Document sharing and management
The method addresses inefficiencies in document sharing by managing access and confidentiality at the component level, ensuring secure and efficient information sharing based on relevance and trust calculations.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- KYNDRYL INC
- Filing Date
- 2025-01-31
- Publication Date
- 2026-04-30
Smart Images

Figure 2026072045000001_ABST
Abstract
Description
Technical Field
[0004] , ,
[0001] The present invention relates to a computer system, and more particularly, to a method executed by a computer configured and arranged to share documents, a computer system, and a computer program product.
Background Art
[0002] Various systems for securely sharing documents have been proposed. For example, Patent Document 1 discloses a system having a backup infrastructure for preventing loss or modification of documents.
[0003] Many systems for managing document sharing manage the granting of access rights to documents to users in order to suppress the disclosure of secrets due to document sharing. For example, depending on the department or project organization to which a user belongs within an organization, the documents that the user can access are determined.
[0004] Conventional access management of documents is performed on the entire document. Therefore, even if the part that the user needs is a part that does not contain secrets in the document, if the user does not have access rights to this document, the user cannot access any part of the document. Also, although departments and project organizations change dynamically, the dynamic change of access rights accompanying these changes is complicated and often cannot be responded to in a timely manner. Therefore, appropriate sharing of the information contained in the document may not be possible.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
[0006] This summary is provided to introduce in a simplified form the selection of concepts further described below in modes for carrying out the invention. This summary is not intended to identify any important or essential features of the claimed subject matter, nor is it intended to be used as an aid in determining the scope of the claimed subject matter.
[0007] In one or more embodiments, a method for managing document sharing includes: receiving a search request using a search query entered by a user into a client device by one or more processors; determining the degree of relevance between each part of a document stored in a document database and the search query; determining a candidate part to be shared that is part of the document based on the degree of relevance; determining that at least one of the candidate parts to be shared is a part to be shared, separating the part to be shared from the document and storing it in a non-volatile storage area; and managing the granting of access rights to the part to be shared to the user.
[0008] As a technical effect and benefit, because searching and access management are performed at the component / component level of the document, it is possible to share the information contained in the document appropriately and efficiently.
[0009] In addition to or alternative to one or more of the features described above or below, further embodiments disclose that the method may include calculating a risk level indicating the degree of confidentiality contained in a shared candidate part, based on an analysis of the information contained in the shared candidate part by one or more processors.
[0010] As a technical effect and benefit, the degree of confidentiality contained in the candidate parts to be shared can be quantified, allowing this degree of confidentiality to be reflected in the management of document sharing.
[0011] In addition to or alternative to one or more of the features described above or below, further embodiments disclose that the method may include, by one or more processors, calculating a confidence level indicating the degree of trust the administrator has in the user, by referring to log data of communications between the user and the administrator of a document containing the candidate shared parts using a communication tool.
[0012] As a technical effect and benefit, the degree of administrator trust in users can be quantified, allowing this level of trust to be reflected in the management of document sharing.
[0013] In addition to or alternative to one or more of the features described above or below, further embodiments disclose that calculating the reliability level may include determining the frequency of communication between the user and the administrator based on log data, and calculating the reliability level using at least the communication frequency.
[0014] One of the technical benefits and advantages is the ability to accurately calculate reliability levels. In addition to or alternative to one or more of the features described above or below, further embodiments disclose that calculating the reliability level may include determining the communication time between the user and the administrator based on log data, and using at least the communication time to calculate the reliability level.
[0015] As a technical effect and advantage, this method allows for the accurate calculation of reliability levels. In addition to or alternative to one or more of the features described above or below, further embodiments disclose that calculating the reliability level may include estimating the emotions of at least one of the user and the administrator during communication between the user and the administrator based on log data, and calculating the reliability level using data indicating at least the estimated emotions.
[0016] As a technical effect and advantage, this method improves the accuracy of calculating reliability levels. In addition to or alternative to one or more of the features described above or below, further embodiments of the method may include, by one or more processors, calculating risk levels and reliability levels of shared candidate parts, and generating data for displaying search results by determining, based on the risk levels and reliability levels, information about the shared candidate parts to be included in the display of search results for a search request.
[0017] As a technical effect and benefit, the information included in the search results is determined by considering not only the content of the shared candidate parts but also the relationship between the user and the administrator, thus enabling appropriate information disclosure in the search results.
[0018] In addition to or alternative to one or more of the features described above or below, further embodiments disclose that generating data for displaying search results may include generating data for displaying search results with more information about shared candidate parts to be included in the display of search results when the confidence level is greater than the risk level than when the confidence level is less than the risk level.
[0019] As a technical effect and benefit, the degree of confidentiality contained in the candidate shared parts and the degree of trust the administrator has in the users are quantitatively evaluated. When the level of confidentiality is high relative to the level of trust, more information is disclosed. Therefore, more appropriate information disclosure becomes possible.
[0020] In addition to or alternative to one or more of the features described above or below, further embodiments disclose that generating data for displaying search results may include generating data for displaying search results without including information about shared candidate parts in the display of search results when the confidence level is at its lowest value.
