system
The system addresses the inflexibility of conventional security systems by dynamically generating security rules based on user behavior and environmental changes, enhancing security accuracy and convenience.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-22
- Publication Date
- 2026-03-06
AI Technical Summary
Conventional security systems based on fixed algorithms and rule sets lack flexibility, failing to adapt to changes in user behavior patterns and environmental conditions, leading to vulnerabilities and reduced accuracy in detecting abnormal activity.
A system that collects user authentication information, performs dynamic analysis on a server, and generates flexible security rules, including two-factor authentication when anomalies are detected, to adapt security measures to user behavior and environmental changes.
The system provides enhanced security accuracy and flexibility by dynamically adjusting security levels based on user behavior and environmental conditions, ensuring high security and user convenience.
Smart Images

Figure 2026038124000001_ABST
Abstract
Description
[Technical Field]
[0001] The technology of the present disclosure relates to a system. [Background technology]
[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]
[0004] Conventional security walls are built based on fixed algorithms and rule sets, which means they lack flexibility. As a result, they are unable to adapt to changes in user behavior patterns and the environment, which can lead to vulnerabilities in certain scenarios. Furthermore, static rules alone are not sufficiently accurate when detecting abnormal activity. The present invention aims to solve these problems and provide a security wall that can respond dynamically and flexibly. [Means for solving the problem]
[0005] The present invention provides a system that includes means for collecting user authentication information, means for transmitting the authentication information to a server, means for verifying the collected user authentication information at the server and performing authentication, means for analyzing the additional authentication information and detecting anomalies, means for generating dynamic security rules and requesting additional authentication when an anomaly is detected, and means for ultimately determining whether to permit or deny access. This enables flexible security measures that respond to user behavior and the environment, achieving higher accuracy and safety than conventional fixed rules.
[0006] "Authentication information" refers to information collected to verify access rights, such as user ID, password, location information, device information, and access time.
[0007] "Additional authentication information" is information collected in addition to basic authentication information, such as location information and device information, that is used for anomaly detection.
[0008] A "server" is a system that provides services over a network, collates authentication information, analyzes abnormalities, and grants or denies access.
[0009] "Dynamic security rules" are security countermeasure rules that are generated when an abnormality is detected and are flexibly adapted.
[0010] "Two-factor authentication" is an authentication method that strengthens security by using a second authentication method (e.g., a transmitted authentication code) in addition to one piece of authentication information.
[0011] "Anomaly detection" is the process of flagging a user's additional authentication information as suspicious if it doesn't match previous access history or known information.
[0012] "Allow or deny" means that the server makes the final decision to allow or deny access to a resource based on the user's authentication information and dynamic security rules. [Brief explanation of the drawings]
[0013] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram showing a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION
[0014] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.
[0015] First, the terms used in the following description will be explained.
[0016] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).
[0017] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.
[0018] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.
[0019] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.
[0020] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."
[0021] [First embodiment]
[0022] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.
[0023] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0024] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0025] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.
[0026] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0027] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0028] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.
[0029] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0030] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0031] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0032] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[0033] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0034] The system of the present invention dynamically builds a security wall based on user behavior patterns and environmental conditions. This system collects user authentication information, performs dynamic analysis on the server, and generates dynamic security rules when an abnormality is detected. This provides greater flexibility and security accuracy than conventional static security rules.
[0035] System configuration
[0036] The system of the present invention includes the following major components:
[0037] User terminal: The device used by the user to access the server, where authentication information is collected.
[0038] Server: Receives authentication information, performs analysis, matching, and anomaly detection, and generates dynamic security rules to determine whether access is allowed or denied.
[0039] Program processing explanation
[0040] Credential collection and transmission
[0041] When a user attempts to access the system using a terminal, the terminal collects the following information: user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and the time of access. The terminal encrypts this information and sends it to the server.
[0042] Authentication process on the server
[0043] The server performs basic authentication processing based on the received authentication information. It checks the user ID and password against a database to determine whether authentication was successful. If authentication is successful, it proceeds to the next step, but if it is unsuccessful, it denies access and returns an error message to the user.
[0044] Analysis of additional conditions and anomaly detection
[0045] After basic authentication is successful, the server analyzes additional authentication information (location and device information). This includes comparing it with past access history and assessing the degree of match. For example, if the location information changes suddenly or access from a new device is detected, the server flags this as an anomaly and uses this information to generate dynamic security rules.
[0046] Dynamic security rule generation
[0047] If the server flags an anomaly, it will generate dynamic security rules that require additional authentication steps, such as a rule requiring two-factor authentication (2FA) and requiring the user to enter a verification code sent to a registered email address or mobile phone number.
[0048] Enforcing additional authentication and access permissions
[0049] The user enters the authentication code sent in response to a request for additional authentication from the server. The terminal then sends this authentication code back to the server, which then verifies its validity. If authentication is successful, the server finally grants access and provides the user with access to the resource. If authentication fails, access is denied and the reason is displayed to the user.
[0050] Specific examples
[0051] Access during normal times
[0052] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), and access time, and sends them to the server. The server performs basic authentication based on this information and analyzes additional conditions. In this case, since all the information matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[0053] Abnormal access
[0054] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), and access time, and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, and the server requests two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[0055] As described above, the system of the present invention can dynamically and flexibly adjust the security level, achieving both high security and user convenience.
[0056] The processing flow will be explained below.
[0057] Step 1:
[0058] A user attempts to access the system using a terminal, entering a user ID and password.
[0059] Step 2:
[0060] In addition to user IDs and passwords, the devices collect location information (e.g., IP addresses), device information (e.g., the type of device used and browser information), and access times.
[0061] Step 3:
[0062] The device encrypts all collected authentication information and sends it to the server.
[0063] Step 4:
[0064] The server performs basic authentication by checking the received user ID and password against the information in its database. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0065] Step 5:
[0066] After successful authentication, the server analyzes the additional authentication information (location and device information), which includes comparing it with past access history to assess the degree of match.
[0067] Step 6:
[0068] The server will flag any location or device information that differs from previous databases as an anomaly, such as a sudden change in location or the use of a new device.
[0069] Step 7:
[0070] If an anomaly is flagged, the server generates dynamic security rules, which may include requiring two-factor authentication (2FA).
[0071] Step 8:
[0072] As part of two-factor authentication, the server sends a verification code to the user's registered email address or mobile phone number.
[0073] Step 9:
[0074] The user enters the received authentication code into the terminal and attempts authentication again.
[0075] Step 10:
[0076] The terminal sends the entered authentication code to the server.
[0077] Step 11:
[0078] The server checks the received authentication code and verifies its validity. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0079] Step 12:
[0080] The server ultimately makes the decision to allow or deny the user access. If access is granted, the resource is accessible. If access is denied, the reason is presented to the user.
[0081] In this way, the present invention provides a dynamic and flexible security wall, capable of adapting security levels according to user behavior and environmental conditions.
[0082] Example 1
[0083] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0084] As remote access and online services via the Internet become more widespread, the risk of unauthorized access is increasing. Conventional static security rules cannot adequately address dynamically changing security risks, so a dynamic security wall with high flexibility and accuracy is required. Current systems lack dynamic security measures based on user behavior patterns and environmental conditions, which can lead to security vulnerabilities.
[0085] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[0086] In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for collating the user authentication information collected by the server and performing authentication, means for analyzing the user's additional authentication information and detecting anomalies based on the additional authentication information, means for generating dynamic security rules and requesting additional authentication when an anomaly is detected, means for using a high-level encryption algorithm and a secure communication protocol for the additional authentication, means for comparing the user's location information and device information with past access history and evaluating the degree of match and abnormal patterns, means for generating an authentication code when an abnormality flag is raised and notifying the user of the authentication code, and means for ultimately determining whether to allow or deny access. This makes it possible to dynamically and flexibly adjust the security level and achieve both high security and user convenience.
[0087] "Authentication information" refers to a series of information required when a user accesses a system, such as user ID, password, location information, device information, and access time period.
[0088] A "server" is a device or system that receives authentication information sent by a user, analyzes, collates, and detects anomalies, and generates dynamic security rules to determine whether to allow or deny access.
[0089] "Encryption" is the process of transforming data using a specific algorithm to make it unreadable to third parties in order to ensure its security.
[0090] A "high-level encryption algorithm" is an encryption technology that uses complex mathematical techniques to increase the confidentiality of information, such as AES-256.
[0091] A "secure communication protocol" is a set of rules that define communication procedures for securely sending and receiving data, and specific examples include TLS (Transport Layer Security).
[0092] "Additional authentication information" is information that indicates more detailed user characteristics, such as location information and device information, in addition to basic authentication information.
[0093] "Location information" refers to information that indicates the geographical location (e.g., IP address) from which a user accesses the site.
[0094] "Device information" refers to information indicating the type of device and browser information used when a user accesses the system.
[0095] An "abnormal flag" is an indicator or marking that the server sets when it detects an abnormal situation based on the analysis results of the additional authentication information.
[0096] "Dynamic security rules" are security measures that are set in real time according to the situation, based on the user's authentication information and additional authentication information.
[0097] "Two-factor authentication (2FA)" is a method of authenticating a user using two different factors (e.g., a password and an authentication code) when accessing a system.
[0098] An "authentication code" is a combination of characters and numbers that is temporarily provided to a user for security purposes and is valid for only a specific period of time.
[0099] The present invention is a system that dynamically builds a security wall based on user behavior patterns and environmental conditions. The system includes the following main components:
[0100] User terminal
[0101] This is the device that users use to access the server. Authentication information is collected here. The terminal collects user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and the time of access, and encrypts this information before sending it to the server. A high-level encryption algorithm (e.g., AES-256) is used for encryption, and the communication protocol is Transport Layer Security (TLS).
[0102] server
[0103] The server decrypts the received encrypted data and verifies the authentication information by checking it against a database. If authentication is successful, it analyzes additional authentication information (location information and device information) and evaluates the degree of match and abnormal patterns against past access history. If an abnormality flag is raised, the server generates dynamic security rules, for example, requiring two-factor authentication (2FA). Based on the abnormality flag being raised, it generates an authentication code and notifies the user. Finally, the server verifies the authentication code entered by the user and decides whether to allow or deny access.
[0104] Software Configuration
[0105] The following software components are used to implement this system:
[0106] Database management system: Stores user authentication information. For example, MySQL (registered trademark) or PostgreSQL is used.
[0107] Cryptography library: Used to encrypt the credentials, for example, OpenSSL.
[0108] Web server: Accepts access from users and performs authentication processing. For example, Apache (registered trademark) or Nginx is used.
[0109] Specific system operation explanation
[0110] A specific example of system operation is shown below.
[0111] Access during normal times
[0112] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), and access time, and sends them to the server. The server performs basic authentication based on this information and analyzes additional conditions. In this case, since all the information matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[0113] Abnormal access
[0114] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), and access time, and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, and the server requests two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[0115] Prompt Sentence Examples
[0116] Below is an example of a prompt sentence to input to the generative AI model.
[0117] If your system dynamically builds a security wall based on user behavior patterns or environmental conditions, please explain what data you collect, how you analyze it, and what additional authentication you perform when an anomaly is detected.
[0118] The flow of the identification process in the first embodiment will be described with reference to FIG.
[0119] Step 1:
[0120] Credential collection and transmission
[0121] The user accesses the system login screen and enters their user ID and password.
[0122] The device collects the entered user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and access time.
[0123] Input: User ID, password, location information, device information, access time
[0124] The device encrypts this information using the AES-256 encryption algorithm and uses TLS as the communication protocol to securely transmit the encrypted data to the server.
[0125] Output: Encrypted credentials
[0126] Step 2:
[0127] Basic authentication processing on the server
[0128] The server decrypts the encrypted data it receives.
[0129] Input: Encrypted credentials
[0130] The server queries the database for authentication information (user ID and password) and verifies it: it uses an SQL query to look up the target user ID in the database and compares it with the corresponding password hash.
[0131] Output: Authentication success / failure
[0132] Step 3:
[0133] Determining authentication results and notifying users
[0134] If the basic authentication is successful, the server proceeds to the next step, otherwise it generates an error message and sends it back to the user for notification.
[0135] Input: Authentication success / failure
[0136] The server sets a flag indicating that authentication was successful, and if authentication failed, generates an error message and sends it back as an HTTP response.
[0137] Output: Authentication success / failure notification
[0138] Step 4:
[0139] Analysis of additional authentication information and anomaly detection
[0140] After a successful authentication, the server analyzes additional authentication information (location and device information).
[0141] Input: User location information, device information
[0142] The server compares the location information with past access history and evaluates any abnormal patterns (e.g., sudden location changes, use of new devices). To do this, it compares past access logs with location and device information.
[0143] Output: Abnormal flag (abnormal / normal)
[0144] Step 5:
[0145] Dynamic security rule generation
[0146] If the server flags an anomaly, it will generate dynamic security rules and require two-factor authentication (2FA).
[0147] Input: Abnormal flag (abnormal / normal)
[0148] The server generates an authentication code and sends it to the user via the registered email address or SMS gateway.
[0149] Output: The authentication code sent to the user.
[0150] Step 6:
[0151] Requesting and Enforcing Additional Authentication
[0152] The user enters the received authentication code into the terminal and transmits it.
[0153] Input:Authentication Code
[0154] The terminal sends the entered authentication code back to the server.
[0155] Output: The authentication code sent
[0156] Step 7:
[0157] Final authentication result and access permission
[0158] The server verifies the validity of the authentication code.
[0159] Input: The verification code sent to you
[0160] The server checks the authentication code against the system-generated code, and if they match, sets the final "access permitted flag", otherwise it returns an error message.
[0161] Output: Access allowed / denied notification
[0162] Through the above steps, this system can dynamically and flexibly adjust the security level, achieving both high security and user convenience.
[0163] (Application example 1)
[0164] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0165] Conventional security systems determine whether to allow access based on static authentication information, making them unable to flexibly adapt to changes in user behavior or the environment. This reduces the accuracy of detecting unauthorized access and increases security risks. However, there is a need for a method that achieves high security while maintaining user convenience.
[0166] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[0167] In this invention, the server includes means for verifying authentication information and performing authentication, means for analyzing additional authentication information and detecting anomalies based on the additional authentication information (including location information and device information), means for generating dynamic security rules and requesting two-factor authentication when an anomaly is detected, means for ultimately determining whether to permit or deny access, and means for collecting authentication information using a smartphone and transmitting it to the server. This makes it possible to dynamically apply security rules based on changes in user behavior and the environment, providing flexible and highly accurate security.
[0168] "Authentication information" means information including the user ID and password used when a user accesses the system.
[0169] "Additional Authentication Information" is information collected in addition to basic authentication information, such as location information and device information.
[0170] "Location information" is geographical information obtained based on the IP address and GPS data of the network to which the device is connected.
[0171] "Device information" refers to information about the device itself that the user is using, including, for example, the type of device, the type of browser, and the OS version.
[0172] "Abnormal" refers to access information or behavior that is significantly different from the user's past behavior patterns.
[0173] "Dynamic security rules" are temporary security rules that are generated by the server in response to detected anomalies and to require additional authentication steps.
[0174] "Two-factor authentication" is an authentication method in which a user uses an additional authentication factor (e.g., an authentication code sent via SMS) in addition to their initial authentication information (user ID and password).
[0175] A "smartphone" is a multi-functional mobile device that can connect to the Internet.
[0176] A "server" is a computer system that receives authentication information sent by a user and performs authentication, anomaly detection, and dynamic security rule generation.
[0177] "Allowing or denying access" refers to the server determining whether to allow or deny a user access to a resource based on the user's authentication information.
[0178] The system of the present invention dynamically applies security rules when a user uses a smartphone to access online accounts or services that require high security. This system dynamically adjusts security rules based on the user's behavioral patterns and environmental conditions, providing flexible and highly accurate security.
[0179] System configuration
[0180] Hardware and Software
[0181] Smartphone: A device used by users to access the system. This terminal collects user IDs, passwords, location information, and device information and sends them to the server.
[0182] Server: A computer system that receives authentication information and performs parsing, matching, and anomaly detection. This server runs on Python and Flask and contains the logic for generating dynamic security rules.
[0183] Geocoder Library: A library used to obtain location information. The Geocoder library obtains location information from the IP address of a smartphone.
[0184] System Operation
[0185] 1. Collecting and transmitting authentication information
[0186] The smartphone collects user ID, password, location information, and device information, encrypts them, and sends them to the server. At this time, the Geocoder library is used to obtain location information from the IP address.
[0187] 2. Authentication process on the server
[0188] The server performs basic authentication by checking the user ID and password against a database based on the received authentication information. If authentication is successful, it proceeds to the next step; if it fails, it denies access.
[0189] 3. Analysis of additional conditions and anomaly detection
[0190] If basic authentication is successful, the server analyzes the additional authentication information (location and device information), comparing it with past access history and checking for sudden changes in location or device information. If a sudden change is detected, an anomaly is flagged.
[0191] 4. Dynamic Security Rule Generation
[0192] If an anomaly is flagged, the server generates a dynamic security rule (e.g., two-factor authentication), which requires the user to enter a verification code sent to a registered email address or mobile phone number.
[0193] 5. Performing additional authentication and granting access
[0194] The user responds to the server's request for additional authentication and enters the authentication code sent to them on their smartphone. The server then checks the validity of the authentication code, and allows access if authentication is successful. If authentication fails, access is denied.
[0195] Specific examples
[0196] Access during normal times
[0197] When a user accesses an online account from their smartphone at home, the smartphone collects the user ID, password, location information (home IP address), and device information (smartphone) and sends them to the server. The server performs basic authentication based on this information and analyzes any additional conditions. In this case, since the access matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[0198] Abnormal access
[0199] When a user accesses an online account from a hotel while on a business trip, the smartphone collects the user ID, password, location information (hotel IP address), and device information (smartphone) and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, requiring two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[0200] Prompt Sentence Examples
[0201] "Attempt to log in with the user ID 'example_user', password 'secure_password', and device 'smartphone'. If the location information is different from the previous time, notify the user of the abnormality and request additional authentication."
[0202] As a result, this system dynamically applies security rules based on changes in user behavior and the environment, achieving both high security and convenience.
[0203] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[0204] Step 1:
[0205] The terminal receives an access request from a user. The terminal collects the user ID, password, location information, and device information. This location information is obtained from the IP address using the Geocoder library. The collected data specifically includes the user ID, password, location information (IP address), and device type (smartphone, browser type, etc.).
[0206] Step 2:
[0207] The device sends the collected information to the server. The sent information is encrypted. The input is the user ID, password, location information, and device information, and the output is encrypted authentication information.
[0208] Step 3:
[0209] The server performs basic authentication by checking the received authentication information against a database. The input is encrypted authentication information and the user ID and password are checked against the database. The output is the success or failure of the authentication. If authentication is successful, proceed to the next step. If it fails, access is denied.
[0210] Step 4:
[0211] The server analyzes the additional authentication information (location and device information). This is a process that compares it with past access history and detects sudden changes in location or device information. The input is location and device information, and the output is an anomaly detection flag.
[0212] Step 5:
[0213] The server generates dynamic security rules when an abnormality flag is raised. Specifically, a rule requiring two-factor authentication is generated. The input is the abnormality flag, and the output is a message requesting additional authentication.
[0214] Step 6:
[0215] The user enters an additional authentication code in response to a two-factor authentication request. The input is the authentication code sent by the server, and the output is the authentication code entered by the user.
