System

The system addresses security risks in AI office environments by integrating user authentication, real-time monitoring, and periodic reporting to ensure immediate response and compliance with corporate policies, enhancing security management.

JP2026024061APending Publication Date: 2026-02-13SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024126382
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-01
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

The integration of AI technology in office environments has increased security risks and made real-time security management difficult, leading to inadequate protection of information assets due to the challenges of detecting anomalies and enforcing corporate security policies.

Method used

A system that includes user authentication, real-time monitoring of terminal activities, and periodic security reporting to detect and respond to security risks, ensuring compliance with corporate security policies.

Benefits of technology

The system effectively reduces security risks by enabling real-time monitoring and immediate response to potential breaches, providing comprehensive security management from user authentication to risk detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026024061000001_ABST
    Figure 2026024061000001_ABST
Patent Text Reader

Abstract

A system is provided.SOLUTION: A system comprising: means for receiving user authentication information and performing authentication; means for sending an authentication result to a management server; means for the management server scanning applications and tools installed on each terminal based on a security policy of an enterprise and setting permissions and prohibitions based on the policy; means for sending activity data of each terminal to the management server in real time and detecting security risks at the management server; means for notifying a user of detected risks; and means for periodically generating and providing a security report to the user.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technology of the present disclosure relates to a system. [Background technology]

[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]

[0004] In recent years, the integration of AI technology into the basic office environments adopted by companies has improved convenience, but security risks have also increased exponentially. In particular, the use of a wide variety of AI tools and external services by employees increases the risk of information leaks and security breaches. As a result, real-time security management using conventional monitoring methods has become difficult, resulting in situations where companies' information assets cannot be adequately protected. This invention aims to solve this problem by providing a system that reduces security risks in companies' AI office environments and enables real-time monitoring and appropriate countermeasures. [Means for solving the problem]

[0005] To solve the above problems, the present invention provides a system including: a means for receiving user authentication information and performing authentication; a means for transmitting authentication results to a management server; a means for the management server to scan applications and tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy; a means for transmitting activity data from each terminal to the management server in real time and detecting security risks on the management server; a means for notifying users of detected risks; and a means for periodically generating and providing security reports to users. This system enables companies to reduce security risks in AI office environments and achieve appropriate security management. Furthermore, real-time monitoring enables immediate risk detection and response, minimizing the impact of security breaches.

[0006] "User Credentials" means a user's identification and authentication means for accessing a system, typically consisting of a username and password.

[0007] "Authentication" refers to the process of verifying that a user has valid authority based on user authentication information.

[0008] "Management server" refers to the central system that manages and enforces corporate security policies and monitors the activity of each terminal.

[0009] "Security policy" means the security rules and standards established by an enterprise that define permitted and prohibited actions.

[0010] "Terminal" means a computing device used by a user to access the system, including a personal computer or smartphone.

[0011] "Application" means software installed on a terminal to fulfill a specific purpose.

[0012] "AI Tools" refers to software or features that use artificial intelligence technology to provide specific functions.

[0013] "Real-time monitoring" refers to the process of instantly monitoring system and terminal activity and immediately detecting abnormalities.

[0014] "Security risk" means the possibility that systems or data may be exposed to threats such as unauthorized access or information leakage.

[0015] "Activity data" refers to information about the operations and behavior of a user or device, which allows us to understand how the system is being used.

[0016] A "security report" is a document that summarizes compliance with security policies and risk assessments based on monitored activity data. [Brief explanation of the drawings]

[0017] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7]FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram showing a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION

[0018] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.

[0019] First, the terms used in the following description will be explained.

[0020] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).

[0021] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.

[0022] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.

[0023] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.

[0024] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."

[0025] [First embodiment]

[0026] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0027] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0028] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0029] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.

[0030] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0031] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0032] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.

[0033] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0034] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0035] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0036] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0037] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0038] User Authentication and Login

[0039] To access the system, a user must first log in using their user authentication information. The user displays a login screen on their terminal and enters their username and password. The terminal sends these authentication information to the server, which verifies the authentication information. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and displays the dashboard screen to the user.

[0040] For example, when a user attempts to log in by entering their ID and password, the device sends this information to the server, which then verifies the authentication information and, if correct, displays the dashboard to the user.

[0041] Customizing your Office environment

[0042] After logging in, the server sends instructions to each device based on the company's security policy. Based on this, the device scans Office applications and checks the installed AI tools. Based on the policy received from the server, the device enables permitted tools and disables prohibited tools.

[0043] For example, if the server distributes a policy that "prohibits a specific AI tool," the device will disable that tool and be configured to only use other permitted tools.

[0044] Security Monitoring

[0045] The server monitors the activity of each device in real time. The device records user operations and behavior as a log and periodically sends this to the server. The server analyzes the received activity data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and prompts them to take action.

[0046] For example, if the server detects suspicious data transmission activity from a specific device, it notifies the administrator in real time and takes necessary measures.

[0047] Generate regular security reports

[0048] The server periodically generates security reports based on the collected activity data, including policy violation statistics, risk assessments, and recommended countermeasures. The reports are provided to administrators to help them review and improve their security policies.

[0049] As a specific example, data from the past month is compiled and a report is created that details data transmission, usage of AI tools, detected risks, etc., and shared with administrators.

[0050] Attack detection and alerting

[0051] The server monitors known attack patterns and anomalous activity in real time to detect possible unauthorized access or security breaches. If a device detects anomalous activity, it notifies the server. The server then performs a detailed analysis and immediately sends an alert to the administrator in the event of an emergency. If necessary, it also restricts the device's network connection and implements additional security measures.

[0052] For example, if a server detects abnormal activity such as an attempt to send a large amount of data externally, it will immediately issue an alert and temporarily block the network connection of the device in question. Administrators will receive a notification, investigate the cause, and take measures.

[0053] The processing flow will be explained below.

[0054] User Authentication and Login

[0055] Step 1:

[0056] The user opens the login screen. The device displays the login screen.

[0057] Step 2:

[0058] The user enters their authentication information (username and password). The user enters their username and password and clicks the "Login" button.

[0059] Step 3:

[0060] The device sends authentication information to the server. The device sends the entered username and password to the server.

[0061] Step 4:

[0062] The server validates the credentials: it checks against its database to see if the username and password are correct.

[0063] Step 5:

[0064] The server sends the authentication result to the terminal. If the authentication is successful, the server generates a security token and sends it to the terminal.

[0065] Step 6:

[0066] The terminal displays the authentication result to the user. If authentication is successful, the terminal displays the dashboard screen, and if authentication is unsuccessful, it displays an error message.

[0067] Customizing your Office environment

[0068] Step 1:

[0069] The server sends the security policy to the terminal. The server obtains the company's security policy and sends that information to the terminal.

[0070] Step 2:

[0071] The device scans the Office applications. The device scans the installed Office applications and lists the AI ​​tools used.

[0072] Step 3:

[0073] The device checks whether the AI ​​tool can be used. The device compares the listed AI tools with the security policy obtained from the server to identify permitted and prohibited tools.

[0074] Step 4:

[0075] The device updates the settings for Office applications, disabling prohibited AI tools based on security policies and updating the settings so that only permitted tools are available.

[0076] Step 5:

[0077] The device sends the results of the configuration update to the server, providing information about which tools were allowed and which were disabled.

[0078] Security Monitoring

[0079] Step 1:

[0080] The server starts real-time monitoring. The server receives activity data from each device in real time and starts monitoring.

[0081] Step 2:

[0082] The device sends activity data to the server. The device records user activity (use of AI tools, external access attempts, etc.) as a log and periodically sends it to the server.

[0083] Step 3:

[0084] The server analyzes the activity. The server analyzes the received activity data to detect any behavior that violates security policies or suspicious activity.

[0085] Step 4:

[0086] If the server detects an abnormality, it issues an alert. The server generates an alert about the detected abnormality or security violation and notifies the user (administrator).

[0087] Step 5:

[0088] The server will take action and, if necessary, temporarily restrict access to the affected device to carry out further analysis and / or action.

[0089] Generate regular security reports

[0090] Step 1:

[0091] The server aggregates the activity data collected from all devices on a weekly or monthly basis.

[0092] Step 2:

[0093] The server generates security reports. The server automatically generates security reports based on the aggregated data, including risk assessments, policy violations, and recommended actions.

[0094] Step 3:

[0095] The server sends the report to the user (administrator). The server displays the generated report on the dashboard and sends a notification email to the user (administrator).

[0096] Step 4:

[0097] The user (administrator) checks the report. The user (administrator) checks the report and implements necessary countermeasures or policy adjustments.

[0098] Attack detection and alerting

[0099] Step 1:

[0100] The server monitors attack patterns. The server monitors known attack patterns and new anomalous activity in real time.

[0101] Step 2:

[0102] If the device detects any abnormal activity, it will notify the server. The device can also detect any abnormal activity on its own and notify the server of any suspicious activity.

[0103] Step 3:

[0104] The server performs a detailed analysis. The server performs a detailed analysis of the notified abnormal activity and evaluates the urgency of the event.

[0105] Step 4:

[0106] The server sends an alert to the user (administrator). If the level of urgency is high, the server immediately sends an alert to the user (administrator) to prompt them to take action.

[0107] Step 5:

[0108] The server will initiate countermeasures, including restricting the network connection of the affected device and contacting the security team, if necessary.

[0109] Example 1

[0110] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0111] In conventional systems, user authentication, terminal application management, and security monitoring are all performed separately, making it difficult to implement integrated security measures.In addition, there are issues with high security risks due to the difficulty of detecting anomalies in real time and strictly enforcing corporate security policies.

[0112] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0113] In this invention, the server includes means for receiving user authentication information and performing authentication, means for transmitting authentication results to a management server, means for the management server to scan software and tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy, means for transmitting operation records of each terminal to the management server in real time and detecting security risks in the management server, means for notifying an administrator of detected risks, means for periodically generating security reports and providing them to the administrator, means for generating a security token if authentication is successful and displaying a dashboard screen to the user, and means for monitoring known attack patterns and abnormal activity in real time and sending an alert to the administrator in the event of an emergency. This enables consistent management from user authentication to security monitoring and effectively reduces security risks.

[0114] "User Credentials" means information a user provides to identify themselves to a system, typically including a username and password.

[0115] "Authentication" is the process of verifying whether the authentication information provided by a user is correct and granting access to a system.

[0116] The "management server" is a central server that applies the company's security policies and monitors the activity of each terminal.

[0117] A "security policy" refers to the rules and standards that a company sets to protect information and prevent unauthorized access.

[0118] "Software" is a general term for programs and applications installed on a terminal.

[0119] A "tool" is a program used for a specific function or purpose.

[0120] "Operation record" is data that records the operations and actions of a user on a terminal.

[0121] A "security risk" is a situation that could threaten the security of a system, such as information leakage or unauthorized access.

[0122] A "security token" is digital information issued to a user who has been successfully authenticated, allowing access to a system.

[0123] The "dashboard screen" is a screen that displays system operation and management information, which can be accessed by a user after logging in.

[0124] "Attack patterns" refer to the methods and characteristics of known cyber attacks.

[0125] "Activity" is a general term for all operations and actions performed on a device.

[0126] An "alert" is a warning message sent to an administrator when an abnormality or risk is detected.

[0127] The present invention provides a system that realizes consistent management from user authentication to security monitoring, and effectively reduces security risks within a company. Specific embodiments of the system will be described below.

[0128] User Authentication and Login

[0129] In order for a user to access a system, they must first log in using their user authentication information. The user displays a login screen on their terminal and enters their username and password. The terminal sends this authentication information to the server, which then verifies it. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and displays the dashboard screen to the user. For example, when a user attempts to log in by entering their ID and password, the terminal sends this information to the server. The server verifies the authentication information, and if it is correct, displays the dashboard to the user.

[0130] Customizing your Office environment

[0131] After logging in, the server sends instructions to each device based on the company's security policy. Based on this, the device scans Office applications and checks for installed AI tools. Based on the policy received from the server, the device enables permitted tools and disables prohibited tools. For example, if the server distributes a policy that "prohibits a specific AI tool," the device will disable that tool and be configured to use only other permitted tools.

[0132] Security Monitoring

[0133] The server monitors the activity of each device in real time. The device records user operations and behavior as a log and periodically sends this to the server. The server analyzes the received activity data and detects security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and urges them to take measures. For example, if the server detects suspicious data transmission activity from a specific device, it notifies the administrator of this information in real time and takes the necessary measures.

[0134] Generate regular security reports

[0135] The server periodically generates security reports based on the collected activity data. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. The reports are provided to administrators and are used to review and improve security policies. For example, data from the past month is aggregated to create a report detailing data transmission, AI tool usage, and detected risks, which is shared with administrators.

[0136] Attack detection and alerting

[0137] The server monitors known attack patterns and abnormal activity in real time to detect possible unauthorized access or security breaches. If a terminal detects abnormal activity, it also notifies the server. The server performs a detailed analysis and, in the event of an emergency, immediately sends an alert to the administrator. If necessary, it will also restrict the network connection of the terminal in question and implement additional security measures. For example, if the server detects abnormal activity that attempts to send a large amount of data externally, it will immediately issue an alert and temporarily block the network connection of the terminal in question. The administrator receives the notification, investigates the cause, and takes measures.

[0138] Example prompts to input to the generative AI model

[0139] "We need documentation that explains how the server and device work together during the user authentication and login process. If the user credentials are correct, please provide details on how the server and device exchange security tokens and display the dashboard screen."

[0140] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0141] Step 1:

[0142] The user launches an application on the terminal and the login screen is displayed. The user enters a username and password. This input data is sent to the terminal. Specifically, the user enters the required information into the login form and clicks "Login."

[0143] Step 2:

[0144] The terminal sends the entered user authentication information to the server. As a specific example, the terminal sends an HTTP POST request and includes the user name and password in the payload. At this time, it receives the user authentication information as input data and executes the process of sending it to the server.

[0145] Step 3:

[0146] The server checks the received authentication information against its database. Specifically, it runs an SQL query against the database to see if the matching username and password combination exists. Based on this input, it validates the authentication information and, if authentication is successful, performs a data calculation to generate a security token.

[0147] Step 4:

[0148] If authentication is successful, the server generates a security token and sends it to the device. Specifically, the server generates a JWT (JSON Web Token) and embeds user and session information in it. The generated security token is sent as output data to the device.

[0149] Step 5:

[0150] The terminal uses the received security token to display the dashboard screen to the user. Specifically, the terminal includes the token in the HTTP header, retrieves the dashboard data from the server, and displays it on the screen. As a result, the user can access the dashboard screen.

[0151] Step 6:

[0152] The server sends the company's security policy to the device. Specifically, the server sends the policy data in JSON format to the device. Based on this input data, the server prepares policy data to scan the Office applications on the device.

[0153] Step 7:

[0154] The device scans the Office application based on the received policy and checks the installed AI tools. Specifically, the device's script compares the installed applications with the policy data. Based on this input data, the device outputs the scan results.

[0155] Step 8:

[0156] The device enables permitted tools and disables prohibited tools. Specifically, the device modifies registry settings and application configuration files and executes scripts to enable permitted tools. The output data sets the enabled / disabled status of the tools on the device.

[0157] Step 9:

[0158] The server monitors the activity of each device in real time. Specifically, the server monitors specific ports and records communications from each device as a log. Based on this input data, real-time monitoring data is generated.

[0159] Step 10:

[0160] The terminal records the user's operations and behavior as a log and periodically sends it to the server. Specifically, the terminal uploads the log file to the server at regular intervals. An operation log is generated based on this input data and sent.

[0161] Step 11:

[0162] The server analyzes the received activity data to detect security risks and policy violations. Specifically, the server uses machine learning models to detect abnormal patterns. This data is then processed to generate risk assessment data.

[0163] Step 12:

[0164] If an abnormality is detected, the server notifies the administrator and prompts them to take measures. Specifically, when the server detects an abnormality, it sends an alert to the administrator using a messaging service. The administrator receives this notification as output data.

[0165] Step 13:

[0166] The server periodically generates security reports based on collected activity data. Specifically, the server aggregates and analyzes the data using Python scripts, and generates reports based on this input data.

[0167] Step 14:

[0168] The server provides the generated report to the administrator. Specifically, the server uses report generation software to visualize the aggregated results and create a report in PDF format. The report generated as output data is then sent to the administrator via the mail server.

[0169] Step 15:

[0170] The server monitors known attack patterns and anomalous activity in real time. Specifically, the server analyzes data in real time using a log analysis tool. Based on this input data, the server outputs monitoring data.

[0171] Step 16:

[0172] If the device detects abnormal activity, it notifies the server. Specifically, the device runs the anomaly detection script and notifies the server via an API request. Anomaly notification data is generated based on this input data.

[0173] Step 17:

[0174] The server performs a detailed analysis and sends an alert to the administrator in the event of an emergency. Specifically, the server immediately sends an alert to the administrator via SMS or email based on the analysis results. The administrator receives an emergency notification as output data.

[0175] Step 18:

[0176] If necessary, the server restricts the network access of the relevant device and implements additional security measures. Specifically, the server changes the firewall settings to restrict the network access of the specific device. The output data is the network restriction for the device.

[0177] (Application example 1)

[0178] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0179] In recent years, the security of robots used in factories has become increasingly important. However, these robots require complex operations, making it difficult for administrators to monitor security risks in real time, and there is a lack of mechanisms for immediate response in the event of abnormal operations. Furthermore, generating regular security reports and detecting policy violations is often a manual process, creating a demand for efficient security management. For this reason, it has become essential to introduce a system that monitors robot operation logs in real time and issues immediate alerts when an abnormality occurs.

[0180] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0181] In this invention, the server includes: means for receiving user authentication information and performing authentication; means for transmitting authentication results to a management device; means for scanning software and tools installed on each terminal based on a company's security policy and setting permissions and prohibitions based on the policy; means for transmitting activity data from each terminal to the management device and detecting security risks in the management device; means for the management device to monitor robot operation logs and detect security risks in real time; means for notifying users of detected risks; means for periodically generating and providing security reports to users; and means for immediately issuing alerts when abnormal operations or security risks are detected. This enables real-time monitoring of operation logs of robots used in a factory and immediate alerts when abnormalities occur. Furthermore, automatic generation of periodic security reports enables efficient security management.

[0182] Definition statement:

[0183] "User authentication information" refers to identification information required for a user to access the system, and is primarily composed of a username and password.

[0184] A "management server" is a server for centrally managing multiple terminals and devices connected to a network.

[0185] A "security policy" is a set of rules that define security standards and norms for systems and devices.

[0186] "Software" is a set of instructions executed by a computer, a program that performs a specific purpose or function.

[0187] A "tool" is a part of software, a module or application that realizes a specific function or operation.

[0188] "Activity data" is a record of operations and events performed by users and systems.

[0189] A "security risk" is a threat or danger to the safety or reliability of a system or data.

[0190] "Risk notification" is the process of sending alerts to users and administrators about detected security risks.

[0191] "Security Report" means documents and data that analyze, evaluate, and report system activity and security status.

[0192] A "robot operation log" is a record of the operation and behavior of robots used in a factory.

[0193] "Anomaly detection" is the process by which a system automatically identifies and detects unusual operations or patterns.

[0194] "Real-time monitoring" is the process of monitoring the operation of systems and devices in real time and responding immediately.

[0195] An "alert" is a warning message that notifies a user or administrator when an abnormality or problem occurs.

[0196] The system for implementing this invention includes a series of processes that start with receiving user authentication information, control terminals based on security policies and perform real-time monitoring, and monitor the robot's operation log and detect abnormalities. The specific processing method for each step is described below.

[0197] First, user authentication information is received and authentication is performed. The user enters their authentication information (e.g., username and password) into the terminal. The terminal sends this authentication information to the management server. The management server verifies the received authentication information and confirms that the user is a valid user. If this authentication is successful, the management server generates a security token and sends it to the terminal. Using this token, the user can access the system and view the dashboard.

[0198] Next, the management server scans the software and tools installed on each terminal based on the company's security policy and sets allowed and prohibited tools. Specifically, the management server enables only allowed tools and disables prohibited tools according to the security policy. This process keeps the terminal environment in line with the security policy.

[0199] Furthermore, activity data from each device is sent to a management server in real time, and security risks are detected by the management server. For example, if a device uses a specific tool or performs an unauthorized operation, the operation log is sent to the server. The management server analyzes these logs and detects abnormal operations and security risks in real time.

[0200] The management server monitors the robot's operation log in real time and immediately issues an alert if an abnormality occurs. For example, if a robot attempts to use a prohibited tool, the log is immediately sent to the management server and detected as an abnormality. The management server uses this information to issue an alert and notify the user. The user receives this notification and can respond promptly.

[0201] This system generates security reports periodically. The management server automatically generates security reports based on activity data over a certain period of time. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. The generated reports are provided to users and can be used to review and improve security policies.

[0202] For example, if a log is sent when a robot used in a factory attempts to use "unapproved_tool," it will be detected as an unauthorized operation and an alert will be sent immediately to the administrator, who can then take prompt action based on this notification to prevent security risks.

[0203] Example prompt sentence:

[0204] "Please enter the logs of the robots used in the factory. Based on the security policy, we will determine whether this log violates the policy."

[0205] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0206] Step 1:

[0207] To access the system, a user enters a username and password into a terminal. The terminal sends this authentication information to a server. The server checks the received authentication information against a database to verify that the user is a valid user. If authentication is successful, the server generates a security token and sends it to the terminal. The input is the user's authentication information, and the output is a security token.

[0208] Step 2:

[0209] The terminal uses the security token received from the server to authenticate the user's access. If successful, the dashboard screen is displayed to the user. The input is the security token and the output is the dashboard screen. The terminal is configured to allow the user to access the authorized services and tools.

[0210] Step 3:

[0211] The server scans the software and tools installed on the terminal based on the company's security policy, enables permitted tools, and disables prohibited tools. The input is the security policy and the terminal's software information, and the output is instructions to change the settings. The server instructs the terminal to change the settings based on the policy.

