Temporary container centered on security measures for real-time creation during digital meetings

By utilizing geographically specific temporary containers to manage shared documents during web conferences, the solution addresses the issue of data privacy violations in existing web conferencing technologies, ensuring secure and compliant data transmission.

JP2025516461APending Publication Date: 2025-05-30INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024560592
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-09
Filing Date
2023-04-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing web conferencing technologies often violate national data privacy laws due to the uncontrolled transmission of shared files across borders, posing risks to personal and sensitive data.

Method used

The implementation of temporary containers that are geographically specific, allowing shared documents to be stored and accessed within these containers, ensuring compliance with data privacy laws by preventing cross-border data transmission.

Benefits of technology

This solution effectively secures shared data within temporary containers, ensuring compliance with data privacy regulations, such as GDPR, by isolating data transmission within national borders, thereby protecting sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025516461000001_ABST
    Figure 2025516461000001_ABST
Patent Text Reader

Abstract

According to one embodiment, a method, computer system, and computer program product for generating temporary containers are provided. The embodiment may include identifying a geographical location associated with a user device for each user within a web conference. The embodiment may also include generating a temporary container for each identified geographical location on one or more commonly controlled servers. The embodiment may further include allocating to each user a temporary container corresponding to the geographical location associated with the user device. The embodiment may also include storing a document in each temporary container in response to a user within the web conference sharing a document. The embodiment may further include granting to each user the right to access the shared documents within the temporary container allocated to each user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to the field of computing, and more particularly to web conferencing.

[0002] Web conferencing, including but not limited to voice and video conferencing, is communication between two or more individuals over a network such as the Internet, and can relate to any communication in which the participating members utilize an audio stream or a video stream or both. Web conferencing enables users in remote locations to communicate as efficiently as if they were meeting in person by enabling face-to-face interaction and sharing files among the participating users, thereby providing a dynamic interface. Popular web conferencing applications include Zoom (registered trademark) (Zoom and all Zoom-based trademarks and logos are trademarks or registered trademarks of Zoom Video Communications Inc. or its affiliates or both), Webex (registered trademark) (Webex and all Webex-based trademarks and logos are trademarks or registered trademarks of Webex Communications, Inc. or its affiliates or both), GoToMeeting (registered trademark) (GoToMeeting and all GoToMeeting-based trademarks and logos are trademarks or registered trademarks of Citrix Online, LLC. or its affiliates or both), FaceTime (registered trademark) (FaceTime and all FaceTime-based trademarks and logos are trademarks or registered trademarks of Apple Inc. or its affiliates or both), and the like.

Summary of the Invention

[0003] According to one embodiment, a method, computer system, and computer program product for generating temporary containers are provided. The embodiment may include identifying a geographical location associated with a user device for each user within a web conference. The embodiment may also include generating a temporary container for each identified geographical location on one or more commonly controlled servers. The embodiment may further include allocating to each user a temporary container corresponding to the geographical location associated with the user device. The embodiment may also include storing a document in each temporary container in response to a user within the web conference sharing the document. The embodiment may further include providing to each user the right to access the shared document within the temporary container allocated to each user.

[0004] Next, preferred embodiments of the present invention will be judged by way of mere example with reference to the following drawings.

Brief Description of the Drawings

[0005]

Figure 1

Figure 2

Figure 3A

Figure 3B

Figure 3C

Figure 4

Figure 5

Figure 6

Best Mode for Carrying Out the Invention

[0006] The drawings are provided to clearly facilitate understanding of the present invention by those skilled in the art in conjunction with the detailed description, and the various features of the drawings are not to scale.

[0007] Although detailed embodiments of the claimed structures and methods are disclosed herein, it is to be understood that the disclosed embodiments are merely illustrative of the claimed structures and methods that may be embodied in various forms. However, the present invention may be implemented in many different forms and should not be construed as limited to the exemplary embodiments described herein. Well-known features and techniques may be omitted herein to avoid unnecessarily obscuring the presented embodiments.

[0008] Unless the context clearly dictates otherwise, it should be understood that the singular forms "a," "an," and "the" include plural referents. Thus, for example, a reference to "a component surface" includes a reference to one or more such surfaces unless the context clearly dictates otherwise.

[0009] Embodiments of the present invention relate to the field of computing, and more particularly to web conferencing. The exemplary embodiments described below provide, among other things, a system, method, and program product for transmitting files shared during a web conference through a temporary container. Accordingly, the present embodiment has the ability to improve the technical field of web conferencing by ensuring that national data privacy laws are complied with during the transmission of data, which may otherwise be inadvertently violated by standard data transmission methods in web conferencing, which is an important possibility.