[0021] As technical effects and technical advantages, when the trust of the administrator in the user is extremely low, information on candidate shared parts is not disclosed, thus preventing the disclosure of information. In addition to, or as an alternative to, one or more of the features described above or below, a further embodiment discloses that generating data for displaying search results may include generating data for displaying search results without including information on candidate shared parts when the risk level is at its maximum value.
[0022] As technical effects and technical advantages, when the confidentiality included in candidate shared parts is high (at a predefined level), information on candidate shared parts is not disclosed, thus preventing the disclosure of information.
[0023] In addition to, or as an alternative to, one or more of the features described above or below, a further embodiment discloses that the method further includes calculating the risk level and reliability level of candidate shared parts by one or more processors, and managing the granting of access rights to shared target parts for the user may include determining the scope of authority of the access rights granted to the user based on the risk level and the reliability level.
[0024] As technical effects and technical advantages, in addition to the content of the shared target parts, the relationship between the user and the administrator is also considered, and the user's access to the shared target parts is managed, so that appropriate information sharing is possible.
[0025] In addition to, or as an alternative to, one or more of the features described above or below, a further embodiment discloses that determining the scope of authority of the access rights granted to the user may include strengthening the authority when the reliability level is greater than the risk level compared to when the reliability level is less than the risk level.
[0026] As technical effects and technical advantages, the degree of confidentiality included in the parts to be shared and the degree of trust of the administrator in the user are quantitatively evaluated, and when the trust is large with respect to the confidentiality level, a higher degree of freedom of access is permitted. Therefore, more appropriate information sharing is possible.
[0027] In addition to or as an alternative to one or more of the above-described or below-described features, a further embodiment discloses that determining the scope of authority of the access right granted to the user may include not permitting the user to access the parts to be shared when the reliability level is at the lowest value.
[0028] As technical effects and technical advantages, when the trust of the administrator in the user is small (at a predefined level), the user cannot access the parts to be shared, thus preventing the disclosure of information.
[0029] In addition to or as an alternative to one or more of the above-described or below-described features, a further embodiment discloses that determining the scope of authority of the access right granted to the user may include not permitting the user to access the parts to be shared when the risk level is at the highest value.
[0030] As technical effects and technical advantages, when the confidentiality included in the parts to be shared is large (at a preset level in advance), the user cannot access the parts to be shared, thus preventing the disclosure of information.
[0031] In addition to or as an alternative to one or more of the above-described or below-described features, a further embodiment discloses that the method may include outputting a sharing link to the parts to be shared according to the determined scope of authority of the access right to a client device by one or more processors.
[0032] As technical effects and technical advantages, according to the above method, the access right according to the determination is accurately granted to the user. In addition to or alternative to one or more of the features described above or below, further embodiments disclose that the shared parts may be shared candidate parts designated by the user.
[0033] As a technical effect and benefit, compared to designating all candidate shared parts as shared parts, the processor load related to data partitioning and access permission settings is reduced.
[0034] Furthermore, this disclosure may take the form of a computer system or a computer program product usable by a computer or any programmable data processing device.
[0035] In this specification, the phrase "at least one of A and B" should be understood to mean "A only, or B only, or both A and B." Other features and embodiments will become apparent from the following detailed description, drawings, and claims. [Brief explanation of the drawing]
[0036] [Figure 1] Figure 1 shows the configuration of a document sharing system according to one embodiment. [Figure 2] Figure 2 is a flowchart showing the processing flow in the document sharing candidate determination function of the document sharing system according to the above embodiment. [Figure 3] Figure 3 is a flowchart showing the processing flow in the reliability calculation function of the document sharing system of the above embodiment. [Figure 4] Figure 4 is a flowchart showing the processing flow in the search result generation function of the document sharing system of the above embodiment. [Figure 5] Figure 5 is a flowchart showing the processing flow in the access management function of the document sharing system of the above embodiment. [Modes for carrying out the invention]
[0037] Throughout the drawings and detailed descriptions, the same reference numerals refer to the same elements, the drawings are not to a fixed scale, and the relative sizes, proportions, and depictions of elements in the drawings may be exaggerated for clarity, explanation, and convenience.
[0038] The embodiments for carrying out this invention provide a comprehensive understanding of the described methods, apparatus, and / or systems, and modifications and equivalents of the described methods, apparatus, and / or systems will be obvious to those skilled in the art. The sequence of operations is illustrative and can be modified as will be obvious to those skilled in the art, except for operations that necessarily occur in a particular order. Descriptions of functions and configurations that are well known to those skilled in the art may be omitted.
[0039] The exemplary embodiments may have different forms and are not limited to those described. However, the examples described are sufficiently detailed and complete that those skilled in the art can understand the full scope of this disclosure.
[0040] In this specification, the phrase "at least one of A and B" should be understood to mean "A only, or B only, or both A and B." One aspect of this disclosure includes determining the degree of relevance between each part of a document stored in a document database and a search query, determining a candidate shared part that is part of the document based on this relevance, extracting / splitting the shared part from the document and storing it in non-volatile storage for at least one of the candidate shared parts, and managing the granting of access rights to the shared part to users.
[0041] Another aspect of this disclosure includes calculating a confidence level that indicates the degree of trust the document administrator has in users requesting document sharing, and, based on the confidence level, determining the information to include in search results and the scope of access permissions to grant users.