[0212] Step 4:

[0213] Each device sends activity data to the server in real time. The input is the device's activity data, and the output is data sent to the server. The server receives this data and analyzes the date, time, and log content. As a result of the analysis, security risks are detected.

[0214] Step 5:

[0215] The server analyzes the received activity data and immediately notifies the user if a security risk is detected. The input is the analyzed activity data, and the output is a notification to the user. The server identifies specific unauthorized operations or suspicious behavior in real time and issues warnings as necessary.

[0216] Step 6:

[0217] The server periodically generates a security report based on the collected activity data. The input is the collected activity data, and the output is a security report. The report contains statistics on policy violations, risk assessments, and recommended countermeasures. The generated report is provided to the user.

[0218] Step 7:

[0219] The server monitors the robot's operation log in real time and immediately issues an alert if an abnormality occurs. The input is the operation log and the output is an alert notification. Specifically, when the robot attempts to use the "unapproved_tool," the log is sent to the server and detected as an unauthorized operation. Based on this, the server issues an alert to the administrator, enabling a prompt response.

[0220] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0221] User Authentication and Login

[0222] To access the system, a user logs in using user authentication information. The user displays a login screen on the terminal and enters their username and password. The terminal sends this authentication information to the server, which verifies the authentication information and verifies its validity. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and provides the dashboard screen to the user.

[0223] As a specific example, when a user attempts to log in by entering their ID and password, the device sends this information to the server, and if the server successfully authenticates, it displays a dashboard to the user.

[0224] Customizing your Office environment

[0225] After logging in, the server sends instructions based on the company's security policy to each device. The device then scans the Office applications and lists the installed AI tools. The server then enables permitted tools and disables prohibited tools based on the policy.

[0226] As a specific example, if a policy stating that "certain AI tools are prohibited" is distributed from the server, the device will disable that tool and be configured to use only other permitted tools.

[0227] Security Monitoring

[0228] The server monitors the activity of each device in real time. The device records user behavior and operations as a log and periodically sends it to the server. The server analyzes the received activity data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and takes necessary measures.

[0229] As a specific example, if the server detects suspicious data transmission from a specific device, it notifies the administrator of this information in real time and takes the necessary measures.

[0230] Generate regular security reports

[0231] The server periodically generates security reports based on collected activity data. These reports include policy violation statistics, risk assessments, and recommended countermeasures. The reports provided to administrators can be used to review and improve security policies.

[0232] As a specific example, data from the past month will be aggregated and a report will be generated that details data transmission, usage of AI tools, detected risks, etc., and provided to administrators.

[0233] Attack detection and alerting

[0234] The server monitors known attack patterns and anomalous activity in real time to detect potential unauthorized access or security breaches. This includes notifying users when anomalous activity is detected on the device. If anomalous activity is detected, the server performs detailed analysis and immediately sends an alert to the administrator. If necessary, the server temporarily restricts the device's network connection and takes additional security measures.

[0235] For example, if a server detects abnormal activity such as an attempt to transmit large amounts of data, it will immediately issue an alert and temporarily restrict the network connection of the device in question. Administrators will receive a notification, investigate the cause, and take measures.

[0236] Emotion recognition by emotion engine

[0237] An emotion engine is used to recognize the user's emotions. This engine uses the user's facial recognition information and voice analysis to identify emotions. Facial recognition information is captured using the device's camera, and the emotion engine analyzes it. Voice analysis is captured using the microphone, and the emotion engine analyzes it. The recognized emotion data is sent to the management server.

[0238] For example, when a user works on a device, the device's camera captures the user's facial expressions, and the emotion engine detects "stress." If the stress level is high, the system notifies the administrator.

[0239] Integrating emotion and activity data

[0240] By integrating the emotional data recognized by the emotion engine with the activity data sent from the device, highly accurate security risk assessment becomes possible. The server analyzes this data in real time and assesses risk based on emotional fluctuations and abnormal activity. This allows the system to immediately detect the possibility of increased risk when the user is experiencing emotional stress, allowing early countermeasures to be taken.

[0241] As a specific example, if the analysis of emotional and activity data detects an abnormality such as "attempting to send a large amount of data externally while under high stress levels," the server will immediately issue an alert and take measures such as restricting the user's activity.

[0242] The processing flow will be explained below.

[0243] User Authentication and Login

[0244] Step 1:

[0245] The user opens the login screen. The device displays the login screen.

[0246] Step 2:

[0247] The user enters their authentication information (username and password). The user enters their username and password and clicks the "Login" button.

[0248] Step 3:

[0249] The device sends authentication information to the server. The device sends the entered username and password to the server.

[0250] Step 4:

[0251] The server validates the credentials: it checks against its database to see if the username and password are correct.

[0252] Step 5:

[0253] The server sends the authentication result to the terminal. If the authentication is successful, the server generates a security token and sends it to the terminal.

[0254] Step 6:

[0255] The terminal displays the authentication result to the user. If authentication is successful, the terminal displays the dashboard screen, and if authentication is unsuccessful, it displays an error message.

[0256] Customizing your Office environment

[0257] Step 1:

[0258] The server sends the security policy to the terminal. The server obtains the company's security policy and sends that information to the terminal.

[0259] Step 2:

[0260] The device scans the Office applications. The device scans the installed Office applications and lists the AI ​​tools used.

[0261] Step 3:

[0262] The device checks whether the AI ​​tool can be used. The device compares the listed AI tools with the security policy obtained from the server to identify permitted and prohibited tools.

[0263] Step 4:

[0264] The device updates the settings for Office applications, disabling prohibited AI tools based on security policies and updating the settings so that only permitted tools are available.

[0265] Step 5:

[0266] The device sends the results of the configuration update to the server, providing information about which tools were allowed and which were disabled.

[0267] Security Monitoring

[0268] Step 1:

[0269] The server starts real-time monitoring. The server receives activity data from each device in real time and starts monitoring.

[0270] Step 2:

[0271] The device sends activity data to the server. The device records user activity (use of AI tools, external access attempts, etc.) as a log and periodically sends it to the server.

[0272] Step 3:

[0273] The server analyzes the activity. The server analyzes the received activity data to detect any behavior that violates security policies or suspicious activity.

[0274] Step 4:

[0275] If the server detects an abnormality, it issues an alert. The server generates an alert about the detected abnormality or security violation and notifies the user (administrator).

[0276] Step 5:

[0277] The server will take action and, if necessary, temporarily restrict access to the affected device to carry out further analysis and / or action.

[0278] Generate regular security reports

[0279] Step 1:

[0280] The server aggregates the activity data collected from all devices on a weekly or monthly basis.

[0281] Step 2:

[0282] The server generates security reports. The server automatically generates security reports based on the aggregated data, including risk assessments, policy violations, and recommended actions.

[0283] Step 3:

[0284] The server sends the report to the user (administrator). The server displays the generated report on the dashboard and sends a notification email to the user (administrator).

[0285] Step 4:

[0286] The user (administrator) checks the report. The user (administrator) checks the report and implements necessary countermeasures or policy adjustments.

[0287] Attack detection and alerting

[0288] Step 1:

[0289] The server monitors attack patterns. The server monitors known attack patterns and new anomalous activity in real time.

[0290] Step 2:

[0291] If the device detects any abnormal activity, it will notify the server. The device can also detect any abnormal activity on its own and notify the server of any suspicious activity.

[0292] Step 3:

[0293] The server performs a detailed analysis. The server performs a detailed analysis of the notified abnormal activity and evaluates the urgency of the event.

[0294] Step 4:

[0295] The server sends an alert to the user (administrator). If the level of urgency is high, the server immediately sends an alert to the user (administrator) to prompt them to take action.

[0296] Step 5:

[0297] The server will initiate countermeasures, including restricting the network connection of the affected device and contacting the security team, if necessary.

[0298] Emotion recognition by emotion engine

[0299] Step 1:

[0300] When a user uses the device, their actions are captured by the camera and microphone. The device uses the camera to recognize the user's face and the microphone to record their voice.

[0301] Step 2:

[0302] The device launches an emotion engine to analyze the captured data, which then recognizes emotions from the user's facial expressions and voice.

[0303] Step 3:

[0304] The device sends the recognized emotion data to the server in real time for use in assessing security risks.

[0305] Integrating emotion and activity data

[0306] Step 1:

[0307] The server receives emotion data and activity data in real time, and prepares the data for integration and analysis.

[0308] Step 2:

[0309] The server analyzes the emotion and activity data and performs an integrated risk assessment based on the user's stress level and abnormal activity.

[0310] Step 3:

[0311] The server notifies the results of the integrated risk assessment in real time, and if an abnormality is detected, the server immediately sends an alert to the administrator so that necessary measures can be taken.

[0312] As a specific example, if a user attempts to send a large amount of data while under high stress, the server will immediately issue an alert and take measures such as restricting the user's activity.

[0313] Stress level assessment and alerts

[0314] Step 1:

[0315] The device periodically captures the user's emotional data and transmits it to the server, allowing the server to continuously understand the user's emotional state.

[0316] Step 2:

[0317] The server evaluates the user's stress level based on the emotional data. Based on the data detected by the emotion engine, the server calculates the user's stress level.

[0318] Step 3:

[0319] If the server detects a high stress state, it notifies the administrator. If the stress level exceeds a certain threshold, the server immediately issues an alert, prompting the administrator to take action.

[0320] As a specific example, if the server detects an increase in the user's stress level and this reaches a dangerous level, the administrator will be notified to take timely action.

[0321] Example 2

[0322] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0323] While conventional systems provide basic security functions such as user authentication, security policy enforcement, and real-time monitoring, they lack risk assessment that takes into account the emotional state of the user and highly accurate risk detection using integrated data. Furthermore, early detection of security risks and notification to administrators can be delayed, requiring rapid response.

[0324] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0325] In this invention, the server includes means for receiving user authentication information and performing authentication, means for transmitting the authentication result to the management server, means for the management server to scan the software and support tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy, means for transmitting activity data of each terminal to the management server in real time and detecting security risks in the management server, means for notifying an administrator of detected risks, means for periodically generating security reports and providing them to the administrator, means for capturing information using the terminal's camera and microphone to recognize user emotions and analyzing it with an emotion engine, and means for evaluating risks by integrating the emotion data and activity data and notifying an administrator if a high risk is detected. This enables highly accurate risk evaluation that takes the user's emotional state into consideration and rapid risk response.

[0326] "User Credentials" means information such as a username and password provided by a user to access a system.

[0327] "Authentication" is the process of verifying that the user credentials provided are valid.

[0328] A "management server" is a central management device for applying security policies, analyzing activity data, and detecting risks.

[0329] A "corporate security policy" is a set of rules and guidelines regarding information security established by a company.

[0330] A "terminal" is a device, such as a computer or smartphone, that a user uses to access the system.

[0331] "Software" is a general term for applications and programs installed on a terminal.

[0332] "Support tools" are software and applications that support users' work and tasks.

[0333] "Activity data" is a record of information about the user's operations and actions performed on the terminal.

[0334] "Security risks" are threats to systems and data, such as unauthorized access, data leakage, and destruction.

[0335] An "emotion engine" is software that analyzes emotions from a user's facial expressions and voice.

[0336] "Emotion data" is information about the user's emotions analyzed by the emotion engine.

[0337] This invention relates to a system that includes receiving user authentication information, authentication, applying security policies, real-time monitoring, emotion recognition using an emotion engine, and integrated risk assessment. This system is composed of elements including a server, a terminal, and a user, and specific embodiments thereof are described below.

[0338] First, the user opens the login screen on the device and enters their username and password. The device encrypts this authentication information and sends it to the server. The server compares the received authentication information with a database to verify its validity. If authentication is successful, the server generates a security token and sends it to the device. The device receives the security token and displays the dashboard screen to the user. For example, if a user attempts to log in by entering "user123" and "password123," the server authenticates and the dashboard is displayed.

[0339] Next, after logging in, the server sends the company's security policy to each terminal. Based on this, the terminal scans the installed Office applications and creates a list of available assistive tools. Based on the policy, the server enables permitted tools and disables prohibited tools. For example, if the server distributes a policy that "a specific assistive tool is prohibited," the terminal disables that tool and allows only other permitted tools to be used.

[0340] The server also monitors the activity data of each device in real time. The device records user operations as a log and periodically sends it to the server. The server analyzes this data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and takes necessary measures. For example, if the server detects suspicious data transmission from a specific device, it notifies the administrator in real time and implements necessary measures.

[0341] The server periodically generates security reports based on collected activity data. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. Administrators can review and improve security policies based on these reports. As a specific example, data from the past month is aggregated to generate a security report that includes statistics on policy violations and risk assessments, and the report is provided to administrators.

[0342] Furthermore, this system has the ability to recognize the user's emotions using an emotion engine. The device's camera and microphone are used to capture the user's facial expressions and voice, which the emotion engine analyzes to identify the emotion. The recognized emotion data is sent to the server. For example, if the camera captures the user's facial expressions while the user is working on the device and the emotion engine detects "stress," the information is notified to the administrator.

[0343] Finally, the server integrates the emotion data and activity data to perform a highly accurate risk assessment. By integrating the emotion data recognized by the emotion engine with the activity data sent from the device, the accuracy of the risk assessment is improved. For example, if a large amount of data transmission is detected in a state of high stress, the server will immediately issue an alert and take measures such as restricting the user's activity.

[0344] Example prompts for generative AI models

[0345] Here are some examples of prompts for generative AI models:

[0346] "The system you are trying to log into first requires a username and password. You enter this into the login screen, the server authenticates you, generates a security token, and if successful, displays the dashboard. Can you please explain the process in detail?"

[0347]

[0348] After logging in, the server issues instructions to the terminal based on the company's security policy. The terminal scans the Office applications and creates a list of support tools. Explain how the server controls the tools based on the policy.

[0349] These prompts can be used to obtain instructions from the generative AI model regarding specific system processing steps.

[0350] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0351] Step 1: Enter and submit user credentials

[0352] The user enters their username and password into the login screen of the device.

[0353] Input: Username and Password

[0354] The terminal encrypts the entered information and sends it to the server.

[0355] Output: Encrypted username and password

[0356] As a specific example of operation, the user inputs "user123" and "password123".

[0357] Step 2: Verify credentials

[0358] The server receives the encrypted username and password and checks it against a database.

[0359] Input: Encrypted username and password

[0360] A database check is performed to verify that the user is a valid user.

[0361] Output: Authentication result (success or failure)

[0362] As a specific example of operation, the server checks the database to see if the combination of "user123" and "password123" is correct.

[0363] Step 3: Generate and send a security token

[0364] If the authentication is successful, the server generates a security token and sends it to the terminal.

[0365] Input: Authentication result (success)

[0366] A security token is generated and sent to the terminal via the network.

[0367] Output: Security token

[0368] As a specific example of operation, the server generates a security token for "user123" and sends it to the terminal.

[0369] Step 4: View the dashboard

[0370] The terminal stores the received security token and displays the dashboard screen to the user.

[0371] Input: Security Token

[0372] Save the security token and display the dashboard screen.

[0373] Output: Dashboard screen displayed

[0374] As a specific example of operation, the terminal uses the security token to display a dashboard to the user.

[0375] Step 5: Applying security policies

[0376] The server transmits the security policy to the terminal.

[0377] Input: None (Policy is set in advance)

[0378] The security policy is sent to each terminal.

[0379] Output: Security policy

[0380] As a specific example of operation, the server sends a policy to the terminal that "certain support tools are prohibited."

[0381] Step 6: Scanning Office applications

[0382] The device receives the security policy and scans the installed Office applications.

[0383] Input: Security policy

[0384] Scan your Office applications and create a list of available assistive tools.

[0385] Output: List of supporting tools

[0386] As a specific example of operation, it scans the tools installed on the device and creates a list.

[0387] Step 7: Enable and disable tools

[0388] The server receives the list and enables or disables the tools based on the policy.

[0389] Input: A list of support tools and security policies

[0390] Parse the list and control the tool based on your policy.

[0391] Output: Tool enable / disable setting

[0392] As a specific example of operation, a specific support tool is disabled and other tools are enabled.

[0393] Step 8: Real-time monitoring

[0394] The terminal records the user's operations as a log and periodically sends it to the server.

[0395] Input: User operation log

[0396] Operation logs are recorded and periodically sent to the server.

[0397] Output: Operation log data

[0398] As a specific example of operation, the terminal records the user's operations in real time and transmits them to the server.

[0399] Step 9: Detect security risks

[0400] The server analyzes the received operation log data and detects security risks and policy violations.

[0401] Input: Operation log data

[0402] Analyze log data and assess risk.

[0403] Output: Risk assessment results and alert notifications

[0404] As a specific example of operation, the server detects suspicious data transmission and notifies the administrator.

[0405] Step 10: Generate and provide security reports

[0406] The server generates security reports based on periodically collected operation log data.

[0407] Input: Operation log data

[0408] Consolidate log data and generate reports.

[0409] Output: Security report

[0410] As a specific example of how it works, a report is generated that includes statistics on policy violations over the past month and a risk assessment.

[0411] Step 11: Capture and analyze emotion data

[0412] The device's camera and microphone are used to capture the user's facial expressions and voice, which are then analyzed by the emotion engine.

[0413] Input: User's facial expression data and voice data

[0414] The emotion engine analyzes the data and identifies emotions.

[0415] Output: Emotion data

[0416] As a specific example of operation, the user's facial expression is captured and "stress" is detected.

[0417] Step 12: Integrating emotion and activity data

[0418] The server integrates the emotion data and operation log data to perform risk assessment.

[0419] Input: Emotion data and operation log data

[0420] Integrate data to assess risk with precision.

[0421] Output: Risk assessment results and alert notifications

[0422] As a specific example of operation, if a large amount of data transmission is detected while the stress level is high, the server will issue an alert.

[0423] (Application example 2)

[0424] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0425] Traditional user authentication and security monitoring systems lack real-time analysis and integration of emotional data, making it difficult to properly detect security risks when users are in emotionally unstable situations. Furthermore, it is difficult to respond immediately when abnormal activity occurs, making it impossible to prevent potential security risks. This has resulted in serious gaps in enterprise-wide security measures.

[0426] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes: means for receiving user authentication information and performing authentication; means for transmitting the authentication result to the management server; means for the management server to scan applications and tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy; means for transmitting activity data of each terminal to the management server in real time and detecting security risks in the management server; means for notifying the user of the detected risks; means for periodically generating security reports and providing them to the user; means for analyzing the emotion data of the user of each terminal using an emotion engine and transmitting the analysis results to the management server; means for integrating the emotion data and activity data to evaluate security risks in real time; and means for immediately notifying the administrator when an abnormality is detected. This enables highly accurate security risk evaluation using emotion data, allowing for early detection of risks caused by abnormal activity or emotions and rapid response.

[0427] "User authentication information" refers to information provided by a user to authenticate themselves to the system, such as a user ID and password or biometric information.

[0428] A "management server" is a central server device that manages security policies within a company and monitors the status and operation of terminals.

[0429] A "security policy" is a set of guidelines and standards established by a company to protect information and maintain the security of its systems.

[0430] "Applications and Tools" refers to software products and utilities installed on the device.

[0431] "Activity data" is data that records a user's operation history and system usage.

[0432] "Security risk" refers to potential dangers such as unauthorized access to systems and data, information leaks, and attacks.

[0433] An "emotion engine" is a system that analyzes a user's facial expressions and voice to identify their emotional state at that time (for example, stress, joy, anger, etc.).

[0434] "Emotion data" is data that indicates the user's emotional state analyzed by the emotion engine.

[0435] An "anomaly" is unexpected behavior, such as irregular operations or data transmissions that are not considered normal.

[0436] "Notifying the user" means alerting the user about the detected security risk.

[0437] "Security Report" means a document generated periodically that contains detailed information about compliance with security policies and detected risks.

[0438] "Integration" means combining multiple pieces of data or information into one and analyzing it.

[0439] The programs that make up part of the system that realizes this application example provide various functions such as user authentication, security monitoring, emotion recognition, etc. Specifically, the following hardware and software are used:

[0440] Hardware used

[0441] Client terminal: High-performance PC or smart device

[0442] Camera and microphone: High-resolution camera (e.g., a generic webcam), high-quality microphone (e.g., a high-end microphone)

[0443] Software used

[0444] Server: A general-purpose cloud service provider's server (e.g., cloud server)

[0445] Software framework: Java, Spring Boot, TensorFlow (for emotion recognition)

[0446] Specific details of processing

[0447] 1. User authentication function

[0448] The terminal acquires user authentication information and sends it to the server. The server verifies the authentication information and, if valid, generates a security token and sends it to the terminal. This allows the user to access the system and use various functions.

[0449] 2. Customizing the Office environment

[0450] The server scans the tools installed on each device based on the company's security policy. Only tools permitted by the server are enabled, and prohibited tools are disabled. This creates an environment that complies with the company's security policy.

[0451] 3. Security monitoring function

[0452] The device records user operations and activity data and periodically sends it to the server. The server analyzes the received data in real time and detects security risks. If suspicious activity is detected, the server notifies the administrator. It also periodically generates security reports and provides them to the user.

[0453] 4. Emotion recognition function

[0454] The device's camera and microphone are used to analyze the user's emotions. The emotion engine identifies the user's emotions based on the facial recognition information and voice data acquired, and sends the data to the server as emotion data.

[0455] 5. Integrated analysis of emotion data and activity data

[0456] The server integrates and analyzes emotion data and activity data to perform highly accurate security risk assessments. If the activity of a user experiencing emotional stress is abnormal, the server detects the risk early and notifies the administrator.

[0457] Examples of concrete examples and prompts

[0458] Examples:

[0459] "After a user logs into their system, the Office environment is scanned and the appropriate tools are enabled based on the security policy."

[0460] "The device's camera and microphone recognize the user's emotions, and if a stress state is detected, this is reported to the server."