[0216] Step 7:
[0217] The terminal sends the authentication code entered by the user back to the server. The input is the authentication code entered by the user and data is sent. The output is the completion of sending the authentication code to the server.
[0218] Step 8:
[0219] The server verifies the validity of the received authentication code. The input is the authentication code entered by the user, and the output is the result of authentication success or failure. If authentication is successful, access is granted; if it fails, access is denied.
[0220] Through the above process, this system dynamically applies security rules based on changes in user behavior and the environment, enabling high levels of security and convenience.
[0221] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.
[0222] The system of the present invention strengthens security by using an authentication process based on user credentials, additional authentication information, and an emotion engine to provide a dynamic security wall, which can dynamically apply security measures according to the user's behavior and emotions.
[0223] System configuration
[0224] The system of the present invention includes the following major components:
[0225] User device: The device from which the user attempts access, where authentication information and emotional data are collected.
[0226] Server: Receives authentication information and performs analysis, matching, anomaly detection, dynamic security rule generation, and sentiment analysis using the sentiment engine.
[0227] Emotion Engine: An engine that analyzes emotions based on user input and behavioral patterns, and adjusts security rules based on the analysis results.
[0228] Program processing explanation
[0229] Collection and transmission of authentication information and emotional data
[0230] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., the type of device used and browser information), access time, and emotional data (e.g., emotional state using facial recognition and text analysis). The device encrypts this information and sends it to the server.
[0231] Authentication process on the server
[0232] The server performs basic authentication by checking the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0233] Analysis of additional conditions and anomaly detection
[0234] After successful authentication, the server analyzes the additional authentication information (location and device information). It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[0235] Emotion analysis using an emotion engine
[0236] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the server detects that the user is clearly impatient, it can determine that the security risk is high.
[0237] Dynamic security rule generation
[0238] The server will then generate dynamic security rules based on the anomaly flags and emotion engine analysis, as needed, for example, a rule requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[0239] Enforcing additional authentication and access permissions
[0240] The user enters the authentication code into their device and sends it back to the server. The server checks the received authentication code and verifies its validity. If authentication is successful, access is permitted. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[0241] Specific examples
[0242] Access during normal times
[0243] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), access time, and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately allowing access.
[0244] Impact of abnormal access and emotional data
[0245] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), access time, and emotional data (impatience is detected), and sends these to the server. After the server successfully completes basic authentication, it flags an anomaly based on the location information, device information, and emotional data. This allows the server to generate dynamic security rules and request two-factor authentication. The user enters the authentication code, and the server finally verifies the authentication and allows access.
[0246] In this way, the system of the present invention realizes a dynamic and flexible security wall, and can adapt the security level according to the user's behavior and emotions.
[0247] The processing flow will be explained below.
[0248] Step 1:
[0249] A user attempts to access the system using a terminal, entering a user ID and password.
[0250] Step 2:
[0251] In addition to user IDs and passwords, the devices collect location information (e.g., IP addresses), device information (e.g., the type of device used and browser information), access times, and user emotional data (e.g., emotional state determined using facial recognition and text analysis).
[0252] Step 3:
[0253] The device encrypts all collected authentication information and sends it to the server.
[0254] Step 4:
[0255] The server performs basic authentication by checking the received user ID and password against the information in its database. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0256] Step 5:
[0257] After successful authentication, the server analyzes the additional authentication information (location and device information), compares it with past access history, and evaluates the degree of match.
[0258] Step 6:
[0259] The server will flag any location or device information that differs from previous databases as an anomaly, such as a sudden change in location or the use of a new device.
[0260] Step 7:
[0261] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the emotion of the user based on facial recognition data and input text, and incorporates the results into security decisions.
[0262] Step 8:
[0263] Based on the analysis results of the emotion engine, the server determines that additional security is necessary if the emotional state is abnormal (e.g., a sense of irritation is detected).
[0264] Step 9:
[0265] The server generates dynamic security rules based on the anomaly flags and the results of the emotion engine, including requiring two-factor authentication (2FA).
[0266] Step 10:
[0267] As part of two-factor authentication, the server sends a verification code to the user's registered email address or mobile phone number.
[0268] Step 11:
[0269] The user enters the received authentication code into the terminal and sends it to the server.
[0270] Step 12:
[0271] The server receives the entered authentication code and verifies its validity. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0272] Step 13:
[0273] The server finally decides whether to grant access based on the analysis of the authentication information, additional authentication information, and emotion data. If access is granted, the user can access the resource. If access is denied, the reason is presented to the user.
[0274] In this way, by realizing a dynamic and flexible security wall, the present invention can adapt the security level according to the user's behavior and emotions, thereby providing higher safety.
[0275] Example 2
[0276] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0277] In recent years, the increasing sophistication and diversification of cyber attacks has led to the problem that traditional, fixed security measures are insufficient. In particular, with the spread of remote work, the increase in access from new devices and new locations has further increased security risks. To address this, a dynamic and flexible security system is required.
[0278] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.
[0279] In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for verifying the collected authentication information in the server and performing authentication, means for analyzing the user's additional authentication information and detecting anomalies, means for collecting and analyzing sensor information including the user's emotional data, means for generating dynamic security rules based on the results of the emotional analysis and when an anomaly is detected, and for requesting additional authentication, and means for ultimately determining whether to permit or deny access. This makes it possible to apply dynamic security measures according to the user's behavior and emotions.
[0280] "User authentication information" refers to information, such as a user ID and password, used to identify a user and authorize access to the system.
[0281] A "server" is a computer system that operates on a network and processes, stores, and transmits data it receives.
[0282] "Verification" is the process by which the server compares the authentication information it receives with its internal database to see if there is a match.
[0283] "Additional authentication information" is data collected in addition to basic authentication information, such as location information and device information.
[0284] An "anomaly" is the detection of an unusual pattern, such as new location information or device information, compared with past normal access history.
[0285] "Dynamic security rules" are rules for security measures that are generated in real time and are flexibly changed according to the situation that arises.
[0286] "Additional authentication" means additional security verification procedures performed on top of basic authentication, such as two-factor authentication (2FA).
[0287] "Emotion data" is information that indicates the user's emotional state, and includes facial recognition data, text analysis results, and the like.
[0288] "Sensor information" is digital data collected from a user's devices and environment, and includes emotional data, location information, device information, and more.
[0289] The system of the present invention strengthens security by using an authentication process based on user credentials, additional authentication information, and an emotion engine to provide a dynamic security wall, which can dynamically apply security measures according to the user's behavior and emotions.
[0290] System configuration
[0291] The system of the present invention includes the following major components:
[0292] User device: The device from which the user attempts access, where authentication information and emotional data are collected.
[0293] Server: Receives authentication information and performs analysis, matching, anomaly detection, dynamic security rule generation, and sentiment analysis using the sentiment engine.
[0294] Emotion engine: An engine that analyzes emotions based on user input and behavioral patterns, and adjusts security rules based on the analysis results.
[0295] Program processing explanation
[0296] Collection and transmission of authentication information and emotional data
[0297] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., the type of device being used and browser information), access time, and emotional data (e.g., emotional state using facial recognition and text analysis). The device encrypts this information and sends it to the server.
[0298] Authentication process on the server
[0299] The server checks the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0300] Analysis of additional conditions and anomaly detection
[0301] After successful authentication, the server analyzes the additional authentication information (location and device information). It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[0302] Emotion analysis using an emotion engine
[0303] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the server detects that the user is clearly impatient, it can determine that the security risk is high.
[0304] Dynamic security rule generation
[0305] The server will then generate dynamic security rules based on the anomaly flags and emotion engine analysis, as needed, for example, a rule requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[0306] Enforcing additional authentication and access permissions
[0307] The user enters the authentication code into their device and sends it back to the server. The server checks the received authentication code and verifies its validity. If authentication is successful, access is permitted. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[0308] Specific examples
[0309] Access during normal times
[0310] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), access time, and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately allowing access.
[0311] Impact of abnormal access and emotional data
[0312] When a user attempts to access a company server from a hotel while on a business trip, the terminal collects and sends the user ID, password, location information (hotel IP address), device information (new laptop), access time, and emotional data (impatience detected) to the server. After the server successfully completes basic authentication, it flags an anomaly based on the location information, device information, and emotional data. This allows the server to generate dynamic security rules and request two-factor authentication. The user enters the authentication code, and the server finally verifies the authentication and allows access. In this way, the system of the present invention realizes a dynamic and flexible security wall, adapting the security level according to the user's behavior and emotions.
[0313] Examples of prompts for generative AI models
[0314] To develop a security system, create a prompt like this: Explain how you would detect anomalies and require additional security procedures when a user attempts to log in from a new device.
[0315] The flow of the identification process in the second embodiment will be described with reference to FIG.
[0316] Step 1:
[0317] Collection and transmission of authentication information and emotional data
[0318] A user attempts to log in to a system using a terminal. The user enters their user ID and password on the login screen. Based on the input, the terminal collects location information (IP address), device information (device type, OS version, browser version), access time, and emotional data (facial expressions using a facial recognition camera, and the emotional state of the input text using text analysis). This data is encrypted using TLS / SSL and sent to the server.
[0319] input:
[0320] User ID, password, location information, device information, access time, emotional data (face recognition, text analysis)
[0321] output:
[0322] Encrypted credentials and sentiment data
[0323] Specific behavior:
[0324] The user enters their login information into a browser or dedicated application. The device then runs location information, a facial recognition camera, and a text analysis engine to collect the necessary data. This data is then encrypted using TLS / SSL and sent to the server according to the transmission protocol.
[0325] Step 2:
[0326] Authentication process on the server
[0327] The server receives the encrypted authentication information sent from the terminal and decodes the data. The server compares the decoded user ID and password with its internal database to perform authentication. If authentication is successful, the server proceeds to the next processing step. If authentication fails, the server denies access and returns an error message to the user.
[0328] input:
[0329] Encrypted user ID and password
[0330] output:
[0331] Authentication success or failure flag, error message on failure
[0332] Specific behavior:
[0333] The server receives the encrypted data based on the TLS / SSL protocol. It decodes the user ID and password and queries the database. If authentication is successful, it sets an authentication success flag and proceeds to the next step. If authentication fails, it generates a detailed error message and sends it to the user.
[0334] Step 3:
[0335] Analysis of additional conditions and anomaly detection
[0336] After successful authentication, the server analyzes the location and device information sent. It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[0337] input:
[0338] Location information, device information, past access history
[0339] output:
[0340] Anomaly detection flag, match evaluation result
[0341] Specific behavior:
[0342] The server uses the location information to determine the user's geographic location and compares it with past access records. An algorithm evaluates the degree of match and flags any anomalies. For example, if a new IP address or device is detected, an anomaly flag will be raised.
[0343] Step 4:
[0344] Emotion analysis using an emotion engine
[0345] The server activates an emotion engine and analyzes the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the user shows signs of impatience, the server reassess the security risk based on that information.
[0346] input:
[0347] Facial recognition data, text analysis data
[0348] output:
[0349] Sentiment analysis results, security risk assessment results
[0350] Specific behavior:
[0351] The server uses an emotion engine (e.g., facial recognition API or text analysis API) to analyze the received data, record the determined emotional state, and incorporate it into the overall security risk assessment.
[0352] Step 5:
[0353] Dynamic security rule generation
[0354] The server generates the necessary dynamic security rules based on the anomaly flags and the analysis results of the emotion engine. For example, if the security risk is determined to be high, it will request two-factor authentication (2FA) and send an additional authentication code to the user according to the rules.
[0355] input:
[0356] Anomaly flags, sentiment analysis results, security policies
[0357] output:
[0358] Dynamic security rules, 2FA authentication codes
[0359] Specific behavior:
[0360] The server evaluates anomaly flags and sentiment analysis results to determine dynamic security measures. If additional measures such as two-factor authentication are required, an authentication code is sent to the user's registered contact method (e.g., SMS, email).
[0361] Step 6:
[0362] Enforcing additional authentication and access permissions
[0363] The user enters the authentication code into the device. The device sends the code to the server. The server checks the validity of the authentication code, and if authentication is successful, access is permitted. If authentication is unsuccessful, access is denied, and the reason is displayed to the user.
[0364] input:
[0365] Authentication code, server-generated code
[0366] output:
[0367] Access or deny decision, reason message
[0368] Specific behavior:
[0369] The user enters the received authentication code into the terminal and sends it. The server compares the received authentication code with the internally generated code. If they match, it flags access as allowed and proceeds to the next step. If they do not match, it generates an access denied message and notifies the user.
[0370] (Application example 2)
[0371] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0372] Conventional authentication systems are based only on static user authentication information (e.g., user ID and password) and fixed additional authentication information (e.g., location information, device information), making it difficult to improve security. Furthermore, these systems have the problem of not being able to fully detect abnormal access because they do not take into account the user's mental or emotional state. This makes unauthorized access and security breaches more likely to occur.
[0373] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for verifying the collected authentication information at the server and performing authentication, and means for analyzing the user's additional authentication information and detecting anomalies. It also includes means for analyzing the user's emotional state as the user's additional authentication information, and means for generating dynamic security rules and requesting additional authentication when an anomaly is detected and based on the emotional state. This enables more advanced and dynamic security measures.
[0374] "Authentication information" refers to information such as ID and password provided by a user when accessing a system.
[0375] "Emotional state" is data that indicates the user's psychological and emotional state, and is obtained from facial recognition data and input text.
[0376] "Location information" refers to geographical information based on the IP address of the device from which the user is accessing the site.
[0377] "Device information" refers to the type and identification information of the device used by the user.
[0378] "Dynamic security rules" are rules for security measures that are generated in real time depending on the situation, and include, for example, requirements for two-factor authentication.
[0379] "Additional authentication" is an additional authentication method performed in addition to basic authentication, and is based on location information, device information, or emotional state.
[0380] "Two-factor authentication" is a method that requires a second authentication method (e.g., SMS code or email code) in addition to the user's ID and password when accessing a system.
[0381] "Anomaly detection" is the detection of access attempts or behavior that is unusual or considered fraudulent.
[0382] The present invention is a system that uses user authentication information and emotion data to apply dynamic security rules and prevent abnormal access. A specific embodiment for realizing this system is shown below.
[0383] System configuration
[0384] The system of the present invention includes the following major components:
[0385] 1. User device: A device such as a smartphone or PC that collects user authentication information and emotional data. It includes a facial recognition camera, a GPS for acquiring location information, and software for acquiring device information.
[0386] 2. Server: Receives authentication information and performs parsing, matching, anomaly detection, dynamic security rule generation, and emotion analysis using the emotion engine. It uses Python, OpenCV, the face_recognition library, and the emotion_recognition module.
[0387] 3. Emotion engine: An engine that analyzes emotions based on user input and behavioral patterns, for example, using Python's emotion_recognition module.
[0388] Program processing flow
[0389] 1. Collection and transmission of authentication information and emotional data
[0390] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., device type and browser information), and emotional data (e.g., facial recognition data and emotional state analyzed from input text).
[0391] The collected data is encrypted and sent to a server.
[0392] 2. Authentication process on the server
[0393] The server performs basic authentication by checking the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0394] 3. Analysis of additional conditions and anomaly detection
[0395] After successful authentication, the server analyzes the additional authentication information (location and device information) and compares it with past access history. It detects anomalies by evaluating the degree of match and flags any new location or device information as an anomaly.
[0396] 4. Emotion analysis using an emotion engine
[0397] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if a sense of impatience is detected, it will be determined that there is a high security risk.
[0398] 5. Dynamic Security Rule Generation
[0399] The server generates dynamic security rules based on the anomaly flags and emotion engine analysis, such as requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[0400] 6. Performing additional authentication and granting access
[0401] The user enters the authentication code into their device and sends it back to the server. The server then checks the validity of the received authentication code, and if authentication is successful, allows access. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[0402] Specific examples
[0403] Example 1: Access during normal times
[0404] When a user accesses the system from a home device, the device collects the user ID, password, location information (home IP address), device information (home device), and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately granting access.
[0405] Example 2: Abnormal access
[0406] When a user accesses the system from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new device), and emotional data (anxiety is detected), and sends them to the server. After the server successfully completes basic authentication, it detects an anomaly and generates a dynamic security rule to request two-factor authentication. The user enters the authentication code sent, and the server finally verifies the authentication, after which access is granted.
[0407] Example prompts to input to the generative AI model
[0408] An example prompt to input to the generative AI model is, "Describe an application that applies dynamic security rules based on authentication information and sentiment analysis data when a user accesses their account."
[0409] As a result, the system of the present invention can provide more advanced and flexible security measures and realize a security mechanism that is adaptable to the user's behavior and emotions.
[0410] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[0411] Step 1:
[0412] The user starts up the device and accesses the authentication screen. The device prompts the user to enter their ID and password. The entered data is temporarily stored on the device.
[0413] input:
[0414] The ID and password entered by the user.
[0415] output:
[0416] Saved IDs and passwords.
[0417] Operation:
[0418] The terminal receives the user's ID and password from the input form and stores them in memory.
[0419] Step 2:
[0420] The device activates the camera and recognizes the user's face. The facial recognition data is acquired and emotion analysis is performed using the emotion engine. The analyzed emotion data is also temporarily stored on the device.
[0421] input:
[0422] Video data from the camera.
[0423] output:
[0424] Facial recognition data and analyzed emotion data.
[0425] Operation:
[0426] The device captures video from the camera, applies a facial recognition algorithm to obtain facial data, then uses the emotion_recognition module to perform emotion analysis and save the results.
[0427] Step 3:
[0428] The device collects location information and device information. Location information is obtained from the GPS sensor and IP address, and device information is obtained from the device type and browser information.
[0429] input:
[0430] GPS sensor or IP address, device information.
[0431] output:
[0432] Location and Device Information.
[0433] Operation:
[0434] The device obtains location information from the IP address via a GPS sensor or the network, and collects device information such as device type and browser information.
[0435] Step 4:
[0436] The device encrypts the collected data (ID, password, facial recognition data, emotional data, location information, device information) and sends it to the server.
[0437] input:
[0438] ID, password, facial recognition data, emotional data, location information, device information.
[0439] output:
[0440] Encrypted data.
[0441] Operation:
[0442] The device securely encrypts all collected data and transmits it over the network to a server.
[0443] Step 5:
[0444] The server checks the ID and password from the received data and performs basic authentication. It checks against the database, and if it is correct, it proceeds to the next step. If it is invalid, it immediately returns a message to the terminal denying access.
[0445] input:
[0446] Encrypted ID and password.
[0447] output:
[0448] The authentication result (success or failure).
[0449] Operation:
[0450] The server decrypts the data and checks the user ID and password against the information in its database. Depending on the result, it either proceeds to the next processing step or denies access.
[0451] Step 6:
[0452] The server analyzes the additional authentication information (location information, device information) and compares it with past access history to evaluate the degree of match and detect any abnormalities.
[0453] input:
[0454] Location information, device information, and past access history.
[0455] output:
[0456] Abnormal flag (abnormal or normal).
[0457] Operation:
[0458] The server compares the location and device information with past access history to assess the degree of match, and based on this assessment, detects any anomalies and sets an anomaly flag.
[0459] Step 7:
[0460] The server uses an emotion engine to analyze the emotion data sent from the device and incorporates the results into security decisions. For example, if a sense of impatience is detected, it will be determined that the security risk is high.
[0461] input:
[0462] Emotional data.