[0042] An exemplary configuration of a document sharing system is presented. An embodiment of the document sharing system will be described with reference to the drawings. As shown in Figure 1, one embodiment of the document sharing system 100 includes a sharing management system 10 and one or more client devices 20.
[0043] The shared management system 10 is a system composed of one or more computers. The shared management system 10 may be, for example, a server such as a file server, a database server, or a mail server, a personal computer, or a combination of these.
[0044] The shared management system 10 manages the sharing of documents owned / stored by an organization. An organization is a group formed to achieve a specific purpose. An organization may be various types of groups, such as a company or a government agency. An organization may engage in profit-making or non-profit activities. An organization may be a group involved in economics, administration, education, academia, sports, culture, health, welfare, the environment, etc.
[0045] Documents held by an organization may be electronic documents containing text data. Documents may also contain image data. Documents may include, for example, proposals, design specifications, instruction manuals, service delivery procedures, and project management documents. Documents may be files created using word processing software, presentation software, or spreadsheet software. Documents may also be online documents created using the functions of collaboration tools. The file format and form of documents are not particularly limited.
[0046] A document consists of multiple parts. A part might be, for example, a page, a slide, or a sheet within the document. A part can also be defined by any arbitrary division.
[0047] In other examples, if the document is a document file, units such as chapters and sections defined by the table of contents may also be units / divisions of parts. In the case of online documents, the document may be divided into multiple parts based on the attributes of heading characters or specific keywords. Specific keywords may include, for example, keywords indicating a change in the text, such as "about".
[0048] Thus, the division points of parts within a document can be made variable depending on the specifications and characteristics of the document in question. Client device 20 is a computer operated by a user requesting document sharing. The user is a member of an organization. Client device 20 may be, for example, a personal computer, a tablet device, a smartphone, etc.
[0049] The shared management system 10 and the client device 20 are connected via a network. The network may be a local area network, a wide area network, any other type of network, or a combination thereof. The network may also be a wireless network, a wired network, or a combination thereof.
[0050] The hardware configuration of the shared management system 10 and the client device 20 will be described. The shared management system 10 comprises one or more processors 11, one or more memory 12, one or more storage 13, and one or more communication units 14. For convenience, the following example describes a shared management system 10 comprising one processor 11, one memory 12, one storage 13, and one communication unit 14.
[0051] Storage 13 stores the program 15 and the database 16. At least a portion of the program 15 and the database 16 may be stored in memory 12. The processor 11 executes the program 15 loaded into the memory 12. The program 15 is configured so that the shared management system 10 implements various functions described in one or more embodiments. These functions include a shared candidate determination function, a reliability calculation function, a search result generation function, and an access management function. The program 15 may include program modules that cause the processor 11 to execute processing corresponding to each function.
[0052] The communication unit 14 enables communication between the shared management system 10 and other devices, including the client device 20, via the network. The client device 20 comprises one or more processors 21, one or more memories 22, one or more storage devices 23, one or more communication units 24, one or more input devices 25, and one or more displays 26. For convenience, the following example describes a client device 20 comprising one processor 21, one memory 22, one storage device 23, one communication unit 24, one input device 25, and one display 26.
[0053] Storage 23 stores application 27. At least a portion of application 27 may be stored in memory 22. Application 27 includes programs and data that enable client devices 20 to implement functions for using the shared management system 10. The functions of application 27 include functions for searching for and requesting the sharing of documents from the shared management system 10, and functions for displaying responses from the shared management system 10. The processor 21 performs processing corresponding to these functions by executing application 27.
[0054] The communication unit 24 enables communication between the client device 20 and other devices, including the shared management system 10, via the network. The input device 25 receives user input and outputs a signal corresponding to the input to the processor 11. The input device 25 may be, for example, a keyboard, mouse, or touch panel. The display 26 displays information such as characters and images based on signals and data from the processor 11. The display 26 may be, for example, a panel or monitor using liquid crystal or organic electroluminescence.
[0055] The processors 11,21 may include, but are not limited to, other processors including CPUs (central processing units), GPUs (graphics processing units), APUs (accelerated processing units), NPUs (neural network processing units), microprocessors, microcontrollers, DSPs (digital signal processors), FPGAs (field programmable gate arrays), CPLDs (complex programmable logic devices), application-specific integrated circuits (ASICs), general-purpose processors, or any combination thereof designed to perform the functions described herein.
[0056] The memories 12, 22 and the storages 13, 23 are computer-readable storage media, including non-transitory computer-readable media. Computer-readable storage media are tangible devices capable of holding or storing instructions for use by a processor. Computer-readable storage media may include, but are not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any preferred combination thereof. Computer-readable storage media as used herein should not be interpreted as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating within waveguides or other transmission bodies, or electrical signals transmitted through wires.
[0057] Memory 12,22 includes RAM (random access memory). Memory 12,22 may include volatile or non-volatile computer-readable storage media that function as main memory or cache memory.
[0058] Storage 13, 23 includes non-volatile computer-readable storage media. Storage 13, 23 may include, but are not limited to, ROM (read-only memory), SSD (solid-state drive), HDD (hard disk drive), flash memory, memory card, optical media, magneto-optical media, removable media, CD-ROM, or combinations thereof.