[0461] Example prompt sentence:

[0462] "How do I implement a security monitoring system that notifies administrators when anomalous activity is detected?"

[0463] "How do I implement emotion recognition using the EmotionEngine class?"

[0464] This improves the accuracy of security risk assessments, enabling early detection of risks caused by abnormal activity or emotions and rapid response.

[0465] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0466] Step 1:

[0467] The user displays a login screen on the client terminal and enters user authentication information (user name and password). The terminal sends this authentication information to the server, which receives it and verifies its validity by comparing it with an authentication database. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal that receives this token displays the dashboard screen for the user.

[0468] Input: Username, Password

[0469] Output: Security token, dashboard screen

[0470] Step 2:

[0471] The server instructs each device to scan the applications and tools installed on it based on the company's security policy. The device uses the Office scanner to generate a list of installed tools and sends it to the server. The server then enables permitted tools and disables prohibited tools based on the policy.

[0472] Input: List of installed applications and tools

[0473] Output: A list of tools you are allowed to use.

[0474] Step 3:

[0475] The device records user operations and system activity in real time and periodically sends it to the management server. The server analyzes the received activity data and detects security risks. If abnormal activity is detected, the server immediately notifies the administrator.

[0476] Input: Activity data

[0477] Output: Security risk detection results, alert notification

[0478] Step 4:

[0479] The device uses a camera and microphone to capture the user's facial expressions and voice, which are then analyzed by an emotion recognition engine, which determines the user's emotional state and sends the results to a management server as emotion data.

[0480] Input: Facial recognition information, voice data

[0481] Output: Emotion data

[0482] Step 5:

[0483] The server integrates and analyzes the received emotion data and activity data to perform highly accurate security risk assessments. If it determines that a user experiencing emotional stress is engaging in abnormal activity, it will detect the risk early and notify the administrator.

[0484] Input: Emotion data, activity data

[0485] Output: Highly accurate security risk assessment results and alert notifications

[0486] Step 6:

[0487] The server periodically generates security reports based on the collected activity and sentiment data. These reports include policy violation statistics, risk assessments, and recommended countermeasures. The generated reports are provided to administrators to help them review and improve their security policies.

[0488] Input: Activity data, emotion data

[0489] Output: Security report

[0490] This allows the system to smoothly perform a series of processes, from user authentication to emotional data analysis, security risk assessment, and periodic report generation.

[0491] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0492] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0493] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.

[0494] [Second embodiment]

[0495] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.

[0496] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0497] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0498] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.

[0499] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0500] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0501] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0502] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0503] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0504] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0505] In the smart glasses 214, the reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0506] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."

[0507] User Authentication and Login

[0508] To access the system, a user must first log in using their user authentication information. The user displays a login screen on their terminal and enters their username and password. The terminal sends these authentication information to the server, which verifies the authentication information. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and displays the dashboard screen to the user.

[0509] For example, when a user attempts to log in by entering their ID and password, the device sends this information to the server, which then verifies the authentication information and, if correct, displays the dashboard to the user.

[0510] Customizing your Office environment

[0511] After logging in, the server sends instructions to each device based on the company's security policy. Based on this, the device scans Office applications and checks the installed AI tools. Based on the policy received from the server, the device enables permitted tools and disables prohibited tools.

[0512] For example, if the server distributes a policy that "prohibits a specific AI tool," the device will disable that tool and be configured to only use other permitted tools.

[0513] Security Monitoring

[0514] The server monitors the activity of each device in real time. The device records user operations and behavior as a log and periodically sends this to the server. The server analyzes the received activity data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and prompts them to take action.

[0515] For example, if the server detects suspicious data transmission activity from a specific device, it notifies the administrator in real time and takes necessary measures.

[0516] Generate regular security reports

[0517] The server periodically generates security reports based on the collected activity data, including policy violation statistics, risk assessments, and recommended countermeasures. The reports are provided to administrators to help them review and improve their security policies.

[0518] As a specific example, data from the past month is compiled and a report is created that details data transmission, usage of AI tools, detected risks, etc., and shared with administrators.

[0519] Attack detection and alerting

[0520] The server monitors known attack patterns and anomalous activity in real time to detect possible unauthorized access or security breaches. If a device detects anomalous activity, it notifies the server. The server then performs a detailed analysis and immediately sends an alert to the administrator in the event of an emergency. If necessary, it also restricts the device's network connection and implements additional security measures.

[0521] For example, if a server detects abnormal activity such as an attempt to send a large amount of data externally, it will immediately issue an alert and temporarily block the network connection of the device in question. Administrators will receive a notification, investigate the cause, and take measures.

[0522] The processing flow will be explained below.

[0523] User Authentication and Login

[0524] Step 1:

[0525] The user opens the login screen. The device displays the login screen.

[0526] Step 2:

[0527] The user enters their authentication information (username and password). The user enters their username and password and clicks the "Login" button.

[0528] Step 3:

[0529] The device sends authentication information to the server. The device sends the entered username and password to the server.

[0530] Step 4:

[0531] The server validates the credentials: it checks against its database to see if the username and password are correct.

[0532] Step 5:

[0533] The server sends the authentication result to the terminal. If the authentication is successful, the server generates a security token and sends it to the terminal.

[0534] Step 6:

[0535] The terminal displays the authentication result to the user. If authentication is successful, the terminal displays the dashboard screen, and if authentication is unsuccessful, it displays an error message.

[0536] Customizing your Office environment

[0537] Step 1:

[0538] The server sends the security policy to the terminal. The server obtains the company's security policy and sends that information to the terminal.

[0539] Step 2:

[0540] The device scans the Office applications. The device scans the installed Office applications and lists the AI ​​tools used.

[0541] Step 3:

[0542] The device checks whether the AI ​​tool can be used. The device compares the listed AI tools with the security policy obtained from the server to identify permitted and prohibited tools.

[0543] Step 4:

[0544] The device updates the settings for Office applications, disabling prohibited AI tools based on security policies and updating the settings so that only permitted tools are available.

[0545] Step 5:

[0546] The device sends the results of the configuration update to the server, providing information about which tools were allowed and which were disabled.

[0547] Security Monitoring

[0548] Step 1:

[0549] The server starts real-time monitoring. The server receives activity data from each device in real time and starts monitoring.

[0550] Step 2:

[0551] The device sends activity data to the server. The device records user activity (use of AI tools, external access attempts, etc.) as a log and periodically sends it to the server.

[0552] Step 3:

[0553] The server analyzes the activity. The server analyzes the received activity data to detect any behavior that violates security policies or suspicious activity.

[0554] Step 4:

[0555] If the server detects an abnormality, it issues an alert. The server generates an alert about the detected abnormality or security violation and notifies the user (administrator).

[0556] Step 5:

[0557] The server will take action and, if necessary, temporarily restrict access to the affected device to carry out further analysis and / or action.

[0558] Generate regular security reports

[0559] Step 1:

[0560] The server aggregates the activity data collected from all devices on a weekly or monthly basis.

[0561] Step 2:

[0562] The server generates security reports. The server automatically generates security reports based on the aggregated data, including risk assessments, policy violations, and recommended actions.

[0563] Step 3:

[0564] The server sends the report to the user (administrator). The server displays the generated report on the dashboard and sends a notification email to the user (administrator).

[0565] Step 4:

[0566] The user (administrator) checks the report. The user (administrator) checks the report and implements necessary countermeasures or policy adjustments.

[0567] Attack detection and alerting

[0568] Step 1:

[0569] The server monitors attack patterns. The server monitors known attack patterns and new anomalous activity in real time.

[0570] Step 2:

[0571] If the device detects any abnormal activity, it will notify the server. The device can also detect any abnormal activity on its own and notify the server of any suspicious activity.

[0572] Step 3:

[0573] The server performs a detailed analysis. The server performs a detailed analysis of the notified abnormal activity and evaluates the urgency of the event.

[0574] Step 4:

[0575] The server sends an alert to the user (administrator). If the level of urgency is high, the server immediately sends an alert to the user (administrator) to prompt them to take action.

[0576] Step 5:

[0577] The server will initiate countermeasures, including restricting the network connection of the affected device and contacting the security team, if necessary.

[0578] Example 1

[0579] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0580] In conventional systems, user authentication, terminal application management, and security monitoring are all performed separately, making it difficult to implement integrated security measures.In addition, there are issues with high security risks due to the difficulty of detecting anomalies in real time and strictly enforcing corporate security policies.

[0581] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0582] In this invention, the server includes means for receiving user authentication information and performing authentication, means for transmitting authentication results to a management server, means for the management server to scan software and tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy, means for transmitting operation records of each terminal to the management server in real time and detecting security risks in the management server, means for notifying an administrator of detected risks, means for periodically generating security reports and providing them to the administrator, means for generating a security token if authentication is successful and displaying a dashboard screen to the user, and means for monitoring known attack patterns and abnormal activity in real time and sending an alert to the administrator in the event of an emergency. This enables consistent management from user authentication to security monitoring and effectively reduces security risks.

[0583] "User Credentials" means information a user provides to identify themselves to a system, typically including a username and password.

[0584] "Authentication" is the process of verifying whether the authentication information provided by a user is correct and granting access to a system.

[0585] The "management server" is a central server that applies the company's security policies and monitors the activity of each terminal.

[0586] A "security policy" refers to the rules and standards that a company sets to protect information and prevent unauthorized access.

[0587] "Software" is a general term for programs and applications installed on a terminal.

[0588] A "tool" is a program used for a specific function or purpose.

[0589] "Operation record" is data that records the operations and actions of a user on a terminal.

[0590] A "security risk" is a situation that could threaten the security of a system, such as information leakage or unauthorized access.

[0591] A "security token" is digital information issued to a user who has been successfully authenticated, allowing access to a system.

[0592] The "dashboard screen" is a screen that displays system operation and management information, which can be accessed by a user after logging in.

[0593] "Attack patterns" refer to the methods and characteristics of known cyber attacks.

[0594] "Activity" is a general term for all operations and actions performed on a device.

[0595] An "alert" is a warning message sent to an administrator when an abnormality or risk is detected.

[0596] The present invention provides a system that realizes consistent management from user authentication to security monitoring, and effectively reduces security risks within a company. Specific embodiments of the system will be described below.

[0597] User Authentication and Login

[0598] In order for a user to access a system, they must first log in using their user authentication information. The user displays a login screen on their terminal and enters their username and password. The terminal sends this authentication information to the server, which then verifies it. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and displays the dashboard screen to the user. For example, when a user attempts to log in by entering their ID and password, the terminal sends this information to the server. The server verifies the authentication information, and if it is correct, displays the dashboard to the user.

[0599] Customizing your Office environment

[0600] After logging in, the server sends instructions to each device based on the company's security policy. Based on this, the device scans Office applications and checks for installed AI tools. Based on the policy received from the server, the device enables permitted tools and disables prohibited tools. For example, if the server distributes a policy that "prohibits a specific AI tool," the device will disable that tool and be configured to use only other permitted tools.

[0601] Security Monitoring

[0602] The server monitors the activity of each device in real time. The device records user operations and behavior as a log and periodically sends this to the server. The server analyzes the received activity data and detects security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and urges them to take measures. For example, if the server detects suspicious data transmission activity from a specific device, it notifies the administrator of this information in real time and takes the necessary measures.

[0603] Generate regular security reports

[0604] The server periodically generates security reports based on the collected activity data. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. The reports are provided to administrators and are used to review and improve security policies. For example, data from the past month is aggregated to create a report detailing data transmission, AI tool usage, and detected risks, which is shared with administrators.

[0605] Attack detection and alerting

[0606] The server monitors known attack patterns and abnormal activity in real time to detect possible unauthorized access or security breaches. If a terminal detects abnormal activity, it also notifies the server. The server performs a detailed analysis and, in the event of an emergency, immediately sends an alert to the administrator. If necessary, it will also restrict the network connection of the terminal in question and implement additional security measures. For example, if the server detects abnormal activity that attempts to send a large amount of data externally, it will immediately issue an alert and temporarily block the network connection of the terminal in question. The administrator receives the notification, investigates the cause, and takes measures.

[0607] Example prompts to input to the generative AI model

[0608] "We need documentation that explains how the server and device work together during the user authentication and login process. If the user credentials are correct, please provide details on how the server and device exchange security tokens and display the dashboard screen."

[0609] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0610] Step 1:

[0611] The user launches an application on the terminal and the login screen is displayed. The user enters a username and password. This input data is sent to the terminal. Specifically, the user enters the required information into the login form and clicks "Login."

[0612] Step 2:

[0613] The terminal sends the entered user authentication information to the server. As a specific example, the terminal sends an HTTP POST request and includes the user name and password in the payload. At this time, it receives the user authentication information as input data and executes the process of sending it to the server.

[0614] Step 3:

[0615] The server checks the received authentication information against its database. Specifically, it runs an SQL query against the database to see if the matching username and password combination exists. Based on this input, it validates the authentication information and, if authentication is successful, performs a data calculation to generate a security token.

[0616] Step 4:

[0617] If authentication is successful, the server generates a security token and sends it to the device. Specifically, the server generates a JWT (JSON Web Token) and embeds user and session information in it. The generated security token is sent as output data to the device.

[0618] Step 5:

[0619] The terminal uses the received security token to display the dashboard screen to the user. Specifically, the terminal includes the token in the HTTP header, retrieves the dashboard data from the server, and displays it on the screen. As a result, the user can access the dashboard screen.

[0620] Step 6:

[0621] The server sends the company's security policy to the device. Specifically, the server sends the policy data in JSON format to the device. Based on this input data, the server prepares policy data to scan the Office applications on the device.

[0622] Step 7:

[0623] The device scans the Office application based on the received policy and checks the installed AI tools. Specifically, the device's script compares the installed applications with the policy data. Based on this input data, the device outputs the scan results.

[0624] Step 8:

[0625] The device enables permitted tools and disables prohibited tools. Specifically, the device modifies registry settings and application configuration files and executes scripts to enable permitted tools. The output data sets the enabled / disabled status of the tools on the device.

[0626] Step 9:

[0627] The server monitors the activity of each device in real time. Specifically, the server monitors specific ports and records communications from each device as a log. Based on this input data, real-time monitoring data is generated.

[0628] Step 10:

[0629] The terminal records the user's operations and behavior as a log and periodically sends it to the server. Specifically, the terminal uploads the log file to the server at regular intervals. An operation log is generated based on this input data and sent.

[0630] Step 11:

[0631] The server analyzes the received activity data to detect security risks and policy violations. Specifically, the server uses machine learning models to detect abnormal patterns. This data is then processed to generate risk assessment data.

[0632] Step 12:

[0633] If an abnormality is detected, the server notifies the administrator and prompts them to take measures. Specifically, when the server detects an abnormality, it sends an alert to the administrator using a messaging service. The administrator receives this notification as output data.

[0634] Step 13:

[0635] The server periodically generates security reports based on collected activity data. Specifically, the server aggregates and analyzes the data using Python scripts, and generates reports based on this input data.

[0636] Step 14:

[0637] The server provides the generated report to the administrator. Specifically, the server uses report generation software to visualize the aggregated results and create a report in PDF format. The report generated as output data is then sent to the administrator via the mail server.

[0638] Step 15:

[0639] The server monitors known attack patterns and anomalous activity in real time. Specifically, the server analyzes data in real time using a log analysis tool. Based on this input data, the server outputs monitoring data.

[0640] Step 16:

[0641] If the device detects abnormal activity, it notifies the server. Specifically, the device runs the anomaly detection script and notifies the server via an API request. Anomaly notification data is generated based on this input data.

[0642] Step 17:

[0643] The server performs a detailed analysis and sends an alert to the administrator in the event of an emergency. Specifically, the server immediately sends an alert to the administrator via SMS or email based on the analysis results. The administrator receives an emergency notification as output data.

[0644] Step 18:

[0645] If necessary, the server restricts the network access of the relevant device and implements additional security measures. Specifically, the server changes the firewall settings to restrict the network access of the specific device. The output data is the network restriction for the device.

[0646] (Application example 1)

[0647] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0648] In recent years, the security of robots used in factories has become increasingly important. However, these robots require complex operations, making it difficult for administrators to monitor security risks in real time, and there is a lack of mechanisms for immediate response in the event of abnormal operations. Furthermore, generating regular security reports and detecting policy violations is often a manual process, creating a demand for efficient security management. For this reason, it has become essential to introduce a system that monitors robot operation logs in real time and issues immediate alerts when an abnormality occurs.

[0649] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0650] In this invention, the server includes: means for receiving user authentication information and performing authentication; means for transmitting authentication results to a management device; means for scanning software and tools installed on each terminal based on a company's security policy and setting permissions and prohibitions based on the policy; means for transmitting activity data from each terminal to the management device and detecting security risks in the management device; means for the management device to monitor robot operation logs and detect security risks in real time; means for notifying users of detected risks; means for periodically generating and providing security reports to users; and means for immediately issuing alerts when abnormal operations or security risks are detected. This enables real-time monitoring of operation logs of robots used in a factory and immediate alerts when abnormalities occur. Furthermore, automatic generation of periodic security reports enables efficient security management.

[0651] Definition statement:

[0652] "User authentication information" refers to identification information required for a user to access the system, and is primarily composed of a username and password.

[0653] A "management server" is a server for centrally managing multiple terminals and devices connected to a network.

[0654] A "security policy" is a set of rules that define security standards and norms for systems and devices.

[0655] "Software" is a set of instructions executed by a computer, a program that performs a specific purpose or function.

[0656] A "tool" is a part of software, a module or application that realizes a specific function or operation.

[0657] "Activity data" is a record of operations and events performed by users and systems.

[0658] A "security risk" is a threat or danger to the safety or reliability of a system or data.

[0659] "Risk notification" is the process of sending alerts to users and administrators about detected security risks.

[0660] "Security Report" means documents and data that analyze, evaluate, and report system activity and security status.

[0661] A "robot operation log" is a record of the operation and behavior of robots used in a factory.

[0662] "Anomaly detection" is the process by which a system automatically identifies and detects unusual operations or patterns.

[0663] "Real-time monitoring" is the process of monitoring the operation of systems and devices in real time and responding immediately.

[0664] An "alert" is a warning message that notifies a user or administrator when an abnormality or problem occurs.

[0665] The system for implementing this invention includes a series of processes that start with receiving user authentication information, control terminals based on security policies and perform real-time monitoring, and monitor the robot's operation log and detect abnormalities. The specific processing method for each step is described below.

[0666] First, user authentication information is received and authentication is performed. The user enters their authentication information (e.g., username and password) into the terminal. The terminal sends this authentication information to the management server. The management server verifies the received authentication information and confirms that the user is a valid user. If this authentication is successful, the management server generates a security token and sends it to the terminal. Using this token, the user can access the system and view the dashboard.

[0667] Next, the management server scans the software and tools installed on each terminal based on the company's security policy and sets allowed and prohibited tools. Specifically, the management server enables only allowed tools and disables prohibited tools according to the security policy. This process keeps the terminal environment in line with the security policy.

[0668] Furthermore, activity data from each device is sent to a management server in real time, and security risks are detected by the management server. For example, if a device uses a specific tool or performs an unauthorized operation, the operation log is sent to the server. The management server analyzes these logs and detects abnormal operations and security risks in real time.

[0669] The management server monitors the robot's operation log in real time and immediately issues an alert if an abnormality occurs. For example, if a robot attempts to use a prohibited tool, the log is immediately sent to the management server and detected as an abnormality. The management server uses this information to issue an alert and notify the user. The user receives this notification and can respond promptly.

[0670] This system generates security reports periodically. The management server automatically generates security reports based on activity data over a certain period of time. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. The generated reports are provided to users and can be used to review and improve security policies.

[0671] For example, if a log is sent when a robot used in a factory attempts to use "unapproved_tool," it will be detected as an unauthorized operation and an alert will be sent immediately to the administrator, who can then take prompt action based on this notification to prevent security risks.

[0672] Example prompt sentence:

[0673] "Please enter the logs of the robots used in the factory. Based on the security policy, we will determine whether this log violates the policy."

[0674] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0675] Step 1:

[0676] To access the system, a user enters a username and password into a terminal. The terminal sends this authentication information to a server. The server checks the received authentication information against a database to verify that the user is a valid user. If authentication is successful, the server generates a security token and sends it to the terminal. The input is the user's authentication information, and the output is a security token.

[0677] Step 2:

[0678] The terminal uses the security token received from the server to authenticate the user's access. If successful, the dashboard screen is displayed to the user. The input is the security token and the output is the dashboard screen. The terminal is configured to allow the user to access the authorized services and tools.

[0679] Step 3:

[0680] The server scans the software and tools installed on the terminal based on the company's security policy, enables permitted tools, and disables prohibited tools. The input is the security policy and the terminal's software information, and the output is instructions to change the settings. The server instructs the terminal to change the settings based on the policy.

[0681] Step 4:

[0682] Each device sends activity data to the server in real time. The input is the device's activity data, and the output is data sent to the server. The server receives this data and analyzes the date, time, and log content. As a result of the analysis, security risks are detected.

[0683] Step 5:

[0684] The server analyzes the received activity data and immediately notifies the user if a security risk is detected. The input is the analyzed activity data, and the output is a notification to the user. The server identifies specific unauthorized operations or suspicious behavior in real time and issues warnings as necessary.

[0685] Step 6:

[0686] The server periodically generates a security report based on the collected activity data. The input is the collected activity data, and the output is a security report. The report contains statistics on policy violations, risk assessments, and recommended countermeasures. The generated report is provided to the user.

[0687] Step 7:

[0688] The server monitors the robot's operation log in real time and immediately issues an alert if an abnormality occurs. The input is the operation log and the output is an alert notification. Specifically, when the robot attempts to use the "unapproved_tool," the log is sent to the server and detected as an unauthorized operation. Based on this, the server issues an alert to the administrator, enabling a prompt response.