[0010] As mentioned above, a video conference, i.e., a web conference, is a communication between two or more individuals over a network such as the Internet and can relate to any communication in which the participating members utilize an audio stream or a video stream or both. A web conference enables users in remote locations to communicate efficiently as if they were meeting in person by enabling face-to-face interaction and sharing files among the participating users. Popular web conferencing applications include Zoom (registered trademark) (Zoom and all Zoom-based trademarks and logos are trademarks or registered trademarks of Zoom Video Communications Inc. or its affiliates or both), Webex (registered trademark) (Webex and all Webex-based trademarks and logos are trademarks or registered trademarks of Webex Communications, Inc. or its affiliates or both), GoToMeeting (registered trademark) (GoToMeeting and all GoToMeeting-based trademarks and logos are trademarks or registered trademarks of Citrix Online, LLC. or its affiliates or both), FaceTime (registered trademark) (FaceTime and all FaceTime-based trademarks and logos are trademarks or registered trademarks of Apple Inc. or its affiliates or both), and the like.

[0011] During an online meeting or chat session, information may be exchanged quickly in order to make timely decisions or selections. Among the transmitted data shared during a web conference, there are also some that are originally stored in various high-security systems that can only be accessed by some of the users attending the meeting. For example, in a web conference with five people, only three people can access the data shared within the group. Under certain circumstances, it may be permitted to view the transmitted data, but retaining shared files may expose the personal data, identifiable data, or important data contained therein, or combinations thereof, to risk. Therefore, in particular, it may be advantageous to appropriately secure any data transmitted to meeting participants within a web conference in one or more temporary containers that can be automatically deleted or destroyed at the end of the meeting.

[0012] According to at least one embodiment, files shared during a web conference can be shared within one or more temporary data containers. Each meeting participant can be placed in a different temporary container based on the role, age, system access level, data access level, location, or other pre-set characteristics of each attendee. The temporary container can be created on demand as needed based on the approval of the shared meeting participants for the shared data. In at least one embodiment, the created temporary container may be country-specific so that the data does not cross national borders in order to comply with the data privacy framework of the General Data Protection Regulation (GDPR).

[0013] The present invention can be a system, a method, or a computer program product, or a combination thereof, at any possible level of technical detail integration. The computer program product may include a computer-readable storage medium (or multiple computer-readable storage media) having computer-readable program instructions for causing a processor to implement aspects of the present invention.

[0014] The computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. The computer-readable storage medium can be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. A non-exhaustive listing of more specific examples of computer-readable storage media includes the following: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory stick (registered trademark), floppy (registered trademark) disk, mechanically encoded devices such as punch cards or raised structures engraved in grooves having instructions recorded thereon, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium is not to be construed as being a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through an optical fiber cable), or an electrical signal transmitted through a wire.

[0015] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computing / processing devices, or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface of each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions for storage in a computer-readable storage medium within the respective computing / processing device.

[0016] Computer-readable program instructions for carrying out the operations of the present invention may be source code or object code written in any combination of one or more programming languages, including assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or any combination of object-oriented programming languages such as Smalltalk® and C++, and procedural programming languages such as the “C” programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer as a stand-alone software package, partly on the user's computer, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, via the Internet using an Internet service provider). In some embodiments, for example, an electronic circuit including a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer-readable program instructions to individually configure the electronic circuit by utilizing the state information of the computer-readable program instructions to carry out aspects of the present invention.

[0017] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0018] These computer-readable program instructions, when executed via the processor of a computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in one or more blocks of a flowchart, a block diagram, or both, and may thus provide to the processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to create a machine. These computer-readable program instructions may also be stored in a computer-readable storage medium that includes instructions for implementing the functions / acts of the manner specified in one or more blocks of a flowchart, a block diagram, or both, and may be stored in a computer-readable medium, including a manufactured article that includes a computer, a programmable data processing apparatus, or other device or a combination thereof, and may be instructed to function in a specific manner.

[0019] The computer-readable program instructions may also be loaded onto a computer, other programmable apparatus, or other device to create a computer-implemented process such that the instructions executed on the computer, other programmable apparatus, or other device implement the functions / operations specified in one or more blocks of a flowchart, a block diagram, or both, and cause a series of operational steps to be executed on the computer, other programmable apparatus, or other device.

[0020] The flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a module, segment, or portion of instructions that include one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions represented by the blocks may occur in a different order than shown in the drawings. For example, two blocks shown in succession may actually be executed substantially simultaneously, or the blocks may be executed in reverse order depending on the functionality involved. It should also be noted that each block of the block diagram or flowchart diagram, or combinations of blocks of the block diagram or flowchart diagram or both, can be implemented by a dedicated hardware-based system that performs the specified function or action, or that executes a combination of dedicated hardware and computer instructions.

[0021] The exemplary embodiments described below provide a system, method, and program product that generate a temporary container for data shared among web conference attendees that enables data privacy protection of the shared data.