[0059] The communication units 14, 24 may include, for example, a TCP / IP adapter card, a wireless LAN interface card or antenna, a cellular network interface card, or other wired or wireless network adapters or interfaces.
[0060] Furthermore, both the shared management system 10 and the client device 20 may be equipped with various data transmission paths, such as buses, to connect the components of the devices. The shared management system 10 may also be equipped with input devices and displays.
[0061] Several examples of the shared candidate selection function are presented. Refer to Figure 2 to explain the processes performed in the shared candidate selection function. As shown in Figure 2, the processor 11 of the shared management system 10 receives a request to search for documents from the client device 20 (step S10).
[0062] In detail, a user requesting document sharing operates the input device 25, thereby inputting a search query into the client device 20. Based on this, a search request, along with the search query, is sent from the client device 20 to the sharing management system 10. The search query may be a keyword. Furthermore, the search query may be a phrase or sentence expressed in natural language. The user only needs to input a search query related to the content of the document they wish to share into the client device 20.
[0063] Upon receiving a search request, the processor 11 determines whether the search query is a keyword (step S11). If the search query is not a keyword, the processor 11 extracts a keyword from the search query using natural language processing (step S12). Any known technique can be used for natural language processing.
[0064] The processor 11 uses the keyword that is the search query, or the keyword extracted from the search query, to extract one or more documents related to the keyword from the set of documents contained in the document database 17 (step S13). The extracted documents are the documents to be processed, i.e., the target documents.
[0065] The document database 17 stores data on documents owned by the organization. Each document is assigned attribute data. This attribute data includes administrator data, which indicates the document's administrator. The administrator may be a member of the same organization as the users who wish to share the document. The administrator may, for example, be the creator or owner of the document. The document database 17 may be contained within database 16 or an external device.
[0066] Any publicly known technology may be used for the search process. Furthermore, the search query is not limited to text strings. The search query may include images in addition to or instead of text strings.
[0067] The processor 11 calculates the degree of relevance and risk level with respect to the search query for each part of the document to be processed, i.e., the target document (step S14). The degree of relevance indicates the degree of relationship between the content of the part and the search query. If the search query is a string, the degree of relevance indicates the degree of relationship between the content of the part and the keyword. The degree of relevance is calculated using a numerical value, such as a coefficient. Any known method can be used to calculate the degree of relevance. For example, the processor 11 increases the degree of relevance the higher the frequency of keyword occurrences in the text contained in the part of the target document.
[0068] The risk level indicates the degree of confidentiality contained in the contents of the part. Processor 11 calculates the risk level based on an analysis of the information contained in the part. For example, the processor 11 increases the risk level the more specific the information contained in the part, such as personal information, price information, and confidential information. Publicly known methods may be used to calculate the risk level. For example, indicators showing data anonymity such as k-anonymity, I-diversity, k-map, and δ-existence can be used to calculate the risk level. Furthermore, processor 11 may calculate the risk level based on a determination of whether pre-set keywords or information are contained in the part.
[0069] The processor 11 selects shared candidate parts, which are parts of the document that are candidates for sharing, based on their relevance, and outputs shared candidate information (step S15). For example, the processor 11 designates parts with a relevance of 1 or more that is above a predetermined value as shared candidate parts. The shared candidate information includes the risk level of the shared candidate parts. The processor 11 may assign data containing the shared candidate information as attribute data to the shared candidate parts. Note that the calculation of the risk level may be performed only for the shared candidate parts after the shared candidate parts have been determined.
[0070] An example of a reliability calculation function will be explained. Refer to Figure 3 to explain the processes performed in the reliability calculation function. As shown in Figure 3, after determining the candidate shared parts, the processor 11 obtains user data indicating the user who requested the search and administrator data for the target document containing the candidate shared parts (step S20).
[0071] User data is data that uniquely identifies a user within an organization, and may include, for example, a user's identification number or email address. Processor 11 can obtain user data through access from client device 20. Administrator data is data that uniquely identifies an administrator within an organization, and may include, for example, an administrator's identification number or email address. Processor 11 can obtain administrator data from document attribute data.
[0072] The processor 11 calculates the reliability level by referring to the communication database 18 based on user data and administrator data (step S21). The communication database 18 contains log data of communication tools used by the organization. Communication tools include, for example, email, chat, and other collaboration tools. The communication database 18 may be contained in database 16 or an external device.
[0073] The reliability level indicates the degree of trust the administrator has in the user. The processor 11 obtains user identification information (as indicated by user data) and the history of communication with the administrator (as indicated by administrator data) from the log data of the communication database 18, and calculates the reliability level by analyzing this history and evaluating the density of communication.
[0074] For example, the processor 11 can determine the frequency and duration of communication between the user and the administrator from the communication history. Then, the processor 11 can calculate the reliability level using at least one of the communication frequency and / or communication duration.
[0075] Furthermore, the processor 11 may use natural language processing to estimate the emotions of at least one of the users and / or administrators during communication from the text data, which is the history of communication. A machine learning model can be used to estimate emotions. The processor 11 can then calculate a reliability level using the emotion data, which is numerical data or other data indicating the estimated emotions. For example, the reliability level may be a function of three variables: communication frequency, communication time, and emotion data.
