask processing means performs a mask processing according to a level of browsing authority of the user authenticated by the authentication means.
[0101] The image processing system according to Configuration 4, wherein the level of the browsing authority has a plurality of levels of browsing authority.
[0102] When the detection means detects the confidential character string by searching for a keyword from among the recognized character strings, the mask processing means does not perform a mask processing on a character string that does not match the confidential character string that matches the keyword, in the image processing system according to Configuration 1.
[0103] Configuration 7: When the detection means detects the confidential character string by searching for keywords from the recognized character string, the masking processing means masks the confidential character string that matches the keyword, in the image processing system according to Configuration 1.
[0104] Configuration 8: When the detection means detects the confidential character string by searching for keywords from the recognized character string, the masking processing means does not mask the part representing the category of the confidential character string in the confidential character string, in the image processing system according to Configuration 1.
[0105] Configuration 9: When the detection means detects the confidential character string by searching for keywords from the recognized character string, the masking processing means masks the part that does not represent the category of the confidential character string in the confidential character string, in the image processing system according to Configuration 1.
[0106] Configuration 10: An information processing apparatus comprising: reception means for receiving data in which a document image, a confidential character string detected as corresponding to confidential information from among recognized character strings obtained by performing OCR processing on a character region within the document image, position information of the confidential character string, and a category of the confidential character string are associated; masking processing means for masking a character region corresponding to the confidential character string within the character region of the document image; and display control means for causing a display means to display the document image in which information indicating the category of the confidential character string corresponding to the masked character region is added to the masked character region.
[0107] Configuration 11: The information processing apparatus according to Configuration 10, further comprising authentication means for performing user authentication on a user who logs in, wherein the masking processing means performs masking processing according to the level of browsing authority of the user authenticated by the authentication means.
[0108] (Configuration 12) The information processing apparatus according to Configuration 11, wherein the level of the viewing authority has a plurality of levels of viewing authority.
[0109] (Configuration 13) A step of receiving data in which a document image, a confidential character string detected as corresponding to confidential information from among recognized character strings obtained by performing OCR processing on a character region in the document image, position information of the confidential character string, and a category of the confidential character string are associated; a step of masking a character region corresponding to the confidential character string in the character regions in the document image; and a step of displaying, on a display means, the document image in which information indicating the category of the confidential character string corresponding to the masked character region is added to the masked character region in the masking step. A control method for an information processing apparatus, characterized by comprising the steps.
[0110] (Configuration 14) A program for causing a computer to function as the information processing apparatus according to any one of Configurations 10 to 12.
Claims
1. Detection means for detecting a confidential character string corresponding to confidential information from among the recognized character strings obtained by performing OCR processing on a character region in a document image; Determination means for determining the category of the detected confidential character string; Mask processing means for masking the character region corresponding to the confidential character string among the character regions in the document image; Display control means for causing a display means to display the document image in which information indicating the category of the confidential character string determined by the determination means is added to the character region masked by the mask processing means; An image processing system, characterized by comprising:
2. The image processing system according to claim 1, wherein the mask by the mask processing means is performed on a part of the confidential character string.
3. The image processing system according to claim 1, wherein the detection means also detects a confidential character string regarding confidential information related to the confidential character string.
4. Further comprising authentication means for performing user authentication on a user who logs in, The image processing system according to claim 1, wherein the mask processing means performs mask processing according to the level of the browsing authority of the user authenticated by the authentication means.
5. The image processing system according to claim 4, wherein the level of the browsing authority has a plurality of levels of browsing authority.
6. When the detection means detects the confidential character string by searching for a keyword from among the recognized character strings, the mask processing means does not perform mask processing on a character string that does not match the confidential character string that matches the keyword. The image processing system according to claim 1.
7. When the detection means detects the confidential character string by searching for a keyword from among the recognized character strings, the mask processing means performs mask processing on the confidential character string that matches the keyword. The image processing system according to claim 1.
8. When the detection means detects the confidential character string by searching for a keyword from among the recognized character strings, the mask processing means does not perform mask processing on a part of the confidential character string that represents the category of the confidential character string. The image processing system according to claim 1.
9. When the detection means detects the confidential character string by searching for a keyword from among the recognition character strings, the masking processing means performs masking processing on a portion of the confidential character string that does not represent the category of the confidential character string. The image processing system according to claim 1.
10. A reception means for receiving data in which a document image, a confidential character string detected as corresponding to confidential information from among recognition character strings obtained by performing OCR processing on a character region in the document image, position information of the confidential character string, and a category of the confidential character string are associated; A masking processing means for masking a character region corresponding to the confidential character string among character regions in the document image; A display control means for causing a display means to display the document image in which information indicating the category of the confidential character string corresponding to the masked character region is added to the masked character region by the masking processing means; An information processing apparatus characterized by comprising:
11. Further comprising an authentication means for performing user authentication on a user who logs in, The information processing apparatus according to claim 10, wherein the masking processing means performs masking processing according to a level of browsing authority of the user authenticated by the authentication means.
12. The information processing apparatus according to claim 11, wherein the level of the browsing authority has a plurality of levels of browsing authority.
13. A step of receiving data in which a document image, a confidential character string detected as corresponding to confidential information from among recognition character strings obtained by performing OCR processing on a character region in the document image, position information of the confidential character string, and a category of the confidential character string are associated; A step of masking a character region corresponding to the confidential character string among character regions in the document image; A step of causing a display means to display the document image in which information indicating the category of the confidential character string corresponding to the masked character region is added to the masked character region in the masking step; A control method for an information processing apparatus characterized by comprising:
14. A program for causing a computer to function as the information processing apparatus according to any one of claims 10 to 12.
Citation Information
Patent Citations
Document processing apparatus, method executed by computer in order to process document, and program
JP2021190749A