[0689] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[0690] User Authentication and Login

[0691] To access the system, a user logs in using user authentication information. The user displays a login screen on the terminal and enters their username and password. The terminal sends this authentication information to the server, which verifies the authentication information and verifies its validity. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and provides the dashboard screen to the user.

[0692] As a specific example, when a user attempts to log in by entering their ID and password, the device sends this information to the server, and if the server successfully authenticates, it displays a dashboard to the user.

[0693] Customizing your Office environment

[0694] After logging in, the server sends instructions based on the company's security policy to each device. The device then scans the Office applications and lists the installed AI tools. The server then enables permitted tools and disables prohibited tools based on the policy.

[0695] As a specific example, if a policy stating that "certain AI tools are prohibited" is distributed from the server, the device will disable that tool and be configured to use only other permitted tools.

[0696] Security Monitoring

[0697] The server monitors the activity of each device in real time. The device records user behavior and operations as a log and periodically sends it to the server. The server analyzes the received activity data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and takes necessary measures.

[0698] As a specific example, if the server detects suspicious data transmission from a specific device, it notifies the administrator of this information in real time and takes the necessary measures.

[0699] Generate regular security reports

[0700] The server periodically generates security reports based on collected activity data. These reports include policy violation statistics, risk assessments, and recommended countermeasures. The reports provided to administrators can be used to review and improve security policies.

[0701] As a specific example, data from the past month will be aggregated and a report will be generated that details data transmission, usage of AI tools, detected risks, etc., and provided to administrators.

[0702] Attack detection and alerting

[0703] The server monitors known attack patterns and anomalous activity in real time to detect potential unauthorized access or security breaches. This includes notifying users when anomalous activity is detected on the device. If anomalous activity is detected, the server performs detailed analysis and immediately sends an alert to the administrator. If necessary, the server temporarily restricts the device's network connection and takes additional security measures.

[0704] For example, if a server detects abnormal activity such as an attempt to transmit large amounts of data, it will immediately issue an alert and temporarily restrict the network connection of the device in question. Administrators will receive a notification, investigate the cause, and take measures.

[0705] Emotion recognition by emotion engine

[0706] An emotion engine is used to recognize the user's emotions. This engine uses the user's facial recognition information and voice analysis to identify emotions. Facial recognition information is captured using the device's camera, and the emotion engine analyzes it. Voice analysis is captured using the microphone, and the emotion engine analyzes it. The recognized emotion data is sent to the management server.

[0707] For example, when a user works on a device, the device's camera captures the user's facial expressions, and the emotion engine detects "stress." If the stress level is high, the system notifies the administrator.

[0708] Integrating emotion and activity data

[0709] By integrating the emotional data recognized by the emotion engine with the activity data sent from the device, highly accurate security risk assessment becomes possible. The server analyzes this data in real time and assesses risk based on emotional fluctuations and abnormal activity. This allows the system to immediately detect the possibility of increased risk when the user is experiencing emotional stress, allowing early countermeasures to be taken.

[0710] As a specific example, if the analysis of emotional and activity data detects an abnormality such as "attempting to send a large amount of data externally while under high stress levels," the server will immediately issue an alert and take measures such as restricting the user's activity.

[0711] The processing flow will be explained below.

[0712] User Authentication and Login

[0713] Step 1:

[0714] The user opens the login screen. The device displays the login screen.

[0715] Step 2:

[0716] The user enters their authentication information (username and password). The user enters their username and password and clicks the "Login" button.

[0717] Step 3:

[0718] The device sends authentication information to the server. The device sends the entered username and password to the server.

[0719] Step 4:

[0720] The server validates the credentials: it checks against its database to see if the username and password are correct.

[0721] Step 5:

[0722] The server sends the authentication result to the terminal. If the authentication is successful, the server generates a security token and sends it to the terminal.

[0723] Step 6:

[0724] The terminal displays the authentication result to the user. If authentication is successful, the terminal displays the dashboard screen, and if authentication is unsuccessful, it displays an error message.

[0725] Customizing your Office environment

[0726] Step 1:

[0727] The server sends the security policy to the terminal. The server obtains the company's security policy and sends that information to the terminal.

[0728] Step 2:

[0729] The device scans the Office applications. The device scans the installed Office applications and lists the AI ​​tools used.

[0730] Step 3:

[0731] The device checks whether the AI ​​tool can be used. The device compares the listed AI tools with the security policy obtained from the server to identify permitted and prohibited tools.

[0732] Step 4:

[0733] The device updates the settings for Office applications, disabling prohibited AI tools based on security policies and updating the settings so that only permitted tools are available.

[0734] Step 5:

[0735] The device sends the results of the configuration update to the server, providing information about which tools were allowed and which were disabled.

[0736] Security Monitoring

[0737] Step 1:

[0738] The server starts real-time monitoring. The server receives activity data from each device in real time and starts monitoring.

[0739] Step 2:

[0740] The device sends activity data to the server. The device records user activity (use of AI tools, external access attempts, etc.) as a log and periodically sends it to the server.

[0741] Step 3:

[0742] The server analyzes the activity. The server analyzes the received activity data to detect any behavior that violates security policies or suspicious activity.

[0743] Step 4:

[0744] If the server detects an abnormality, it issues an alert. The server generates an alert about the detected abnormality or security violation and notifies the user (administrator).

[0745] Step 5:

[0746] The server will take action and, if necessary, temporarily restrict access to the affected device to carry out further analysis and / or action.

[0747] Generate regular security reports

[0748] Step 1:

[0749] The server aggregates the activity data collected from all devices on a weekly or monthly basis.

[0750] Step 2:

[0751] The server generates security reports. The server automatically generates security reports based on the aggregated data, including risk assessments, policy violations, and recommended actions.

[0752] Step 3:

[0753] The server sends the report to the user (administrator). The server displays the generated report on the dashboard and sends a notification email to the user (administrator).

[0754] Step 4:

[0755] The user (administrator) checks the report. The user (administrator) checks the report and implements necessary countermeasures or policy adjustments.

[0756] Attack detection and alerting

[0757] Step 1:

[0758] The server monitors attack patterns. The server monitors known attack patterns and new anomalous activity in real time.

[0759] Step 2:

[0760] If the device detects any abnormal activity, it will notify the server. The device can also detect any abnormal activity on its own and notify the server of any suspicious activity.

[0761] Step 3:

[0762] The server performs a detailed analysis. The server performs a detailed analysis of the notified abnormal activity and evaluates the urgency of the event.

[0763] Step 4:

[0764] The server sends an alert to the user (administrator). If the level of urgency is high, the server immediately sends an alert to the user (administrator) to prompt them to take action.

[0765] Step 5:

[0766] The server will initiate countermeasures, including restricting the network connection of the affected device and contacting the security team, if necessary.

[0767] Emotion recognition by emotion engine

[0768] Step 1:

[0769] When a user uses the device, their actions are captured by the camera and microphone. The device uses the camera to recognize the user's face and the microphone to record their voice.

[0770] Step 2:

[0771] The device launches an emotion engine to analyze the captured data, which then recognizes emotions from the user's facial expressions and voice.

[0772] Step 3:

[0773] The device sends the recognized emotion data to the server in real time for use in assessing security risks.

[0774] Integrating emotion and activity data

[0775] Step 1:

[0776] The server receives emotion data and activity data in real time, and prepares the data for integration and analysis.

[0777] Step 2:

[0778] The server analyzes the emotion and activity data and performs an integrated risk assessment based on the user's stress level and abnormal activity.

[0779] Step 3:

[0780] The server notifies the results of the integrated risk assessment in real time, and if an abnormality is detected, the server immediately sends an alert to the administrator so that necessary measures can be taken.

[0781] As a specific example, if a user attempts to send a large amount of data while under high stress, the server will immediately issue an alert and take measures such as restricting the user's activity.

[0782] Stress level assessment and alerts

[0783] Step 1:

[0784] The device periodically captures the user's emotional data and transmits it to the server, allowing the server to continuously understand the user's emotional state.

[0785] Step 2:

[0786] The server evaluates the user's stress level based on the emotional data. Based on the data detected by the emotion engine, the server calculates the user's stress level.

[0787] Step 3:

[0788] If the server detects a high stress state, it notifies the administrator. If the stress level exceeds a certain threshold, the server immediately issues an alert, prompting the administrator to take action.

[0789] As a specific example, if the server detects an increase in the user's stress level and this reaches a dangerous level, the administrator will be notified to take timely action.

[0790] Example 2

[0791] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0792] While conventional systems provide basic security functions such as user authentication, security policy enforcement, and real-time monitoring, they lack risk assessment that takes into account the emotional state of the user and highly accurate risk detection using integrated data. Furthermore, early detection of security risks and notification to administrators can be delayed, requiring rapid response.

[0793] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0794] In this invention, the server includes means for receiving user authentication information and performing authentication, means for transmitting the authentication result to the management server, means for the management server to scan the software and support tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy, means for transmitting activity data of each terminal to the management server in real time and detecting security risks in the management server, means for notifying an administrator of detected risks, means for periodically generating security reports and providing them to the administrator, means for capturing information using the terminal's camera and microphone to recognize user emotions and analyzing it with an emotion engine, and means for evaluating risks by integrating the emotion data and activity data and notifying an administrator if a high risk is detected. This enables highly accurate risk evaluation that takes the user's emotional state into consideration and rapid risk response.

[0795] "User Credentials" means information such as a username and password provided by a user to access a system.

[0796] "Authentication" is the process of verifying that the user credentials provided are valid.

[0797] A "management server" is a central management device for applying security policies, analyzing activity data, and detecting risks.

[0798] A "corporate security policy" is a set of rules and guidelines regarding information security established by a company.

[0799] A "terminal" is a device, such as a computer or smartphone, that a user uses to access the system.

[0800] "Software" is a general term for applications and programs installed on a terminal.

[0801] "Support tools" are software and applications that support users' work and tasks.

[0802] "Activity data" is a record of information about the user's operations and actions performed on the terminal.

[0803] "Security risks" are threats to systems and data, such as unauthorized access, data leakage, and destruction.

[0804] An "emotion engine" is software that analyzes emotions from a user's facial expressions and voice.

[0805] "Emotion data" is information about the user's emotions analyzed by the emotion engine.

[0806] This invention relates to a system that includes receiving user authentication information, authentication, applying security policies, real-time monitoring, emotion recognition using an emotion engine, and integrated risk assessment. This system is composed of elements including a server, a terminal, and a user, and specific embodiments thereof are described below.

[0807] First, the user opens the login screen on the device and enters their username and password. The device encrypts this authentication information and sends it to the server. The server compares the received authentication information with a database to verify its validity. If authentication is successful, the server generates a security token and sends it to the device. The device receives the security token and displays the dashboard screen to the user. For example, if a user attempts to log in by entering "user123" and "password123," the server authenticates and the dashboard is displayed.

[0808] Next, after logging in, the server sends the company's security policy to each terminal. Based on this, the terminal scans the installed Office applications and creates a list of available assistive tools. Based on the policy, the server enables permitted tools and disables prohibited tools. For example, if the server distributes a policy that "a specific assistive tool is prohibited," the terminal disables that tool and allows only other permitted tools to be used.

[0809] The server also monitors the activity data of each device in real time. The device records user operations as a log and periodically sends it to the server. The server analyzes this data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and takes necessary measures. For example, if the server detects suspicious data transmission from a specific device, it notifies the administrator in real time and implements necessary measures.

[0810] The server periodically generates security reports based on collected activity data. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. Administrators can review and improve security policies based on these reports. As a specific example, data from the past month is aggregated to generate a security report that includes statistics on policy violations and risk assessments, and the report is provided to administrators.

[0811] Furthermore, this system has the ability to recognize the user's emotions using an emotion engine. The device's camera and microphone are used to capture the user's facial expressions and voice, which the emotion engine analyzes to identify the emotion. The recognized emotion data is sent to the server. For example, if the camera captures the user's facial expressions while the user is working on the device and the emotion engine detects "stress," the information is notified to the administrator.

[0812] Finally, the server integrates the emotion data and activity data to perform a highly accurate risk assessment. By integrating the emotion data recognized by the emotion engine with the activity data sent from the device, the accuracy of the risk assessment is improved. For example, if a large amount of data transmission is detected in a state of high stress, the server will immediately issue an alert and take measures such as restricting the user's activity.

[0813] Example prompts for generative AI models

[0814] Here are some examples of prompts for generative AI models:

[0815] "The system you are trying to log into first requires a username and password. You enter this into the login screen, the server authenticates you, generates a security token, and if successful, displays the dashboard. Can you please explain the process in detail?"

[0816]

[0817] After logging in, the server issues instructions to the terminal based on the company's security policy. The terminal scans the Office applications and creates a list of support tools. Explain how the server controls the tools based on the policy.

[0818] These prompts can be used to obtain instructions from the generative AI model regarding specific system processing steps.

[0819] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0820] Step 1: Enter and submit user credentials

[0821] The user enters their username and password into the login screen of the device.

[0822] Input: Username and Password

[0823] The terminal encrypts the entered information and sends it to the server.

[0824] Output: Encrypted username and password

[0825] As a specific example of operation, the user inputs "user123" and "password123".

[0826] Step 2: Verify credentials

[0827] The server receives the encrypted username and password and checks it against a database.

[0828] Input: Encrypted username and password

[0829] A database check is performed to verify that the user is a valid user.

[0830] Output: Authentication result (success or failure)

[0831] As a specific example of operation, the server checks the database to see if the combination of "user123" and "password123" is correct.

[0832] Step 3: Generate and send a security token

[0833] If the authentication is successful, the server generates a security token and sends it to the terminal.

[0834] Input: Authentication result (success)

[0835] A security token is generated and sent to the terminal via the network.

[0836] Output: Security token

[0837] As a specific example of operation, the server generates a security token for "user123" and sends it to the terminal.

[0838] Step 4: View the dashboard

[0839] The terminal stores the received security token and displays the dashboard screen to the user.

[0840] Input: Security Token

[0841] Save the security token and display the dashboard screen.

[0842] Output: Dashboard screen displayed

[0843] As a specific example of operation, the terminal uses the security token to display a dashboard to the user.

[0844] Step 5: Applying security policies

[0845] The server transmits the security policy to the terminal.

[0846] Input: None (Policy is set in advance)

[0847] The security policy is sent to each terminal.

[0848] Output: Security policy

[0849] As a specific example of operation, the server sends a policy to the terminal that "certain support tools are prohibited."

[0850] Step 6: Scanning Office applications

[0851] The device receives the security policy and scans the installed Office applications.

[0852] Input: Security policy

[0853] Scan your Office applications and create a list of available assistive tools.

[0854] Output: List of supporting tools

[0855] As a specific example of operation, it scans the tools installed on the device and creates a list.

[0856] Step 7: Enable and disable tools

[0857] The server receives the list and enables or disables the tools based on the policy.

[0858] Input: A list of support tools and security policies

[0859] Parse the list and control the tool based on your policy.

[0860] Output: Tool enable / disable setting

[0861] As a specific example of operation, a specific support tool is disabled and other tools are enabled.

[0862] Step 8: Real-time monitoring

[0863] The terminal records the user's operations as a log and periodically sends it to the server.

[0864] Input: User operation log

[0865] Operation logs are recorded and periodically sent to the server.

[0866] Output: Operation log data

[0867] As a specific example of operation, the terminal records the user's operations in real time and transmits them to the server.

[0868] Step 9: Detect security risks

[0869] The server analyzes the received operation log data and detects security risks and policy violations.

[0870] Input: Operation log data

[0871] Analyze log data and assess risk.

[0872] Output: Risk assessment results and alert notifications

[0873] As a specific example of operation, the server detects suspicious data transmission and notifies the administrator.

[0874] Step 10: Generate and provide security reports

[0875] The server generates security reports based on periodically collected operation log data.

[0876] Input: Operation log data

[0877] Consolidate log data and generate reports.

[0878] Output: Security report

[0879] As a specific example of how it works, a report is generated that includes statistics on policy violations over the past month and a risk assessment.

[0880] Step 11: Capture and analyze emotion data

[0881] The device's camera and microphone are used to capture the user's facial expressions and voice, which are then analyzed by the emotion engine.

[0882] Input: User's facial expression data and voice data

[0883] The emotion engine analyzes the data and identifies emotions.

[0884] Output: Emotion data

[0885] As a specific example of operation, the user's facial expression is captured and "stress" is detected.

[0886] Step 12: Integrating emotion and activity data

[0887] The server integrates the emotion data and operation log data to perform risk assessment.

[0888] Input: Emotion data and operation log data

[0889] Integrate data to assess risk with precision.

[0890] Output: Risk assessment results and alert notifications

[0891] As a specific example of operation, if a large amount of data transmission is detected while the stress level is high, the server will issue an alert.

[0892] (Application example 2)

[0893] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0894] Traditional user authentication and security monitoring systems lack real-time analysis and integration of emotional data, making it difficult to properly detect security risks when users are in emotionally unstable situations. Furthermore, it is difficult to respond immediately when abnormal activity occurs, making it impossible to prevent potential security risks. This has resulted in serious gaps in enterprise-wide security measures.

[0895] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes: means for receiving user authentication information and performing authentication; means for transmitting the authentication result to the management server; means for the management server to scan applications and tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy; means for transmitting activity data of each terminal to the management server in real time and detecting security risks in the management server; means for notifying the user of the detected risks; means for periodically generating security reports and providing them to the user; means for analyzing the emotion data of the user of each terminal using an emotion engine and transmitting the analysis results to the management server; means for integrating the emotion data and activity data to evaluate security risks in real time; and means for immediately notifying the administrator when an abnormality is detected. This enables highly accurate security risk evaluation using emotion data, allowing for early detection of risks caused by abnormal activity or emotions and rapid response.

[0896] "User authentication information" refers to information provided by a user to authenticate themselves to the system, such as a user ID and password or biometric information.

[0897] A "management server" is a central server device that manages security policies within a company and monitors the status and operation of terminals.

[0898] A "security policy" is a set of guidelines and standards established by a company to protect information and maintain the security of its systems.

[0899] "Applications and Tools" refers to software products and utilities installed on the device.

[0900] "Activity data" is data that records a user's operation history and system usage.

[0901] "Security risk" refers to potential dangers such as unauthorized access to systems and data, information leaks, and attacks.

[0902] An "emotion engine" is a system that analyzes a user's facial expressions and voice to identify their emotional state at that time (for example, stress, joy, anger, etc.).

[0903] "Emotion data" is data that indicates the user's emotional state analyzed by the emotion engine.

[0904] An "anomaly" is unexpected behavior, such as irregular operations or data transmissions that are not considered normal.

[0905] "Notifying the user" means alerting the user about the detected security risk.

[0906] "Security Report" means a document generated periodically that contains detailed information about compliance with security policies and detected risks.

[0907] "Integration" means combining multiple pieces of data or information into one and analyzing it.

[0908] The programs that make up part of the system that realizes this application example provide various functions such as user authentication, security monitoring, emotion recognition, etc. Specifically, the following hardware and software are used:

[0909] Hardware used

[0910] Client terminal: High-performance PC or smart device

[0911] Camera and microphone: High-resolution camera (e.g., a generic webcam), high-quality microphone (e.g., a high-end microphone)

[0912] Software used

[0913] Server: A general-purpose cloud service provider's server (e.g., cloud server)

[0914] Software framework: Java, Spring Boot, TensorFlow (for emotion recognition)

[0915] Specific details of processing

[0916] 1. User authentication function

[0917] The terminal acquires user authentication information and sends it to the server. The server verifies the authentication information and, if valid, generates a security token and sends it to the terminal. This allows the user to access the system and use various functions.

[0918] 2. Customizing the Office environment

[0919] The server scans the tools installed on each device based on the company's security policy. Only tools permitted by the server are enabled, and prohibited tools are disabled. This creates an environment that complies with the company's security policy.

[0920] 3. Security monitoring function

[0921] The device records user operations and activity data and periodically sends it to the server. The server analyzes the received data in real time and detects security risks. If suspicious activity is detected, the server notifies the administrator. It also periodically generates security reports and provides them to the user.

[0922] 4. Emotion recognition function

[0923] The device's camera and microphone are used to analyze the user's emotions. The emotion engine identifies the user's emotions based on the facial recognition information and voice data acquired, and sends the data to the server as emotion data.

[0924] 5. Integrated analysis of emotion data and activity data

[0925] The server integrates and analyzes emotion data and activity data to perform highly accurate security risk assessments. If the activity of a user experiencing emotional stress is abnormal, the server detects the risk early and notifies the administrator.

[0926] Examples of concrete examples and prompts

[0927] Examples:

[0928] "After a user logs into their system, the Office environment is scanned and the appropriate tools are enabled based on the security policy."

[0929] "The device's camera and microphone recognize the user's emotions, and if a stress state is detected, this is reported to the server."

[0930] Example prompt sentence:

[0931] "How do I implement a security monitoring system that notifies administrators when anomalous activity is detected?"

[0932] "How do I implement emotion recognition using the EmotionEngine class?"

[0933] This improves the accuracy of security risk assessments, enabling early detection of risks caused by abnormal activity or emotions and rapid response.

[0934] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0935] Step 1:

[0936] The user displays a login screen on the client terminal and enters user authentication information (user name and password). The terminal sends this authentication information to the server, which receives it and verifies its validity by comparing it with an authentication database. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal that receives this token displays the dashboard screen for the user.

[0937] Input: Username, Password

[0938] Output: Security token, dashboard screen

[0939] Step 2:

[0940] The server instructs each device to scan the applications and tools installed on it based on the company's security policy. The device uses the Office scanner to generate a list of installed tools and sends it to the server. The server then enables permitted tools and disables prohibited tools based on the policy.

[0941] Input: List of installed applications and tools

[0942] Output: A list of tools you are allowed to use.

[0943] Step 3:

[0944] The device records user operations and system activity in real time and periodically sends it to the management server. The server analyzes the received activity data and detects security risks. If abnormal activity is detected, the server immediately notifies the administrator.