[0076] The reliability level is calculated using a scale comparable to the risk level. For example, both the reliability level and the risk level may be expressed as numerical values within the range of 0 to 1.0 after normalization.
[0077] An example of a search result generation function is presented. Refer to Figure 4 to explain the processes performed in the search result generation function. As shown in Figure 4, for each shared candidate part, the processor 11 determines the information to be displayed as a search result based on the risk level and reliability level contained in the shared candidate information (step S30).
[0078] In detail, when the reliability level is greater than the risk level, the processor 11 includes more information about the shared candidate part in the search results than when the reliability level is less than the risk level. The information about the shared candidate part may include attribute information of the shared candidate part and attribute information of the target document containing the shared candidate part.
[0079] Specifically, for example, if the reliability level is greater than the risk level, the processor 11 includes the attribute information of the shared candidate part and the attribute information of the target document containing the shared candidate part in the display of the search results. If the reliability level is less than the risk level, the processor 11 includes the attribute information of the document containing the shared candidate part in the display of the search results, but does not include the attribute information of the shared candidate part in the display of the search results.
[0080] The attribute information of the shared candidate part is, for example, an overview of the shared candidate part. The overview of the shared candidate part may be, for example, an excerpt of the part containing keywords, and may be created by the processor 11. The attribute information of the document is, for example, the document title and administrator. The attribute information of the document may be information included in the attribute data assigned to the document.
[0081] The processor 11 may increase the amount of information about shared candidate parts included in the search results display as the reliability level increases relative to the risk level. Furthermore, if the reliability level is at a predetermined minimum value, such as when the reliability level is 0, the processor 11 does not need to include information about shared candidate parts in the search results display, regardless of the risk level. In other words, information about shared candidate parts with an extremely low reliability level (a predetermined level) is not output as a search result. The processor 11 does not need to include information about shared candidate parts in the search results display when the reliability level is below a predetermined value, including when the reliability level is at its minimum value.
[0082] Furthermore, if the risk level is at a predetermined maximum value, such as when the risk level is 1.0, the processor 11 does not need to include information about shared candidate parts in the search results display, regardless of the reliability level. In other words, information about shared candidate parts with an extremely high risk level (a predetermined level) is not output as a search result. The processor 11 does not need to include information about shared candidate parts in the search results display when the risk level is at or above a predetermined value, including when the risk level is at its maximum value.
[0083] The processor 11 generates data for displaying the search results according to the determined display content. Then, the processor 11 causes the communication unit 14 to send the data for displaying the search results to the client device 20 (step S31).
[0084] As a result, the processor 21 of the client device 20 uses the data received from the client device 20 to display the search results on the display 26. An example of an access management function is presented. Refer to Figure 5 to explain the processes performed within the access management function.
[0085] As shown in Figure 5, the processor 11 receives a request from the client device 20 to access a candidate shared part (step S40). In detail, the user operates the input device 25 to select one shared candidate part from the search results displayed on the client device 20. Based on this, a request for access to the shared candidate part is sent from the client device 20 to the sharing management system 10. The shared candidate part for which access has been requested is the shared part, i.e., the shared portion.
[0086] The processor 11 extracts the data of the shared part (shared portion) from the data of the document (target document) containing this part and saves it to the non-volatile memory area of the memory 12 or storage 13 (step S41). In other words, the shared part that has been separated / deleted / removed from the document is saved. The saving of the shared part (shared portion) may be temporary, and for example, the shared part (shared portion) may be erased from the non-volatile memory area after a predetermined period of time has elapsed.
[0087] The processor 11 determines the scope of access rights granted to the user based on the risk level and reliability level of the shared part (shared portion) (step S42). For example, the processor 11 may determine the scope of access rights by setting the access rights granted to the user to one of several types of access rights with different levels of authority. These several types of access rights may include read-only access rights to the shared part (shared portion) and downloadable access rights to the shared part (shared portion).
[0088] When the reliability level is greater than the risk level, the processor 11 strengthens the privileges included in the access rights compared to when the reliability level is less than the risk level. For example, if the reliability level is greater than the risk level, the processor 11 grants the user access rights to download the shared parts (shared portions). In this case, viewing and saving the shared parts (shared portions) are granted as access rights. Specifically, the processor 11 creates a shared link, which is a link to the storage area of the shared parts, and sends this shared link to the client device 20 to enable access. The shared link is configured to allow downloading of the shared parts (shared portions).
[0089] If the reliability level is lower than the risk level, the processor 11 grants the user read-only access to the shared part (shared portion). In this case, only viewing of the shared part (shared portion) is permitted as access. Specifically, the processor 11 creates a shared link configured to allow read-only access to the shared part (shared portion) and sends that shared link to the client device 20.
[0090] The processor 11 may grant stronger access rights to users as the reliability level increases relative to the risk level. Furthermore, if the reliability level is at its lowest value, such as when the reliability level is 0, the processor 11 does not have to grant the user access to the shared parts (shared portions), regardless of the risk level. In other words, a shared link is not created. The processor 11 does not have to grant the user access to the shared parts (shared portions) if the reliability level is below a predetermined value, including when the reliability level is at its lowest value.