[0463] output:
[0464] Sentiment analysis result (normal or abnormal).
[0465] Operation:
[0466] The server uses the emotion_recognition module to analyze the emotional data and evaluate the security risk based on the results.
[0467] Step 8:
[0468] The server generates dynamic security rules based on anomaly flags and sentiment analysis results, as needed, such as requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[0469] input:
[0470] Abnormal flags, sentiment analysis results.
[0471] output:
[0472] Dynamic security rules (e.g. requiring 2FA).
[0473] Operation:
[0474] The server generates dynamic security rules based on the anomaly flags and sentiment analysis results, and if necessary, requests additional authentication procedures from the user.
[0475] Step 9:
[0476] The user receives the authentication code sent from the server, enters it again into the terminal, and sends it to the server.
[0477] input:
[0478] Authentication code.
[0479] output:
[0480] The final authentication result (success or failure).
[0481] Operation:
[0482] The user enters the authentication code received from the server into the terminal and sends it to the server, which then checks the received authentication code to verify its validity.
[0483] Step 10:
[0484] If the authentication is successful, the server sends a message to the terminal permitting access. If the authentication is unsuccessful, the server returns a message indicating the reason for denial of access to the terminal.
[0485] input:
[0486] Final authentication result.
[0487] output:
[0488] An access allowed or denied message.
[0489] Operation:
[0490] Based on the final authentication result, the server sends a message to the terminal permitting access if successful, or a message including the reason for denial of access if unsuccessful.
[0491] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0492] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (registered trademark) (Internet search engine).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0493] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.
[0494] [Second embodiment]
[0495] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.
[0496] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0497] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0498] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.
[0499] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[0500] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[0501] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[0502] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[0503] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0504] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0505] In the smart glasses 214, the reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[0506] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."
[0507] The system of the present invention dynamically builds a security wall based on user behavior patterns and environmental conditions. This system collects user authentication information, performs dynamic analysis on the server, and generates dynamic security rules when an abnormality is detected. This provides greater flexibility and security accuracy than conventional static security rules.
[0508] System configuration
[0509] The system of the present invention includes the following major components:
[0510] User terminal: The device used by the user to access the server, where authentication information is collected.
[0511] Server: Receives authentication information, performs analysis, matching, and anomaly detection, and generates dynamic security rules to determine whether access is allowed or denied.
[0512] Program processing explanation
[0513] Credential collection and transmission
[0514] When a user attempts to access the system using a terminal, the terminal collects the following information: user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and the time of access. The terminal encrypts this information and sends it to the server.
[0515] Authentication process on the server
[0516] The server performs basic authentication processing based on the received authentication information. It checks the user ID and password against a database to determine whether authentication was successful. If authentication is successful, it proceeds to the next step, but if it is unsuccessful, it denies access and returns an error message to the user.
[0517] Analysis of additional conditions and anomaly detection
[0518] After basic authentication is successful, the server analyzes additional authentication information (location and device information). This includes comparing it with past access history and assessing the degree of match. For example, if the location information changes suddenly or access from a new device is detected, the server flags this as an anomaly and uses this information to generate dynamic security rules.
[0519] Dynamic security rule generation
[0520] If the server flags an anomaly, it will generate dynamic security rules that require additional authentication steps, such as a rule requiring two-factor authentication (2FA) and requiring the user to enter a verification code sent to a registered email address or mobile phone number.
[0521] Enforcing additional authentication and access permissions
[0522] The user enters the authentication code sent in response to a request for additional authentication from the server. The terminal then sends this authentication code back to the server, which then verifies its validity. If authentication is successful, the server finally grants access and provides the user with access to the resource. If authentication fails, access is denied and the reason is displayed to the user.
[0523] Specific examples
[0524] Access during normal times
[0525] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), and access time, and sends them to the server. The server performs basic authentication based on this information and analyzes additional conditions. In this case, since all the information matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[0526] Abnormal access
[0527] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), and access time, and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, and the server requests two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[0528] As described above, the system of the present invention can dynamically and flexibly adjust the security level, achieving both high security and user convenience.
[0529] The processing flow will be explained below.
[0530] Step 1:
[0531] A user attempts to access the system using a terminal, entering a user ID and password.
[0532] Step 2:
[0533] In addition to user IDs and passwords, the devices collect location information (e.g., IP addresses), device information (e.g., the type of device used and browser information), and access times.
[0534] Step 3:
[0535] The device encrypts all collected authentication information and sends it to the server.
[0536] Step 4:
[0537] The server performs basic authentication by checking the received user ID and password against the information in its database. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0538] Step 5:
[0539] After successful authentication, the server analyzes the additional authentication information (location and device information), which includes comparing it with past access history to assess the degree of match.
[0540] Step 6:
[0541] The server will flag any location or device information that differs from previous databases as an anomaly, such as a sudden change in location or the use of a new device.
[0542] Step 7:
[0543] If an anomaly is flagged, the server generates dynamic security rules, which may include requiring two-factor authentication (2FA).
[0544] Step 8:
[0545] As part of two-factor authentication, the server sends a verification code to the user's registered email address or mobile phone number.
[0546] Step 9:
[0547] The user enters the received authentication code into the terminal and attempts authentication again.
[0548] Step 10:
[0549] The terminal sends the entered authentication code to the server.
[0550] Step 11:
[0551] The server checks the received authentication code and verifies its validity. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0552] Step 12:
[0553] The server ultimately makes the decision to allow or deny the user access. If access is granted, the resource is accessible. If access is denied, the reason is presented to the user.
[0554] In this way, the present invention provides a dynamic and flexible security wall, capable of adapting security levels according to user behavior and environmental conditions.
[0555] Example 1
[0556] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0557] As remote access and online services via the Internet become more widespread, the risk of unauthorized access is increasing. Conventional static security rules cannot adequately address dynamically changing security risks, so a dynamic security wall with high flexibility and accuracy is required. Current systems lack dynamic security measures based on user behavior patterns and environmental conditions, which can lead to security vulnerabilities.
[0558] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[0559] In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for collating the user authentication information collected by the server and performing authentication, means for analyzing the user's additional authentication information and detecting anomalies based on the additional authentication information, means for generating dynamic security rules and requesting additional authentication when an anomaly is detected, means for using a high-level encryption algorithm and a secure communication protocol for the additional authentication, means for comparing the user's location information and device information with past access history and evaluating the degree of match and abnormal patterns, means for generating an authentication code when an abnormality flag is raised and notifying the user of the authentication code, and means for ultimately determining whether to allow or deny access. This makes it possible to dynamically and flexibly adjust the security level and achieve both high security and user convenience.
[0560] "Authentication information" refers to a series of information required when a user accesses a system, such as user ID, password, location information, device information, and access time period.
[0561] A "server" is a device or system that receives authentication information sent by a user, analyzes, collates, and detects anomalies, and generates dynamic security rules to determine whether to allow or deny access.
[0562] "Encryption" is the process of transforming data using a specific algorithm to make it unreadable to third parties in order to ensure its security.
[0563] A "high-level encryption algorithm" is an encryption technology that uses complex mathematical techniques to increase the confidentiality of information, such as AES-256.
[0564] A "secure communication protocol" is a set of rules that define communication procedures for securely sending and receiving data, and specific examples include TLS (Transport Layer Security).
[0565] "Additional authentication information" is information that indicates more detailed user characteristics, such as location information and device information, in addition to basic authentication information.
[0566] "Location information" refers to information that indicates the geographical location (e.g., IP address) from which a user accesses the site.
[0567] "Device information" refers to information indicating the type of device and browser information used when a user accesses the system.
[0568] An "abnormal flag" is an indicator or marking that the server sets when it detects an abnormal situation based on the analysis results of the additional authentication information.
[0569] "Dynamic security rules" are security measures that are set in real time according to the situation, based on the user's authentication information and additional authentication information.
[0570] "Two-factor authentication (2FA)" is a method of authenticating a user using two different factors (e.g., a password and an authentication code) when accessing a system.
[0571] An "authentication code" is a combination of characters and numbers that is temporarily provided to a user for security purposes and is valid for only a specific period of time.
[0572] The present invention is a system that dynamically builds a security wall based on user behavior patterns and environmental conditions. The system includes the following main components:
[0573] User terminal
[0574] This is the device that users use to access the server. Authentication information is collected here. The terminal collects user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and the time of access, and encrypts this information before sending it to the server. A high-level encryption algorithm (e.g., AES-256) is used for encryption, and the communication protocol is Transport Layer Security (TLS).
[0575] server
[0576] The server decrypts the received encrypted data and verifies the authentication information by checking it against a database. If authentication is successful, it analyzes additional authentication information (location information and device information) and evaluates the degree of match and abnormal patterns against past access history. If an abnormality flag is raised, the server generates dynamic security rules, for example, requiring two-factor authentication (2FA). Based on the abnormality flag being raised, it generates an authentication code and notifies the user. Finally, the server verifies the authentication code entered by the user and decides whether to allow or deny access.
[0577] Software Configuration
[0578] The following software components are used to implement this system:
[0579] A database management system that stores user authentication information, such as MySQL or PostgreSQL.
[0580] Cryptography library: Used to encrypt the credentials, for example, OpenSSL.
[0581] Web server: Accepts user access and handles authentication. For example, Apache or Nginx is used.
[0582] Specific system operation explanation
[0583] A specific example of system operation is shown below.
[0584] Access during normal times
[0585] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), and access time, and sends them to the server. The server performs basic authentication based on this information and analyzes additional conditions. In this case, since all the information matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[0586] Abnormal access
[0587] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), and access time, and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, and the server requests two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[0588] Prompt Sentence Examples
[0589] Below is an example of a prompt sentence to input to the generative AI model.
[0590] If your system dynamically builds a security wall based on user behavior patterns or environmental conditions, please explain what data you collect, how you analyze it, and what additional authentication you perform when an anomaly is detected.
[0591] The flow of the identification process in the first embodiment will be described with reference to FIG.
[0592] Step 1:
[0593] Credential collection and transmission
[0594] The user accesses the system login screen and enters their user ID and password.
[0595] The device collects the entered user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and access time.
[0596] Input: User ID, password, location information, device information, access time
[0597] The device encrypts this information using the AES-256 encryption algorithm and uses TLS as the communication protocol to securely transmit the encrypted data to the server.
[0598] Output: Encrypted credentials
[0599] Step 2:
[0600] Basic authentication processing on the server
[0601] The server decrypts the encrypted data it receives.
[0602] Input: Encrypted credentials
[0603] The server queries the database for authentication information (user ID and password) and verifies it: it uses an SQL query to look up the target user ID in the database and compares it with the corresponding password hash.
[0604] Output: Authentication success / failure
[0605] Step 3:
[0606] Determining authentication results and notifying users
[0607] If the basic authentication is successful, the server proceeds to the next step, otherwise it generates an error message and sends it back to the user for notification.
[0608] Input: Authentication success / failure
[0609] The server sets a flag indicating that authentication was successful, and if authentication failed, generates an error message and sends it back as an HTTP response.
[0610] Output: Authentication success / failure notification
[0611] Step 4:
[0612] Analysis of additional authentication information and anomaly detection
[0613] After a successful authentication, the server analyzes additional authentication information (location and device information).
[0614] Input: User location information, device information
[0615] The server compares the location information with past access history and evaluates any abnormal patterns (e.g., sudden location changes, use of new devices). To do this, it compares past access logs with location and device information.
[0616] Output: Abnormal flag (abnormal / normal)
[0617] Step 5:
[0618] Dynamic security rule generation
[0619] If the server flags an anomaly, it will generate dynamic security rules and require two-factor authentication (2FA).
[0620] Input: Abnormal flag (abnormal / normal)
[0621] The server generates an authentication code and sends it to the user via the registered email address or SMS gateway.
[0622] Output: The authentication code sent to the user.
[0623] Step 6:
[0624] Requesting and Enforcing Additional Authentication
[0625] The user enters the received authentication code into the terminal and transmits it.
[0626] Input:Authentication Code
[0627] The terminal sends the entered authentication code back to the server.
[0628] Output: The authentication code sent
[0629] Step 7:
[0630] Final authentication result and access permission
[0631] The server verifies the validity of the authentication code.
[0632] Input: The verification code sent to you
[0633] The server checks the authentication code against the system-generated code, and if they match, sets the final "access permitted flag", otherwise it returns an error message.
[0634] Output: Access allowed / denied notification
[0635] Through the above steps, this system can dynamically and flexibly adjust the security level, achieving both high security and user convenience.
[0636] (Application example 1)
[0637] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0638] Conventional security systems determine whether to allow access based on static authentication information, making them unable to flexibly adapt to changes in user behavior or the environment. This reduces the accuracy of detecting unauthorized access and increases security risks. However, there is a need for a method that achieves high security while maintaining user convenience.
[0639] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[0640] In this invention, the server includes means for verifying authentication information and performing authentication, means for analyzing additional authentication information and detecting anomalies based on the additional authentication information (including location information and device information), means for generating dynamic security rules and requesting two-factor authentication when an anomaly is detected, means for ultimately determining whether to permit or deny access, and means for collecting authentication information using a smartphone and transmitting it to the server. This makes it possible to dynamically apply security rules based on changes in user behavior and the environment, providing flexible and highly accurate security.
[0641] "Authentication information" means information including the user ID and password used when a user accesses the system.
[0642] "Additional Authentication Information" is information collected in addition to basic authentication information, such as location information and device information.
[0643] "Location information" is geographical information obtained based on the IP address and GPS data of the network to which the device is connected.
[0644] "Device information" refers to information about the device itself that the user is using, including, for example, the type of device, the type of browser, and the OS version.
[0645] "Abnormal" refers to access information or behavior that is significantly different from the user's past behavior patterns.
[0646] "Dynamic security rules" are temporary security rules that are generated by the server in response to detected anomalies and to require additional authentication steps.
[0647] "Two-factor authentication" is an authentication method in which a user uses an additional authentication factor (e.g., an authentication code sent via SMS) in addition to their initial authentication information (user ID and password).
[0648] A "smartphone" is a multi-functional mobile device that can connect to the Internet.
[0649] A "server" is a computer system that receives authentication information sent by a user and performs authentication, anomaly detection, and dynamic security rule generation.
[0650] "Allowing or denying access" refers to the server determining whether to allow or deny a user access to a resource based on the user's authentication information.
[0651] The system of the present invention dynamically applies security rules when a user uses a smartphone to access online accounts or services that require high security. This system dynamically adjusts security rules based on the user's behavioral patterns and environmental conditions, providing flexible and highly accurate security.
[0652] System configuration
[0653] Hardware and Software
[0654] Smartphone: A device used by users to access the system. This terminal collects user IDs, passwords, location information, and device information and sends them to the server.
[0655] Server: A computer system that receives authentication information and performs parsing, matching, and anomaly detection. This server runs on Python and Flask and contains the logic for generating dynamic security rules.
[0656] Geocoder Library: A library used to obtain location information. The Geocoder library obtains location information from the IP address of a smartphone.
[0657] System Operation
[0658] 1. Collecting and transmitting authentication information
[0659] The smartphone collects user ID, password, location information, and device information, encrypts them, and sends them to the server. At this time, the Geocoder library is used to obtain location information from the IP address.
[0660] 2. Authentication process on the server
[0661] The server performs basic authentication by checking the user ID and password against a database based on the received authentication information. If authentication is successful, it proceeds to the next step; if it fails, it denies access.
[0662] 3. Analysis of additional conditions and anomaly detection
[0663] If basic authentication is successful, the server analyzes the additional authentication information (location and device information), comparing it with past access history and checking for sudden changes in location or device information. If a sudden change is detected, an anomaly is flagged.
[0664] 4. Dynamic Security Rule Generation
[0665] If an anomaly is flagged, the server generates a dynamic security rule (e.g., two-factor authentication), which requires the user to enter a verification code sent to a registered email address or mobile phone number.
[0666] 5. Performing additional authentication and granting access
[0667] The user responds to the server's request for additional authentication and enters the authentication code sent to them on their smartphone. The server then checks the validity of the authentication code, and allows access if authentication is successful. If authentication fails, access is denied.
[0668] Specific examples
[0669] Access during normal times
[0670] When a user accesses an online account from their smartphone at home, the smartphone collects the user ID, password, location information (home IP address), and device information (smartphone) and sends them to the server. The server performs basic authentication based on this information and analyzes any additional conditions. In this case, since the access matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[0671] Abnormal access
[0672] When a user accesses an online account from a hotel while on a business trip, the smartphone collects the user ID, password, location information (hotel IP address), and device information (smartphone) and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, requiring two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[0673] Prompt Sentence Examples
[0674] "Attempt to log in with the user ID 'example_user', password 'secure_password', and device 'smartphone'. If the location information is different from the previous time, notify the user of the abnormality and request additional authentication."
[0675] As a result, this system dynamically applies security rules based on changes in user behavior and the environment, achieving both high security and convenience.
[0676] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[0677] Step 1:
[0678] The terminal receives an access request from a user. The terminal collects the user ID, password, location information, and device information. This location information is obtained from the IP address using the Geocoder library. The collected data specifically includes the user ID, password, location information (IP address), and device type (smartphone, browser type, etc.).
[0679] Step 2:
[0680] The device sends the collected information to the server. The sent information is encrypted. The input is the user ID, password, location information, and device information, and the output is encrypted authentication information.
[0681] Step 3:
[0682] The server performs basic authentication by checking the received authentication information against a database. The input is encrypted authentication information and the user ID and password are checked against the database. The output is the success or failure of the authentication. If authentication is successful, proceed to the next step. If it fails, access is denied.
[0683] Step 4:
[0684] The server analyzes the additional authentication information (location and device information). This is a process that compares it with past access history and detects sudden changes in location or device information. The input is location and device information, and the output is an anomaly detection flag.
[0685] Step 5:
[0686] The server generates dynamic security rules when an abnormality flag is raised. Specifically, a rule requiring two-factor authentication is generated. The input is the abnormality flag, and the output is a message requesting additional authentication.
[0687] Step 6:
[0688] The user enters an additional authentication code in response to a two-factor authentication request. The input is the authentication code sent by the server, and the output is the authentication code entered by the user.
[0689] Step 7:
[0690] The terminal sends the authentication code entered by the user back to the server. The input is the authentication code entered by the user and data is sent. The output is the completion of sending the authentication code to the server.
[0691] Step 8:
[0692] The server verifies the validity of the received authentication code. The input is the authentication code entered by the user, and the output is the result of authentication success or failure. If authentication is successful, access is granted; if it fails, access is denied.
[0693] Through the above process, this system dynamically applies security rules based on changes in user behavior and the environment, enabling high levels of security and convenience.
[0694] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[0695] The system of the present invention strengthens security by using an authentication process based on user credentials, additional authentication information, and an emotion engine to provide a dynamic security wall, which can dynamically apply security measures according to the user's behavior and emotions.
[0696] System configuration
[0697] The system of the present invention includes the following major components:
[0698] User device: The device from which the user attempts access, where authentication information and emotional data are collected.
[0699] Server: Receives authentication information and performs analysis, matching, anomaly detection, dynamic security rule generation, and sentiment analysis using the sentiment engine.
[0700] Emotion Engine: An engine that analyzes emotions based on user input and behavioral patterns, and adjusts security rules based on the analysis results.
[0701] Program processing explanation
[0702] Collection and transmission of authentication information and emotional data
[0703] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., the type of device used and browser information), access time, and emotional data (e.g., emotional state using facial recognition and text analysis). The device encrypts this information and sends it to the server.