[0945] Input: Activity data

[0946] Output: Security risk detection results, alert notification

[0947] Step 4:

[0948] The device uses a camera and microphone to capture the user's facial expressions and voice, which are then analyzed by an emotion recognition engine, which determines the user's emotional state and sends the results to a management server as emotion data.

[0949] Input: Facial recognition information, voice data

[0950] Output: Emotion data

[0951] Step 5:

[0952] The server integrates and analyzes the received emotion data and activity data to perform highly accurate security risk assessments. If it determines that a user experiencing emotional stress is engaging in abnormal activity, it will detect the risk early and notify the administrator.

[0953] Input: Emotion data, activity data

[0954] Output: Highly accurate security risk assessment results and alert notifications

[0955] Step 6:

[0956] The server periodically generates security reports based on the collected activity and sentiment data. These reports include policy violation statistics, risk assessments, and recommended countermeasures. The generated reports are provided to administrators to help them review and improve their security policies.

[0957] Input: Activity data, emotion data

[0958] Output: Security report

[0959] This allows the system to smoothly perform a series of processes, from user authentication to emotional data analysis, security risk assessment, and periodic report generation.

[0960] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0961] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0962] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.

[0963] [Third embodiment]

[0964] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.

[0965] 5, the data processing system 310 includes the data processing device 12 and a headset type terminal 314. An example of the data processing device 12 is a server.

[0966] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0967] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.

[0968] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0969] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0970] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0971] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0972] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0973] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0974] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0975] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."

[0976] User Authentication and Login

[0977] To access the system, a user must first log in using their user authentication information. The user displays a login screen on their terminal and enters their username and password. The terminal sends these authentication information to the server, which verifies the authentication information. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and displays the dashboard screen to the user.

[0978] For example, when a user attempts to log in by entering their ID and password, the device sends this information to the server, which then verifies the authentication information and, if correct, displays the dashboard to the user.

[0979] Customizing your Office environment

[0980] After logging in, the server sends instructions to each device based on the company's security policy. Based on this, the device scans Office applications and checks the installed AI tools. Based on the policy received from the server, the device enables permitted tools and disables prohibited tools.

[0981] For example, if the server distributes a policy that "prohibits a specific AI tool," the device will disable that tool and be configured to only use other permitted tools.

[0982] Security Monitoring

[0983] The server monitors the activity of each device in real time. The device records user operations and behavior as a log and periodically sends this to the server. The server analyzes the received activity data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and prompts them to take action.

[0984] For example, if the server detects suspicious data transmission activity from a specific device, it notifies the administrator in real time and takes necessary measures.

[0985] Generate regular security reports

[0986] The server periodically generates security reports based on the collected activity data, including policy violation statistics, risk assessments, and recommended countermeasures. The reports are provided to administrators to help them review and improve their security policies.

[0987] As a specific example, data from the past month is compiled and a report is created that details data transmission, usage of AI tools, detected risks, etc., and shared with administrators.

[0988] Attack detection and alerting

[0989] The server monitors known attack patterns and anomalous activity in real time to detect possible unauthorized access or security breaches. If a device detects anomalous activity, it notifies the server. The server then performs a detailed analysis and immediately sends an alert to the administrator in the event of an emergency. If necessary, it also restricts the device's network connection and implements additional security measures.

[0990] For example, if a server detects abnormal activity such as an attempt to send a large amount of data externally, it will immediately issue an alert and temporarily block the network connection of the device in question. Administrators will receive a notification, investigate the cause, and take measures.

[0991] The processing flow will be explained below.

[0992] User Authentication and Login

[0993] Step 1:

[0994] The user opens the login screen. The device displays the login screen.

[0995] Step 2:

[0996] The user enters their authentication information (username and password). The user enters their username and password and clicks the "Login" button.

[0997] Step 3:

[0998] The device sends authentication information to the server. The device sends the entered username and password to the server.

[0999] Step 4:

[1000] The server validates the credentials: it checks against its database to see if the username and password are correct.

[1001] Step 5:

[1002] The server sends the authentication result to the terminal. If the authentication is successful, the server generates a security token and sends it to the terminal.

[1003] Step 6:

[1004] The terminal displays the authentication result to the user. If authentication is successful, the terminal displays the dashboard screen, and if authentication is unsuccessful, it displays an error message.

[1005] Customizing your Office environment

[1006] Step 1:

[1007] The server sends the security policy to the terminal. The server obtains the company's security policy and sends that information to the terminal.

[1008] Step 2:

[1009] The device scans the Office applications. The device scans the installed Office applications and lists the AI ​​tools used.

[1010] Step 3:

[1011] The device checks whether the AI ​​tool can be used. The device compares the listed AI tools with the security policy obtained from the server to identify permitted and prohibited tools.

[1012] Step 4:

[1013] The device updates the settings for Office applications, disabling prohibited AI tools based on security policies and updating the settings so that only permitted tools are available.

[1014] Step 5:

[1015] The device sends the results of the configuration update to the server, providing information about which tools were allowed and which were disabled.

[1016] Security Monitoring

[1017] Step 1:

[1018] The server starts real-time monitoring. The server receives activity data from each device in real time and starts monitoring.

[1019] Step 2:

[1020] The device sends activity data to the server. The device records user activity (use of AI tools, external access attempts, etc.) as a log and periodically sends it to the server.

[1021] Step 3:

[1022] The server analyzes the activity. The server analyzes the received activity data to detect any behavior that violates security policies or suspicious activity.

[1023] Step 4:

[1024] If the server detects an abnormality, it issues an alert. The server generates an alert about the detected abnormality or security violation and notifies the user (administrator).

[1025] Step 5:

[1026] The server will take action and, if necessary, temporarily restrict access to the affected device to carry out further analysis and / or action.

[1027] Generate regular security reports

[1028] Step 1:

[1029] The server aggregates the activity data collected from all devices on a weekly or monthly basis.

[1030] Step 2:

[1031] The server generates security reports. The server automatically generates security reports based on the aggregated data, including risk assessments, policy violations, and recommended actions.

[1032] Step 3:

[1033] The server sends the report to the user (administrator). The server displays the generated report on the dashboard and sends a notification email to the user (administrator).

[1034] Step 4:

[1035] The user (administrator) checks the report. The user (administrator) checks the report and implements necessary countermeasures or policy adjustments.

[1036] Attack detection and alerting

[1037] Step 1:

[1038] The server monitors attack patterns. The server monitors known attack patterns and new anomalous activity in real time.

[1039] Step 2:

[1040] If the device detects any abnormal activity, it will notify the server. The device can also detect any abnormal activity on its own and notify the server of any suspicious activity.

[1041] Step 3:

[1042] The server performs a detailed analysis. The server performs a detailed analysis of the notified abnormal activity and evaluates the urgency of the event.

[1043] Step 4:

[1044] The server sends an alert to the user (administrator). If the level of urgency is high, the server immediately sends an alert to the user (administrator) to prompt them to take action.

[1045] Step 5:

[1046] The server will initiate countermeasures, including restricting the network connection of the affected device and contacting the security team, if necessary.

[1047] Example 1

[1048] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1049] In conventional systems, user authentication, terminal application management, and security monitoring are all performed separately, making it difficult to implement integrated security measures.In addition, there are issues with high security risks due to the difficulty of detecting anomalies in real time and strictly enforcing corporate security policies.

[1050] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1051] In this invention, the server includes means for receiving user authentication information and performing authentication, means for transmitting authentication results to a management server, means for the management server to scan software and tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy, means for transmitting operation records of each terminal to the management server in real time and detecting security risks in the management server, means for notifying an administrator of detected risks, means for periodically generating security reports and providing them to the administrator, means for generating a security token if authentication is successful and displaying a dashboard screen to the user, and means for monitoring known attack patterns and abnormal activity in real time and sending an alert to the administrator in the event of an emergency. This enables consistent management from user authentication to security monitoring and effectively reduces security risks.

[1052] "User Credentials" means information a user provides to identify themselves to a system, typically including a username and password.

[1053] "Authentication" is the process of verifying whether the authentication information provided by a user is correct and granting access to a system.

[1054] The "management server" is a central server that applies the company's security policies and monitors the activity of each terminal.

[1055] A "security policy" refers to the rules and standards that a company sets to protect information and prevent unauthorized access.

[1056] "Software" is a general term for programs and applications installed on a terminal.

[1057] A "tool" is a program used for a specific function or purpose.

[1058] "Operation record" is data that records the operations and actions of a user on a terminal.

[1059] A "security risk" is a situation that could threaten the security of a system, such as information leakage or unauthorized access.

[1060] A "security token" is digital information issued to a user who has been successfully authenticated, allowing access to a system.

[1061] The "dashboard screen" is a screen that displays system operation and management information, which can be accessed by a user after logging in.

[1062] "Attack patterns" refer to the methods and characteristics of known cyber attacks.

[1063] "Activity" is a general term for all operations and actions performed on a device.

[1064] An "alert" is a warning message sent to an administrator when an abnormality or risk is detected.

[1065] The present invention provides a system that realizes consistent management from user authentication to security monitoring, and effectively reduces security risks within a company. Specific embodiments of the system will be described below.

[1066] User Authentication and Login

[1067] In order for a user to access a system, they must first log in using their user authentication information. The user displays a login screen on their terminal and enters their username and password. The terminal sends this authentication information to the server, which then verifies it. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and displays the dashboard screen to the user. For example, when a user attempts to log in by entering their ID and password, the terminal sends this information to the server. The server verifies the authentication information, and if it is correct, displays the dashboard to the user.

[1068] Customizing your Office environment

[1069] After logging in, the server sends instructions to each device based on the company's security policy. Based on this, the device scans Office applications and checks for installed AI tools. Based on the policy received from the server, the device enables permitted tools and disables prohibited tools. For example, if the server distributes a policy that "prohibits a specific AI tool," the device will disable that tool and be configured to use only other permitted tools.

[1070] Security Monitoring

[1071] The server monitors the activity of each device in real time. The device records user operations and behavior as a log and periodically sends this to the server. The server analyzes the received activity data and detects security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and urges them to take measures. For example, if the server detects suspicious data transmission activity from a specific device, it notifies the administrator of this information in real time and takes the necessary measures.

[1072] Generate regular security reports

[1073] The server periodically generates security reports based on the collected activity data. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. The reports are provided to administrators and are used to review and improve security policies. For example, data from the past month is aggregated to create a report detailing data transmission, AI tool usage, and detected risks, which is shared with administrators.

[1074] Attack detection and alerting

[1075] The server monitors known attack patterns and abnormal activity in real time to detect possible unauthorized access or security breaches. If a terminal detects abnormal activity, it also notifies the server. The server performs a detailed analysis and, in the event of an emergency, immediately sends an alert to the administrator. If necessary, it will also restrict the network connection of the terminal in question and implement additional security measures. For example, if the server detects abnormal activity that attempts to send a large amount of data externally, it will immediately issue an alert and temporarily block the network connection of the terminal in question. The administrator receives the notification, investigates the cause, and takes measures.

[1076] Example prompts to input to the generative AI model

[1077] "We need documentation that explains how the server and device work together during the user authentication and login process. If the user credentials are correct, please provide details on how the server and device exchange security tokens and display the dashboard screen."

[1078] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1079] Step 1:

[1080] The user launches an application on the terminal and the login screen is displayed. The user enters a username and password. This input data is sent to the terminal. Specifically, the user enters the required information into the login form and clicks "Login."

[1081] Step 2:

[1082] The terminal sends the entered user authentication information to the server. As a specific example, the terminal sends an HTTP POST request and includes the user name and password in the payload. At this time, it receives the user authentication information as input data and executes the process of sending it to the server.

[1083] Step 3:

[1084] The server checks the received authentication information against its database. Specifically, it runs an SQL query against the database to see if the matching username and password combination exists. Based on this input, it validates the authentication information and, if authentication is successful, performs a data calculation to generate a security token.

[1085] Step 4:

[1086] If authentication is successful, the server generates a security token and sends it to the device. Specifically, the server generates a JWT (JSON Web Token) and embeds user and session information in it. The generated security token is sent as output data to the device.

[1087] Step 5:

[1088] The terminal uses the received security token to display the dashboard screen to the user. Specifically, the terminal includes the token in the HTTP header, retrieves the dashboard data from the server, and displays it on the screen. As a result, the user can access the dashboard screen.

[1089] Step 6:

[1090] The server sends the company's security policy to the device. Specifically, the server sends the policy data in JSON format to the device. Based on this input data, the server prepares policy data to scan the Office applications on the device.

[1091] Step 7:

[1092] The device scans the Office application based on the received policy and checks the installed AI tools. Specifically, the device's script compares the installed applications with the policy data. Based on this input data, the device outputs the scan results.

[1093] Step 8:

[1094] The device enables permitted tools and disables prohibited tools. Specifically, the device modifies registry settings and application configuration files and executes scripts to enable permitted tools. The output data sets the enabled / disabled status of the tools on the device.

[1095] Step 9:

[1096] The server monitors the activity of each device in real time. Specifically, the server monitors specific ports and records communications from each device as a log. Based on this input data, real-time monitoring data is generated.

[1097] Step 10:

[1098] The terminal records the user's operations and behavior as a log and periodically sends it to the server. Specifically, the terminal uploads the log file to the server at regular intervals. An operation log is generated based on this input data and sent.

[1099] Step 11:

[1100] The server analyzes the received activity data to detect security risks and policy violations. Specifically, the server uses machine learning models to detect abnormal patterns. This data is then processed to generate risk assessment data.

[1101] Step 12:

[1102] If an abnormality is detected, the server notifies the administrator and prompts them to take measures. Specifically, when the server detects an abnormality, it sends an alert to the administrator using a messaging service. The administrator receives this notification as output data.

[1103] Step 13:

[1104] The server periodically generates security reports based on collected activity data. Specifically, the server aggregates and analyzes the data using Python scripts, and generates reports based on this input data.

[1105] Step 14:

[1106] The server provides the generated report to the administrator. Specifically, the server uses report generation software to visualize the aggregated results and create a report in PDF format. The report generated as output data is then sent to the administrator via the mail server.

[1107] Step 15:

[1108] The server monitors known attack patterns and anomalous activity in real time. Specifically, the server analyzes data in real time using a log analysis tool. Based on this input data, the server outputs monitoring data.

[1109] Step 16:

[1110] If the device detects abnormal activity, it notifies the server. Specifically, the device runs the anomaly detection script and notifies the server via an API request. Anomaly notification data is generated based on this input data.

[1111] Step 17:

[1112] The server performs a detailed analysis and sends an alert to the administrator in the event of an emergency. Specifically, the server immediately sends an alert to the administrator via SMS or email based on the analysis results. The administrator receives an emergency notification as output data.

[1113] Step 18:

[1114] If necessary, the server restricts the network access of the relevant device and implements additional security measures. Specifically, the server changes the firewall settings to restrict the network access of the specific device. The output data is the network restriction for the device.

[1115] (Application example 1)

[1116] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1117] In recent years, the security of robots used in factories has become increasingly important. However, these robots require complex operations, making it difficult for administrators to monitor security risks in real time, and there is a lack of mechanisms for immediate response in the event of abnormal operations. Furthermore, generating regular security reports and detecting policy violations is often a manual process, creating a demand for efficient security management. For this reason, it has become essential to introduce a system that monitors robot operation logs in real time and issues immediate alerts when an abnormality occurs.

[1118] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1119] In this invention, the server includes: means for receiving user authentication information and performing authentication; means for transmitting authentication results to a management device; means for scanning software and tools installed on each terminal based on a company's security policy and setting permissions and prohibitions based on the policy; means for transmitting activity data from each terminal to the management device and detecting security risks in the management device; means for the management device to monitor robot operation logs and detect security risks in real time; means for notifying users of detected risks; means for periodically generating and providing security reports to users; and means for immediately issuing alerts when abnormal operations or security risks are detected. This enables real-time monitoring of operation logs of robots used in a factory and immediate alerts when abnormalities occur. Furthermore, automatic generation of periodic security reports enables efficient security management.

[1120] Definition statement:

[1121] "User authentication information" refers to identification information required for a user to access the system, and is primarily composed of a username and password.

[1122] A "management server" is a server for centrally managing multiple terminals and devices connected to a network.

[1123] A "security policy" is a set of rules that define security standards and norms for systems and devices.

[1124] "Software" is a set of instructions executed by a computer, a program that performs a specific purpose or function.

[1125] A "tool" is a part of software, a module or application that realizes a specific function or operation.

[1126] "Activity data" is a record of operations and events performed by users and systems.

[1127] A "security risk" is a threat or danger to the safety or reliability of a system or data.

[1128] "Risk notification" is the process of sending alerts to users and administrators about detected security risks.

[1129] "Security Report" means documents and data that analyze, evaluate, and report system activity and security status.

[1130] A "robot operation log" is a record of the operation and behavior of robots used in a factory.

[1131] "Anomaly detection" is the process by which a system automatically identifies and detects unusual operations or patterns.

[1132] "Real-time monitoring" is the process of monitoring the operation of systems and devices in real time and responding immediately.

[1133] An "alert" is a warning message that notifies a user or administrator when an abnormality or problem occurs.

[1134] The system for implementing this invention includes a series of processes that start with receiving user authentication information, control terminals based on security policies and perform real-time monitoring, and monitor the robot's operation log and detect abnormalities. The specific processing method for each step is described below.

[1135] First, user authentication information is received and authentication is performed. The user enters their authentication information (e.g., username and password) into the terminal. The terminal sends this authentication information to the management server. The management server verifies the received authentication information and confirms that the user is a valid user. If this authentication is successful, the management server generates a security token and sends it to the terminal. Using this token, the user can access the system and view the dashboard.

[1136] Next, the management server scans the software and tools installed on each terminal based on the company's security policy and sets allowed and prohibited tools. Specifically, the management server enables only allowed tools and disables prohibited tools according to the security policy. This process keeps the terminal environment in line with the security policy.

[1137] Furthermore, activity data from each device is sent to a management server in real time, and security risks are detected by the management server. For example, if a device uses a specific tool or performs an unauthorized operation, the operation log is sent to the server. The management server analyzes these logs and detects abnormal operations and security risks in real time.

[1138] The management server monitors the robot's operation log in real time and immediately issues an alert if an abnormality occurs. For example, if a robot attempts to use a prohibited tool, the log is immediately sent to the management server and detected as an abnormality. The management server uses this information to issue an alert and notify the user. The user receives this notification and can respond promptly.

[1139] This system generates security reports periodically. The management server automatically generates security reports based on activity data over a certain period of time. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. The generated reports are provided to users and can be used to review and improve security policies.

[1140] For example, if a log is sent when a robot used in a factory attempts to use "unapproved_tool," it will be detected as an unauthorized operation and an alert will be sent immediately to the administrator, who can then take prompt action based on this notification to prevent security risks.

[1141] Example prompt sentence:

[1142] "Please enter the logs of the robots used in the factory. Based on the security policy, we will determine whether this log violates the policy."

[1143] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1144] Step 1:

[1145] To access the system, a user enters a username and password into a terminal. The terminal sends this authentication information to a server. The server checks the received authentication information against a database to verify that the user is a valid user. If authentication is successful, the server generates a security token and sends it to the terminal. The input is the user's authentication information, and the output is a security token.

[1146] Step 2:

[1147] The terminal uses the security token received from the server to authenticate the user's access. If successful, the dashboard screen is displayed to the user. The input is the security token and the output is the dashboard screen. The terminal is configured to allow the user to access the authorized services and tools.

[1148] Step 3:

[1149] The server scans the software and tools installed on the terminal based on the company's security policy, enables permitted tools, and disables prohibited tools. The input is the security policy and the terminal's software information, and the output is instructions to change the settings. The server instructs the terminal to change the settings based on the policy.

[1150] Step 4:

[1151] Each device sends activity data to the server in real time. The input is the device's activity data, and the output is data sent to the server. The server receives this data and analyzes the date, time, and log content. As a result of the analysis, security risks are detected.

[1152] Step 5:

[1153] The server analyzes the received activity data and immediately notifies the user if a security risk is detected. The input is the analyzed activity data, and the output is a notification to the user. The server identifies specific unauthorized operations or suspicious behavior in real time and issues warnings as necessary.

[1154] Step 6:

[1155] The server periodically generates a security report based on the collected activity data. The input is the collected activity data, and the output is a security report. The report contains statistics on policy violations, risk assessments, and recommended countermeasures. The generated report is provided to the user.

[1156] Step 7:

[1157] The server monitors the robot's operation log in real time and immediately issues an alert if an abnormality occurs. The input is the operation log and the output is an alert notification. Specifically, when the robot attempts to use the "unapproved_tool," the log is sent to the server and detected as an unauthorized operation. Based on this, the server issues an alert to the administrator, enabling a prompt response.

[1158] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1159] User Authentication and Login

[1160] To access the system, a user logs in using user authentication information. The user displays a login screen on the terminal and enters their username and password. The terminal sends this authentication information to the server, which verifies the authentication information and verifies its validity. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and provides the dashboard screen to the user.

[1161] As a specific example, when a user attempts to log in by entering their ID and password, the device sends this information to the server, and if the server successfully authenticates, it displays a dashboard to the user.

[1162] Customizing your Office environment

[1163] After logging in, the server sends instructions based on the company's security policy to each device. The device then scans the Office applications and lists the installed AI tools. The server then enables permitted tools and disables prohibited tools based on the policy.

[1164] As a specific example, if a policy stating that "certain AI tools are prohibited" is distributed from the server, the device will disable that tool and be configured to use only other permitted tools.

[1165] Security Monitoring

[1166] The server monitors the activity of each device in real time. The device records user behavior and operations as a log and periodically sends it to the server. The server analyzes the received activity data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and takes necessary measures.

[1167] As a specific example, if the server detects suspicious data transmission from a specific device, it notifies the administrator of this information in real time and takes the necessary measures.