[0022] Referring to FIG. 1, an exemplary network computer environment 100 according to at least one embodiment is illustrated. The network computer environment 100 can include client computing devices 102 and a server 112 interconnected via a communication network 114. According to at least one implementation, the network computer environment 100 can include a plurality of client computing devices 102 and servers 112, and only one of each is shown for simplicity of illustration. Additionally, in one or more embodiments, the client computing devices 102 and the server 112 can each individually host transient container programs 110A, 110B. In one or more other embodiments, the transient container programs 110A, 110B can be partially hosted on both the client computing device 102 and the server 112 so as to enable functionality to be separated between the devices.

[0023] The communication network 114 can include various types of communication networks such as a wide area network (WAN), a local area network (LAN), a telecommunications network, a wireless network, a public switched network, or a satellite network, or combinations thereof. The communication network 114 may include wired or wireless communication links, or connections such as fiber optic cables. It will be understood that FIG. 1 merely provides an example of one implementation and does not imply any limitation with respect to the environments in which different embodiments may be implemented. Many changes can be made to the depicted environment based on design and implementation requirements.

[0024] According to one embodiment of the present invention, the client computing device 102 can include a processor 104 and a data storage device 106, host and execute a software program 108 and a temporary container program 110A, and communicate with a server 112 via a communication network 114. In one or more other embodiments, the client computing device 102 can be, for example, a mobile device, a telephone, a personal digital assistant, a netbook, a laptop computer, a tablet computer, a desktop computer, or any type of computing device capable of executing a program and accessing a network. As described above, although one client computing device 102 is depicted in FIG. 1 for illustrative purposes, any number of client computing devices 102 can be utilized. As will be discussed with reference to FIG. 4, the client computing device 102 can each include internal components 402a and external components 404a.

[0025] According to an embodiment of the present invention, the server computer 112 may be any programmable electronic device or any network of programmable electronic devices that hosts and executes a laptop computer, a netbook computer, a personal computer (PC), a desktop computer, a temporary container program 110B, and a database 116, and can communicate with the client computing device 102 via the communication network 114. As will be discussed with reference to FIG. 4, the server computer 112 may include internal components 402b and external components 404b, respectively. The server 112 may also operate in a cloud computing service model such as SaaS (Software as a Service), PaaS (Platform as a Service), or IaaS (Infrastructure as a Service). The server 112 may also be deployed in a cloud computing deployment model such as a private cloud, a community cloud, a public cloud, or a hybrid cloud.

[0026] According to this embodiment, the temporary container programs 110A and 110B can receive various items of user information when the user participates in a web conference, use the user information to group each web conference participant into a temporary container for the purpose of data and document sharing, and ensure that data privacy laws are complied with and important personal information is protected during and at the end of the web conference. The method of the temporary container will be further described in detail below with reference to FIG. 2.

[0027] Next, referring to FIG. 2, an operational flowchart diagram showing a temporary container generation process 200 according to at least one embodiment is depicted. At 202, the temporary container programs 110A, 110B receive user and device information for each user participating in the video conference. When a user joins a web conference, the temporary container programs 110A, 110B can query for preconfigured information required for implementation. In at least one embodiment, the temporary container programs 110A, 110B can request that the user opt in to the disclosure of preconfigured user and device information before entering the web conference. If a user wishes to opt out of the disclosure of user and device information before or after a disclosure request when joining the web conference, the temporary container programs 110A, 110B can tag the user's opt out accordingly and can restrict certain functions of the web conference. For example, if a user opts out, the temporary container programs 110A, 110B may not be able to accurately assign the user to the appropriate temporary container as described in more detail below, so the user can be prevented from receiving or viewing shared documents during the web conference.

[0028] In at least one embodiment, the user and device information received by the temporary container programs 110A, 110B includes, but is not limited to, the user's role in the web conference, user age, user system access level, user data access level, type of user device, serial number of the user device, manufacturer number of the user device, IP address of the user device, connection type of the user device, connection strength of the user device, and other unique characteristics.

[0029] Next, at 204, the temporary container programs 110A, 110B identify the country associated with each user IP address. Upon receiving opt-in approval from each user participating in the web conference, the temporary container programs 110A, 110B can utilize the IP address associated with each user device to identify the country corresponding to the location of that device. For example, in a meeting with 8 participants, the temporary container programs 110A, 110B can utilize the IP addresses of each user device to determine that 4 of the participants are in Italy, 2 participants are in Spain, 1 participant is in Croatia, and 1 participant is in France. In at least one other embodiment, the temporary container programs 110A, 110B can utilize the connected user ID, device type, web browser, open applications, installed applications, or the locale of the operating system, or a combination thereof, to identify the user's current country / locale.