[0091] Furthermore, if the risk level is at its highest value, such as when the risk level is 1.0, the processor 11 may not grant the user access to the shared parts (shared portions), regardless of the reliability level. In other words, a shared link will not be created. The processor 11 may not grant the user access to the shared parts (shared portions) if the risk level is above a predetermined value, including when the risk level is at its highest value.
[0092] The processor 11 causes the communication unit 14 to send access information to the shared parts (shared portions) to the client device 20 (step S43). Specifically, a shared link is sent to the client device 20. The client device 20 accesses the shared parts (shared portions) using the shared link, thereby sharing the shared parts (shared portions) with the user.
[0093] Furthermore, if access is possible in accordance with the determined access rights, access information may be provided to the client device 20 in a format different from a shared link. Alternatively, steps S40 and S41 may be performed for each shared candidate part, and access information for each shared candidate part may be provided to the client device 20 along with the search results. In this case, all shared candidate parts are shared target parts (shared target portions).
[0094] One or more embodiments of this disclosure offer the following advantages. However, it is not necessary for one or more embodiments of this disclosure to possess all of these advantages. Some embodiments may not possess some of these advantages.
[0095] (1) The degree of relevance between document parts and search queries is determined, which parts are candidates for sharing. The shared parts (shared portions) separated from the document are then saved, and access rights for users requesting searches for these shared parts (shared portions) are managed. Therefore, since searching and access management are performed at the part / section level of the document, appropriate and efficient sharing of the information contained in the document is possible. In other words, compared to cases where access is not managed at the part / section level of the document, users can more easily obtain the information they want, while the disclosure of irrelevant information to users is suppressed, thus ensuring security.
[0096] (2) The risk level of the shared candidate parts is calculated. This quantifies the degree of confidentiality contained in the shared candidate parts, and allows the degree of confidentiality contained in the shared candidate parts to be reflected in the management of document sharing.
[0097] (3) The trust level between the administrator of the document containing the candidate parts to be shared and the user who wishes to share it is calculated. This quantifies the degree of trust the administrator has in the user, and therefore the degree of trust the administrator has in the user can be reflected in the document sharing management process.
[0098] (4) By using the frequency of communication, it is possible to accurately calculate the reliability level. (5) By using communication time, it is possible to accurately calculate the reliability level.
[0099] (6) The use of sentiment data improves the accuracy of calculating the reliability level. (7) Based on the risk level and reliability level, information about the candidate shared parts to be included in the display of search results is determined. In this way, the information to be included in the display of search results is determined by taking into account not only the content of the candidate shared parts but also the relationship between the user and the administrator, so that appropriate information disclosure is possible in the search results.
[0100] (8) When the reliability level is greater than the risk level, more information about the shared candidate parts is included in the search results than when the reliability level is less than the risk level. This means that the degree of confidentiality contained in the shared candidate parts and the degree of trust the administrator has in the user are quantitatively evaluated, and when the level of trust is greater than the level of confidentiality, more information is disclosed. Therefore, more appropriate information disclosure is possible.
[0101] (9) When the reliability level is at the lowest value and / or the risk level is at the highest value, information about the shared candidate part will not be included in the display of search results. This will prevent inappropriate information disclosure when the administrator's trust in the user is very low (at a predetermined level) or when the confidentiality contained in the shared candidate part is very high (at a predetermined level).
[0102] (10) The search results display include, as information about the shared candidate part, a summary of the shared candidate part, the title of the document containing the shared candidate part, and / or at least one of the administrators of the document containing the shared candidate part. This enables the disclosure of appropriate information as a search result.
[0103] (11) Based on the risk level and reliability level, the scope of access rights granted to users is determined. This ensures that user access to shared parts (shared portions) is managed by taking into account not only the content of the shared parts (shared portions) but also the relationship between the user and the administrator, thereby enabling the disclosure of appropriate information.
[0104] (12) When the reliability level is greater than the risk level, the user's access rights to the shared parts (shared portions) are stronger than when the reliability level is less than the risk level. This allows for a quantitative evaluation of the degree of confidentiality contained in the shared parts and the degree of trust the administrator has in the user. When the level of confidentiality is high, greater freedom of access is granted. Therefore, more appropriate information disclosure is possible.
[0105] (13) When the reliability level is at the lowest value and the risk level is at the highest value, the user will not be allowed access to the shared parts (shared portions). This means that when the administrator's trust in the user is very low (at a predetermined level), or when the confidentiality contained in the shared parts (shared portions) is very high (at a predetermined level), the user will not be able to access the shared parts, thus preventing inappropriate disclosure of information.
[0106] (14) The access rights granted to the user are set from among read-only access rights to the shared parts (shared portions) and downloadable access rights to the shared parts (shared portions). This ensures that the differences in the permissions that are set are appropriately specified.
[0107] (15) A sharing link to the shared parts (shared portions) corresponding to the determined access rights scope is output to the client device. This ensures that the user is accurately granted access rights according to the determination.
[0108] (16) The shared candidate parts (shared portions) specified by the user are designated as shared parts. This reduces the processor load related to data partitioning and access rights settings compared to the case where all shared candidate parts (shared portions) are designated as shared parts.
[0109] Multiple examples of one or more embodiments are described below. This embodiment can be implemented with modifications as follows. This embodiment and the following modifications can be combined with each other to the extent that they do not conflict with the technical standards.