[0704] Authentication process on the server
[0705] The server performs basic authentication by checking the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0706] Analysis of additional conditions and anomaly detection
[0707] After successful authentication, the server analyzes the additional authentication information (location and device information). It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[0708] Emotion analysis using an emotion engine
[0709] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the server detects that the user is clearly impatient, it can determine that the security risk is high.
[0710] Dynamic security rule generation
[0711] The server will then generate dynamic security rules based on the anomaly flags and emotion engine analysis, as needed, for example, a rule requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[0712] Enforcing additional authentication and access permissions
[0713] The user enters the authentication code into their device and sends it back to the server. The server checks the received authentication code and verifies its validity. If authentication is successful, access is permitted. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[0714] Specific examples
[0715] Access during normal times
[0716] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), access time, and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately allowing access.
[0717] Impact of abnormal access and emotional data
[0718] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), access time, and emotional data (impatience is detected), and sends these to the server. After the server successfully completes basic authentication, it flags an anomaly based on the location information, device information, and emotional data. This allows the server to generate dynamic security rules and request two-factor authentication. The user enters the authentication code, and the server finally verifies the authentication and allows access.
[0719] In this way, the system of the present invention realizes a dynamic and flexible security wall, and can adapt the security level according to the user's behavior and emotions.
[0720] The processing flow will be explained below.
[0721] Step 1:
[0722] A user attempts to access the system using a terminal, entering a user ID and password.
[0723] Step 2:
[0724] In addition to user IDs and passwords, the devices collect location information (e.g., IP addresses), device information (e.g., the type of device used and browser information), access times, and user emotional data (e.g., emotional state determined using facial recognition and text analysis).
[0725] Step 3:
[0726] The device encrypts all collected authentication information and sends it to the server.
[0727] Step 4:
[0728] The server performs basic authentication by checking the received user ID and password against the information in its database. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0729] Step 5:
[0730] After successful authentication, the server analyzes the additional authentication information (location and device information), compares it with past access history, and evaluates the degree of match.
[0731] Step 6:
[0732] The server will flag any location or device information that differs from previous databases as an anomaly, such as a sudden change in location or the use of a new device.
[0733] Step 7:
[0734] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the emotion of the user based on facial recognition data and input text, and incorporates the results into security decisions.
[0735] Step 8:
[0736] Based on the analysis results of the emotion engine, the server determines that additional security is necessary if the emotional state is abnormal (e.g., a sense of irritation is detected).
[0737] Step 9:
[0738] The server generates dynamic security rules based on the anomaly flags and the results of the emotion engine, including requiring two-factor authentication (2FA).
[0739] Step 10:
[0740] As part of two-factor authentication, the server sends a verification code to the user's registered email address or mobile phone number.
[0741] Step 11:
[0742] The user enters the received authentication code into the terminal and sends it to the server.
[0743] Step 12:
[0744] The server receives the entered authentication code and verifies its validity. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0745] Step 13:
[0746] The server finally decides whether to grant access based on the analysis of the authentication information, additional authentication information, and emotion data. If access is granted, the user can access the resource. If access is denied, the reason is presented to the user.
[0747] In this way, by realizing a dynamic and flexible security wall, the present invention can adapt the security level according to the user's behavior and emotions, thereby providing higher safety.
[0748] Example 2
[0749] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0750] In recent years, the increasing sophistication and diversification of cyber attacks has led to the problem that traditional, fixed security measures are insufficient. In particular, with the spread of remote work, the increase in access from new devices and new locations has further increased security risks. To address this, a dynamic and flexible security system is required.
[0751] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.
[0752] In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for verifying the collected authentication information in the server and performing authentication, means for analyzing the user's additional authentication information and detecting anomalies, means for collecting and analyzing sensor information including the user's emotional data, means for generating dynamic security rules based on the results of the emotional analysis and when an anomaly is detected, and for requesting additional authentication, and means for ultimately determining whether to permit or deny access. This makes it possible to apply dynamic security measures according to the user's behavior and emotions.
[0753] "User authentication information" refers to information, such as a user ID and password, used to identify a user and authorize access to the system.
[0754] A "server" is a computer system that operates on a network and processes, stores, and transmits data it receives.
[0755] "Verification" is the process by which the server compares the authentication information it receives with its internal database to see if there is a match.
[0756] "Additional authentication information" is data collected in addition to basic authentication information, such as location information and device information.
[0757] An "anomaly" is the detection of an unusual pattern, such as new location information or device information, compared with past normal access history.
[0758] "Dynamic security rules" are rules for security measures that are generated in real time and are flexibly changed according to the situation that arises.
[0759] "Additional authentication" means additional security verification procedures performed on top of basic authentication, such as two-factor authentication (2FA).
[0760] "Emotion data" is information that indicates the user's emotional state, and includes facial recognition data, text analysis results, and the like.
[0761] "Sensor information" is digital data collected from a user's devices and environment, and includes emotional data, location information, device information, and more.
[0762] The system of the present invention strengthens security by using an authentication process based on user credentials, additional authentication information, and an emotion engine to provide a dynamic security wall, which can dynamically apply security measures according to the user's behavior and emotions.
[0763] System configuration
[0764] The system of the present invention includes the following major components:
[0765] User device: The device from which the user attempts access, where authentication information and emotional data are collected.
[0766] Server: Receives authentication information and performs analysis, matching, anomaly detection, dynamic security rule generation, and sentiment analysis using the sentiment engine.
[0767] Emotion engine: An engine that analyzes emotions based on user input and behavioral patterns, and adjusts security rules based on the analysis results.
[0768] Program processing explanation
[0769] Collection and transmission of authentication information and emotional data
[0770] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., the type of device being used and browser information), access time, and emotional data (e.g., emotional state using facial recognition and text analysis). The device encrypts this information and sends it to the server.
[0771] Authentication process on the server
[0772] The server checks the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0773] Analysis of additional conditions and anomaly detection
[0774] After successful authentication, the server analyzes the additional authentication information (location and device information). It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[0775] Emotion analysis using an emotion engine
[0776] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the server detects that the user is clearly impatient, it can determine that the security risk is high.
[0777] Dynamic security rule generation
[0778] The server will then generate dynamic security rules based on the anomaly flags and emotion engine analysis, as needed, for example, a rule requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[0779] Enforcing additional authentication and access permissions
[0780] The user enters the authentication code into their device and sends it back to the server. The server checks the received authentication code and verifies its validity. If authentication is successful, access is permitted. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[0781] Specific examples
[0782] Access during normal times
[0783] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), access time, and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately allowing access.
[0784] Impact of abnormal access and emotional data
[0785] When a user attempts to access a company server from a hotel while on a business trip, the terminal collects and sends the user ID, password, location information (hotel IP address), device information (new laptop), access time, and emotional data (impatience detected) to the server. After the server successfully completes basic authentication, it flags an anomaly based on the location information, device information, and emotional data. This allows the server to generate dynamic security rules and request two-factor authentication. The user enters the authentication code, and the server finally verifies the authentication and allows access. In this way, the system of the present invention realizes a dynamic and flexible security wall, adapting the security level according to the user's behavior and emotions.
[0786] Examples of prompts for generative AI models
[0787] To develop a security system, create a prompt like this: Explain how you would detect anomalies and require additional security procedures when a user attempts to log in from a new device.
[0788] The flow of the identification process in the second embodiment will be described with reference to FIG.
[0789] Step 1:
[0790] Collection and transmission of authentication information and emotional data
[0791] A user attempts to log in to a system using a terminal. The user enters their user ID and password on the login screen. Based on the input, the terminal collects location information (IP address), device information (device type, OS version, browser version), access time, and emotional data (facial expressions using a facial recognition camera, and the emotional state of the input text using text analysis). This data is encrypted using TLS / SSL and sent to the server.
[0792] input:
[0793] User ID, password, location information, device information, access time, emotional data (face recognition, text analysis)
[0794] output:
[0795] Encrypted credentials and sentiment data
[0796] Specific behavior:
[0797] The user enters their login information into a browser or dedicated application. The device then runs location information, a facial recognition camera, and a text analysis engine to collect the necessary data. This data is then encrypted using TLS / SSL and sent to the server according to the transmission protocol.
[0798] Step 2:
[0799] Authentication process on the server
[0800] The server receives the encrypted authentication information sent from the terminal and decodes the data. The server compares the decoded user ID and password with its internal database to perform authentication. If authentication is successful, the server proceeds to the next processing step. If authentication fails, the server denies access and returns an error message to the user.
[0801] input:
[0802] Encrypted user ID and password
[0803] output:
[0804] Authentication success or failure flag, error message on failure
[0805] Specific behavior:
[0806] The server receives the encrypted data based on the TLS / SSL protocol. It decodes the user ID and password and queries the database. If authentication is successful, it sets an authentication success flag and proceeds to the next step. If authentication fails, it generates a detailed error message and sends it to the user.
[0807] Step 3:
[0808] Analysis of additional conditions and anomaly detection
[0809] After successful authentication, the server analyzes the location and device information sent. It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[0810] input:
[0811] Location information, device information, past access history
[0812] output:
[0813] Anomaly detection flag, match evaluation result
[0814] Specific behavior:
[0815] The server uses the location information to determine the user's geographic location and compares it with past access records. An algorithm evaluates the degree of match and flags any anomalies. For example, if a new IP address or device is detected, an anomaly flag will be raised.
[0816] Step 4:
[0817] Emotion analysis using an emotion engine
[0818] The server activates an emotion engine and analyzes the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the user shows signs of impatience, the server reassess the security risk based on that information.
[0819] input:
[0820] Facial recognition data, text analysis data
[0821] output:
[0822] Sentiment analysis results, security risk assessment results
[0823] Specific behavior:
[0824] The server uses an emotion engine (e.g., facial recognition API or text analysis API) to analyze the received data, record the determined emotional state, and incorporate it into the overall security risk assessment.
[0825] Step 5:
[0826] Dynamic security rule generation
[0827] The server generates the necessary dynamic security rules based on the anomaly flags and the analysis results of the emotion engine. For example, if the security risk is determined to be high, it will request two-factor authentication (2FA) and send an additional authentication code to the user according to the rules.
[0828] input:
[0829] Anomaly flags, sentiment analysis results, security policies
[0830] output:
[0831] Dynamic security rules, 2FA authentication codes
[0832] Specific behavior:
[0833] The server evaluates anomaly flags and sentiment analysis results to determine dynamic security measures. If additional measures such as two-factor authentication are required, an authentication code is sent to the user's registered contact method (e.g., SMS, email).
[0834] Step 6:
[0835] Enforcing additional authentication and access permissions
[0836] The user enters the authentication code into the device. The device sends the code to the server. The server checks the validity of the authentication code, and if authentication is successful, access is permitted. If authentication is unsuccessful, access is denied, and the reason is displayed to the user.
[0837] input:
[0838] Authentication code, server-generated code
[0839] output:
[0840] Access or deny decision, reason message
[0841] Specific behavior:
[0842] The user enters the received authentication code into the terminal and sends it. The server compares the received authentication code with the internally generated code. If they match, it flags access as allowed and proceeds to the next step. If they do not match, it generates an access denied message and notifies the user.
[0843] (Application example 2)
[0844] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0845] Conventional authentication systems are based only on static user authentication information (e.g., user ID and password) and fixed additional authentication information (e.g., location information, device information), making it difficult to improve security. Furthermore, these systems have the problem of not being able to fully detect abnormal access because they do not take into account the user's mental or emotional state. This makes unauthorized access and security breaches more likely to occur.
[0846] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for verifying the collected authentication information at the server and performing authentication, and means for analyzing the user's additional authentication information and detecting anomalies. It also includes means for analyzing the user's emotional state as the user's additional authentication information, and means for generating dynamic security rules and requesting additional authentication when an anomaly is detected and based on the emotional state. This enables more advanced and dynamic security measures.
[0847] "Authentication information" refers to information such as ID and password provided by a user when accessing a system.
[0848] "Emotional state" is data that indicates the user's psychological and emotional state, and is obtained from facial recognition data and input text.
[0849] "Location information" refers to geographical information based on the IP address of the device from which the user is accessing the site.
[0850] "Device information" refers to the type and identification information of the device used by the user.
[0851] "Dynamic security rules" are rules for security measures that are generated in real time depending on the situation, and include, for example, requirements for two-factor authentication.
[0852] "Additional authentication" is an additional authentication method performed in addition to basic authentication, and is based on location information, device information, or emotional state.
[0853] "Two-factor authentication" is a method that requires a second authentication method (e.g., SMS code or email code) in addition to the user's ID and password when accessing a system.
[0854] "Anomaly detection" is the detection of access attempts or behavior that is unusual or considered fraudulent.
[0855] The present invention is a system that uses user authentication information and emotion data to apply dynamic security rules and prevent abnormal access. A specific embodiment for realizing this system is shown below.
[0856] System configuration
[0857] The system of the present invention includes the following major components:
[0858] 1. User device: A device such as a smartphone or PC that collects user authentication information and emotional data. It includes a facial recognition camera, a GPS for acquiring location information, and software for acquiring device information.
[0859] 2. Server: Receives authentication information and performs parsing, matching, anomaly detection, dynamic security rule generation, and emotion analysis using the emotion engine. It uses Python, OpenCV, the face_recognition library, and the emotion_recognition module.
[0860] 3. Emotion engine: An engine that analyzes emotions based on user input and behavioral patterns, for example, using Python's emotion_recognition module.
[0861] Program processing flow
[0862] 1. Collection and transmission of authentication information and emotional data
[0863] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., device type and browser information), and emotional data (e.g., facial recognition data and emotional state analyzed from input text).
[0864] The collected data is encrypted and sent to a server.
[0865] 2. Authentication process on the server
[0866] The server performs basic authentication by checking the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[0867] 3. Analysis of additional conditions and anomaly detection
[0868] After successful authentication, the server analyzes the additional authentication information (location and device information) and compares it with past access history. It detects anomalies by evaluating the degree of match and flags any new location or device information as an anomaly.
[0869] 4. Emotion analysis using an emotion engine
[0870] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if a sense of impatience is detected, it will be determined that there is a high security risk.
[0871] 5. Dynamic Security Rule Generation
[0872] The server generates dynamic security rules based on the anomaly flags and emotion engine analysis, such as requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[0873] 6. Performing additional authentication and granting access
[0874] The user enters the authentication code into their device and sends it back to the server. The server then checks the validity of the received authentication code, and if authentication is successful, allows access. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[0875] Specific examples
[0876] Example 1: Access during normal times
[0877] When a user accesses the system from a home device, the device collects the user ID, password, location information (home IP address), device information (home device), and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately granting access.
[0878] Example 2: Abnormal access
[0879] When a user accesses the system from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new device), and emotional data (anxiety is detected), and sends them to the server. After the server successfully completes basic authentication, it detects an anomaly and generates a dynamic security rule to request two-factor authentication. The user enters the authentication code sent, and the server finally verifies the authentication, after which access is granted.
[0880] Example prompts to input to the generative AI model
[0881] An example prompt to input to the generative AI model is, "Describe an application that applies dynamic security rules based on authentication information and sentiment analysis data when a user accesses their account."
[0882] As a result, the system of the present invention can provide more advanced and flexible security measures and realize a security mechanism that is adaptable to the user's behavior and emotions.
[0883] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[0884] Step 1:
[0885] The user starts up the device and accesses the authentication screen. The device prompts the user to enter their ID and password. The entered data is temporarily stored on the device.
[0886] input:
[0887] The ID and password entered by the user.
[0888] output:
[0889] Saved IDs and passwords.
[0890] Operation:
[0891] The terminal receives the user's ID and password from the input form and stores them in memory.
[0892] Step 2:
[0893] The device activates the camera and recognizes the user's face. The facial recognition data is acquired and emotion analysis is performed using the emotion engine. The analyzed emotion data is also temporarily stored on the device.
[0894] input:
[0895] Video data from the camera.
[0896] output:
[0897] Facial recognition data and analyzed emotion data.
[0898] Operation:
[0899] The device captures video from the camera, applies a facial recognition algorithm to obtain facial data, then uses the emotion_recognition module to perform emotion analysis and save the results.
[0900] Step 3:
[0901] The device collects location information and device information. Location information is obtained from the GPS sensor and IP address, and device information is obtained from the device type and browser information.
[0902] input:
[0903] GPS sensor or IP address, device information.
[0904] output:
[0905] Location and Device Information.
[0906] Operation:
[0907] The device obtains location information from the IP address via a GPS sensor or the network, and collects device information such as device type and browser information.
[0908] Step 4:
[0909] The device encrypts the collected data (ID, password, facial recognition data, emotional data, location information, device information) and sends it to the server.
[0910] input:
[0911] ID, password, facial recognition data, emotional data, location information, device information.
[0912] output:
[0913] Encrypted data.
[0914] Operation:
[0915] The device securely encrypts all collected data and transmits it over the network to a server.
[0916] Step 5:
[0917] The server checks the ID and password from the received data and performs basic authentication. It checks against the database, and if it is correct, it proceeds to the next step. If it is invalid, it immediately returns a message to the terminal denying access.
[0918] input:
[0919] Encrypted ID and password.
[0920] output:
[0921] The authentication result (success or failure).
[0922] Operation:
[0923] The server decrypts the data and checks the user ID and password against the information in its database. Depending on the result, it either proceeds to the next processing step or denies access.
[0924] Step 6:
[0925] The server analyzes the additional authentication information (location information, device information) and compares it with past access history to evaluate the degree of match and detect any abnormalities.
[0926] input:
[0927] Location information, device information, and past access history.
[0928] output:
[0929] Abnormal flag (abnormal or normal).
[0930] Operation:
[0931] The server compares the location and device information with past access history to assess the degree of match, and based on this assessment, detects any anomalies and sets an anomaly flag.
[0932] Step 7:
[0933] The server uses an emotion engine to analyze the emotion data sent from the device and incorporates the results into security decisions. For example, if a sense of impatience is detected, it will be determined that the security risk is high.
[0934] input:
[0935] Emotional data.
[0936] output:
[0937] Sentiment analysis result (normal or abnormal).
[0938] Operation:
[0939] The server uses the emotion_recognition module to analyze the emotional data and evaluate the security risk based on the results.
[0940] Step 8:
[0941] The server generates dynamic security rules based on anomaly flags and sentiment analysis results, as needed, such as requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[0942] input:
[0943] Abnormal flags, sentiment analysis results.
[0944] output:
[0945] Dynamic security rules (e.g., requiring 2FA).
[0946] Operation:
[0947] The server generates dynamic security rules based on the anomaly flags and sentiment analysis results, and if necessary, requests additional authentication procedures from the user.
[0948] Step 9:
[0949] The user receives the authentication code sent from the server, enters it again into the terminal, and sends it to the server.
[0950] input:
[0951] Authentication code.
[0952] output:
[0953] The final authentication result (success or failure).
[0954] Operation:
[0955] The user enters the authentication code received from the server into the terminal and sends it to the server, which then checks the received authentication code to verify its validity.
[0956] Step 10:
[0957] If the authentication is successful, the server sends a message to the terminal permitting access. If the authentication is unsuccessful, the server returns a message indicating the reason for denial of access to the terminal.
[0958] input:
[0959] Final authentication result.
[0960] output:
[0961] An access allowed or denied message.