[0030] Next, at 206, the temporary container programs 110A, 110B generate one or more temporary containers based on pre-settings. The temporary container programs 110A, 110B can generate one or more temporary containers on a server that controls one or more users or entities for each identified country or geographical location in order to allocate web conference participants based on pre-set characteristics. Since each server that stores the temporary containers is commonly controlled, the data in the shared document is under the supervision of the user or entity that owns the information, thereby ensuring compliance with data privacy laws. The number of temporary containers created can vary from one to the total number of web conference participants depending on the pre-settings established by the web conference host, developer, or administrator. In one or more embodiments, the pre-settings can include, but are not limited to, the role of the user, age, user system access level, user data access level, or other unique user characteristics, or combinations thereof. For example, continuing with the previous example of eight participants, if the temporary container programs 110A, 110B are pre-set to generate a temporary container for each country with at least one web participant, the temporary container programs 110A, 110B can generate four temporary containers. By using each participant's country / locality to generate the temporary containers, the temporary container programs 110A, 110B can ensure that data is not transmitted across borders while outside the control of the owning user or entity. For example, the temporary container programs 110A, 110B can generate a temporary container for each country represented by the web conference participants, so that only the participants placed in the same temporary container can access specific information, ensuring that data privacy laws are observed.

[0031] In another embodiment, the temporary container programs 110A, 110B can generate temporary containers for each data access level of each web conference participant. For example, in a web conference with three participants, where one participant is a senior executive, another is a mid-level manager, and the other is a junior staff member, and the senior executive and mid-level manager can access certain important information documents while the junior staff member cannot, the temporary container programs 110A, 110B can generate two temporary containers based on the access level permissions.

[0032] Next, at 208, the temporary container programs 110A, 110B group each identified user associated with each country into the corresponding country-related temporary container. Once the temporary containers are created, the temporary container programs 110A, 110B can group each participant in the web conference into the corresponding container according to the criteria used for generation. For example, in the aforementioned example of eight web conference participants having temporary containers generated for each represented country (i.e., Italy, Spain, Croatia, and France), the temporary container programs 110A, 110B can group the four participants in Italy into the same temporary container, group the two participants in Spain into the same temporary container, and group each participant from Croatia and France into the corresponding temporary containers respectively.

[0033] Next, at 210, the temporary container programs 110A, 110B determine whether a document is shared during the web conference. During the web conference, the temporary container programs 110A, 110B constantly monitor the interactions among the participants to determine whether a document or information is shared among the participants and can trigger the need to exchange the document or information through the temporary container in which it was generated. For example, if a participant posts a document to a persistent group chat, the temporary container programs 110A, 110B can determine that this shared document should be sent to each temporary container. If the temporary container programs 110A, 110B determine that a document is shared (step 210, branch "Yes"), the temporary container process 200 proceeds to step 212 and can send the document to each temporary container. If the temporary container programs 110A, 110B determine that a document is not shared (step 210, branch "No"), the temporary container process 200 returns to step 204 and can identify the country associated with each user IP address.

[0034] In at least one embodiment, the shared document or information may be through an attachment to a group chat or through screen sharing from one participant to other web conference participants.

[0035] Next, at 212, the temporary container programs 110A, 110B send documents to each temporary container. When a document or information is shared in a web conference, the temporary container programs 110A, 110B can send a copy of the shared document to each temporary container generated in step 206. For example, if a document is shared as an attachment during a web conference according to the example described above, the temporary container programs 110A, 110B can send a copy of the shared document to each temporary container stored on a server controlled by one or more users or entities. In at least one embodiment, the temporary container programs 110A, 110B may permit access to the shared document for participants grouped within the temporary container so that not all members can access the data on the actual system.

[0036] The temporary container programs 110A, 110B can use a cloud storage platform such as Box (registered trademark) (Box and all trademarks and logos based on Box are trademarks or registered trademarks of Box, Inc. or its affiliates or both) to store and share each document within each temporary container. For example, when a participant in a web conference shares a document with other meeting participants, the temporary container programs 110A, 110B can send a copy of the shared document to each generated temporary container for sharing with each participant grouped within its corresponding temporary container.

[0037] During the screen sharing, the temporary container programs 110A and 110B may transfer the shared data to each temporary container before the screen sharing is started and displayed on the graphical user interface of each meeting participant to prevent external data leakage of the geographical location of each participant. Therefore, when a document is shared via screen sharing, only the data that the user is authorized to view during the screen sharing is displayed. In at least one embodiment, the temporary container programs 110A and 110B utilize optical character recognition or image recognition technology or both to identify and obfuscate any data that cannot be separated so that the data is not shared outside the geographical location of the sharing user in violation of the corresponding data privacy laws.

[0038] Next, at 214, the temporary container programs 110A and 110B destroy the information related to the documents in each temporary container at the end of the web conference. At the end of the web conference, each temporary container program 110A and 110B can destroy all the information related to each document shared during the meeting and stored in each temporary container. In at least one embodiment, the destruction of the shared documents stored in each temporary container may be related to the complete deletion of the documents or information without the ability to restore the documents or information by known data recovery solutions. For example, the temporary container programs 110A and 110B can utilize a file shredding program that utilizes one or more of the following shredding algorithms: DOD5220.22-M, AFSSI-5020, AR380-19, RCMP TSSIT OPS-II, HMG IS5, VSITR, GOST R 50739-95, Gutmann, Schneier, Random Data, Bit Toggle, NATO Standard, NAVSO P-5239-26, MS Cipher, WipeFile, Write Zero, VSITR, IREC(IRIG), NISPOMSUP Chapter8 Section8-501, and NSA Manual130-2, etc.