[0110] In the shared candidate determination function, the units / categories of parts whose relevance to the search query is required may differ from the units / categories of shared candidate parts. For example, processor 11 may extract multiple parts from the document whose relevance is above a predetermined value and combine them into a single shared candidate part.
[0111] • If access rights are managed for each shared part (shared portion), risk levels and reliability levels do not need to be used to generate search results or set access rights. Either (or only) risk levels and reliability levels may be used to generate search results or set access rights, or different indicators may be used. Also, the type of information included in the display of search results may be the same for all shared candidate parts. If risk levels or reliability levels are not used, the sharing management system 10 does not need to have the function to calculate them.
[0112] The diagrams and flowcharts of this disclosure illustrate the architecture, functionality, and operation of the apparatus, system, method, and program according to embodiments of this disclosure. Each component included in the diagrams and each step included in the flowcharts may correspond to a part of a program containing one or more instructions for realizing a logical functional unit. In other embodiments, some of the illustrated components may be omitted, other components may be included, or the arrangement of components may be changed. Also in other embodiments, some of the illustrated steps may be omitted, other steps may be included, the order of the steps may be different, or some steps may be executed simultaneously. Furthermore, a flowchart described as a series of actions may be divided into several parts and executed, or multiple flowcharts may be executed sequentially or in relation to each other. Furthermore, the functions realized by these components and steps may be realized by hardware, software, or a combination of hardware and software.
[0113] This disclosure may be implemented as a method, computer system, computer program product, or a combination thereof. The computer program product may include a computer-readable storage medium having program instructions for causing a processor to perform aspects of this disclosure. The functions and operations identified by the diagrams, flowcharts, or combinations thereof of this disclosure can each be implemented by program instructions. The program instructions are loaded onto a computer or other programmable data processing device and executed to cause the computer or other programmable data processing device to implement the above functions and operations.
[0114] The program instructions of this disclosure can be downloaded from a computer-readable storage medium to a computer device for processing, and can also be downloaded via a network to a computer device or external storage device. The communication unit of the computer device receives the program instructions from the network and transfers those program instructions for storage in a computer-readable storage medium within the computer device.
[0115] The program instructions in this disclosure may be assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as C++ and conventional procedural programming languages such as the C programming language. The program instructions may be executed in part or in whole on a remote computer.
[0116] Various modifications in form and detail may be made to the above-described examples without departing from the spirit and scope of the claims and their equivalents. The examples are for illustrative purposes only and not to limit. The descriptions of features in each example should be considered applicable to similar features or embodiments in other examples. When sequences are performed in a different order, and / or when components within the described systems, architectures, devices, or circuits are combined in a different way, and / or when they are replaced or complemented by other components or their equivalents, suitable results may be achieved. The scope of this disclosure is defined not by the detailed description, but by the claims and their equivalents. All modifications within the scope of the claims and their equivalents are included in this disclosure.
Claims
1. A method by which a computer performs an action. The processor receives search requests for search queries entered by the user into the client device, For each part of a document stored in the document database, the degree of relevance is determined based on the aforementioned search query, Based on the aforementioned degree of relevance, the parts of the document that will become candidate parts for sharing are determined, and here, at least one of the candidate parts for sharing is a part to be shared. Extract the shared parts from the aforementioned document that the user is allowed to access, Granting the user access rights to the shared parts, Methods that include...
2. Based on an analysis of the information contained in the aforementioned candidate shared parts, a risk level indicating the degree of confidentiality of the aforementioned candidate shared parts is calculated. A method performed by a computer according to claim 1, further comprising:
3. The aforementioned method, The method further includes referring to communication log data to calculate a confidence level indicating the degree of trust the administrator has in the document containing the candidate shared parts with respect to the user, The log data in question is from communications between the user and the administrator, and is acquired by a communication tool. The method performed by the computer according to claim 1.
4. The aforementioned method, The process further includes referring to communication log data to calculate a confidence level indicating the degree of trust the administrator has in the document containing the candidate shared parts with respect to the user, wherein the log data is of communications between the user and the administrator. Calculating the aforementioned reliability level is This includes determining the frequency of communication between the user and the administrator based on the log data of the aforementioned communication, and calculating the reliability level using the aforementioned communication frequency. The method performed by the computer according to claim 1.
5. The aforementioned method, The process further includes referring to communication log data to calculate a confidence level indicating the degree of trust the administrator has in the document containing the candidate shared parts with respect to the user, wherein the log data is of communications between the user and the administrator. Calculating the aforementioned reliability level is This includes determining the communication time between the user and the administrator based on the log data of the aforementioned communication, and using the aforementioned communication time to calculate the reliability level. The method performed by the computer according to claim 1.
6. The aforementioned method, The process further includes referring to communication log data to calculate a confidence level indicating the degree of trust the administrator has in the document containing the candidate shared parts with respect to the user, wherein the log data is of communications between the user and the administrator. Calculating the aforementioned reliability level is This includes estimating the emotions of at least one of the user and the administrator during communication between the user and the administrator based on the log data of the aforementioned communication, and calculating the reliability level using the data indicating the estimated emotions. The method performed by the computer according to claim 1.