[0962] Operation:
[0963] Based on the final authentication result, the server sends a message to the terminal permitting access if successful, or a message including the reason for denial of access if unsuccessful.
[0964] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0965] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0966] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.
[0967] [Third embodiment]
[0968] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.
[0969] 5, the data processing system 310 includes the data processing device 12 and a headset type terminal 314. An example of the data processing device 12 is a server.
[0970] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0971] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.
[0972] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[0973] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[0974] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[0975] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[0976] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0977] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0978] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[0979] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."
[0980] The system of the present invention dynamically builds a security wall based on user behavior patterns and environmental conditions. This system collects user authentication information, performs dynamic analysis on the server, and generates dynamic security rules when an abnormality is detected. This provides greater flexibility and security accuracy than conventional static security rules.
[0981] System configuration
[0982] The system of the present invention includes the following major components:
[0983] User terminal: The device used by the user to access the server, where authentication information is collected.
[0984] Server: Receives authentication information, performs analysis, matching, and anomaly detection, and generates dynamic security rules to determine whether access is allowed or denied.
[0985] Program processing explanation
[0986] Credential collection and transmission
[0987] When a user attempts to access the system using a terminal, the terminal collects the following information: user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and the time of access. The terminal encrypts this information and sends it to the server.
[0988] Authentication process on the server
[0989] The server performs basic authentication processing based on the received authentication information. It checks the user ID and password against a database to determine whether authentication was successful. If authentication is successful, it proceeds to the next step, but if it is unsuccessful, it denies access and returns an error message to the user.
[0990] Analysis of additional conditions and anomaly detection
[0991] After basic authentication is successful, the server analyzes additional authentication information (location and device information). This includes comparing it with past access history and assessing the degree of match. For example, if the location information changes suddenly or access from a new device is detected, the server flags this as an anomaly and uses this information to generate dynamic security rules.
[0992] Dynamic security rule generation
[0993] If the server flags an anomaly, it will generate dynamic security rules that require additional authentication steps, such as a rule requiring two-factor authentication (2FA) and requiring the user to enter a verification code sent to a registered email address or mobile phone number.
[0994] Enforcing additional authentication and access permissions
[0995] The user enters the authentication code sent in response to a request for additional authentication from the server. The terminal then sends this authentication code back to the server, which then verifies its validity. If authentication is successful, the server finally grants access and provides the user with access to the resource. If authentication fails, access is denied and the reason is displayed to the user.
[0996] Specific examples
[0997] Access during normal times
[0998] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), and access time, and sends them to the server. The server performs basic authentication based on this information and analyzes additional conditions. In this case, since all the information matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[0999] Abnormal access
[1000] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), and access time, and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, and the server requests two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[1001] As described above, the system of the present invention can dynamically and flexibly adjust the security level, achieving both high security and user convenience.
[1002] The processing flow will be explained below.
[1003] Step 1:
[1004] A user attempts to access the system using a terminal, entering a user ID and password.
[1005] Step 2:
[1006] In addition to user IDs and passwords, the devices collect location information (e.g., IP addresses), device information (e.g., the type of device used and browser information), and access times.
[1007] Step 3:
[1008] The device encrypts all collected authentication information and sends it to the server.
[1009] Step 4:
[1010] The server performs basic authentication by checking the received user ID and password against the information in its database. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1011] Step 5:
[1012] After successful authentication, the server analyzes the additional authentication information (location and device information), which includes comparing it with past access history to assess the degree of match.
[1013] Step 6:
[1014] The server will flag any location or device information that differs from previous databases as an anomaly, such as a sudden change in location or the use of a new device.
[1015] Step 7:
[1016] If an anomaly is flagged, the server generates dynamic security rules, which may include requiring two-factor authentication (2FA).
[1017] Step 8:
[1018] As part of two-factor authentication, the server sends a verification code to the user's registered email address or mobile phone number.
[1019] Step 9:
[1020] The user enters the received authentication code into the terminal and attempts authentication again.
[1021] Step 10:
[1022] The terminal sends the entered authentication code to the server.
[1023] Step 11:
[1024] The server checks the received authentication code and verifies its validity. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1025] Step 12:
[1026] The server ultimately makes the decision to allow or deny the user access. If access is granted, the resource is accessible. If access is denied, the reason is presented to the user.
[1027] In this way, the present invention provides a dynamic and flexible security wall, capable of adapting security levels according to user behavior and environmental conditions.
[1028] Example 1
[1029] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1030] As remote access and online services via the Internet become more widespread, the risk of unauthorized access is increasing. Conventional static security rules cannot adequately address dynamically changing security risks, so a dynamic security wall with high flexibility and accuracy is required. Current systems lack dynamic security measures based on user behavior patterns and environmental conditions, which can lead to security vulnerabilities.
[1031] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[1032] In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for collating the user authentication information collected by the server and performing authentication, means for analyzing the user's additional authentication information and detecting anomalies based on the additional authentication information, means for generating dynamic security rules and requesting additional authentication when an anomaly is detected, means for using a high-level encryption algorithm and a secure communication protocol for the additional authentication, means for comparing the user's location information and device information with past access history and evaluating the degree of match and abnormal patterns, means for generating an authentication code when an abnormality flag is raised and notifying the user of the authentication code, and means for ultimately determining whether to allow or deny access. This makes it possible to dynamically and flexibly adjust the security level and achieve both high security and user convenience.
[1033] "Authentication information" refers to a series of information required when a user accesses a system, such as user ID, password, location information, device information, and access time period.
[1034] A "server" is a device or system that receives authentication information sent by a user, analyzes, collates, and detects anomalies, and generates dynamic security rules to determine whether to allow or deny access.
[1035] "Encryption" is the process of transforming data using a specific algorithm to make it unreadable to third parties in order to ensure its security.
[1036] A "high-level encryption algorithm" is an encryption technology that uses complex mathematical techniques to increase the confidentiality of information, such as AES-256.
[1037] A "secure communication protocol" is a set of rules that define communication procedures for securely sending and receiving data, and specific examples include TLS (Transport Layer Security).
[1038] "Additional authentication information" is information that indicates more detailed user characteristics, such as location information and device information, in addition to basic authentication information.
[1039] "Location information" refers to information that indicates the geographical location (e.g., IP address) from which a user accesses the site.
[1040] "Device information" refers to information indicating the type of device and browser information used when a user accesses the system.
[1041] An "abnormal flag" is an indicator or marking that the server sets when it detects an abnormal situation based on the analysis results of the additional authentication information.
[1042] "Dynamic security rules" are security measures that are set in real time according to the situation, based on the user's authentication information and additional authentication information.
[1043] "Two-factor authentication (2FA)" is a method of authenticating a user using two different factors (e.g., a password and an authentication code) when accessing a system.
[1044] An "authentication code" is a combination of characters and numbers that is temporarily provided to a user for security purposes and is valid for only a specific period of time.
[1045] The present invention is a system that dynamically builds a security wall based on user behavior patterns and environmental conditions. The system includes the following main components:
[1046] User terminal
[1047] This is the device that users use to access the server. Authentication information is collected here. The terminal collects user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and the time of access, and encrypts this information before sending it to the server. A high-level encryption algorithm (e.g., AES-256) is used for encryption, and the communication protocol is Transport Layer Security (TLS).
[1048] server
[1049] The server decrypts the received encrypted data and verifies the authentication information by checking it against a database. If authentication is successful, it analyzes additional authentication information (location information and device information) and evaluates the degree of match and abnormal patterns against past access history. If an abnormality flag is raised, the server generates dynamic security rules, for example, requiring two-factor authentication (2FA). Based on the abnormality flag being raised, it generates an authentication code and notifies the user. Finally, the server verifies the authentication code entered by the user and decides whether to allow or deny access.
[1050] Software Configuration
[1051] The following software components are used to implement this system:
[1052] A database management system that stores user authentication information, such as MySQL or PostgreSQL.
[1053] Cryptography library: Used to encrypt the credentials, for example, OpenSSL.
[1054] Web server: Accepts user access and handles authentication. For example, Apache or Nginx is used.
[1055] Specific system operation explanation
[1056] A specific example of system operation is shown below.
[1057] Access during normal times
[1058] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), and access time, and sends them to the server. The server performs basic authentication based on this information and analyzes additional conditions. In this case, since all the information matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[1059] Abnormal access
[1060] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), and access time, and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, and the server requests two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[1061] Prompt Sentence Examples
[1062] Below is an example of a prompt sentence to be input to the generative AI model.
[1063] If your system dynamically builds a security wall based on user behavior patterns or environmental conditions, please explain what data you collect, how you analyze it, and what additional authentication you perform when an anomaly is detected.
[1064] The flow of the identification process in the first embodiment will be described with reference to FIG.
[1065] Step 1:
[1066] Credential collection and transmission
[1067] The user accesses the system login screen and enters their user ID and password.
[1068] The device collects the entered user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and access time.
[1069] Input: User ID, password, location information, device information, access time
[1070] The device encrypts this information using the AES-256 encryption algorithm and uses TLS as the communication protocol to securely transmit the encrypted data to the server.
[1071] Output: Encrypted credentials
[1072] Step 2:
[1073] Basic authentication processing on the server
[1074] The server decrypts the encrypted data it receives.
[1075] Input: Encrypted credentials
[1076] The server queries the database for authentication information (user ID and password) and verifies it: it uses an SQL query to look up the target user ID in the database and compares it with the corresponding password hash.
[1077] Output: Authentication success / failure
[1078] Step 3:
[1079] Determining authentication results and notifying users
[1080] If the basic authentication is successful, the server proceeds to the next step, otherwise it generates an error message and sends it back to the user for notification.
[1081] Input: Authentication success / failure
[1082] The server sets a flag indicating that authentication was successful, and if authentication failed, generates an error message and sends it back as an HTTP response.
[1083] Output: Authentication success / failure notification
[1084] Step 4:
[1085] Analysis of additional authentication information and anomaly detection
[1086] After a successful authentication, the server analyzes additional authentication information (location and device information).
[1087] Input: User location information, device information
[1088] The server compares the location information with past access history and evaluates abnormal patterns (e.g., sudden location changes, use of new devices). To do this, it compares past access logs with location and device information.
[1089] Output: Abnormal flag (abnormal / normal)
[1090] Step 5:
[1091] Dynamic security rule generation
[1092] If the server flags an anomaly, it will generate dynamic security rules and require two-factor authentication (2FA).
[1093] Input: Abnormal flag (abnormal / normal)
[1094] The server generates an authentication code and sends it to the user via the registered email address or SMS gateway.
[1095] Output: The authentication code sent to the user.
[1096] Step 6:
[1097] Requesting and Enforcing Additional Authentication
[1098] The user enters the received authentication code into the terminal and transmits it.
[1099] Input:Authentication Code
[1100] The terminal sends the entered authentication code back to the server.
[1101] Output: The authentication code sent
[1102] Step 7:
[1103] Final authentication result and access permission
[1104] The server verifies the validity of the authentication code.
[1105] Input: The verification code sent to you
[1106] The server checks the authentication code against the system-generated code, and if they match, sets the final "access permitted flag", otherwise it returns an error message.
[1107] Output: Access allowed / denied notification
[1108] Through the above steps, this system can dynamically and flexibly adjust the security level, achieving both high security and user convenience.
[1109] (Application example 1)
[1110] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1111] Conventional security systems determine whether to allow access based on static authentication information, making them unable to flexibly adapt to changes in user behavior or the environment. This reduces the accuracy of detecting unauthorized access and increases security risks. However, there is a need for a method that achieves high security while maintaining user convenience.
[1112] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[1113] In this invention, the server includes means for verifying authentication information and performing authentication, means for analyzing additional authentication information and detecting anomalies based on the additional authentication information (including location information and device information), means for generating dynamic security rules and requesting two-factor authentication when an anomaly is detected, means for ultimately determining whether to permit or deny access, and means for collecting authentication information using a smartphone and transmitting it to the server. This makes it possible to dynamically apply security rules based on changes in user behavior and the environment, providing flexible and highly accurate security.
[1114] "Authentication information" means information including the user ID and password used when a user accesses the system.
[1115] "Additional Authentication Information" is information collected in addition to basic authentication information, such as location information and device information.
[1116] "Location information" is geographical information obtained based on the IP address and GPS data of the network to which the device is connected.
[1117] "Device information" refers to information about the device itself that the user is using, including, for example, the type of device, the type of browser, and the OS version.
[1118] "Abnormal" refers to access information or behavior that is significantly different from the user's past behavior patterns.
[1119] A "dynamic security rule" is a temporary security rule that is generated by the server in response to an anomaly it detects and requires an additional authentication step.
[1120] "Two-factor authentication" is an authentication method in which a user uses an additional authentication factor (e.g., an authentication code sent via SMS) in addition to their initial authentication information (user ID and password).
[1121] A "smartphone" is a multi-functional mobile device that can connect to the Internet.
[1122] A "server" is a computer system that receives authentication information sent by a user and performs authentication, anomaly detection, and dynamic security rule generation.
[1123] "Allowing or denying access" refers to the server determining whether to allow or deny a user access to a resource based on the user's authentication information.
[1124] The system of the present invention dynamically applies security rules when a user uses a smartphone to access online accounts or services that require high security. This system dynamically adjusts security rules based on the user's behavioral patterns and environmental conditions, providing flexible and highly accurate security.
[1125] System configuration
[1126] Hardware and Software
[1127] Smartphone: A device used by users to access the system. This terminal collects user IDs, passwords, location information, and device information and sends them to the server.
[1128] Server: A computer system that receives authentication information and performs parsing, matching, and anomaly detection. This server runs on Python and Flask and contains the logic for generating dynamic security rules.
[1129] Geocoder Library: A library used to obtain location information. The Geocoder library obtains location information from the IP address of a smartphone.
[1130] System Operation
[1131] 1. Collecting and transmitting authentication information
[1132] The smartphone collects user ID, password, location information, and device information, encrypts them, and sends them to the server. At this time, the Geocoder library is used to obtain location information from the IP address.
[1133] 2. Authentication process on the server
[1134] The server performs basic authentication by checking the user ID and password against a database based on the received authentication information. If authentication is successful, it proceeds to the next step; if it fails, it denies access.
[1135] 3. Analysis of additional conditions and anomaly detection
[1136] If basic authentication is successful, the server analyzes the additional authentication information (location and device information), comparing it with past access history and checking for sudden changes in location or device information. If a sudden change is detected, an anomaly is flagged.
[1137] 4. Dynamic Security Rule Generation
[1138] If an anomaly is flagged, the server generates a dynamic security rule (e.g., two-factor authentication), which requires the user to enter a verification code sent to a registered email address or mobile phone number.
[1139] 5. Performing additional authentication and granting access
[1140] The user responds to the server's request for additional authentication and enters the authentication code sent to them on their smartphone. The server then checks the validity of the authentication code, and allows access if authentication is successful. If authentication fails, access is denied.
[1141] Specific examples
[1142] Access during normal times
[1143] When a user accesses an online account from their smartphone at home, the smartphone collects the user ID, password, location information (home IP address), and device information (smartphone) and sends them to the server. The server performs basic authentication based on this information and analyzes any additional conditions. In this case, since the access matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[1144] Abnormal access
[1145] When a user accesses an online account from a hotel while on a business trip, the smartphone collects the user ID, password, location information (hotel IP address), and device information (smartphone) and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, requiring two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[1146] Prompt Sentence Examples
[1147] "Attempt to log in with the user ID 'example_user', password 'secure_password', and device 'smartphone'. If the location information is different from the previous time, notify the user of the abnormality and request additional authentication."
[1148] As a result, this system dynamically applies security rules based on changes in user behavior and the environment, achieving both high security and convenience.
[1149] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[1150] Step 1:
[1151] The terminal receives an access request from a user. The terminal collects the user ID, password, location information, and device information. This location information is obtained from the IP address using the Geocoder library. The collected data specifically includes the user ID, password, location information (IP address), and device type (smartphone, browser type, etc.).
[1152] Step 2:
[1153] The device sends the collected information to the server. The sent information is encrypted. The input is the user ID, password, location information, and device information, and the output is encrypted authentication information.
[1154] Step 3:
[1155] The server performs basic authentication by checking the received authentication information against a database. The input is encrypted authentication information and the user ID and password are checked against the database. The output is the success or failure of the authentication. If authentication is successful, proceed to the next step. If it fails, access is denied.
[1156] Step 4:
[1157] The server analyzes the additional authentication information (location and device information). This is a process that compares it with past access history and detects sudden changes in location or device information. The input is location and device information, and the output is an anomaly detection flag.
[1158] Step 5:
[1159] The server generates dynamic security rules when an abnormality flag is raised. Specifically, a rule requiring two-factor authentication is generated. The input is the abnormality flag, and the output is a message requesting additional authentication.
[1160] Step 6:
[1161] The user enters an additional authentication code in response to a two-factor authentication request. The input is the authentication code sent by the server, and the output is the authentication code entered by the user.
[1162] Step 7:
[1163] The terminal sends the authentication code entered by the user back to the server. The input is the authentication code entered by the user and data is sent. The output is the completion of sending the authentication code to the server.
[1164] Step 8:
[1165] The server verifies the validity of the received authentication code. The input is the authentication code entered by the user, and the output is the result of authentication success or failure. If authentication is successful, access is granted; if it fails, access is denied.
[1166] Through the above process, this system dynamically applies security rules based on changes in user behavior and the environment, enabling high levels of security and convenience.
[1167] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[1168] The system of the present invention strengthens security by using an authentication process based on user credentials, additional authentication information, and an emotion engine to provide a dynamic security wall, which can dynamically apply security measures according to the user's behavior and emotions.
[1169] System configuration
[1170] The system of the present invention includes the following major components:
[1171] User device: The device from which the user attempts access, where authentication information and emotional data are collected.
[1172] Server: Receives authentication information and performs analysis, matching, anomaly detection, dynamic security rule generation, and sentiment analysis using the sentiment engine.
[1173] Emotion Engine: An engine that analyzes emotions based on user input and behavioral patterns, and adjusts security rules based on the analysis results.
[1174] Program processing explanation
[1175] Collection and transmission of authentication information and emotional data
[1176] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., the type of device used and browser information), access time, and emotional data (e.g., emotional state using facial recognition and text analysis). The device encrypts this information and sends it to the server.
[1177] Authentication process on the server
[1178] The server performs basic authentication by checking the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1179] Analysis of additional conditions and anomaly detection
[1180] After successful authentication, the server analyzes the additional authentication information (location and device information). It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[1181] Emotion analysis using an emotion engine
[1182] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the server detects that the user is clearly impatient, it can determine that the security risk is high.
[1183] Dynamic security rule generation
[1184] The server will then generate dynamic security rules based on the anomaly flags and emotion engine analysis, as needed, for example, a rule requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[1185] Enforcing additional authentication and access permissions
[1186] The user enters the authentication code into their device and sends it back to the server. The server checks the received authentication code and verifies its validity. If authentication is successful, access is permitted. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[1187] Specific examples
[1188] Access during normal times
[1189] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), access time, and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately allowing access.
[1190] Impact of abnormal access and emotional data
[1191] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), access time, and emotional data (impatience is detected), and sends these to the server. After the server successfully completes basic authentication, it flags an anomaly based on the location information, device information, and emotional data. This allows the server to generate dynamic security rules and request two-factor authentication. The user enters the authentication code, and the server finally verifies the authentication and allows access.