[0039] In at least one embodiment, the temporary container programs 110A, 110B may be preconfigured to delete or destroy, or both, each temporary container at the end of a web conference or when a chat session has ended or closed. Further, if all participants grouped in a particular temporary container have exited the web conference, the temporary container programs 110A, 110B may be able to delete or destroy, or both, that temporary container. For example, continuing with the previous example, if both participants located in Spain exit the web conference and only participants from Italy, Croatia, and France remain, the temporary container programs 110A, 110B may delete or destroy, or both, the temporary container for Spain and may retain the temporary containers for Italy, Croatia, and France.

[0040] In another embodiment, the temporary container programs 110A, 110B can also delete or destroy, or both, one or more temporary containers after a preset period has elapsed without user communication or sharing of documents or information. For example, if a group of participants takes a 15-minute break and the temporary container programs 110A, 110B are set to delete or destroy, or both, the temporary containers when 10 minutes have passed without a chat conversation or document sharing occurring, the temporary container programs 110A, 110B can delete or destroy, or both, each temporary container. In a situation where one or more temporary containers are deleted or destroyed, or both, due to inactivity of chat or document sharing, the temporary container programs 110A, 110B can retain information related to the generation of one or more temporary containers that were deleted or destroyed, or both, in order to regenerate each temporary container that was deleted or destroyed, or both, when chat or document, or both, sharing resumes. In this way, the temporary container programs 110A, 110B can save bandwidth and processing power consumed by maintaining unnecessary temporary containers during periods of inactivity of chat or document sharing.

[0041] Next, referring to FIG. 3A, there is depicted an exemplary block diagram of a video conferencing graphical user interface during temporary container generation, according to at least one embodiment. The graphical user interface 300 of a web conferencing application such as Zoom (registered trademark), Webex (registered trademark), GoToMeeting (registered trademark), or FaceTime (registered trademark) can depict various users, such as user A 302, user B 304, user C 306, user D 308, user E 310, user F 312, user G 314, and user H 316, participating in a web conference together. Each user 302 - 316 may be represented in a different section of the graphical user interface 300. In at least one embodiment, the temporary container programs 110A, 110B, or the web conferencing application can also depict or record each user's device type or geographical location, or both. For example, user A 302 may be participating in the web conference using a laptop computer within Croatia, while user C 306 may be participating in the web conference using a tablet within France. As previously described in step 202 above, the temporary container programs 110A, 110B can receive user and device information if each user opts in to provide such information upon joining the web conference.

[0042] Next, referring to FIG. 3B, an exemplary block diagram of a participant data table created during temporary container generation according to at least one embodiment is depicted. When receiving user and device information from each participant, the temporary container programs 110A, 110B can aggregate and distribute the received user and device information into a table such as table 318. The generated table 318 is utilized by the temporary container programs 110A, 110B to determine the total number of temporary containers to generate and to determine to which of the generated temporary containers each participant can be assigned based on the geographical location of each participant determined by the received user and device information. For example, the temporary container programs 110A, 110B can determine that users 302A to 316H represent the countries of Italy, Spain, France, and Croatia based on an analysis of the corresponding IP addresses disclosed by each user when participating in a web conference. Thus, the temporary container programs 110A, 110B can determine that temporary containers should be generated for each identified country and can assign each user to the temporary container of its corresponding country as shown in the rightmost column of table 318 (i.e., user A302 is in Croatia and is assigned to temporary container 1, users B304, D308, E310, and H316 are in Italy and are assigned to temporary container 2, user C306 is in France and is assigned to temporary container 3, and users F312 and G314 are in Spain and are assigned to temporary container 4).

[0043] Next, referring to FIG. 3C, an exemplary block diagram of document sharing between generated temporary containers according to at least one embodiment is depicted. When temporary containers 322-328 are generated, temporary container programs 110A, 110B can send copies of documents or information shared in the web conference to each of the temporary containers 322-328. Each user 302-316 can view only the copy of the document or information stored in the temporary container corresponding to their geographical location. For example, user A 302 can view only the documents stored in temporary container 1 322. When the web conference ends, the temporary container programs 110A, 110B can delete or destroy or both any data (e.g., stored documents and information) within each of the temporary containers 322-328, and the temporary containers 322-328 themselves.

[0044] FIGS. 2 and 3A-3C merely provide examples of one implementation form and are not meant to impose any limitations on how various implementation forms can be implemented. It will be understood that many changes can be made to the depicted environment based on design and implementation requirements.