[1168] Generate regular security reports

[1169] The server periodically generates security reports based on collected activity data. These reports include policy violation statistics, risk assessments, and recommended countermeasures. The reports provided to administrators can be used to review and improve security policies.

[1170] As a specific example, data from the past month will be aggregated and a report will be generated that details data transmission, usage of AI tools, detected risks, etc., and provided to administrators.

[1171] Attack detection and alerting

[1172] The server monitors known attack patterns and anomalous activity in real time to detect potential unauthorized access or security breaches. This includes notifying users when anomalous activity is detected on the device. If anomalous activity is detected, the server performs detailed analysis and immediately sends an alert to the administrator. If necessary, the server temporarily restricts the device's network connection and takes additional security measures.

[1173] For example, if a server detects abnormal activity such as an attempt to transmit large amounts of data, it will immediately issue an alert and temporarily restrict the network connection of the device in question. Administrators will receive a notification, investigate the cause, and take measures.

[1174] Emotion recognition by emotion engine

[1175] An emotion engine is used to recognize the user's emotions. This engine uses the user's facial recognition information and voice analysis to identify emotions. Facial recognition information is captured using the device's camera, and the emotion engine analyzes it. Voice analysis is captured using the microphone, and the emotion engine analyzes it. The recognized emotion data is sent to the management server.

[1176] For example, when a user works on a device, the device's camera captures the user's facial expressions, and the emotion engine detects "stress." If the stress level is high, the system notifies the administrator.

[1177] Integrating emotion and activity data

[1178] By integrating the emotional data recognized by the emotion engine with the activity data sent from the device, highly accurate security risk assessment becomes possible. The server analyzes this data in real time and assesses risk based on emotional fluctuations and abnormal activity. This allows the system to immediately detect the possibility of increased risk when the user is experiencing emotional stress, allowing early countermeasures to be taken.

[1179] As a specific example, if the analysis of emotional and activity data detects an abnormality such as "attempting to send a large amount of data externally while under high stress levels," the server will immediately issue an alert and take measures such as restricting the user's activity.

[1180] The processing flow will be explained below.

[1181] User Authentication and Login

[1182] Step 1:

[1183] The user opens the login screen. The device displays the login screen.

[1184] Step 2:

[1185] The user enters their authentication information (username and password). The user enters their username and password and clicks the "Login" button.

[1186] Step 3:

[1187] The device sends authentication information to the server. The device sends the entered username and password to the server.

[1188] Step 4:

[1189] The server validates the credentials: it checks against its database to see if the username and password are correct.

[1190] Step 5:

[1191] The server sends the authentication result to the terminal. If the authentication is successful, the server generates a security token and sends it to the terminal.

[1192] Step 6:

[1193] The terminal displays the authentication result to the user. If authentication is successful, the terminal displays the dashboard screen, and if authentication is unsuccessful, it displays an error message.

[1194] Customizing your Office environment

[1195] Step 1:

[1196] The server sends the security policy to the terminal. The server obtains the company's security policy and sends that information to the terminal.

[1197] Step 2:

[1198] The device scans the Office applications. The device scans the installed Office applications and lists the AI ​​tools used.

[1199] Step 3:

[1200] The device checks whether the AI ​​tool can be used. The device compares the listed AI tools with the security policy obtained from the server to identify permitted and prohibited tools.

[1201] Step 4:

[1202] The device updates the settings for Office applications, disabling prohibited AI tools based on security policies and updating the settings so that only permitted tools are available.

[1203] Step 5:

[1204] The device sends the results of the configuration update to the server, providing information about which tools were allowed and which were disabled.

[1205] Security Monitoring

[1206] Step 1:

[1207] The server starts real-time monitoring. The server receives activity data from each device in real time and starts monitoring.

[1208] Step 2:

[1209] The device sends activity data to the server. The device records user activity (use of AI tools, external access attempts, etc.) as a log and periodically sends it to the server.

[1210] Step 3:

[1211] The server analyzes the activity. The server analyzes the received activity data to detect any behavior that violates security policies or suspicious activity.

[1212] Step 4:

[1213] If the server detects an abnormality, it issues an alert. The server generates an alert about the detected abnormality or security violation and notifies the user (administrator).

[1214] Step 5:

[1215] The server will take action and, if necessary, temporarily restrict access to the affected device to carry out further analysis and / or action.

[1216] Generate regular security reports

[1217] Step 1:

[1218] The server aggregates the activity data collected from all devices on a weekly or monthly basis.

[1219] Step 2:

[1220] The server generates security reports. The server automatically generates security reports based on the aggregated data, including risk assessments, policy violations, and recommended actions.

[1221] Step 3:

[1222] The server sends the report to the user (administrator). The server displays the generated report on the dashboard and sends a notification email to the user (administrator).

[1223] Step 4:

[1224] The user (administrator) checks the report. The user (administrator) checks the report and implements necessary countermeasures or policy adjustments.

[1225] Attack detection and alerting

[1226] Step 1:

[1227] The server monitors attack patterns. The server monitors known attack patterns and new anomalous activity in real time.

[1228] Step 2:

[1229] If the device detects any abnormal activity, it will notify the server. The device can also detect any abnormal activity on its own and notify the server of any suspicious activity.

[1230] Step 3:

[1231] The server performs a detailed analysis. The server performs a detailed analysis of the notified abnormal activity and evaluates the urgency of the event.

[1232] Step 4:

[1233] The server sends an alert to the user (administrator). If the level of urgency is high, the server immediately sends an alert to the user (administrator) to prompt them to take action.

[1234] Step 5:

[1235] The server will initiate countermeasures, including restricting the network connection of the affected device and contacting the security team, if necessary.

[1236] Emotion recognition by emotion engine

[1237] Step 1:

[1238] When a user uses the device, their actions are captured by the camera and microphone. The device uses the camera to recognize the user's face and the microphone to record their voice.

[1239] Step 2:

[1240] The device launches an emotion engine to analyze the captured data, which then recognizes emotions from the user's facial expressions and voice.

[1241] Step 3:

[1242] The device sends the recognized emotion data to the server in real time for use in assessing security risks.

[1243] Integrating emotion and activity data

[1244] Step 1:

[1245] The server receives emotion data and activity data in real time, and prepares the data for integration and analysis.

[1246] Step 2:

[1247] The server analyzes the emotion and activity data and performs an integrated risk assessment based on the user's stress level and abnormal activity.

[1248] Step 3:

[1249] The server notifies the results of the integrated risk assessment in real time, and if an abnormality is detected, the server immediately sends an alert to the administrator so that necessary measures can be taken.

[1250] As a specific example, if a user attempts to send a large amount of data while under high stress, the server will immediately issue an alert and take measures such as restricting the user's activity.

[1251] Stress level assessment and alerts

[1252] Step 1:

[1253] The device periodically captures the user's emotional data and transmits it to the server, allowing the server to continuously understand the user's emotional state.

[1254] Step 2:

[1255] The server evaluates the user's stress level based on the emotional data. Based on the data detected by the emotion engine, the server calculates the user's stress level.

[1256] Step 3:

[1257] If the server detects a high stress state, it notifies the administrator. If the stress level exceeds a certain threshold, the server immediately issues an alert, prompting the administrator to take action.

[1258] As a specific example, if the server detects an increase in the user's stress level and this reaches a dangerous level, the administrator will be notified to take timely action.

[1259] Example 2

[1260] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1261] While conventional systems provide basic security functions such as user authentication, security policy enforcement, and real-time monitoring, they lack risk assessment that takes into account the emotional state of the user and highly accurate risk detection using integrated data. Furthermore, early detection of security risks and notification to administrators can be delayed, requiring rapid response.

[1262] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[1263] In this invention, the server includes means for receiving user authentication information and performing authentication, means for transmitting the authentication result to the management server, means for the management server to scan the software and support tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy, means for transmitting activity data of each terminal to the management server in real time and detecting security risks in the management server, means for notifying an administrator of detected risks, means for periodically generating security reports and providing them to the administrator, means for capturing information using the terminal's camera and microphone to recognize user emotions and analyzing it with an emotion engine, and means for evaluating risks by integrating the emotion data and activity data and notifying an administrator if a high risk is detected. This enables highly accurate risk evaluation that takes the user's emotional state into consideration and rapid risk response.

[1264] "User Credentials" means information such as a username and password provided by a user to access a system.

[1265] "Authentication" is the process of verifying that the user credentials provided are valid.

[1266] A "management server" is a central management device for applying security policies, analyzing activity data, and detecting risks.

[1267] A "corporate security policy" is a set of rules and guidelines regarding information security established by a company.

[1268] A "terminal" is a device, such as a computer or smartphone, that a user uses to access the system.

[1269] "Software" is a general term for applications and programs installed on a terminal.

[1270] "Support tools" are software and applications that support users' work and tasks.

[1271] "Activity data" is a record of information about the user's operations and actions performed on the terminal.

[1272] "Security risks" are threats to systems and data, such as unauthorized access, data leakage, and destruction.

[1273] An "emotion engine" is software that analyzes emotions from a user's facial expressions and voice.

[1274] "Emotion data" is information about the user's emotions analyzed by the emotion engine.

[1275] This invention relates to a system that includes receiving user authentication information, authentication, applying security policies, real-time monitoring, emotion recognition using an emotion engine, and integrated risk assessment. This system is composed of elements including a server, a terminal, and a user, and specific embodiments thereof are described below.

[1276] First, the user opens the login screen on the device and enters their username and password. The device encrypts this authentication information and sends it to the server. The server compares the received authentication information with a database to verify its validity. If authentication is successful, the server generates a security token and sends it to the device. The device receives the security token and displays the dashboard screen to the user. For example, if a user attempts to log in by entering "user123" and "password123," the server authenticates and the dashboard is displayed.

[1277] Next, after logging in, the server sends the company's security policy to each terminal. Based on this, the terminal scans the installed Office applications and creates a list of available assistive tools. Based on the policy, the server enables permitted tools and disables prohibited tools. For example, if the server distributes a policy that "a specific assistive tool is prohibited," the terminal disables that tool and allows only other permitted tools to be used.

[1278] The server also monitors the activity data of each device in real time. The device records user operations as a log and periodically sends it to the server. The server analyzes this data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and takes necessary measures. For example, if the server detects suspicious data transmission from a specific device, it notifies the administrator in real time and implements necessary measures.

[1279] The server periodically generates security reports based on collected activity data. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. Administrators can review and improve security policies based on these reports. As a specific example, data from the past month is aggregated to generate a security report that includes statistics on policy violations and risk assessments, and the report is provided to administrators.

[1280] Furthermore, this system has the ability to recognize the user's emotions using an emotion engine. The device's camera and microphone are used to capture the user's facial expressions and voice, which the emotion engine analyzes to identify the emotion. The recognized emotion data is sent to the server. For example, if the camera captures the user's facial expressions while the user is working on the device and the emotion engine detects "stress," the information is notified to the administrator.

[1281] Finally, the server integrates the emotion data and activity data to perform a highly accurate risk assessment. By integrating the emotion data recognized by the emotion engine with the activity data sent from the device, the accuracy of the risk assessment is improved. For example, if a large amount of data transmission is detected in a state of high stress, the server will immediately issue an alert and take measures such as restricting the user's activity.

[1282] Example prompts for generative AI models

[1283] Here are some examples of prompts for generative AI models:

[1284] "The system you are trying to log into first requires a username and password. You enter this into the login screen, the server authenticates you, generates a security token, and if successful, displays the dashboard. Can you please explain the process in detail?"

[1285]

[1286] After logging in, the server issues instructions to the terminal based on the company's security policy. The terminal scans the Office applications and creates a list of support tools. Explain how the server controls the tools based on the policy.

[1287] These prompts can be used to obtain instructions from the generative AI model regarding specific system processing steps.

[1288] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1289] Step 1: Enter and submit user credentials

[1290] The user enters their username and password into the login screen of the device.

[1291] Input: Username and Password

[1292] The terminal encrypts the entered information and sends it to the server.

[1293] Output: Encrypted username and password

[1294] As a specific example of operation, the user inputs "user123" and "password123".

[1295] Step 2: Verify credentials

[1296] The server receives the encrypted username and password and checks it against a database.

[1297] Input: Encrypted username and password

[1298] A database check is performed to verify that the user is a valid user.

[1299] Output: Authentication result (success or failure)

[1300] As a specific example of operation, the server checks the database to see if the combination of "user123" and "password123" is correct.

[1301] Step 3: Generate and send a security token

[1302] If the authentication is successful, the server generates a security token and sends it to the terminal.

[1303] Input: Authentication result (success)

[1304] A security token is generated and sent to the terminal via the network.

[1305] Output: Security token

[1306] As a specific example of operation, the server generates a security token for "user123" and sends it to the terminal.

[1307] Step 4: View the dashboard

[1308] The terminal stores the received security token and displays the dashboard screen to the user.

[1309] Input: Security Token

[1310] Save the security token and display the dashboard screen.

[1311] Output: Dashboard screen displayed

[1312] As a specific example of operation, the terminal uses the security token to display a dashboard to the user.

[1313] Step 5: Applying security policies

[1314] The server transmits the security policy to the terminal.

[1315] Input: None (Policy is set in advance)

[1316] The security policy is sent to each terminal.

[1317] Output: Security policy

[1318] As a specific example of operation, the server sends a policy to the terminal that "certain support tools are prohibited."

[1319] Step 6: Scanning Office applications

[1320] The device receives the security policy and scans the installed Office applications.

[1321] Input: Security policy

[1322] Scan your Office applications and create a list of available assistive tools.

[1323] Output: List of supporting tools

[1324] As a specific example of operation, it scans the tools installed on the device and creates a list.

[1325] Step 7: Enable and disable tools

[1326] The server receives the list and enables or disables the tools based on the policy.

[1327] Input: A list of support tools and security policies

[1328] Parse the list and control the tool based on your policy.

[1329] Output: Tool enable / disable setting

[1330] As a specific example of operation, a specific support tool is disabled and other tools are enabled.

[1331] Step 8: Real-time monitoring

[1332] The terminal records the user's operations as a log and periodically sends it to the server.

[1333] Input: User operation log

[1334] Operation logs are recorded and periodically sent to the server.

[1335] Output: Operation log data

[1336] As a specific example of operation, the terminal records the user's operations in real time and transmits them to the server.

[1337] Step 9: Detect security risks

[1338] The server analyzes the received operation log data and detects security risks and policy violations.

[1339] Input: Operation log data

[1340] Analyze log data and assess risk.

[1341] Output: Risk assessment results and alert notifications

[1342] As a specific example of operation, the server detects suspicious data transmission and notifies the administrator.

[1343] Step 10: Generate and provide security reports

[1344] The server generates security reports based on periodically collected operation log data.

[1345] Input: Operation log data

[1346] Consolidate log data and generate reports.

[1347] Output: Security report

[1348] As a specific example of how it works, a report is generated that includes statistics on policy violations over the past month and a risk assessment.

[1349] Step 11: Capture and analyze emotion data

[1350] The device's camera and microphone are used to capture the user's facial expressions and voice, which are then analyzed by the emotion engine.

[1351] Input: User's facial expression data and voice data

[1352] The emotion engine analyzes the data and identifies emotions.

[1353] Output: Emotion data

[1354] As a specific example of operation, the user's facial expression is captured and "stress" is detected.

[1355] Step 12: Integrating emotion and activity data

[1356] The server integrates the emotion data and operation log data to perform risk assessment.

[1357] Input: Emotion data and operation log data

[1358] Integrate data to assess risk with precision.

[1359] Output: Risk assessment results and alert notifications

[1360] As a specific example of operation, if a large amount of data transmission is detected while the stress level is high, the server will issue an alert.

[1361] (Application example 2)

[1362] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1363] Traditional user authentication and security monitoring systems lack real-time analysis and integration of emotional data, making it difficult to properly detect security risks when users are in emotionally unstable situations. Furthermore, it is difficult to respond immediately when abnormal activity occurs, making it impossible to prevent potential security risks. This has resulted in serious gaps in enterprise-wide security measures.

[1364] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes: means for receiving user authentication information and performing authentication; means for transmitting the authentication result to the management server; means for the management server to scan applications and tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy; means for transmitting activity data of each terminal to the management server in real time and detecting security risks in the management server; means for notifying the user of the detected risks; means for periodically generating security reports and providing them to the user; means for analyzing the emotion data of the user of each terminal using an emotion engine and transmitting the analysis results to the management server; means for integrating the emotion data and activity data to evaluate security risks in real time; and means for immediately notifying the administrator when an abnormality is detected. This enables highly accurate security risk evaluation using emotion data, allowing for early detection of risks caused by abnormal activity or emotions and rapid response.

[1365] "User authentication information" refers to information provided by a user to authenticate themselves to the system, such as a user ID and password or biometric information.

[1366] A "management server" is a central server device that manages security policies within a company and monitors the status and operation of terminals.

[1367] A "security policy" is a set of guidelines and standards established by a company to protect information and maintain the security of its systems.

[1368] "Applications and Tools" refers to software products and utilities installed on the device.

[1369] "Activity data" is data that records a user's operation history and system usage.

[1370] "Security risk" refers to potential dangers such as unauthorized access to systems and data, information leaks, and attacks.

[1371] An "emotion engine" is a system that analyzes a user's facial expressions and voice to identify their emotional state at that time (for example, stress, joy, anger, etc.).

[1372] "Emotion data" is data that indicates the user's emotional state analyzed by the emotion engine.

[1373] An "anomaly" is unexpected behavior, such as irregular operations or data transmissions that are not considered normal.

[1374] "Notifying the user" means alerting the user about the detected security risk.

[1375] "Security Report" means a document generated periodically that contains detailed information about compliance with security policies and detected risks.

[1376] "Integration" means combining multiple pieces of data or information into one and analyzing it.

[1377] The programs that make up part of the system that realizes this application example provide various functions such as user authentication, security monitoring, emotion recognition, etc. Specifically, the following hardware and software are used:

[1378] Hardware used

[1379] Client terminal: High-performance PC or smart device

[1380] Camera and microphone: High-resolution camera (e.g., a generic webcam), high-quality microphone (e.g., a high-end microphone)

[1381] Software used

[1382] Server: A general-purpose cloud service provider's server (e.g., cloud server)

[1383] Software framework: Java, Spring Boot, TensorFlow (for emotion recognition)

[1384] Specific details of processing

[1385] 1. User authentication function

[1386] The terminal acquires user authentication information and sends it to the server. The server verifies the authentication information and, if valid, generates a security token and sends it to the terminal. This allows the user to access the system and use various functions.

[1387] 2. Customizing the Office environment

[1388] The server scans the tools installed on each device based on the company's security policy. Only tools permitted by the server are enabled, and prohibited tools are disabled. This creates an environment that complies with the company's security policy.

[1389] 3. Security monitoring function

[1390] The device records user operations and activity data and periodically sends it to the server. The server analyzes the received data in real time and detects security risks. If suspicious activity is detected, the server notifies the administrator. It also periodically generates security reports and provides them to the user.

[1391] 4. Emotion recognition function

[1392] The device's camera and microphone are used to analyze the user's emotions. The emotion engine identifies the user's emotions based on the facial recognition information and voice data acquired, and sends the data to the server as emotion data.

[1393] 5. Integrated analysis of emotion data and activity data

[1394] The server integrates and analyzes emotion data and activity data to perform highly accurate security risk assessments. If the activity of a user experiencing emotional stress is abnormal, the server detects the risk early and notifies the administrator.

[1395] Examples of concrete examples and prompts

[1396] Examples:

[1397] "After a user logs into their system, the Office environment is scanned and the appropriate tools are enabled based on the security policy."

[1398] "The device's camera and microphone recognize the user's emotions, and if a stress state is detected, this is reported to the server."

[1399] Example prompt sentence:

[1400] "How do I implement a security monitoring system that notifies administrators when anomalous activity is detected?"

[1401] "How do I implement emotion recognition using the EmotionEngine class?"

[1402] This improves the accuracy of security risk assessments, enabling early detection of risks caused by abnormal activity or emotions and rapid response.

[1403] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1404] Step 1:

[1405] The user displays a login screen on the client terminal and enters user authentication information (user name and password). The terminal sends this authentication information to the server, which receives it and verifies its validity by comparing it with an authentication database. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal that receives this token displays the dashboard screen for the user.

[1406] Input: Username, Password

[1407] Output: Security token, dashboard screen

[1408] Step 2:

[1409] The server instructs each device to scan the applications and tools installed on it based on the company's security policy. The device uses the Office scanner to generate a list of installed tools and sends it to the server. The server then enables permitted tools and disables prohibited tools based on the policy.

[1410] Input: List of installed applications and tools

[1411] Output: A list of tools you are allowed to use.

[1412] Step 3:

[1413] The device records user operations and system activity in real time and periodically sends it to the management server. The server analyzes the received activity data and detects security risks. If abnormal activity is detected, the server immediately notifies the administrator.

[1414] Input: Activity data

[1415] Output: Security risk detection results, alert notification

[1416] Step 4:

[1417] The device uses a camera and microphone to capture the user's facial expressions and voice, which are then analyzed by an emotion recognition engine, which determines the user's emotional state and sends the results to a management server as emotion data.

[1418] Input: Facial recognition information, voice data

[1419] Output: Emotion data

[1420] Step 5:

[1421] The server integrates and analyzes the received emotion data and activity data to perform highly accurate security risk assessments. If it determines that a user experiencing emotional stress is engaging in abnormal activity, it will detect the risk early and notify the administrator.

[1422] Input: Emotion data, activity data

[1423] Output: Highly accurate security risk assessment results and alert notifications

[1424] Step 6:

[1425] The server periodically generates security reports based on the collected activity and sentiment data. These reports include policy violation statistics, risk assessments, and recommended countermeasures. The generated reports are provided to administrators to help them review and improve their security policies.