[1192] In this way, the system of the present invention realizes a dynamic and flexible security wall, and can adapt the security level according to the user's behavior and emotions.
[1193] The processing flow will be explained below.
[1194] Step 1:
[1195] A user attempts to access the system using a terminal, entering a user ID and password.
[1196] Step 2:
[1197] In addition to user IDs and passwords, the devices collect location information (e.g., IP addresses), device information (e.g., the type of device used and browser information), access times, and user emotional data (e.g., emotional state determined using facial recognition and text analysis).
[1198] Step 3:
[1199] The device encrypts all collected authentication information and sends it to the server.
[1200] Step 4:
[1201] The server performs basic authentication by checking the received user ID and password against the information in its database. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1202] Step 5:
[1203] After successful authentication, the server analyzes the additional authentication information (location and device information), compares it with past access history, and evaluates the degree of match.
[1204] Step 6:
[1205] The server will flag any location or device information that differs from previous databases as an anomaly, such as a sudden change in location or the use of a new device.
[1206] Step 7:
[1207] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the emotion of the user based on facial recognition data and input text, and incorporates the results into security decisions.
[1208] Step 8:
[1209] Based on the analysis results of the emotion engine, the server determines that additional security is necessary if the emotional state is abnormal (e.g., a sense of irritation is detected).
[1210] Step 9:
[1211] The server generates dynamic security rules based on the anomaly flags and the results of the emotion engine, including requiring two-factor authentication (2FA).
[1212] Step 10:
[1213] As part of two-factor authentication, the server sends a verification code to the user's registered email address or mobile phone number.
[1214] Step 11:
[1215] The user enters the received authentication code into the terminal and sends it to the server.
[1216] Step 12:
[1217] The server receives the entered authentication code and verifies its validity. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1218] Step 13:
[1219] The server finally decides whether to grant access based on the results of analyzing the authentication information, additional authentication information, and emotion data. If access is granted, the user is allowed to access the resource. If access is denied, the reason is presented to the user.
[1220] In this way, by realizing a dynamic and flexible security wall, the present invention can adapt the security level according to the user's behavior and emotions, thereby providing higher safety.
[1221] Example 2
[1222] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1223] In recent years, the increasing sophistication and diversification of cyber attacks has led to the problem that traditional, fixed security measures are insufficient. In particular, with the spread of remote work, the increase in access from new devices and new locations has further increased security risks. To address this, a dynamic and flexible security system is required.
[1224] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.
[1225] In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for verifying the collected authentication information in the server and performing authentication, means for analyzing the user's additional authentication information and detecting anomalies, means for collecting and analyzing sensor information including the user's emotional data, means for generating dynamic security rules based on the results of the emotional analysis and when an anomaly is detected, and for requesting additional authentication, and means for ultimately determining whether to permit or deny access. This makes it possible to apply dynamic security measures according to the user's behavior and emotions.
[1226] "User authentication information" refers to information, such as a user ID and password, used to identify a user and authorize access to the system.
[1227] A "server" is a computer system that operates on a network and processes, stores, and transmits data it receives.
[1228] "Verification" is the process by which the server compares the authentication information it receives with its internal database to see if there is a match.
[1229] "Additional authentication information" is data collected in addition to basic authentication information, such as location information and device information.
[1230] An "anomaly" is the detection of an unusual pattern, such as new location information or device information, compared with past normal access history.
[1231] "Dynamic security rules" are rules for security measures that are generated in real time and are flexibly changed according to the situation that arises.
[1232] "Additional authentication" means additional security verification procedures performed on top of basic authentication, such as two-factor authentication (2FA).
[1233] "Emotion data" is information that indicates the user's emotional state, and includes facial recognition data, text analysis results, and the like.
[1234] "Sensor information" is digital data collected from a user's devices and environment, and includes emotional data, location information, device information, and more.
[1235] The system of the present invention strengthens security by using an authentication process based on user credentials, additional authentication information, and an emotion engine to provide a dynamic security wall, which can dynamically apply security measures according to the user's behavior and emotions.
[1236] System configuration
[1237] The system of the present invention includes the following major components:
[1238] User device: The device from which the user attempts access, where authentication information and emotional data are collected.
[1239] Server: Receives authentication information and performs analysis, matching, anomaly detection, dynamic security rule generation, and sentiment analysis using the sentiment engine.
[1240] Emotion engine: An engine that analyzes emotions based on user input and behavioral patterns, and adjusts security rules based on the analysis results.
[1241] Program processing explanation
[1242] Collection and transmission of authentication information and emotional data
[1243] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., the type of device being used and browser information), access time, and emotional data (e.g., emotional state using facial recognition and text analysis). The device encrypts this information and sends it to the server.
[1244] Authentication process on the server
[1245] The server checks the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1246] Analysis of additional conditions and anomaly detection
[1247] After successful authentication, the server analyzes the additional authentication information (location and device information). It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[1248] Emotion analysis using an emotion engine
[1249] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the server detects that the user is clearly impatient, it can determine that the security risk is high.
[1250] Dynamic security rule generation
[1251] The server will then generate dynamic security rules based on the anomaly flags and emotion engine analysis, as needed, for example, a rule requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[1252] Enforcing additional authentication and access permissions
[1253] The user enters the authentication code into their device and sends it back to the server. The server checks the received authentication code and verifies its validity. If authentication is successful, access is permitted. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[1254] Specific examples
[1255] Access during normal times
[1256] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), access time, and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately allowing access.
[1257] Impact of abnormal access and emotional data
[1258] When a user attempts to access a company server from a hotel while on a business trip, the terminal collects and sends the user ID, password, location information (hotel IP address), device information (new laptop), access time, and emotional data (impatience detected) to the server. After the server successfully completes basic authentication, it flags an anomaly based on the location information, device information, and emotional data. This allows the server to generate dynamic security rules and request two-factor authentication. The user enters the authentication code, and the server finally verifies the authentication and allows access. In this way, the system of the present invention realizes a dynamic and flexible security wall, adapting the security level according to the user's behavior and emotions.
[1259] Examples of prompts for generative AI models
[1260] To develop a security system, please create a prompt like this: Explain how you would detect anomalies and require additional security procedures when a user attempts to log in from a new device.
[1261] The flow of the identification process in the second embodiment will be described with reference to FIG.
[1262] Step 1:
[1263] Collection and transmission of authentication information and emotional data
[1264] A user attempts to log in to a system using a terminal. The user enters their user ID and password on the login screen. Based on the input, the terminal collects location information (IP address), device information (device type, OS version, browser version), access time, and emotional data (facial expressions using a facial recognition camera, and the emotional state of the input text using text analysis). This data is encrypted using TLS / SSL and sent to the server.
[1265] input:
[1266] User ID, password, location information, device information, access time, emotional data (face recognition, text analysis)
[1267] output:
[1268] Encrypted credentials and sentiment data
[1269] Specific behavior:
[1270] The user enters their login information into a browser or dedicated application. The device then runs location information, a facial recognition camera, and a text analysis engine to collect the necessary data. This data is then encrypted using TLS / SSL and sent to the server according to the transmission protocol.
[1271] Step 2:
[1272] Authentication process on the server
[1273] The server receives the encrypted authentication information sent from the terminal and decodes the data. The server compares the decoded user ID and password with its internal database to perform authentication. If authentication is successful, the server proceeds to the next processing step. If authentication fails, the server denies access and returns an error message to the user.
[1274] input:
[1275] Encrypted user ID and password
[1276] output:
[1277] Authentication success or failure flag, error message on failure
[1278] Specific behavior:
[1279] The server receives the encrypted data based on the TLS / SSL protocol. It decodes the user ID and password and queries the database. If authentication is successful, it sets an authentication success flag and proceeds to the next step. If authentication fails, it generates a detailed error message and sends it to the user.
[1280] Step 3:
[1281] Analysis of additional conditions and anomaly detection
[1282] After successful authentication, the server analyzes the location and device information sent. It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[1283] input:
[1284] Location information, device information, past access history
[1285] output:
[1286] Anomaly detection flag, match evaluation result
[1287] Specific behavior:
[1288] The server uses the location information to determine the user's geographic location and compares it with past access records. An algorithm evaluates the degree of match and flags any anomalies. For example, if a new IP address or device is detected, an anomaly flag will be raised.
[1289] Step 4:
[1290] Emotion analysis using an emotion engine
[1291] The server activates an emotion engine and analyzes the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the user shows signs of impatience, the server reassess the security risk based on that information.
[1292] input:
[1293] Facial recognition data, text analysis data
[1294] output:
[1295] Sentiment analysis results, security risk assessment results
[1296] Specific behavior:
[1297] The server uses an emotion engine (e.g., facial recognition API or text analysis API) to analyze the received data, record the determined emotional state, and incorporate it into the overall security risk assessment.
[1298] Step 5:
[1299] Dynamic security rule generation
[1300] The server generates the necessary dynamic security rules based on the anomaly flags and the analysis results of the emotion engine. For example, if the security risk is determined to be high, it will request two-factor authentication (2FA) and send an additional authentication code to the user according to the rules.
[1301] input:
[1302] Anomaly flags, sentiment analysis results, security policies
[1303] output:
[1304] Dynamic security rules, 2FA authentication codes
[1305] Specific behavior:
[1306] The server evaluates anomaly flags and sentiment analysis results to determine dynamic security measures. If additional measures such as two-factor authentication are required, an authentication code is sent to the user's registered contact method (e.g., SMS, email).
[1307] Step 6:
[1308] Enforcing additional authentication and access permissions
[1309] The user enters the authentication code into the device. The device sends the code to the server. The server checks the validity of the authentication code, and if authentication is successful, access is permitted. If authentication is unsuccessful, access is denied, and the reason is displayed to the user.
[1310] input:
[1311] Authentication code, server-generated code
[1312] output:
[1313] Access or deny decision, reason message
[1314] Specific behavior:
[1315] The user enters the received authentication code into the terminal and sends it. The server compares the received authentication code with the internally generated code. If they match, it flags access as allowed and proceeds to the next step. If they do not match, it generates an access denied message and notifies the user.
[1316] (Application example 2)
[1317] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1318] Conventional authentication systems are based only on static user authentication information (e.g., user ID and password) and fixed additional authentication information (e.g., location information, device information), making it difficult to improve security. Furthermore, these systems have the problem of not being able to fully detect abnormal access because they do not take into account the user's mental or emotional state. This makes unauthorized access and security breaches more likely to occur.
[1319] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for verifying the collected authentication information at the server and performing authentication, and means for analyzing the user's additional authentication information and detecting anomalies. It also includes means for analyzing the user's emotional state as the user's additional authentication information, and means for generating dynamic security rules and requesting additional authentication when an anomaly is detected and based on the emotional state. This enables more advanced and dynamic security measures.
[1320] "Authentication information" refers to information such as ID and password provided by a user when accessing a system.
[1321] "Emotional state" is data that indicates the user's psychological and emotional state, and is obtained from facial recognition data and input text.
[1322] "Location information" refers to geographical information based on the IP address of the device from which the user is accessing the site.
[1323] "Device information" refers to the type and identification information of the device used by the user.
[1324] "Dynamic security rules" are rules for security measures that are generated in real time depending on the situation, and include, for example, requirements for two-factor authentication.
[1325] "Additional authentication" is an additional authentication method performed in addition to basic authentication, and is based on location information, device information, or emotional state.
[1326] "Two-factor authentication" is a method that requires a second authentication method (e.g., SMS code or email code) in addition to the user's ID and password when accessing a system.
[1327] "Anomaly detection" is the detection of access attempts or behavior that is unusual or considered fraudulent.
[1328] The present invention is a system that uses user authentication information and emotion data to apply dynamic security rules and prevent abnormal access. A specific embodiment for realizing this system is shown below.
[1329] System configuration
[1330] The system of the present invention includes the following major components:
[1331] 1. User device: A device such as a smartphone or PC that collects user authentication information and emotional data. It includes a facial recognition camera, a GPS for acquiring location information, and software for acquiring device information.
[1332] 2. Server: Receives authentication information and performs parsing, matching, anomaly detection, dynamic security rule generation, and emotion analysis using the emotion engine. It uses Python, OpenCV, the face_recognition library, and the emotion_recognition module.
[1333] 3. Emotion engine: An engine that analyzes emotions based on user input and behavioral patterns, for example, using Python's emotion_recognition module.
[1334] Program processing flow
[1335] 1. Collection and transmission of authentication information and emotional data
[1336] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., device type and browser information), and emotional data (e.g., facial recognition data and emotional state analyzed from input text).
[1337] The collected data is encrypted and sent to a server.
[1338] 2. Authentication process on the server
[1339] The server performs basic authentication by checking the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1340] 3. Analysis of additional conditions and anomaly detection
[1341] After successful authentication, the server analyzes the additional authentication information (location and device information) and compares it with past access history. It detects anomalies by evaluating the degree of match and flags any new location or device information as an anomaly.
[1342] 4. Emotion analysis using an emotion engine
[1343] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if a sense of impatience is detected, it will be determined that there is a high security risk.
[1344] 5. Dynamic Security Rule Generation
[1345] The server generates dynamic security rules based on the anomaly flags and emotion engine analysis, such as requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[1346] 6. Performing additional authentication and granting access
[1347] The user enters the authentication code into their device and sends it back to the server. The server then checks the validity of the received authentication code, and if authentication is successful, allows access. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[1348] Specific examples
[1349] Example 1: Access during normal times
[1350] When a user accesses the system from a home device, the device collects the user ID, password, location information (home IP address), device information (home device), and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately granting access.
[1351] Example 2: Abnormal access
[1352] When a user accesses the system from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new device), and emotional data (anxiety is detected), and sends them to the server. After the server successfully completes basic authentication, it detects an anomaly and generates a dynamic security rule to request two-factor authentication. The user enters the authentication code sent, and the server finally verifies the authentication, after which access is granted.
[1353] Example prompts to input to the generative AI model
[1354] An example prompt to input to the generative AI model is, "Describe an application that applies dynamic security rules based on authentication information and sentiment analysis data when a user accesses their account."
[1355] As a result, the system of the present invention can provide more advanced and flexible security measures and realize a security mechanism that is adaptable to the user's behavior and emotions.
[1356] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[1357] Step 1:
[1358] The user starts up the device and accesses the authentication screen. The device prompts the user to enter their ID and password. The entered data is temporarily stored on the device.
[1359] input:
[1360] The ID and password entered by the user.
[1361] output:
[1362] Saved IDs and passwords.
[1363] Operation:
[1364] The terminal receives the user's ID and password from the input form and stores them in memory.
[1365] Step 2:
[1366] The device activates the camera and recognizes the user's face. The facial recognition data is acquired and emotion analysis is performed using the emotion engine. The analyzed emotion data is also temporarily stored on the device.
[1367] input:
[1368] Video data from the camera.
[1369] output:
[1370] Facial recognition data and analyzed emotion data.
[1371] Operation:
[1372] The device captures video from the camera, applies a facial recognition algorithm to obtain facial data, then uses the emotion_recognition module to perform emotion analysis and save the results.
[1373] Step 3:
[1374] The device collects location information and device information. Location information is obtained from the GPS sensor and IP address, and device information is obtained from the device type and browser information.
[1375] input:
[1376] GPS sensor or IP address, device information.
[1377] output:
[1378] Location and Device Information.
[1379] Operation:
[1380] The device obtains location information from the IP address via a GPS sensor or the network, and collects device information such as device type and browser information.
[1381] Step 4:
[1382] The device encrypts the collected data (ID, password, facial recognition data, emotional data, location information, device information) and sends it to the server.
[1383] input:
[1384] ID, password, facial recognition data, emotional data, location information, device information.
[1385] output:
[1386] Encrypted data.
[1387] Operation:
[1388] The device securely encrypts all collected data and transmits it over the network to a server.
[1389] Step 5:
[1390] The server checks the ID and password from the received data and performs basic authentication. It checks against the database, and if it is correct, it proceeds to the next step. If it is invalid, it immediately returns a message to the terminal denying access.
[1391] input:
[1392] Encrypted ID and password.
[1393] output:
[1394] The authentication result (success or failure).
[1395] Operation:
[1396] The server decrypts the data and checks the user ID and password against the information in its database. Depending on the result, it either proceeds to the next processing step or denies access.
[1397] Step 6:
[1398] The server analyzes the additional authentication information (location information, device information) and compares it with past access history to evaluate the degree of match and detect any abnormalities.
[1399] input:
[1400] Location information, device information, and past access history.
[1401] output:
[1402] Abnormal flag (abnormal or normal).
[1403] Operation:
[1404] The server compares the location and device information with past access history to assess the degree of match, and based on this assessment, detects any anomalies and sets an anomaly flag.
[1405] Step 7:
[1406] The server uses an emotion engine to analyze the emotion data sent from the device and incorporates the results into security decisions. For example, if a sense of impatience is detected, it will be determined that the security risk is high.
[1407] input:
[1408] Emotional data.
[1409] output:
[1410] Sentiment analysis result (normal or abnormal).
[1411] Operation:
[1412] The server uses the emotion_recognition module to analyze the emotional data and evaluate the security risk based on the results.
[1413] Step 8:
[1414] The server generates dynamic security rules based on anomaly flags and sentiment analysis results, as needed, such as requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[1415] input:
[1416] Abnormal flags, sentiment analysis results.
[1417] output:
[1418] Dynamic security rules (e.g., requiring 2FA).
[1419] Operation:
[1420] The server generates dynamic security rules based on the anomaly flags and sentiment analysis results, and if necessary, requests additional authentication procedures from the user.
[1421] Step 9:
[1422] The user receives the authentication code sent from the server, enters it again into the terminal, and sends it to the server.
[1423] input:
[1424] Authentication code.
[1425] output:
[1426] The final authentication result (success or failure).
[1427] Operation:
[1428] The user enters the authentication code received from the server into the terminal and sends it to the server, which then checks the received authentication code to verify its validity.
[1429] Step 10:
[1430] If the authentication is successful, the server sends a message to the terminal permitting access. If the authentication is unsuccessful, the server returns a message indicating the reason for denial of access to the terminal.
[1431] input:
[1432] Final authentication result.
[1433] output:
[1434] An access allowed or denied message.
[1435] Operation:
[1436] Based on the final authentication result, the server sends a message to the terminal permitting access if successful, or a message including the reason for denial of access if unsuccessful.
[1437] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[1438] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[1439] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.
[1440] [Fourth embodiment]
[1441] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.
[1442] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[1443] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[1444] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.
[1445] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[1446] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[1447] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[1448] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.
[1449] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[1450] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[1451] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[1452] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[1453] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1454] The system of the present invention dynamically builds a security wall based on user behavior patterns and environmental conditions. This system collects user authentication information, performs dynamic analysis on the server, and generates dynamic security rules when an abnormality is detected. This provides greater flexibility and security accuracy than conventional static security rules.
[1455] System configuration
[1456] The system of the present invention includes the following major components:
[1457] User terminal: The device used by the user to access the server, where authentication information is collected.
[1458] Server: Receives authentication information, performs analysis, matching, and anomaly detection, and generates dynamic security rules to determine whether access is allowed or denied.
[1459] Program processing explanation
[1460] Credential collection and transmission
[1461] When a user attempts to access the system using a terminal, the terminal collects the following information: user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and the time of access. The terminal encrypts this information and sends it to the server.
[1462] Authentication process on the server
[1463] The server performs basic authentication processing based on the received authentication information. It checks the user ID and password against a database to determine whether authentication was successful. If authentication is successful, it proceeds to the next step, but if it is unsuccessful, it denies access and returns an error message to the user.