7. Based on an analysis of the information contained in the aforementioned candidate shared parts, a risk level indicating the degree of confidentiality of the aforementioned candidate shared parts is calculated, The process involves referring to communication log data to calculate a confidence level indicating the degree of trust the administrator has in the user of the document containing the candidate shared parts, wherein the log data is from communications between the user and the administrator and is acquired by a communication tool. Based on the risk level and the reliability level, determine the information regarding the shared candidate parts to be included in the display of search results for the search request, Displaying the aforementioned search results, A method performed by a computer according to claim 1, further comprising:
8. Displaying the aforementioned search results means When the reliability level is greater than the risk level, the data for displaying the search results includes increasing the amount of information about the shared candidate parts to be included in the display of the search results, The method performed by the computer according to claim 7.
9. Displaying the aforementioned search results means When the reliability level is a predetermined minimum value, the data for displaying the search results is generated without including information about the shared candidate parts in the display of the search results. The method performed by the computer according to claim 7.
10. Generating data for displaying the aforementioned search results is, When the risk level is the predetermined maximum value, the data for displaying the search results is generated without including information about the shared candidate parts in the display of the search results. The method performed by the computer according to claim 7.
11. The aforementioned method, Based on an analysis of the information contained in the aforementioned candidate shared parts, a risk level indicating the degree of confidentiality of the aforementioned candidate shared parts is calculated, The method further includes referring to communication log data to calculate a confidence level indicating the degree of trust the administrator of the document containing the candidate shared parts has in the user, The log data in question is from communications between the user and the administrator, and is acquired by a communication tool. Granting the aforementioned user access rights to the shared parts is, This includes determining the scope of the access rights to be granted to the user based on the risk level and the reliability level. The method performed by the computer according to claim 1.
12. Determining the scope of permissions to be granted to the aforementioned user is: When the reliability level is greater than the risk level, the authority is strengthened, The method performed by the computer according to claim 11.
13. Output to the client device a shared link to the shared parts according to the determined access rights scope. A method performed by a computer according to claim 11, further comprising:
14. A computer system, Memory containing computer-readable instructions, The system includes one or more processors for executing the computer-readable instructions, and when the computer-readable instructions are executed, the one or more processors cause the system to perform a plurality of processes. The aforementioned multiple processes are, The system accepts search requests for search queries entered by the user into the client device, For each part of a document stored in the document database, the degree of relevance is determined based on the aforementioned search query, Based on the aforementioned degree of relevance, the parts of the document that will become candidate parts for sharing are determined, and here, at least one of the candidate parts for sharing is a part to be shared. Extract the shared parts from the aforementioned document that the user is allowed to access, This includes granting the user access rights to the shared parts, Computer system.
15. The one or more processors mentioned above are: Based on the analysis of the information contained in the candidate shared parts, a further set of processes is performed, including calculating a risk level indicating the degree of confidentiality of the candidate shared parts. The computer system according to claim 14.
16. The one or more processors mentioned above are: Performing a series of processes, which further include referring to communication log data to calculate a confidence level indicating the degree of trust the administrator has in the document containing the candidate shared parts for the user, The log data in question is from communications between the user and the administrator, and is acquired by a communication tool. The computer system according to claim 14.
17. The one or more processors mentioned above are: Perform a series of processes, further including referencing communication log data to calculate a confidence level indicating the degree of trust the administrator has in the document containing the candidate shared parts with respect to the user, wherein the log data is of communications between the user and the administrator. Calculating the aforementioned reliability level is This includes determining the frequency of communication between the user and the administrator based on the log data of the aforementioned communication, and calculating the reliability level using the aforementioned communication frequency. The computer system according to claim 14.
18. The one or more processors mentioned above are: Perform a series of processes, further including referencing communication log data to calculate a confidence level indicating the degree of trust the administrator has in the document containing the candidate shared parts with respect to the user, wherein the log data is of communications between the user and the administrator. Calculating the aforementioned reliability level is This includes determining the communication time between the user and the administrator based on the log data of the aforementioned communication, and using the aforementioned communication time to calculate the reliability level. The computer system according to claim 14.
19. The one or more processors mentioned above are: Perform a series of processes, further including referencing communication log data to calculate a confidence level indicating the degree of trust the administrator has in the document containing the candidate shared parts with respect to the user, wherein the log data is of communications between the user and the administrator. Calculating the aforementioned reliability level is This includes estimating the emotions of at least one of the user and the administrator during communication between the user and the administrator based on the log data of the aforementioned communication, and calculating the reliability level using the data indicating the estimated emotions. The computer system according to claim 14.
20. A computer program product, The computer-readable storage medium includes a program instruction set, the program instruction is executable by one or more processors so that one or more processors perform a plurality of processes, and the plurality of processes are The system accepts search requests using search queries entered by the user into the client device, For each part of a document stored in the document database, the degree of relevance is determined based on the aforementioned search query, Based on the aforementioned degree of relevance, the parts of the document that will become candidate parts for sharing are determined, and here, at least one of the candidate parts for sharing is a part to be shared. Extract the shared parts from the aforementioned document that the user is allowed to access, This includes granting the user access rights to the shared parts, Computer program products.
Citation Information
Patent Citations
High reliability interactive document management system implemented as software-as-a-service (SAAS)
US20210397522A1