[0045] FIG. 4 is a block diagram 400 of the internal and external components of the client computing device 102 and the server 112 depicted in FIG. 1 according to an embodiment of the present invention. It should be understood that FIG. 4 merely provides an example of one implementation form and is not meant to impose any limitations on the environment in which various implementation forms can be implemented. Many changes can be made to the depicted environment based on design and implementation requirements.

[0046] Data processing systems 402, 404 represent any electronic device capable of executing machine-readable program instructions. The data processing systems 402, 404 can represent a smartphone, a computer system, a PDA, or other electronic devices. Examples of computing systems, environments or configurations, or combinations thereof, that can be represented by the data processing systems 402, 404 include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, network PCs, minicomputer systems, and distributed cloud computing environments that include any of the above systems or devices.

[0047] Client computing device 102 and server 112 may each include a respective set of internal components 402a, b and external components 404a, b shown in FIG. 4. Each set of internal components 402 includes, on one or more buses 426, one or more processors 420, one or more computer-readable RAMs 422, and one or more computer-readable ROMs 424, as well as one or more operating systems 428 and one or more computer-readable tangible storage devices 430. One or more operating systems 428, software program 108 and temporary container program 110A within client computing device 102, and temporary container program 110B within server 112 are stored in one or more of respective computer-readable tangible storage devices 430 for execution by one or more of respective processors 420 via one or more of respective RAMs 422 (typically including cache memory). In the embodiment shown in FIG. 4, each of computer-readable tangible storage devices 430 is a magnetic disk storage device of an internal hard drive. Alternatively, each of computer-readable tangible storage devices 430 is a semiconductor storage device such as ROM 424, EPROM, flash memory, or any other computer-readable tangible storage device capable of storing computer programs and digital information.

[0048] Each set of internal components 402a, b also includes an R / W drive or interface 432 for reading from and writing to one or more portable computer-readable tangible storage devices 438 such as CD-ROMs, DVDs, memory sticks (registered trademark), magnetic tapes, magnetic disks, optical disks, or semiconductor storage devices. Software programs such as the temporary container programs 110A, 110B can be stored in one or more of the respective portable computer-readable tangible storage devices 438, read via the respective R / W drives or interfaces 432, and loaded onto the respective hard drives 430.

[0049] Each set of internal components 402a, b also includes a network adapter or interface 436 such as a TCP / IP adapter card, a wireless Wi-Fi interface card, or a 3G, 4G, or 5G wireless interface card, or other wired or wireless communication links. The software program 108 and the temporary container programs 110A within the client computing device 102, and the temporary container program 110B within the server 112 can be downloaded from an external computer to the client computing device 102 and the server 112 via a network (e.g., the Internet, a local area network, or other wide area network) and the respective network adapters or interfaces 436. From the network adapter or interface 436, the software program 108 and the temporary container programs 110A within the client computing device 102, and the temporary container program 110B within the server 112 are loaded onto the respective hard drives 430. The network can include copper wires, optical fibers, wireless transmissions, routers, firewalls, switches, gateway computers or edge servers, or combinations thereof.

[0050] Each set of external components 404a, b can include a computer display monitor 444, a keyboard 442, and a computer mouse 434. The external components 404a, b can also include a touch screen, a virtual keyboard, a touch pad, a pointing device, and other human interface devices. Each set of internal components 402a, b also includes a device driver 440 for interfacing with the computer display monitor 444, the keyboard 442, and the computer mouse 434. The device driver 440, the R / W drive or interface 432, and the network adapter or interface 436 include hardware and software (stored in the storage device 430 or the ROM 424 or both).

[0051] Although the present disclosure includes a detailed description of cloud computing, it should be understood in advance that the implementation of the teachings presented herein is not limited to a cloud computing environment. Rather, embodiments of the present invention can be implemented in conjunction with any other type of computing environment now known or later developed.

[0052] Cloud computing is a service delivery model that enables convenient on-demand network access to a shared pool of configurable computing resources such as networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services, and these resources can be rapidly provisioned and released with minimal management effort or interaction with a service provider. This cloud model can include at least five characteristics, at least three service models, and at least four deployment models.

[0053] The characteristics are as follows. On-demand self-service: Cloud users can automatically and unilaterally provision computing capabilities such as server time and network storage as needed, without the need for human interaction with the service provider. Broad network access: The capabilities are available over the network and can be accessed using standard mechanisms, facilitating use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs). Resource pooling: The provider's computing resources are pooled and provided to multiple users using a multi-tenant model, and various physical and virtual resources are dynamically assigned and re-assigned according to demand. Although users typically have a sense of location independence in that they are usually unaware of and do not manage the exact location of the resources provided, at a higher level of abstraction, the location (e.g., country, state, or data center) can be specified. Rapid elasticity: The capabilities can be provisioned quickly and flexibly, and in some cases automatically, scale out rapidly, and be released quickly to scale in rapidly. The capabilities available for provisioning often appear to the user to be purchasable in any quantity, at any time, without limit. Measured service: The cloud system automatically controls and optimizes resource use at an appropriate level of abstraction for the type of service (e.g., storage, processing, bandwidth, and active user accounts). The amount of resource use can be monitored, controlled, and reported, providing transparency to both the provider and the user of the service being utilized.