[1426] Input: Activity data, emotion data

[1427] Output: Security report

[1428] This allows the system to smoothly perform a series of processes, from user authentication to emotional data analysis, security risk assessment, and periodic report generation.

[1429] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[1430] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1431] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.

[1432] [Fourth embodiment]

[1433] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.

[1434] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[1435] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1436] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.

[1437] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[1438] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[1439] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[1440] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.

[1441] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[1442] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1443] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1444] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[1445] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1446] User Authentication and Login

[1447] To access the system, a user must first log in using their user authentication information. The user displays a login screen on their terminal and enters their username and password. The terminal sends these authentication information to the server, which verifies the authentication information. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and displays the dashboard screen to the user.

[1448] For example, when a user attempts to log in by entering their ID and password, the device sends this information to the server, which then verifies the authentication information and, if correct, displays the dashboard to the user.

[1449] Customizing your Office environment

[1450] After logging in, the server sends instructions to each device based on the company's security policy. Based on this, the device scans Office applications and checks the installed AI tools. Based on the policy received from the server, the device enables permitted tools and disables prohibited tools.

[1451] For example, if the server distributes a policy that "prohibits a specific AI tool," the device will disable that tool and be configured to only use other permitted tools.

[1452] Security Monitoring

[1453] The server monitors the activity of each device in real time. The device records user operations and behavior as a log and periodically sends this to the server. The server analyzes the received activity data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and prompts them to take action.

[1454] For example, if the server detects suspicious data transmission activity from a specific device, it notifies the administrator in real time and takes necessary measures.

[1455] Generate regular security reports

[1456] The server periodically generates security reports based on the collected activity data, including policy violation statistics, risk assessments, and recommended countermeasures. The reports are provided to administrators to help them review and improve their security policies.

[1457] As a specific example, data from the past month is compiled and a report is created that details data transmission, usage of AI tools, detected risks, etc., and shared with administrators.

[1458] Attack detection and alerting

[1459] The server monitors known attack patterns and anomalous activity in real time to detect possible unauthorized access or security breaches. If a device detects anomalous activity, it notifies the server. The server then performs a detailed analysis and immediately sends an alert to the administrator in the event of an emergency. If necessary, it also restricts the device's network connection and implements additional security measures.

[1460] For example, if a server detects abnormal activity such as an attempt to send a large amount of data externally, it will immediately issue an alert and temporarily block the network connection of the device in question. Administrators will receive a notification, investigate the cause, and take measures.

[1461] The processing flow will be explained below.

[1462] User Authentication and Login

[1463] Step 1:

[1464] The user opens the login screen. The device displays the login screen.

[1465] Step 2:

[1466] The user enters their authentication information (username and password). The user enters their username and password and clicks the "Login" button.

[1467] Step 3:

[1468] The device sends authentication information to the server. The device sends the entered username and password to the server.

[1469] Step 4:

[1470] The server validates the credentials: it checks against its database to see if the username and password are correct.

[1471] Step 5:

[1472] The server sends the authentication result to the terminal. If the authentication is successful, the server generates a security token and sends it to the terminal.

[1473] Step 6:

[1474] The terminal displays the authentication result to the user. If authentication is successful, the terminal displays the dashboard screen, and if authentication is unsuccessful, it displays an error message.

[1475] Customizing your Office environment

[1476] Step 1:

[1477] The server sends the security policy to the terminal. The server obtains the company's security policy and sends that information to the terminal.

[1478] Step 2:

[1479] The device scans the Office applications. The device scans the installed Office applications and lists the AI ​​tools used.

[1480] Step 3:

[1481] The device checks whether the AI ​​tool can be used. The device compares the listed AI tools with the security policy obtained from the server to identify permitted and prohibited tools.

[1482] Step 4:

[1483] The device updates the settings for Office applications, disabling prohibited AI tools based on security policies and updating the settings so that only permitted tools are available.

[1484] Step 5:

[1485] The device sends the results of the configuration update to the server, providing information about which tools were allowed and which were disabled.

[1486] Security Monitoring

[1487] Step 1:

[1488] The server starts real-time monitoring. The server receives activity data from each device in real time and starts monitoring.

[1489] Step 2:

[1490] The device sends activity data to the server. The device records user activity (use of AI tools, external access attempts, etc.) as a log and periodically sends it to the server.

[1491] Step 3:

[1492] The server analyzes the activity. The server analyzes the received activity data to detect any behavior that violates security policies or suspicious activity.

[1493] Step 4:

[1494] If the server detects an abnormality, it issues an alert. The server generates an alert about the detected abnormality or security violation and notifies the user (administrator).

[1495] Step 5:

[1496] The server will take action and, if necessary, temporarily restrict access to the affected device to carry out further analysis and / or action.

[1497] Generate regular security reports

[1498] Step 1:

[1499] The server aggregates the activity data collected from all devices on a weekly or monthly basis.

[1500] Step 2:

[1501] The server generates security reports. The server automatically generates security reports based on the aggregated data, including risk assessments, policy violations, and recommended actions.

[1502] Step 3:

[1503] The server sends the report to the user (administrator). The server displays the generated report on the dashboard and sends a notification email to the user (administrator).

[1504] Step 4:

[1505] The user (administrator) checks the report. The user (administrator) checks the report and implements necessary countermeasures or policy adjustments.

[1506] Attack detection and alerting

[1507] Step 1:

[1508] The server monitors attack patterns. The server monitors known attack patterns and new anomalous activity in real time.

[1509] Step 2:

[1510] If the device detects any abnormal activity, it will notify the server. The device can also detect any abnormal activity on its own and notify the server of any suspicious activity.

[1511] Step 3:

[1512] The server performs a detailed analysis. The server performs a detailed analysis of the notified abnormal activity and evaluates the urgency of the event.

[1513] Step 4:

[1514] The server sends an alert to the user (administrator). If the level of urgency is high, the server immediately sends an alert to the user (administrator) to prompt them to take action.

[1515] Step 5:

[1516] The server will initiate countermeasures, including restricting the network connection of the affected device and contacting the security team, if necessary.

[1517] Example 1

[1518] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1519] In conventional systems, user authentication, terminal application management, and security monitoring are all performed separately, making it difficult to implement integrated security measures.In addition, there are issues with high security risks due to the difficulty of detecting anomalies in real time and strictly enforcing corporate security policies.

[1520] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1521] In this invention, the server includes means for receiving user authentication information and performing authentication, means for transmitting authentication results to a management server, means for the management server to scan software and tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy, means for transmitting operation records of each terminal to the management server in real time and detecting security risks in the management server, means for notifying an administrator of detected risks, means for periodically generating security reports and providing them to the administrator, means for generating a security token if authentication is successful and displaying a dashboard screen to the user, and means for monitoring known attack patterns and abnormal activity in real time and sending an alert to the administrator in the event of an emergency. This enables consistent management from user authentication to security monitoring and effectively reduces security risks.

[1522] "User Credentials" means information a user provides to identify themselves to a system, typically including a username and password.

[1523] "Authentication" is the process of verifying whether the authentication information provided by a user is correct and granting access to a system.

[1524] The "management server" is a central server that applies the company's security policies and monitors the activity of each terminal.

[1525] A "security policy" refers to the rules and standards that a company sets to protect information and prevent unauthorized access.

[1526] "Software" is a general term for programs and applications installed on a terminal.

[1527] A "tool" is a program used for a specific function or purpose.

[1528] "Operation record" is data that records the operations and actions of a user on a terminal.

[1529] A "security risk" is a situation that could threaten the security of a system, such as information leakage or unauthorized access.

[1530] A "security token" is digital information issued to a user who has been successfully authenticated, allowing access to a system.

[1531] The "dashboard screen" is a screen that displays system operation and management information, which can be accessed by a user after logging in.

[1532] "Attack patterns" refer to the methods and characteristics of known cyber attacks.

[1533] "Activity" is a general term for all operations and actions performed on a device.

[1534] An "alert" is a warning message sent to an administrator when an abnormality or risk is detected.

[1535] The present invention provides a system that realizes consistent management from user authentication to security monitoring, and effectively reduces security risks within a company. Specific embodiments of the system will be described below.

[1536] User Authentication and Login

[1537] In order for a user to access a system, they must first log in using their user authentication information. The user displays a login screen on their terminal and enters their username and password. The terminal sends this authentication information to the server, which then verifies it. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and displays the dashboard screen to the user. For example, when a user attempts to log in by entering their ID and password, the terminal sends this information to the server. The server verifies the authentication information, and if it is correct, displays the dashboard to the user.

[1538] Customizing your Office environment

[1539] After logging in, the server sends instructions to each device based on the company's security policy. Based on this, the device scans Office applications and checks for installed AI tools. Based on the policy received from the server, the device enables permitted tools and disables prohibited tools. For example, if the server distributes a policy that "prohibits a specific AI tool," the device will disable that tool and be configured to use only other permitted tools.

[1540] Security Monitoring

[1541] The server monitors the activity of each device in real time. The device records user operations and behavior as a log and periodically sends this to the server. The server analyzes the received activity data and detects security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and urges them to take measures. For example, if the server detects suspicious data transmission activity from a specific device, it notifies the administrator of this information in real time and takes the necessary measures.

[1542] Generate regular security reports

[1543] The server periodically generates security reports based on the collected activity data. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. The reports are provided to administrators and are used to review and improve security policies. For example, data from the past month is aggregated to create a report detailing data transmission, AI tool usage, and detected risks, which is shared with administrators.

[1544] Attack detection and alerting

[1545] The server monitors known attack patterns and abnormal activity in real time to detect possible unauthorized access or security breaches. If a terminal detects abnormal activity, it also notifies the server. The server performs a detailed analysis and, in the event of an emergency, immediately sends an alert to the administrator. If necessary, it will also restrict the network connection of the terminal in question and implement additional security measures. For example, if the server detects abnormal activity that attempts to send a large amount of data externally, it will immediately issue an alert and temporarily block the network connection of the terminal in question. The administrator receives the notification, investigates the cause, and takes measures.

[1546] Example prompts to input to the generative AI model

[1547] "We need documentation that explains how the server and device work together during the user authentication and login process. If the user credentials are correct, please provide details on how the server and device exchange security tokens and display the dashboard screen."

[1548] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1549] Step 1:

[1550] The user launches an application on the terminal and the login screen is displayed. The user enters a username and password. This input data is sent to the terminal. Specifically, the user enters the required information into the login form and clicks "Login."

[1551] Step 2:

[1552] The terminal sends the entered user authentication information to the server. As a specific example, the terminal sends an HTTP POST request and includes the user name and password in the payload. At this time, it receives the user authentication information as input data and executes the process of sending it to the server.

[1553] Step 3:

[1554] The server checks the received authentication information against its database. Specifically, it runs an SQL query against the database to see if the matching username and password combination exists. Based on this input, it validates the authentication information and, if authentication is successful, performs a data calculation to generate a security token.

[1555] Step 4:

[1556] If authentication is successful, the server generates a security token and sends it to the device. Specifically, the server generates a JWT (JSON Web Token) and embeds user and session information in it. The generated security token is sent as output data to the device.

[1557] Step 5:

[1558] The terminal uses the received security token to display the dashboard screen to the user. Specifically, the terminal includes the token in the HTTP header, retrieves the dashboard data from the server, and displays it on the screen. As a result, the user can access the dashboard screen.

[1559] Step 6:

[1560] The server sends the company's security policy to the device. Specifically, the server sends the policy data in JSON format to the device. Based on this input data, the server prepares policy data to scan the Office applications on the device.

[1561] Step 7:

[1562] The device scans the Office application based on the received policy and checks the installed AI tools. Specifically, the device's script compares the installed applications with the policy data. Based on this input data, the device outputs the scan results.

[1563] Step 8:

[1564] The device enables permitted tools and disables prohibited tools. Specifically, the device modifies registry settings and application configuration files and executes scripts to enable permitted tools. The output data sets the enabled / disabled status of the tools on the device.

[1565] Step 9:

[1566] The server monitors the activity of each device in real time. Specifically, the server monitors specific ports and records communications from each device as a log. Based on this input data, real-time monitoring data is generated.

[1567] Step 10:

[1568] The terminal records the user's operations and behavior as a log and periodically sends it to the server. Specifically, the terminal uploads the log file to the server at regular intervals. An operation log is generated based on this input data and sent.

[1569] Step 11:

[1570] The server analyzes the received activity data to detect security risks and policy violations. Specifically, the server uses machine learning models to detect abnormal patterns. This data is then processed to generate risk assessment data.

[1571] Step 12:

[1572] If an abnormality is detected, the server notifies the administrator and prompts them to take measures. Specifically, when the server detects an abnormality, it sends an alert to the administrator using a messaging service. The administrator receives this notification as output data.

[1573] Step 13:

[1574] The server periodically generates security reports based on collected activity data. Specifically, the server aggregates and analyzes the data using Python scripts, and generates reports based on this input data.

[1575] Step 14:

[1576] The server provides the generated report to the administrator. Specifically, the server uses report generation software to visualize the aggregated results and create a report in PDF format. The report generated as output data is then sent to the administrator via the mail server.

[1577] Step 15:

[1578] The server monitors known attack patterns and anomalous activity in real time. Specifically, the server analyzes data in real time using a log analysis tool. Based on this input data, the server outputs monitoring data.

[1579] Step 16:

[1580] If the device detects abnormal activity, it notifies the server. Specifically, the device runs the anomaly detection script and notifies the server via an API request. Anomaly notification data is generated based on this input data.

[1581] Step 17:

[1582] The server performs a detailed analysis and sends an alert to the administrator in the event of an emergency. Specifically, the server immediately sends an alert to the administrator via SMS or email based on the analysis results. The administrator receives an emergency notification as output data.

[1583] Step 18:

[1584] If necessary, the server restricts the network access of the relevant device and implements additional security measures. Specifically, the server changes the firewall settings to restrict the network access of the specific device. The output data is the network restriction for the device.

[1585] (Application example 1)

[1586] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1587] In recent years, the security of robots used in factories has become increasingly important. However, these robots require complex operations, making it difficult for administrators to monitor security risks in real time, and there is a lack of mechanisms for immediate response in the event of abnormal operations. Furthermore, generating regular security reports and detecting policy violations is often a manual process, creating a demand for efficient security management. For this reason, it has become essential to introduce a system that monitors robot operation logs in real time and issues immediate alerts when an abnormality occurs.

[1588] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1589] In this invention, the server includes: means for receiving user authentication information and performing authentication; means for transmitting authentication results to a management device; means for scanning software and tools installed on each terminal based on a company's security policy and setting permissions and prohibitions based on the policy; means for transmitting activity data from each terminal to the management device and detecting security risks in the management device; means for the management device to monitor robot operation logs and detect security risks in real time; means for notifying users of detected risks; means for periodically generating and providing security reports to users; and means for immediately issuing alerts when abnormal operations or security risks are detected. This enables real-time monitoring of operation logs of robots used in a factory and immediate alerts when abnormalities occur. Furthermore, automatic generation of periodic security reports enables efficient security management.

[1590] Definition statement:

[1591] "User authentication information" refers to identification information required for a user to access the system, and is primarily composed of a username and password.

[1592] A "management server" is a server for centrally managing multiple terminals and devices connected to a network.

[1593] A "security policy" is a set of rules that define security standards and norms for systems and devices.

[1594] "Software" is a set of instructions executed by a computer, a program that performs a specific purpose or function.

[1595] A "tool" is a part of software, a module or application that realizes a specific function or operation.

[1596] "Activity data" is a record of operations and events performed by users and systems.

[1597] A "security risk" is a threat or danger to the safety or reliability of a system or data.

[1598] "Risk notification" is the process of sending alerts to users and administrators about detected security risks.

[1599] "Security Report" means documents and data that analyze, evaluate, and report system activity and security status.

[1600] A "robot operation log" is a record of the operation and behavior of robots used in a factory.

[1601] "Anomaly detection" is the process by which a system automatically identifies and detects unusual operations or patterns.

[1602] "Real-time monitoring" is the process of monitoring the operation of systems and devices in real time and responding immediately.

[1603] An "alert" is a warning message that notifies a user or administrator when an abnormality or problem occurs.

[1604] The system for implementing this invention includes a series of processes that start with receiving user authentication information, control terminals based on security policies and perform real-time monitoring, and monitor the robot's operation log and detect abnormalities. The specific processing method for each step is described below.

[1605] First, user authentication information is received and authentication is performed. The user enters their authentication information (e.g., username and password) into the terminal. The terminal sends this authentication information to the management server. The management server verifies the received authentication information and confirms that the user is a valid user. If this authentication is successful, the management server generates a security token and sends it to the terminal. Using this token, the user can access the system and view the dashboard.

[1606] Next, the management server scans the software and tools installed on each terminal based on the company's security policy and sets allowed and prohibited tools. Specifically, the management server enables only allowed tools and disables prohibited tools according to the security policy. This process keeps the terminal environment in line with the security policy.

[1607] Furthermore, activity data from each device is sent to a management server in real time, and security risks are detected by the management server. For example, if a device uses a specific tool or performs an unauthorized operation, the operation log is sent to the server. The management server analyzes these logs and detects abnormal operations and security risks in real time.

[1608] The management server monitors the robot's operation log in real time and immediately issues an alert if an abnormality occurs. For example, if a robot attempts to use a prohibited tool, the log is immediately sent to the management server and detected as an abnormality. The management server uses this information to issue an alert and notify the user. The user receives this notification and can respond promptly.

[1609] This system generates security reports periodically. The management server automatically generates security reports based on activity data over a certain period of time. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. The generated reports are provided to users and can be used to review and improve security policies.

[1610] For example, if a log is sent when a robot used in a factory attempts to use "unapproved_tool," it will be detected as an unauthorized operation and an alert will be sent immediately to the administrator, who can then take prompt action based on this notification to prevent security risks.

[1611] Example prompt sentence:

[1612] "Please enter the logs of the robots used in the factory. Based on the security policy, we will determine whether this log violates the policy."

[1613] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1614] Step 1:

[1615] To access the system, a user enters a username and password into a terminal. The terminal sends this authentication information to a server. The server checks the received authentication information against a database to verify that the user is a valid user. If authentication is successful, the server generates a security token and sends it to the terminal. The input is the user's authentication information, and the output is a security token.

[1616] Step 2:

[1617] The terminal uses the security token received from the server to authenticate the user's access. If successful, the dashboard screen is displayed to the user. The input is the security token and the output is the dashboard screen. The terminal is configured to allow the user to access the authorized services and tools.

[1618] Step 3:

[1619] The server scans the software and tools installed on the terminal based on the company's security policy, enables permitted tools, and disables prohibited tools. The input is the security policy and the terminal's software information, and the output is instructions to change the settings. The server instructs the terminal to change the settings based on the policy.

[1620] Step 4:

[1621] Each device sends activity data to the server in real time. The input is the device's activity data, and the output is data sent to the server. The server receives this data and analyzes the date, time, and log content. As a result of the analysis, security risks are detected.

[1622] Step 5:

[1623] The server analyzes the received activity data and immediately notifies the user if a security risk is detected. The input is the analyzed activity data, and the output is a notification to the user. The server identifies specific unauthorized operations or suspicious behavior in real time and issues warnings as necessary.

[1624] Step 6:

[1625] The server periodically generates a security report based on the collected activity data. The input is the collected activity data, and the output is a security report. The report contains statistics on policy violations, risk assessments, and recommended countermeasures. The generated report is provided to the user.

[1626] Step 7:

[1627] The server monitors the robot's operation log in real time and immediately issues an alert if an abnormality occurs. The input is the operation log and the output is an alert notification. Specifically, when the robot attempts to use the "unapproved_tool," the log is sent to the server and detected as an unauthorized operation. Based on this, the server issues an alert to the administrator, enabling a prompt response.

[1628] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1629] User Authentication and Login

[1630] To access the system, a user logs in using user authentication information. The user displays a login screen on the terminal and enters their username and password. The terminal sends this authentication information to the server, which verifies the authentication information and verifies its validity. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal receives this token and provides the dashboard screen to the user.

[1631] As a specific example, when a user attempts to log in by entering their ID and password, the device sends this information to the server, and if the server successfully authenticates, it displays a dashboard to the user.

[1632] Customizing your Office environment

[1633] After logging in, the server sends instructions based on the company's security policy to each device. The device then scans the Office applications and lists the installed AI tools. The server then enables permitted tools and disables prohibited tools based on the policy.

[1634] As a specific example, if a policy stating that "certain AI tools are prohibited" is distributed from the server, the device will disable that tool and be configured to use only other permitted tools.

[1635] Security Monitoring

[1636] The server monitors the activity of each device in real time. The device records user behavior and operations as a log and periodically sends it to the server. The server analyzes the received activity data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and takes necessary measures.

[1637] As a specific example, if the server detects suspicious data transmission from a specific device, it notifies the administrator of this information in real time and takes the necessary measures.

[1638] Generate regular security reports

[1639] The server periodically generates security reports based on collected activity data. These reports include policy violation statistics, risk assessments, and recommended countermeasures. The reports provided to administrators can be used to review and improve security policies.

[1640] As a specific example, data from the past month will be aggregated and a report will be generated that details data transmission, usage of AI tools, detected risks, etc., and provided to administrators.

[1641] Attack detection and alerting

[1642] The server monitors known attack patterns and anomalous activity in real time to detect potential unauthorized access or security breaches. This includes notifying users when anomalous activity is detected on the device. If anomalous activity is detected, the server performs detailed analysis and immediately sends an alert to the administrator. If necessary, the server temporarily restricts the device's network connection and takes additional security measures.

[1643] For example, if a server detects abnormal activity such as an attempt to transmit large amounts of data, it will immediately issue an alert and temporarily restrict the network connection of the device in question. Administrators will receive a notification, investigate the cause, and take measures.