[1464] Analysis of additional conditions and anomaly detection
[1465] After basic authentication is successful, the server analyzes additional authentication information (location and device information). This includes comparing it with past access history and assessing the degree of match. For example, if the location information changes suddenly or access from a new device is detected, the server flags this as an anomaly and uses this information to generate dynamic security rules.
[1466] Dynamic security rule generation
[1467] If the server flags an anomaly, it will generate dynamic security rules that require additional authentication steps, such as a rule requiring two-factor authentication (2FA) and requiring the user to enter a verification code sent to a registered email address or mobile phone number.
[1468] Enforcing additional authentication and access permissions
[1469] The user enters the authentication code sent in response to a request for additional authentication from the server. The terminal then sends this authentication code back to the server, which then verifies its validity. If authentication is successful, the server finally grants access and provides the user with access to the resource. If authentication fails, access is denied and the reason is displayed to the user.
[1470] Specific examples
[1471] Access during normal times
[1472] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), and access time, and sends them to the server. The server performs basic authentication based on this information and analyzes additional conditions. In this case, since all the information matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[1473] Abnormal access
[1474] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), and access time, and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, and the server requests two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[1475] As described above, the system of the present invention can dynamically and flexibly adjust the security level, achieving both high security and user convenience.
[1476] The processing flow will be explained below.
[1477] Step 1:
[1478] A user attempts to access the system using a terminal, entering a user ID and password.
[1479] Step 2:
[1480] In addition to user IDs and passwords, the devices collect location information (e.g., IP addresses), device information (e.g., the type of device used and browser information), and access times.
[1481] Step 3:
[1482] The device encrypts all collected authentication information and sends it to the server.
[1483] Step 4:
[1484] The server performs basic authentication by checking the received user ID and password against the information in its database. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1485] Step 5:
[1486] After successful authentication, the server analyzes the additional authentication information (location and device information), which includes comparing it with past access history to assess the degree of match.
[1487] Step 6:
[1488] The server will flag any location or device information that differs from previous databases as an anomaly, such as a sudden change in location or the use of a new device.
[1489] Step 7:
[1490] If an anomaly is flagged, the server generates dynamic security rules, which may include requiring two-factor authentication (2FA).
[1491] Step 8:
[1492] As part of two-factor authentication, the server sends a verification code to the user's registered email address or mobile phone number.
[1493] Step 9:
[1494] The user enters the received authentication code into the terminal and attempts authentication again.
[1495] Step 10:
[1496] The terminal sends the entered authentication code to the server.
[1497] Step 11:
[1498] The server checks the received authentication code and verifies its validity. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1499] Step 12:
[1500] The server ultimately makes the decision to allow or deny the user access. If access is granted, the resource is accessible. If access is denied, the reason is presented to the user.
[1501] In this way, the present invention provides a dynamic and flexible security wall, capable of adapting security levels according to user behavior and environmental conditions.
[1502] Example 1
[1503] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1504] As remote access and online services via the Internet become more widespread, the risk of unauthorized access is increasing. Conventional static security rules cannot adequately address dynamically changing security risks, so a dynamic security wall with high flexibility and accuracy is required. Current systems lack dynamic security measures based on user behavior patterns and environmental conditions, which can lead to security vulnerabilities.
[1505] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[1506] In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for collating the user authentication information collected by the server and performing authentication, means for analyzing the user's additional authentication information and detecting anomalies based on the additional authentication information, means for generating dynamic security rules and requesting additional authentication when an anomaly is detected, means for using a high-level encryption algorithm and a secure communication protocol for the additional authentication, means for comparing the user's location information and device information with past access history and evaluating the degree of match and abnormal patterns, means for generating an authentication code when an abnormality flag is raised and notifying the user of the authentication code, and means for ultimately determining whether to allow or deny access. This makes it possible to dynamically and flexibly adjust the security level and achieve both high security and user convenience.
[1507] "Authentication information" refers to a series of information required when a user accesses a system, such as user ID, password, location information, device information, and access time period.
[1508] A "server" is a device or system that receives authentication information sent by a user, analyzes, collates, and detects anomalies, and generates dynamic security rules to determine whether to allow or deny access.
[1509] "Encryption" is the process of transforming data using a specific algorithm to make it unreadable to third parties in order to ensure its security.
[1510] A "high-level encryption algorithm" is an encryption technology that uses complex mathematical techniques to increase the confidentiality of information, such as AES-256.
[1511] A "secure communication protocol" is a set of rules that define communication procedures for securely sending and receiving data, and specific examples include TLS (Transport Layer Security).
[1512] "Additional authentication information" is information that indicates more detailed user characteristics, such as location information and device information, in addition to basic authentication information.
[1513] "Location information" refers to information that indicates the geographical location (e.g., IP address) from which a user accesses the site.
[1514] "Device information" refers to information indicating the type of device and browser information used when a user accesses the system.
[1515] An "abnormal flag" is an indicator or marking that the server sets when it detects an abnormal situation based on the analysis results of the additional authentication information.
[1516] "Dynamic security rules" are security measures that are set in real time according to the situation, based on the user's authentication information and additional authentication information.
[1517] "Two-factor authentication (2FA)" is a method of authenticating a user using two different factors (e.g., a password and an authentication code) when accessing a system.
[1518] An "authentication code" is a combination of characters and numbers that is temporarily provided to a user for security purposes and is valid for only a specific period of time.
[1519] The present invention is a system that dynamically builds a security wall based on user behavior patterns and environmental conditions. The system includes the following main components:
[1520] User terminal
[1521] This is the device that users use to access the server. Authentication information is collected here. The terminal collects user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and the time of access, and encrypts this information before sending it to the server. A high-level encryption algorithm (e.g., AES-256) is used for encryption, and the communication protocol is Transport Layer Security (TLS).
[1522] server
[1523] The server decrypts the received encrypted data and verifies the authentication information by checking it against a database. If authentication is successful, it analyzes additional authentication information (location information and device information) and evaluates the degree of match and abnormal patterns against past access history. If an abnormality flag is raised, the server generates dynamic security rules, for example, requiring two-factor authentication (2FA). Based on the abnormality flag being raised, it generates an authentication code and notifies the user. Finally, the server verifies the authentication code entered by the user and decides whether to allow or deny access.
[1524] Software Configuration
[1525] The following software components are used to implement this system:
[1526] A database management system that stores user authentication information, such as MySQL or PostgreSQL.
[1527] Cryptography library: Used to encrypt the credentials, for example, OpenSSL.
[1528] Web server: Accepts user access and handles authentication. For example, Apache or Nginx is used.
[1529] Specific system operation explanation
[1530] A specific example of system operation is shown below.
[1531] Access during normal times
[1532] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), and access time, and sends them to the server. The server performs basic authentication based on this information and analyzes additional conditions. In this case, since all the information matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[1533] Abnormal access
[1534] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), and access time, and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, and the server requests two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[1535] Prompt Sentence Examples
[1536] Below is an example of a prompt sentence to be input to the generative AI model.
[1537] If your system dynamically builds a security wall based on user behavior patterns or environmental conditions, please explain what data you collect, how you analyze it, and what additional authentication you perform when an anomaly is detected.
[1538] The flow of the identification process in the first embodiment will be described with reference to FIG.
[1539] Step 1:
[1540] Credential collection and transmission
[1541] The user accesses the system login screen and enters their user ID and password.
[1542] The device collects the entered user ID and password, location information (e.g., IP address), device information (e.g., the type of device used and browser information), and access time.
[1543] Input: User ID, password, location information, device information, access time
[1544] The device encrypts this information using the AES-256 encryption algorithm and uses TLS as the communication protocol to securely transmit the encrypted data to the server.
[1545] Output: Encrypted credentials
[1546] Step 2:
[1547] Basic authentication processing on the server
[1548] The server decrypts the encrypted data it receives.
[1549] Input: Encrypted credentials
[1550] The server queries the database for authentication information (user ID and password) and verifies it: it uses an SQL query to look up the target user ID in the database and compares it with the corresponding password hash.
[1551] Output: Authentication success / failure
[1552] Step 3:
[1553] Determining authentication results and notifying users
[1554] If the basic authentication is successful, the server proceeds to the next step, otherwise it generates an error message and sends it back to the user for notification.
[1555] Input: Authentication success / failure
[1556] The server sets a flag indicating that authentication was successful, and if authentication failed, generates an error message and sends it back as an HTTP response.
[1557] Output: Authentication success / failure notification
[1558] Step 4:
[1559] Analysis of additional authentication information and anomaly detection
[1560] After a successful authentication, the server analyzes additional authentication information (location and device information).
[1561] Input: User location information, device information
[1562] The server compares the location information with past access history and evaluates abnormal patterns (e.g., sudden location changes, use of new devices). To do this, it compares past access logs with location and device information.
[1563] Output: Abnormal flag (abnormal / normal)
[1564] Step 5:
[1565] Dynamic security rule generation
[1566] If the server flags an anomaly, it will generate dynamic security rules and require two-factor authentication (2FA).
[1567] Input: Abnormal flag (abnormal / normal)
[1568] The server generates an authentication code and sends it to the user via the registered email address or SMS gateway.
[1569] Output: The authentication code sent to the user.
[1570] Step 6:
[1571] Requesting and Enforcing Additional Authentication
[1572] The user enters the received authentication code into the terminal and transmits it.
[1573] Input:Authentication Code
[1574] The terminal sends the entered authentication code back to the server.
[1575] Output: The authentication code sent
[1576] Step 7:
[1577] Final authentication result and access permission
[1578] The server verifies the validity of the authentication code.
[1579] Input: The verification code sent to you
[1580] The server checks the authentication code against the system-generated code, and if they match, sets the final "access permitted flag", otherwise it returns an error message.
[1581] Output: Access allowed / denied notification
[1582] Through the above steps, this system can dynamically and flexibly adjust the security level, achieving both high security and user convenience.
[1583] (Application example 1)
[1584] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1585] Conventional security systems determine whether to allow access based on static authentication information, making them unable to flexibly adapt to changes in user behavior or the environment. This reduces the accuracy of detecting unauthorized access and increases security risks. However, there is a need for a method that achieves high security while maintaining user convenience.
[1586] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[1587] In this invention, the server includes means for verifying authentication information and performing authentication, means for analyzing additional authentication information and detecting anomalies based on the additional authentication information (including location information and device information), means for generating dynamic security rules and requesting two-factor authentication when an anomaly is detected, means for ultimately determining whether to permit or deny access, and means for collecting authentication information using a smartphone and transmitting it to the server. This makes it possible to dynamically apply security rules based on changes in user behavior and the environment, providing flexible and highly accurate security.
[1588] "Authentication information" means information including the user ID and password used when a user accesses the system.
[1589] "Additional Authentication Information" is information collected in addition to basic authentication information, such as location information and device information.
[1590] "Location information" is geographical information obtained based on the IP address and GPS data of the network to which the device is connected.
[1591] "Device information" refers to information about the device itself that the user is using, including, for example, the type of device, the type of browser, and the OS version.
[1592] "Abnormal" refers to access information or behavior that is significantly different from the user's past behavior patterns.
[1593] A "dynamic security rule" is a temporary security rule that is generated by the server in response to an anomaly it detects and requires an additional authentication step.
[1594] "Two-factor authentication" is an authentication method in which a user uses an additional authentication factor (e.g., an authentication code sent via SMS) in addition to their initial authentication information (user ID and password).
[1595] A "smartphone" is a multi-functional mobile device that can connect to the Internet.
[1596] A "server" is a computer system that receives authentication information sent by a user and performs authentication, anomaly detection, and dynamic security rule generation.
[1597] "Allowing or denying access" refers to the server determining whether to allow or deny a user access to a resource based on the user's authentication information.
[1598] The system of the present invention dynamically applies security rules when a user uses a smartphone to access online accounts or services that require high security. This system dynamically adjusts security rules based on the user's behavioral patterns and environmental conditions, providing flexible and highly accurate security.
[1599] System configuration
[1600] Hardware and Software
[1601] Smartphone: A device used by users to access the system. This terminal collects user IDs, passwords, location information, and device information and sends them to the server.
[1602] Server: A computer system that receives authentication information and performs parsing, matching, and anomaly detection. This server runs on Python and Flask and contains the logic for generating dynamic security rules.
[1603] Geocoder Library: A library used to obtain location information. The Geocoder library obtains location information from the IP address of a smartphone.
[1604] System Operation
[1605] 1. Collecting and transmitting authentication information
[1606] The smartphone collects user ID, password, location information, and device information, encrypts them, and sends them to the server. At this time, the Geocoder library is used to obtain location information from the IP address.
[1607] 2. Authentication process on the server
[1608] The server performs basic authentication by checking the user ID and password against a database based on the received authentication information. If authentication is successful, it proceeds to the next step; if it fails, it denies access.
[1609] 3. Analysis of additional conditions and anomaly detection
[1610] If basic authentication is successful, the server analyzes the additional authentication information (location and device information), comparing it with past access history and checking for sudden changes in location or device information. If a sudden change is detected, an anomaly is flagged.
[1611] 4. Dynamic Security Rule Generation
[1612] If an anomaly is flagged, the server generates a dynamic security rule (e.g., two-factor authentication), which requires the user to enter a verification code sent to a registered email address or mobile phone number.
[1613] 5. Performing additional authentication and granting access
[1614] The user responds to the server's request for additional authentication and enters the authentication code sent to them on their smartphone. The server then checks the validity of the authentication code, and allows access if authentication is successful. If authentication fails, access is denied.
[1615] Specific examples
[1616] Access during normal times
[1617] When a user accesses an online account from their smartphone at home, the smartphone collects the user ID, password, location information (home IP address), and device information (smartphone) and sends them to the server. The server performs basic authentication based on this information and analyzes any additional conditions. In this case, since the access matches past access patterns, no abnormality flag is raised and the server immediately allows access.
[1618] Abnormal access
[1619] When a user accesses an online account from a hotel while on a business trip, the smartphone collects the user ID, password, location information (hotel IP address), and device information (smartphone) and sends them to the server. After the server successfully completes basic authentication, it analyzes additional conditions and flags the access as an anomaly. In this case, a dynamic security rule is generated, requiring two-factor authentication. The user enters the authentication code, and the server verifies its validity before finally granting access.
[1620] Prompt Sentence Examples
[1621] "Attempt to log in with the user ID 'example_user', password 'secure_password', and device 'smartphone'. If the location information is different from the previous time, notify the user of the abnormality and request additional authentication."
[1622] As a result, this system dynamically applies security rules based on changes in user behavior and the environment, achieving both high security and convenience.
[1623] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[1624] Step 1:
[1625] The terminal receives an access request from a user. The terminal collects the user ID, password, location information, and device information. This location information is obtained from the IP address using the Geocoder library. The collected data specifically includes the user ID, password, location information (IP address), and device type (smartphone, browser type, etc.).
[1626] Step 2:
[1627] The device sends the collected information to the server. The sent information is encrypted. The input is the user ID, password, location information, and device information, and the output is encrypted authentication information.
[1628] Step 3:
[1629] The server performs basic authentication by checking the received authentication information against a database. The input is encrypted authentication information and the user ID and password are checked against the database. The output is the success or failure of the authentication. If authentication is successful, proceed to the next step. If it fails, access is denied.
[1630] Step 4:
[1631] The server analyzes the additional authentication information (location and device information). This is a process that compares it with past access history and detects sudden changes in location or device information. The input is location and device information, and the output is an anomaly detection flag.
[1632] Step 5:
[1633] The server generates dynamic security rules when an abnormality flag is raised. Specifically, a rule requiring two-factor authentication is generated. The input is the abnormality flag, and the output is a message requesting additional authentication.
[1634] Step 6:
[1635] The user enters an additional authentication code in response to a two-factor authentication request. The input is the authentication code sent by the server, and the output is the authentication code entered by the user.
[1636] Step 7:
[1637] The terminal sends the authentication code entered by the user back to the server. The input is the authentication code entered by the user and data is sent. The output is the completion of sending the authentication code to the server.
[1638] Step 8:
[1639] The server verifies the validity of the received authentication code. The input is the authentication code entered by the user, and the output is the result of authentication success or failure. If authentication is successful, access is granted; if it fails, access is denied.
[1640] Through the above process, this system dynamically applies security rules based on changes in user behavior and the environment, enabling high levels of security and convenience.
[1641] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[1642] The system of the present invention strengthens security by using an authentication process based on user credentials, additional authentication information, and an emotion engine to provide a dynamic security wall, which can dynamically apply security measures according to the user's behavior and emotions.
[1643] System configuration
[1644] The system of the present invention includes the following major components:
[1645] User device: The device from which the user attempts access, where authentication information and emotional data are collected.
[1646] Server: Receives authentication information and performs analysis, matching, anomaly detection, dynamic security rule generation, and sentiment analysis using the sentiment engine.
[1647] Emotion Engine: An engine that analyzes emotions based on user input and behavioral patterns, and adjusts security rules based on the analysis results.
[1648] Program processing explanation
[1649] Collection and transmission of authentication information and emotional data
[1650] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., the type of device used and browser information), access time, and emotional data (e.g., emotional state using facial recognition and text analysis). The device encrypts this information and sends it to the server.
[1651] Authentication process on the server
[1652] The server performs basic authentication by checking the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1653] Analysis of additional conditions and anomaly detection
[1654] After successful authentication, the server analyzes the additional authentication information (location and device information). It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[1655] Emotion analysis using an emotion engine
[1656] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the server detects that the user is clearly impatient, it can determine that the security risk is high.
[1657] Dynamic security rule generation
[1658] The server will then generate dynamic security rules based on the anomaly flags and emotion engine analysis, as needed, for example, a rule requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[1659] Enforcing additional authentication and access permissions
[1660] The user enters the authentication code into their device and sends it back to the server. The server checks the received authentication code and verifies its validity. If authentication is successful, access is permitted. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[1661] Specific examples
[1662] Access during normal times
[1663] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), access time, and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately allowing access.
[1664] Impact of abnormal access and emotional data
[1665] When a user attempts to access a company server from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new laptop), access time, and emotional data (impatience is detected), and sends these to the server. After the server successfully completes basic authentication, it flags an anomaly based on the location information, device information, and emotional data. This allows the server to generate dynamic security rules and request two-factor authentication. The user enters the authentication code, and the server finally verifies the authentication and allows access.
[1666] In this way, the system of the present invention realizes a dynamic and flexible security wall, and can adapt the security level according to the user's behavior and emotions.
[1667] The processing flow will be explained below.
[1668] Step 1:
[1669] A user attempts to access the system using a terminal, entering a user ID and password.
[1670] Step 2:
[1671] In addition to user IDs and passwords, the devices collect location information (e.g., IP addresses), device information (e.g., the type of device used and browser information), access times, and user emotional data (e.g., emotional state determined using facial recognition and text analysis).
[1672] Step 3:
[1673] The device encrypts all collected authentication information and sends it to the server.
[1674] Step 4:
[1675] The server performs basic authentication by checking the received user ID and password against the information in its database. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1676] Step 5:
[1677] After successful authentication, the server analyzes the additional authentication information (location and device information), compares it with past access history, and evaluates the degree of match.
[1678] Step 6:
[1679] The server will flag any location or device information that differs from previous databases as an anomaly, such as a sudden change in location or the use of a new device.