[0054] The service model is as follows. SaaS (Software as a Service): The capabilities provided to users are the use of the provider's applications running on cloud infrastructure. Those applications can be accessed from various client devices via a thin-client interface such as a web browser (e.g., web-based email). Users do not manage or control the underlying cloud infrastructure, which includes the network, servers, operating system, storage, or individual application functionality, except for limited user-specific application configuration settings. PaaS (Platform as a Service): The capabilities provided to users are to deploy the applications created or acquired by users, which are created using programming languages and tools supported by the provider, onto the cloud infrastructure. Users do not manage or control the underlying cloud infrastructure, which includes the network, servers, operating system, or storage, but can control the deployed applications and, in some cases, the configuration of the application hosting environment. IaaS (Infrastructure as a Service): The capabilities provided to users are the provisioning of processing, storage, network, and other basic computing resources, and users can deploy and run any software that can include an operating system and applications. Users do not manage or control the underlying cloud infrastructure, but can control the operating system, storage, deployed applications, and, in some cases, have limited control over selected network components (e.g., host firewall).

[0055] The deployment models are as follows. Private Cloud: The cloud infrastructure is operated solely for an organization. This can be managed by the organization or a third party and can exist on-premises or off-premises. Community Cloud: The cloud infrastructure is shared by multiple organizations and supports a specific community with common concerns (e.g., mission, security requirements, policies, and compliance considerations). This can be managed by an organization or a third party and can exist on-premises or off-premises. Public Cloud: The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization that sells cloud services. Hybrid Cloud: The cloud infrastructure remains a unique entity but is a composite of two or more clouds (private, community, or public) joined by standardized or proprietary technologies (e.g., cloud bursting for load distribution between clouds) that enable data and application portability.

[0056] The cloud computing environment is a service-oriented environment that emphasizes statelessness, loose coupling, modularity, and semantic interoperability. At the center of cloud computing is an infrastructure with a network of interconnected nodes.

[0057] Referring now to FIG. 5, an exemplary cloud computing environment 50 is shown. As illustrated, cloud computing environment 50 includes one or more cloud computing nodes 100 that can communicate with a local computing device used by a cloud user (e.g., a personal digital assistant (PDA) or cellular phone 54A, a desktop computer 54B, a laptop computer 54C, or an automotive computer system 54N, or combinations thereof). The nodes 100 can communicate with one another. These can be physically or virtually grouped (not shown) within one or more networks such as the private cloud, community cloud, public cloud, or hybrid cloud described above, or combinations thereof. Thereby, cloud computing environment 50 can provide an infrastructure, platform, or SaaS, or combinations thereof, for which a cloud user need not maintain resources on a local computing device. The types of computing devices 54A - 54N shown in FIG. 4 are for illustration only, and it is understood that cloud computing nodes 100 and cloud computing environment 50 can communicate with any type of computer control device via any type of network or network addressable connection (e.g., a connection using a web browser) or both.

[0058] Next, referring to FIG. 6, a set of functional abstraction layers 600 provided by cloud computing environment 50 is shown. It should be understood in advance that the components, layers, and functions shown in FIG. 6 are for illustration only and that embodiments of the present invention are not limited thereto. As illustrated, the following layers and corresponding functions are provided.

[0059] Hardware and software layer 60 includes hardware components and software components. Examples of hardware components include mainframe 61, RISC (Reduced Instruction Set Computer) architecture-based server 62, server 63, blade server 64, storage device 65, and network and network components 66. In some embodiments, software components include network application server software 67 and database software 68.

[0060] Virtualization layer 70 provides an abstraction layer that can provide the following examples of virtual entities: virtual server 71, virtual storage 72, virtual network 73 including a virtual private network, virtual applications and operating systems 74, and virtual client 75.

[0061] In one example, the management layer 80 can provide the functions described below. Resource provisioning 81 performs dynamic procurement of computing resources and other resources used to execute tasks within a cloud computing environment. Measurement and pricing 82 performs cost tracking when resources are utilized within a cloud computing environment, and billing or invoicing for the utilization of those resources. In one example, these resources can include application software licenses. Security performs identity verification of cloud users and tasks, and protects data and other resources. The user portal 83 provides access to the cloud computing environment to users and system administrators. Service level management 84 allocates and manages cloud computing resources so as to meet the required service levels. Service level agreement (SLA) planning and execution 85 performs advance preparation and procurement of cloud computing resources for which future demands are anticipated, in accordance with the SLA.