[1644] Emotion recognition by emotion engine

[1645] An emotion engine is used to recognize the user's emotions. This engine uses the user's facial recognition information and voice analysis to identify emotions. Facial recognition information is captured using the device's camera, and the emotion engine analyzes it. Voice analysis is captured using the microphone, and the emotion engine analyzes it. The recognized emotion data is sent to the management server.

[1646] For example, when a user works on a device, the device's camera captures the user's facial expressions, and the emotion engine detects "stress." If the stress level is high, the system notifies the administrator.

[1647] Integrating emotion and activity data

[1648] By integrating the emotional data recognized by the emotion engine with the activity data sent from the device, highly accurate security risk assessment becomes possible. The server analyzes this data in real time and assesses risk based on emotional fluctuations and abnormal activity. This allows the system to immediately detect the possibility of increased risk when the user is experiencing emotional stress, allowing early countermeasures to be taken.

[1649] As a specific example, if the analysis of emotional and activity data detects an abnormality such as "attempting to send a large amount of data externally while under high stress levels," the server will immediately issue an alert and take measures such as restricting the user's activity.

[1650] The processing flow will be explained below.

[1651] User Authentication and Login

[1652] Step 1:

[1653] The user opens the login screen. The device displays the login screen.

[1654] Step 2:

[1655] The user enters their authentication information (username and password). The user enters their username and password and clicks the "Login" button.

[1656] Step 3:

[1657] The device sends authentication information to the server. The device sends the entered username and password to the server.

[1658] Step 4:

[1659] The server validates the credentials: it checks against its database to see if the username and password are correct.

[1660] Step 5:

[1661] The server sends the authentication result to the terminal. If the authentication is successful, the server generates a security token and sends it to the terminal.

[1662] Step 6:

[1663] The terminal displays the authentication result to the user. If authentication is successful, the terminal displays the dashboard screen, and if authentication is unsuccessful, it displays an error message.

[1664] Customizing your Office environment

[1665] Step 1:

[1666] The server sends the security policy to the terminal. The server obtains the company's security policy and sends that information to the terminal.

[1667] Step 2:

[1668] The device scans the Office applications. The device scans the installed Office applications and lists the AI ​​tools used.

[1669] Step 3:

[1670] The device checks whether the AI ​​tool can be used. The device compares the listed AI tools with the security policy obtained from the server to identify permitted and prohibited tools.

[1671] Step 4:

[1672] The device updates the settings for Office applications, disabling prohibited AI tools based on security policies and updating the settings so that only permitted tools are available.

[1673] Step 5:

[1674] The device sends the results of the configuration update to the server, providing information about which tools were allowed and which were disabled.

[1675] Security Monitoring

[1676] Step 1:

[1677] The server starts real-time monitoring. The server receives activity data from each device in real time and starts monitoring.

[1678] Step 2:

[1679] The device sends activity data to the server. The device records user activity (use of AI tools, external access attempts, etc.) as a log and periodically sends it to the server.

[1680] Step 3:

[1681] The server analyzes the activity. The server analyzes the received activity data to detect any behavior that violates security policies or suspicious activity.

[1682] Step 4:

[1683] If the server detects an abnormality, it issues an alert. The server generates an alert about the detected abnormality or security violation and notifies the user (administrator).

[1684] Step 5:

[1685] The server will take action and, if necessary, temporarily restrict access to the affected device to carry out further analysis and / or action.

[1686] Generate regular security reports

[1687] Step 1:

[1688] The server aggregates the activity data collected from all devices on a weekly or monthly basis.

[1689] Step 2:

[1690] The server generates security reports. The server automatically generates security reports based on the aggregated data, including risk assessments, policy violations, and recommended actions.

[1691] Step 3:

[1692] The server sends the report to the user (administrator). The server displays the generated report on the dashboard and sends a notification email to the user (administrator).

[1693] Step 4:

[1694] The user (administrator) checks the report. The user (administrator) checks the report and implements necessary countermeasures or policy adjustments.

[1695] Attack detection and alerting

[1696] Step 1:

[1697] The server monitors attack patterns. The server monitors known attack patterns and new anomalous activity in real time.

[1698] Step 2:

[1699] If the device detects any abnormal activity, it will notify the server. The device can also detect any abnormal activity on its own and notify the server of any suspicious activity.

[1700] Step 3:

[1701] The server performs a detailed analysis. The server performs a detailed analysis of the notified abnormal activity and evaluates the urgency of the event.

[1702] Step 4:

[1703] The server sends an alert to the user (administrator). If the level of urgency is high, the server immediately sends an alert to the user (administrator) to prompt them to take action.

[1704] Step 5:

[1705] The server will initiate countermeasures, including restricting the network connection of the affected device and contacting the security team, if necessary.

[1706] Emotion recognition by emotion engine

[1707] Step 1:

[1708] When a user uses the device, their actions are captured by the camera and microphone. The device uses the camera to recognize the user's face and the microphone to record their voice.

[1709] Step 2:

[1710] The device launches an emotion engine to analyze the captured data, which then recognizes emotions from the user's facial expressions and voice.

[1711] Step 3:

[1712] The device sends the recognized emotion data to the server in real time for use in assessing security risks.

[1713] Integrating emotion and activity data

[1714] Step 1:

[1715] The server receives emotion data and activity data in real time, and prepares the data for integration and analysis.

[1716] Step 2:

[1717] The server analyzes the emotion and activity data and performs an integrated risk assessment based on the user's stress level and abnormal activity.

[1718] Step 3:

[1719] The server notifies the results of the integrated risk assessment in real time, and if an abnormality is detected, the server immediately sends an alert to the administrator so that necessary measures can be taken.

[1720] As a specific example, if a user attempts to send a large amount of data while under high stress, the server will immediately issue an alert and take measures such as restricting the user's activity.

[1721] Stress level assessment and alerts

[1722] Step 1:

[1723] The device periodically captures the user's emotional data and transmits it to the server, allowing the server to continuously understand the user's emotional state.

[1724] Step 2:

[1725] The server evaluates the user's stress level based on the emotional data. Based on the data detected by the emotion engine, the server calculates the user's stress level.

[1726] Step 3:

[1727] If the server detects a high stress state, it notifies the administrator. If the stress level exceeds a certain threshold, the server immediately issues an alert, prompting the administrator to take action.

[1728] As a specific example, if the server detects an increase in the user's stress level and this reaches a dangerous level, the administrator will be notified to take timely action.

[1729] Example 2

[1730] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1731] While conventional systems provide basic security functions such as user authentication, security policy enforcement, and real-time monitoring, they lack risk assessment that takes into account the emotional state of the user and highly accurate risk detection using integrated data. Furthermore, early detection of security risks and notification to administrators can be delayed, requiring rapid response.

[1732] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[1733] In this invention, the server includes means for receiving user authentication information and performing authentication, means for transmitting the authentication result to the management server, means for the management server to scan the software and support tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy, means for transmitting activity data of each terminal to the management server in real time and detecting security risks in the management server, means for notifying an administrator of detected risks, means for periodically generating security reports and providing them to the administrator, means for capturing information using the terminal's camera and microphone to recognize user emotions and analyzing it with an emotion engine, and means for evaluating risks by integrating the emotion data and activity data and notifying an administrator if a high risk is detected. This enables highly accurate risk evaluation that takes the user's emotional state into consideration and rapid risk response.

[1734] "User Credentials" means information such as a username and password provided by a user to access a system.

[1735] "Authentication" is the process of verifying that the user credentials provided are valid.

[1736] A "management server" is a central management device for applying security policies, analyzing activity data, and detecting risks.

[1737] A "corporate security policy" is a set of rules and guidelines regarding information security established by a company.

[1738] A "terminal" is a device, such as a computer or smartphone, that a user uses to access the system.

[1739] "Software" is a general term for applications and programs installed on a terminal.

[1740] "Support tools" are software and applications that support users' work and tasks.

[1741] "Activity data" is a record of information about the user's operations and actions performed on the terminal.

[1742] "Security risks" are threats to systems and data, such as unauthorized access, data leakage, and destruction.

[1743] An "emotion engine" is software that analyzes emotions from a user's facial expressions and voice.

[1744] "Emotion data" is information about the user's emotions analyzed by the emotion engine.

[1745] This invention relates to a system that includes receiving user authentication information, authentication, applying security policies, real-time monitoring, emotion recognition using an emotion engine, and integrated risk assessment. This system is composed of elements including a server, a terminal, and a user, and specific embodiments thereof are described below.

[1746] First, the user opens the login screen on the device and enters their username and password. The device encrypts this authentication information and sends it to the server. The server compares the received authentication information with a database to verify its validity. If authentication is successful, the server generates a security token and sends it to the device. The device receives the security token and displays the dashboard screen to the user. For example, if a user attempts to log in by entering "user123" and "password123," the server authenticates and the dashboard is displayed.

[1747] Next, after logging in, the server sends the company's security policy to each terminal. Based on this, the terminal scans the installed Office applications and creates a list of available assistive tools. Based on the policy, the server enables permitted tools and disables prohibited tools. For example, if the server distributes a policy that "a specific assistive tool is prohibited," the terminal disables that tool and allows only other permitted tools to be used.

[1748] The server also monitors the activity data of each device in real time. The device records user operations as a log and periodically sends it to the server. The server analyzes this data to detect security risks and policy violations. If an abnormality is detected, the server immediately notifies the administrator and takes necessary measures. For example, if the server detects suspicious data transmission from a specific device, it notifies the administrator in real time and implements necessary measures.

[1749] The server periodically generates security reports based on collected activity data. These reports include statistics on policy violations, risk assessments, and recommended countermeasures. Administrators can review and improve security policies based on these reports. As a specific example, data from the past month is aggregated to generate a security report that includes statistics on policy violations and risk assessments, and the report is provided to administrators.

[1750] Furthermore, this system has the ability to recognize the user's emotions using an emotion engine. The device's camera and microphone are used to capture the user's facial expressions and voice, which the emotion engine analyzes to identify the emotion. The recognized emotion data is sent to the server. For example, if the camera captures the user's facial expressions while the user is working on the device and the emotion engine detects "stress," the information is notified to the administrator.

[1751] Finally, the server integrates the emotion data and activity data to perform a highly accurate risk assessment. By integrating the emotion data recognized by the emotion engine with the activity data sent from the device, the accuracy of the risk assessment is improved. For example, if a large amount of data transmission is detected in a state of high stress, the server will immediately issue an alert and take measures such as restricting the user's activity.

[1752] Example prompts for generative AI models

[1753] Here are some examples of prompts for generative AI models:

[1754] "The system you are trying to log into first requires a username and password. You enter this into the login screen, the server authenticates you, generates a security token, and if successful, displays the dashboard. Can you please explain the process in detail?"

[1755]

[1756] After logging in, the server issues instructions to the terminal based on the company's security policy. The terminal scans the Office applications and creates a list of support tools. Explain how the server controls the tools based on the policy.

[1757] These prompts can be used to obtain instructions from the generative AI model regarding specific system processing steps.

[1758] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1759] Step 1: Enter and submit user credentials

[1760] The user enters their username and password into the login screen of the device.

[1761] Input: Username and Password

[1762] The terminal encrypts the entered information and sends it to the server.

[1763] Output: Encrypted username and password

[1764] As a specific example of operation, the user inputs "user123" and "password123".

[1765] Step 2: Verify credentials

[1766] The server receives the encrypted username and password and checks it against a database.

[1767] Input: Encrypted username and password

[1768] A database check is performed to verify that the user is a valid user.

[1769] Output: Authentication result (success or failure)

[1770] As a specific example of operation, the server checks the database to see if the combination of "user123" and "password123" is correct.

[1771] Step 3: Generate and send a security token

[1772] If the authentication is successful, the server generates a security token and sends it to the terminal.

[1773] Input: Authentication result (success)

[1774] A security token is generated and sent to the terminal via the network.

[1775] Output: Security token

[1776] As a specific example of operation, the server generates a security token for "user123" and sends it to the terminal.

[1777] Step 4: View the dashboard

[1778] The terminal stores the received security token and displays the dashboard screen to the user.

[1779] Input: Security Token

[1780] Save the security token and display the dashboard screen.

[1781] Output: Dashboard screen displayed

[1782] As a specific example of operation, the terminal uses the security token to display a dashboard to the user.

[1783] Step 5: Applying security policies

[1784] The server transmits the security policy to the terminal.

[1785] Input: None (Policy is set in advance)

[1786] The security policy is sent to each terminal.

[1787] Output: Security policy

[1788] As a specific example of operation, the server sends a policy to the terminal that "certain support tools are prohibited."

[1789] Step 6: Scanning Office applications

[1790] The device receives the security policy and scans the installed Office applications.

[1791] Input: Security policy

[1792] Scan your Office applications and create a list of available assistive tools.

[1793] Output: List of supporting tools

[1794] As a specific example of operation, it scans the tools installed on the device and creates a list.

[1795] Step 7: Enable and disable tools

[1796] The server receives the list and enables or disables the tools based on the policy.

[1797] Input: A list of support tools and security policies

[1798] Parse the list and control the tool based on your policy.

[1799] Output: Tool enable / disable setting

[1800] As a specific example of operation, a specific support tool is disabled and other tools are enabled.

[1801] Step 8: Real-time monitoring

[1802] The terminal records the user's operations as a log and periodically sends it to the server.

[1803] Input: User operation log

[1804] Operation logs are recorded and periodically sent to the server.

[1805] Output: Operation log data

[1806] As a specific example of operation, the terminal records the user's operations in real time and transmits them to the server.

[1807] Step 9: Detect security risks

[1808] The server analyzes the received operation log data and detects security risks and policy violations.

[1809] Input: Operation log data

[1810] Analyze log data and assess risk.

[1811] Output: Risk assessment results and alert notifications

[1812] As a specific example of operation, the server detects suspicious data transmission and notifies the administrator.

[1813] Step 10: Generate and provide security reports

[1814] The server generates security reports based on periodically collected operation log data.

[1815] Input: Operation log data

[1816] Consolidate log data and generate reports.

[1817] Output: Security report

[1818] As a specific example of how it works, a report is generated that includes statistics on policy violations over the past month and a risk assessment.

[1819] Step 11: Capture and analyze emotion data

[1820] The device's camera and microphone are used to capture the user's facial expressions and voice, which are then analyzed by the emotion engine.

[1821] Input: User's facial expression data and voice data

[1822] The emotion engine analyzes the data and identifies emotions.

[1823] Output: Emotion data

[1824] As a specific example of operation, the user's facial expression is captured and "stress" is detected.

[1825] Step 12: Integrating emotion and activity data

[1826] The server integrates the emotion data and operation log data to perform risk assessment.

[1827] Input: Emotion data and operation log data

[1828] Integrate data to assess risk with precision.

[1829] Output: Risk assessment results and alert notifications

[1830] As a specific example of operation, if a large amount of data transmission is detected while the stress level is high, the server will issue an alert.

[1831] (Application example 2)

[1832] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1833] Traditional user authentication and security monitoring systems lack real-time analysis and integration of emotional data, making it difficult to properly detect security risks when users are in emotionally unstable situations. Furthermore, it is difficult to respond immediately when abnormal activity occurs, making it impossible to prevent potential security risks. This has resulted in serious gaps in enterprise-wide security measures.

[1834] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes: means for receiving user authentication information and performing authentication; means for transmitting the authentication result to the management server; means for the management server to scan applications and tools installed on each terminal based on the company's security policy and set permissions and prohibitions based on the policy; means for transmitting activity data of each terminal to the management server in real time and detecting security risks in the management server; means for notifying the user of the detected risks; means for periodically generating security reports and providing them to the user; means for analyzing the emotion data of the user of each terminal using an emotion engine and transmitting the analysis results to the management server; means for integrating the emotion data and activity data to evaluate security risks in real time; and means for immediately notifying the administrator when an abnormality is detected. This enables highly accurate security risk evaluation using emotion data, allowing for early detection of risks caused by abnormal activity or emotions and rapid response.

[1835] "User authentication information" refers to information provided by a user to authenticate themselves to the system, such as a user ID and password or biometric information.

[1836] A "management server" is a central server device that manages security policies within a company and monitors the status and operation of terminals.

[1837] A "security policy" is a set of guidelines and standards established by a company to protect information and maintain the security of its systems.

[1838] "Applications and Tools" refers to software products and utilities installed on the device.

[1839] "Activity data" is data that records a user's operation history and system usage.

[1840] "Security risk" refers to potential dangers such as unauthorized access to systems and data, information leaks, and attacks.

[1841] An "emotion engine" is a system that analyzes a user's facial expressions and voice to identify their emotional state at that time (for example, stress, joy, anger, etc.).

[1842] "Emotion data" is data that indicates the user's emotional state analyzed by the emotion engine.

[1843] An "anomaly" is unexpected behavior, such as irregular operations or data transmissions that are not considered normal.

[1844] "Notifying the user" means alerting the user about the detected security risk.

[1845] "Security Report" means a document generated periodically that contains detailed information about compliance with security policies and detected risks.

[1846] "Integration" means combining multiple pieces of data or information into one and analyzing it.

[1847] The programs that make up part of the system that realizes this application example provide various functions such as user authentication, security monitoring, emotion recognition, etc. Specifically, the following hardware and software are used:

[1848] Hardware used

[1849] Client terminal: High-performance PC or smart device

[1850] Camera and microphone: High-resolution camera (e.g., a generic webcam), high-quality microphone (e.g., a high-end microphone)

[1851] Software used

[1852] Server: A general-purpose cloud service provider's server (e.g., cloud server)

[1853] Software framework: Java, Spring Boot, TensorFlow (for emotion recognition)

[1854] Specific details of processing

[1855] 1. User authentication function

[1856] The terminal acquires user authentication information and sends it to the server. The server verifies the authentication information and, if valid, generates a security token and sends it to the terminal. This allows the user to access the system and use various functions.

[1857] 2. Customizing the Office environment

[1858] The server scans the tools installed on each device based on the company's security policy. Only tools permitted by the server are enabled, and prohibited tools are disabled. This creates an environment that complies with the company's security policy.

[1859] 3. Security monitoring function

[1860] The device records user operations and activity data and periodically sends it to the server. The server analyzes the received data in real time and detects security risks. If suspicious activity is detected, the server notifies the administrator. It also periodically generates security reports and provides them to the user.

[1861] 4. Emotion recognition function

[1862] The device's camera and microphone are used to analyze the user's emotions. The emotion engine identifies the user's emotions based on the facial recognition information and voice data acquired, and sends the data to the server as emotion data.

[1863] 5. Integrated analysis of emotion data and activity data

[1864] The server integrates and analyzes emotion data and activity data to perform highly accurate security risk assessments. If the activity of a user experiencing emotional stress is abnormal, the server detects the risk early and notifies the administrator.

[1865] Examples of concrete examples and prompts

[1866] Examples:

[1867] "After a user logs into their system, the Office environment is scanned and the appropriate tools are enabled based on the security policy."

[1868] "The device's camera and microphone recognize the user's emotions, and if a stress state is detected, this is reported to the server."

[1869] Example prompt sentence:

[1870] "How do I implement a security monitoring system that notifies administrators when anomalous activity is detected?"

[1871] "How do I implement emotion recognition using the EmotionEngine class?"

[1872] This improves the accuracy of security risk assessments, enabling early detection of risks caused by abnormal activity or emotions and rapid response.

[1873] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1874] Step 1:

[1875] The user displays a login screen on the client terminal and enters user authentication information (user name and password). The terminal sends this authentication information to the server, which receives it and verifies its validity by comparing it with an authentication database. If authentication is successful, the server generates a security token and sends it to the terminal. The terminal that receives this token displays the dashboard screen for the user.

[1876] Input: Username, Password

[1877] Output: Security token, dashboard screen

[1878] Step 2:

[1879] The server instructs each device to scan the applications and tools installed on it based on the company's security policy. The device uses the Office scanner to generate a list of installed tools and sends it to the server. The server then enables permitted tools and disables prohibited tools based on the policy.

[1880] Input: List of installed applications and tools

[1881] Output: A list of tools you are allowed to use.

[1882] Step 3:

[1883] The device records user operations and system activity in real time and periodically sends it to the management server. The server analyzes the received activity data and detects security risks. If abnormal activity is detected, the server immediately notifies the administrator.

[1884] Input: Activity data

[1885] Output: Security risk detection results, alert notification

[1886] Step 4:

[1887] The device uses a camera and microphone to capture the user's facial expressions and voice, which are then analyzed by an emotion recognition engine, which determines the user's emotional state and sends the results to a management server as emotion data.

[1888] Input: Facial recognition information, voice data

[1889] Output: Emotion data

[1890] Step 5:

[1891] The server integrates and analyzes the received emotion data and activity data to perform highly accurate security risk assessments. If it determines that a user experiencing emotional stress is engaging in abnormal activity, it will detect the risk early and notify the administrator.

[1892] Input: Emotion data, activity data

[1893] Output: Highly accurate security risk assessment results and alert notifications

[1894] Step 6:

[1895] The server periodically generates security reports based on the collected activity and sentiment data. These reports include policy violation statistics, risk assessments, and recommended countermeasures. The generated reports are provided to administrators to help them review and improve their security policies.

[1896] Input: Activity data, emotion data

[1897] Output: Security report

[1898] This allows the system to smoothly perform a series of processes, from user authentication to emotional data analysis, security risk assessment, and periodic report generation.

[1899] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.

[1900] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by perform...

Claims

1. means for receiving and authenticating user authentication information; means for transmitting an authentication result to a management server; A management server scans applications and tools installed on each terminal based on the company's security policy and sets permissions and prohibitions based on the policy; a means for transmitting activity data of each terminal to a management server in real time and detecting security risks in the management server; a means for notifying users of detected risks; a means for periodically generating and providing security reports to users; A system including:

2. 2. The system according to claim 1, further comprising means for performing real-time monitoring, transmitting activity data of each terminal to a management server, and detecting abnormalities.

3. 10. The system of claim 1, further comprising means for periodically generating security reports and providing the reports to a user, the reports including policy violations and risk assessments.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A