[1680] Step 7:
[1681] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the emotion of the user based on facial recognition data and input text, and incorporates the results into security decisions.
[1682] Step 8:
[1683] Based on the analysis results of the emotion engine, the server determines that additional security is necessary if the emotional state is abnormal (e.g., a sense of irritation is detected).
[1684] Step 9:
[1685] The server generates dynamic security rules based on the anomaly flags and the results of the emotion engine, including requiring two-factor authentication (2FA).
[1686] Step 10:
[1687] As part of two-factor authentication, the server sends a verification code to the user's registered email address or mobile phone number.
[1688] Step 11:
[1689] The user enters the received authentication code into the terminal and sends it to the server.
[1690] Step 12:
[1691] The server receives the entered authentication code and verifies its validity. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1692] Step 13:
[1693] The server finally decides whether to grant access based on the results of analyzing the authentication information, additional authentication information, and emotion data. If access is granted, the user is allowed to access the resource. If access is denied, the reason is presented to the user.
[1694] In this way, by realizing a dynamic and flexible security wall, the present invention can adapt the security level according to the user's behavior and emotions, thereby providing higher safety.
[1695] Example 2
[1696] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1697] In recent years, the increasing sophistication and diversification of cyber attacks has led to the problem that traditional, fixed security measures are insufficient. In particular, with the spread of remote work, the increase in access from new devices and new locations has further increased security risks. To address this, a dynamic and flexible security system is required.
[1698] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.
[1699] In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for verifying the collected authentication information in the server and performing authentication, means for analyzing the user's additional authentication information and detecting anomalies, means for collecting and analyzing sensor information including the user's emotional data, means for generating dynamic security rules based on the results of the emotional analysis and when an anomaly is detected, and for requesting additional authentication, and means for ultimately determining whether to permit or deny access. This makes it possible to apply dynamic security measures according to the user's behavior and emotions.
[1700] "User authentication information" refers to information, such as a user ID and password, used to identify a user and authorize access to the system.
[1701] A "server" is a computer system that operates on a network and processes, stores, and transmits data it receives.
[1702] "Verification" is the process by which the server compares the authentication information it receives with its internal database to see if there is a match.
[1703] "Additional authentication information" is data collected in addition to basic authentication information, such as location information and device information.
[1704] An "anomaly" is the detection of an unusual pattern, such as new location information or device information, compared with past normal access history.
[1705] "Dynamic security rules" are rules for security measures that are generated in real time and are flexibly changed according to the situation that arises.
[1706] "Additional authentication" means additional security verification procedures performed on top of basic authentication, such as two-factor authentication (2FA).
[1707] "Emotion data" is information that indicates the user's emotional state, and includes facial recognition data, text analysis results, and the like.
[1708] "Sensor information" is digital data collected from a user's devices and environment, and includes emotional data, location information, device information, and more.
[1709] The system of the present invention strengthens security by using an authentication process based on user credentials, additional authentication information, and an emotion engine to provide a dynamic security wall, which can dynamically apply security measures according to the user's behavior and emotions.
[1710] System configuration
[1711] The system of the present invention includes the following major components:
[1712] User device: The device from which the user attempts access, where authentication information and emotional data are collected.
[1713] Server: Receives authentication information and performs analysis, matching, anomaly detection, dynamic security rule generation, and sentiment analysis using the sentiment engine.
[1714] Emotion engine: An engine that analyzes emotions based on user input and behavioral patterns, and adjusts security rules based on the analysis results.
[1715] Program processing explanation
[1716] Collection and transmission of authentication information and emotional data
[1717] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., the type of device being used and browser information), access time, and emotional data (e.g., emotional state using facial recognition and text analysis). The device encrypts this information and sends it to the server.
[1718] Authentication process on the server
[1719] The server checks the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1720] Analysis of additional conditions and anomaly detection
[1721] After successful authentication, the server analyzes the additional authentication information (location and device information). It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[1722] Emotion analysis using an emotion engine
[1723] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the server detects that the user is clearly impatient, it can determine that the security risk is high.
[1724] Dynamic security rule generation
[1725] The server will then generate dynamic security rules based on the anomaly flags and emotion engine analysis, as needed, for example, a rule requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[1726] Enforcing additional authentication and access permissions
[1727] The user enters the authentication code into their device and sends it back to the server. The server checks the received authentication code and verifies its validity. If authentication is successful, access is permitted. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[1728] Specific examples
[1729] Access during normal times
[1730] When a user attempts to access a company server from a home PC, the device collects the user ID, password, location information (home IP address), device information (home PC), access time, and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately allowing access.
[1731] Impact of abnormal access and emotional data
[1732] When a user attempts to access a company server from a hotel while on a business trip, the terminal collects and sends the user ID, password, location information (hotel IP address), device information (new laptop), access time, and emotional data (impatience detected) to the server. After the server successfully completes basic authentication, it flags an anomaly based on the location information, device information, and emotional data. This allows the server to generate dynamic security rules and request two-factor authentication. The user enters the authentication code, and the server finally verifies the authentication and allows access. In this way, the system of the present invention realizes a dynamic and flexible security wall, adapting the security level according to the user's behavior and emotions.
[1733] Examples of prompts for generative AI models
[1734] To develop a security system, please create a prompt like this: Explain how you would detect anomalies and require additional security procedures when a user attempts to log in from a new device.
[1735] The flow of the identification process in the second embodiment will be described with reference to FIG.
[1736] Step 1:
[1737] Collection and transmission of authentication information and emotional data
[1738] A user attempts to log in to a system using a terminal. The user enters their user ID and password on the login screen. Based on the input, the terminal collects location information (IP address), device information (device type, OS version, browser version), access time, and emotional data (facial expressions using a facial recognition camera, and the emotional state of the input text using text analysis). This data is encrypted using TLS / SSL and sent to the server.
[1739] input:
[1740] User ID, password, location information, device information, access time, emotional data (face recognition, text analysis)
[1741] output:
[1742] Encrypted credentials and sentiment data
[1743] Specific behavior:
[1744] The user enters their login information into a browser or dedicated application. The device then runs location information, a facial recognition camera, and a text analysis engine to collect the necessary data. This data is then encrypted using TLS / SSL and sent to the server according to the transmission protocol.
[1745] Step 2:
[1746] Authentication process on the server
[1747] The server receives the encrypted authentication information sent from the terminal and decodes the data. The server compares the decoded user ID and password with its internal database to perform authentication. If authentication is successful, the server proceeds to the next processing step. If authentication fails, the server denies access and returns an error message to the user.
[1748] input:
[1749] Encrypted user ID and password
[1750] output:
[1751] Authentication success or failure flag, error message on failure
[1752] Specific behavior:
[1753] The server receives the encrypted data based on the TLS / SSL protocol. It decodes the user ID and password and queries the database. If authentication is successful, it sets an authentication success flag and proceeds to the next step. If authentication fails, it generates a detailed error message and sends it to the user.
[1754] Step 3:
[1755] Analysis of additional conditions and anomaly detection
[1756] After successful authentication, the server analyzes the location and device information sent. It compares it with past access history and evaluates the degree of match to detect anomalies. If new location or device information is detected, it flags it as an anomaly.
[1757] input:
[1758] Location information, device information, past access history
[1759] output:
[1760] Anomaly detection flag, match evaluation result
[1761] Specific behavior:
[1762] The server uses the location information to determine the user's geographic location and compares it with past access records. An algorithm evaluates the degree of match and flags any anomalies. For example, if a new IP address or device is detected, an anomaly flag will be raised.
[1763] Step 4:
[1764] Emotion analysis using an emotion engine
[1765] The server activates an emotion engine and analyzes the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if the user shows signs of impatience, the server reassess the security risk based on that information.
[1766] input:
[1767] Facial recognition data, text analysis data
[1768] output:
[1769] Sentiment analysis results, security risk assessment results
[1770] Specific behavior:
[1771] The server uses an emotion engine (e.g., facial recognition API or text analysis API) to analyze the received data, record the determined emotional state, and incorporate it into the overall security risk assessment.
[1772] Step 5:
[1773] Dynamic security rule generation
[1774] The server generates the necessary dynamic security rules based on the anomaly flags and the analysis results of the emotion engine. For example, if the security risk is determined to be high, it will request two-factor authentication (2FA) and send an additional authentication code to the user according to the rules.
[1775] input:
[1776] Anomaly flags, sentiment analysis results, security policies
[1777] output:
[1778] Dynamic security rules, 2FA authentication codes
[1779] Specific behavior:
[1780] The server evaluates anomaly flags and sentiment analysis results to determine dynamic security measures. If additional measures such as two-factor authentication are required, an authentication code is sent to the user's registered contact method (e.g., SMS, email).
[1781] Step 6:
[1782] Enforcing additional authentication and access permissions
[1783] The user enters the authentication code into the device. The device sends the code to the server. The server checks the validity of the authentication code, and if authentication is successful, access is permitted. If authentication is unsuccessful, access is denied, and the reason is displayed to the user.
[1784] input:
[1785] Authentication code, server-generated code
[1786] output:
[1787] Access or deny decision, reason message
[1788] Specific behavior:
[1789] The user enters the received authentication code into the terminal and sends it. The server compares the received authentication code with the internally generated code. If they match, it flags access as allowed and proceeds to the next step. If they do not match, it generates an access denied message and notifies the user.
[1790] (Application example 2)
[1791] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1792] Conventional authentication systems are based only on static user authentication information (e.g., user ID and password) and fixed additional authentication information (e.g., location information, device information), making it difficult to improve security. Furthermore, these systems have the problem of not being able to fully detect abnormal access because they do not take into account the user's mental or emotional state. This makes unauthorized access and security breaches more likely to occur.
[1793] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting user authentication information, means for transmitting the authentication information to the server, means for verifying the collected authentication information at the server and performing authentication, and means for analyzing the user's additional authentication information and detecting anomalies. It also includes means for analyzing the user's emotional state as the user's additional authentication information, and means for generating dynamic security rules and requesting additional authentication when an anomaly is detected and based on the emotional state. This enables more advanced and dynamic security measures.
[1794] "Authentication information" refers to information such as ID and password provided by a user when accessing a system.
[1795] "Emotional state" is data that indicates the user's psychological and emotional state, and is obtained from facial recognition data and input text.
[1796] "Location information" refers to geographical information based on the IP address of the device from which the user is accessing the site.
[1797] "Device information" refers to the type and identification information of the device used by the user.
[1798] "Dynamic security rules" are rules for security measures that are generated in real time depending on the situation, and include, for example, requirements for two-factor authentication.
[1799] "Additional authentication" is an additional authentication method performed in addition to basic authentication, and is based on location information, device information, or emotional state.
[1800] "Two-factor authentication" is a method that requires a second authentication method (e.g., SMS code or email code) in addition to the user's ID and password when accessing a system.
[1801] "Anomaly detection" is the detection of access attempts or behavior that is unusual or considered fraudulent.
[1802] The present invention is a system that uses user authentication information and emotion data to apply dynamic security rules and prevent abnormal access. A specific embodiment for realizing this system is shown below.
[1803] System configuration
[1804] The system of the present invention includes the following major components:
[1805] 1. User device: A device such as a smartphone or PC that collects user authentication information and emotional data. It includes a facial recognition camera, a GPS for acquiring location information, and software for acquiring device information.
[1806] 2. Server: Receives authentication information and performs parsing, matching, anomaly detection, dynamic security rule generation, and emotion analysis using the emotion engine. It uses Python, OpenCV, the face_recognition library, and the emotion_recognition module.
[1807] 3. Emotion engine: An engine that analyzes emotions based on user input and behavioral patterns, for example, using Python's emotion_recognition module.
[1808] Program processing flow
[1809] 1. Collection and transmission of authentication information and emotional data
[1810] When a user attempts to access the system using a device, the device collects the user ID and password, as well as location information (e.g., IP address), device information (e.g., device type and browser information), and emotional data (e.g., facial recognition data and emotional state analyzed from input text).
[1811] The collected data is encrypted and sent to a server.
[1812] 2. Authentication process on the server
[1813] The server performs basic authentication by checking the user ID and password against the database based on the authentication information received. If authentication is successful, it proceeds to the next step. If it fails, it denies access and returns an error message to the user.
[1814] 3. Analysis of additional conditions and anomaly detection
[1815] After successful authentication, the server analyzes the additional authentication information (location and device information) and compares it with past access history. It detects anomalies by evaluating the degree of match and flags any new location or device information as an anomaly.
[1816] 4. Emotion analysis using an emotion engine
[1817] The server uses an emotion engine to analyze the emotion data sent from the device. The emotion engine determines the user's emotion from facial recognition data and input text, and incorporates the results into security decisions. For example, if a sense of impatience is detected, it will be determined that there is a high security risk.
[1818] 5. Dynamic Security Rule Generation
[1819] The server generates dynamic security rules based on the anomaly flags and emotion engine analysis, such as requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[1820] 6. Performing additional authentication and granting access
[1821] The user enters the authentication code into their device and sends it back to the server. The server then checks the validity of the received authentication code, and if authentication is successful, allows access. If authentication is unsuccessful, access is denied and the reason is displayed to the user.
[1822] Specific examples
[1823] Example 1: Access during normal times
[1824] When a user accesses the system from a home device, the device collects the user ID, password, location information (home IP address), device information (home device), and emotional data (normal state), and sends them to the server. The server then successfully authenticates the user and determines that the additional conditions are also normal, immediately granting access.
[1825] Example 2: Abnormal access
[1826] When a user accesses the system from a hotel while on a business trip, the device collects the user ID, password, location information (hotel IP address), device information (new device), and emotional data (anxiety is detected), and sends them to the server. After the server successfully completes basic authentication, it detects an anomaly and generates a dynamic security rule to request two-factor authentication. The user enters the authentication code sent, and the server finally verifies the authentication, after which access is granted.
[1827] Example prompts to input to the generative AI model
[1828] An example of a prompt to input to the generative AI model is, "Describe an application that applies dynamic security rules based on authentication information and sentiment analysis data when a user accesses their account."
[1829] As a result, the system of the present invention can provide more advanced and flexible security measures and realize a security mechanism that is adaptable to the user's behavior and emotions.
[1830] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[1831] Step 1:
[1832] The user starts up the device and accesses the authentication screen. The device prompts the user to enter their ID and password. The entered data is temporarily stored on the device.
[1833] input:
[1834] The ID and password entered by the user.
[1835] output:
[1836] Saved IDs and passwords.
[1837] Operation:
[1838] The terminal receives the user's ID and password from the input form and stores them in memory.
[1839] Step 2:
[1840] The device activates the camera and recognizes the user's face. The facial recognition data is acquired and emotion analysis is performed using the emotion engine. The analyzed emotion data is also temporarily stored on the device.
[1841] input:
[1842] Video data from the camera.
[1843] output:
[1844] Facial recognition data and analyzed emotion data.
[1845] Operation:
[1846] The device captures video from the camera, applies a facial recognition algorithm to obtain facial data, then uses the emotion_recognition module to perform emotion analysis and save the results.
[1847] Step 3:
[1848] The device collects location information and device information. Location information is obtained from the GPS sensor and IP address, and device information is obtained from the device type and browser information.
[1849] input:
[1850] GPS sensor or IP address, device information.
[1851] output:
[1852] Location and Device Information.
[1853] Operation:
[1854] The device obtains location information from the IP address via a GPS sensor or the network, and collects device information such as device type and browser information.
[1855] Step 4:
[1856] The device encrypts the collected data (ID, password, facial recognition data, emotional data, location information, device information) and sends it to the server.
[1857] input:
[1858] ID, password, facial recognition data, emotional data, location information, device information.
[1859] output:
[1860] Encrypted data.
[1861] Operation:
[1862] The device securely encrypts all collected data and transmits it over the network to a server.
[1863] Step 5:
[1864] The server checks the ID and password from the received data and performs basic authentication. It checks against the database, and if it is correct, it proceeds to the next step. If it is invalid, it immediately returns a message to the terminal denying access.
[1865] input:
[1866] Encrypted ID and password.
[1867] output:
[1868] The authentication result (success or failure).
[1869] Operation:
[1870] The server decrypts the data and checks the user ID and password against the information in its database. Depending on the result, it either proceeds to the next processing step or denies access.
[1871] Step 6:
[1872] The server analyzes the additional authentication information (location information, device information) and compares it with past access history to evaluate the degree of match and detect any abnormalities.
[1873] input:
[1874] Location information, device information, and past access history.
[1875] output:
[1876] Abnormal flag (abnormal or normal).
[1877] Operation:
[1878] The server compares the location and device information with past access history to assess the degree of match, and based on this assessment, detects any anomalies and sets an anomaly flag.
[1879] Step 7:
[1880] The server uses an emotion engine to analyze the emotion data sent from the device and incorporates the results into security decisions. For example, if a sense of impatience is detected, it will be determined that the security risk is high.
[1881] input:
[1882] Emotional data.
[1883] output:
[1884] Sentiment analysis result (normal or abnormal).
[1885] Operation:
[1886] The server uses the emotion_recognition module to analyze the emotional data and evaluate the security risk based on the results.
[1887] Step 8:
[1888] The server generates dynamic security rules based on anomaly flags and sentiment analysis results, as needed, such as requiring two-factor authentication (2FA) and prompting the user to enter an additional authentication code.
[1889] input:
[1890] Abnormal flags, sentiment analysis results.
[1891] output:
[1892] Dynamic security rules (e.g. requiring 2FA).
[1893] Operation:
[1894] The server generates dynamic security rules based on the anomaly flags and sentiment analysis results, and if necessary, requests additional authentication procedures from the user.
[1895] Step 9:
[1896] The user receives the authentication code sent from the server, enters it again into the terminal, and sends it to the server.
[1897] input:
[1898] Authentication code.
[1899] output:
[1900] The final authentication result (success or failure).
[1901] Operation:
[1902] The user enters the authentication code received from the server into the terminal and sends it to the server, which then checks the received authentication code to verify its validity.
[1903] Step 10:
[1904] If the authentication is successful, the server sends a message to the terminal permitting access. If the authentication is unsuccessful, the server returns a message indicating the reason for denial of access to the terminal.
[1905] input:
[1906] Final authentication result.
[1907] output:
[1908] An access allowed or denied message.
[1909] Operation:
[1910] Based on the final authentication result, the server sends a message to the terminal permitting access if successful, or a message including the reason for denial of access if unsuccessful.
[1911] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.
[1912] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[1913] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the robot 414.
[1914] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[1915] FIG. 9 illustrates an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and behaviors arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion includes both affect and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.
[1916] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.
[1917] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).
[1918] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. Emotions can also be created for robots, automobiles, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on Voice Emotion Recognition and Emotional Brain Physiological Signal Analysis Systems, Tokushima University, Doctoral Dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the "reaction" domain, where sensation is dominant. The right half of the emotion map lists emotions belonging to the "situation" domain, where situational awareness is dominant.
[1919] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."
[1920] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion va...
Claims
1. a means for collecting user authentication information; means for transmitting the authentication information to a server; A means for verifying the authentication information of the user collected by the server and performing authentication; means for analyzing additional authentication information of a user and detecting an abnormality based on the additional authentication information; means for generating dynamic security rules and requiring additional authentication when the anomaly is detected; The means by which the final decision is made to grant or deny access; and A system including:
2. The system of claim 1 , wherein the additional authentication information includes location information and device information.
3. The system of claim 1 , wherein the dynamic security rules include two-factor authentication.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A