[0062] The workload layer 90 provides examples of functionality that can be utilized in a cloud computing environment. Examples of workloads and functions that can result from this layer include: mapping and navigation 91, software development and lifecycle management 92, virtual classroom education delivery 93, data analysis processing 94, transaction processing 95, and temporary container generation 96. Temporary container generation 96 may be related to creating a temporary container that groups each participant based on user and device information received for each participant joining a web conference, for the purpose of protecting important personal information in accordance with country-specific data privacy laws.

[0063] The descriptions of the various embodiments of the present invention are presented for illustrative purposes, but are not intended to be exhaustive and are not limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the described embodiments. The terms used herein are selected to best explain the principles of the embodiments, the practical application, or the technical improvements seen in the market, or to enable other skilled artisans to understand the embodiments disclosed herein.

Claims

1. A computer-implemented method, comprising: identifying, by a processor, a geographical location associated with a user device for each user within a web conference; generating, on one or more centrally controlled servers, a temporary container for each identified geographical location; assigning to each user a temporary container corresponding to the geographical location associated with the user device; storing the document in each temporary container in response to a user within the web conference sharing a document; giving each user access rights to the shared document within the temporary container assigned to each user A computer-implemented method.

2. receiving, in response to a user opting in to participate in the web conference and share information, a plurality of user information and a plurality of device information The method according to claim 1, further comprising.

3. deleting the shared document from each temporary container in response to the web conference ending The method according to claim 1 or 2, further comprising.

4. destroying each temporary container in response to the web conference ending The method according to claim 3, further comprising.

5. generating the temporary container for each identified geographical location further comprises generating one or more additional temporary containers within the geographical location based on the user data access level of each user having a user device IP address corresponding to the geographical location The method according to any one of claims 1 to 4, further comprising.

6. The method according to claim 2, wherein the plurality of device information is selected from the group consisting of a type of user device, a serial number of the user device, a manufacturer number of the user device, an IP address of the user device, a connection type of the user device, and a connection strength of the user device.

7. The method according to claim 2, wherein the plurality of user information is selected from the group consisting of a role of the user in the web conference, a user age, a user system access level, and a user data access level.

8. A computer system, comprising: One or more processors, one or more computer-readable memories, one or more computer-readable tangible storage media, and program instructions stored on at least one of the one or more tangible storage media for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is identifying the geographical location associated with each user's user device within the web conference generating a temporary container for each identified geographical location on one or more commonly controlled servers assigning to each user a temporary container corresponding to the geographical location associated with the user device storing the document in each temporary container in response to a user within the web conference sharing a document granting each user access rights to the shared document within the temporary container assigned to each user A computer system capable of executing a method including

9. Receiving a plurality of user information and a plurality of device information in response to a user opting in to participate in the web conference and share information The computer system according to claim 8, further comprising

10. Deleting the shared document from each temporary container in response to the web conference ending The computer system according to claim 8 or 9, further comprising

11. Destroying each temporary container in response to the web conference ending The computer system according to claim 10, further comprising

12. Generating the temporary container for each identified geographical location is generating one or more additional temporary containers within the geographical location based on the user data access level of each user having a user device IP address corresponding to the geographical location The computer system according to any one of claims 8 to 11, further comprising

13. The computer system according to claim 9, wherein the plurality of device information is selected from the group including the type of the user device, the serial number of the user device, the manufacturer number of the user device, the IP address of the user device, the connection type of the user device, and the connection strength of the user device.

14. The computer system according to claim 9, wherein the plurality of user information is selected from the group including the role of the user in the web conference, the user age, the user system access level, and the user data access level.

15. A computer program product, comprising one or more computer-readable tangible storage media, and program instructions stored in at least one of the one or more computer-readable tangible storage media, the program instructions being executable by a processor capable of executing a method, the method comprising identifying a geographical location associated with a user device for each user within a web conference; generating a temporary container for each identified geographical location on one or more commonly controlled servers; assigning to each user a temporary container corresponding to the geographical location associated with the user device; in response to a user within the web conference sharing a document, saving the document in each temporary container; granting to each user permission to access the shared document within the temporary container assigned to each user and including a computer program product.

16. Further comprising receiving, in response to a user participating in the web conference and opting in to share information, a plurality of user information and a plurality of device information The computer program product according to claim 15.

17. Further comprising deleting the shared document from each temporary container in response to the web conference ending The computer program product according to claim 15 or 16.

18. Further comprising destroying each temporary container in response to the web conference ending The computer program product according to claim 17.

19. generating the temporary container for each identified geographical location is Generating one or more additional temporary containers within the geographical location based on the user data access level of each user having a user device IP address corresponding to the geographical location The computer program product according to any one of claims 15 to 18, further comprising the above. **Claim 20** The computer program product according to claim 16, wherein the plurality of device information is selected from the group including the type of user device, the serial number of the user device, the manufacturer number of the user device, the IP address of the user device, the connection type of the user device, and the connection strength of the user device. **Claim 21** A computer program, comprising program code means adapted to execute the method according to any one of claims 1 to 7 when the program is executed on a computer.