system
An information processing device with real-time email analysis and threat sharing capabilities addresses email security vulnerabilities by isolating suspicious content and offering personalized responses, enhancing security and reducing risks.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SOFTBANK GROUP CORP
- Filing Date
- 2024-12-12
- Publication Date
- 2026-06-24
Smart Images

Figure 2026103483000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a character of the chatbot, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] [[ID= In a conventional email system, defenses against email-based threats such as phishing, malware, and spam are insufficient, and companies are exposed to the risk of leakage of confidential information and security incidents. In particular, with the spread of remote work, the need to establish a secure email usage environment has increased. Furthermore, it is difficult for users to confirm the security of received emails themselves, and since threat information is not shared immediately, it is a problem that new threats cannot be dealt with promptly.
Means for Solving the Problems
[0005] This invention provides an information processing device that monitors email communications and analyzes received electronic messages in real time. This device uses natural language processing to evaluate electronic messages, enabling immediate identification and isolation of suspicious emails. It also includes a generation mechanism for quickly responding to user inquiries and providing security recommendations. Furthermore, it effectively enhances security in corporate email usage by sharing threat information with other organizations via a global information sharing network and providing administrators with a display mechanism for monitoring and managing the system status.
[0006] "Email communication" refers to the act of sending and receiving electronic messages via a network such as the internet.
[0007] An "information processing device" refers to an electronic device that has the function of inputting data, performing specific processing, and then outputting the result.
[0008] "Natural language processing" refers to the technology that enables computers to understand and analyze the language that humans use on a daily basis.
[0009] An "electronic message" refers to a message that transmits communication content, including text, files, and images, in digital format.
[0010] "Protective measures" refer to mechanisms that protect specific elements or data in order to ensure security.
[0011] "Generation means" refers to a function that automatically generates new information based on input information.
[0012] "Information exchange means" refers to a mechanism for providing and sharing data among multiple information sources.
[0013] "Display means" refers to an interface for visually presenting data to the user. [Brief explanation of the drawing]
[0014] [Figure 1] It is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] It is a conceptual diagram showing an example of the main functions of a data processing device and a smart device according to the first embodiment. [Figure 3] It is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] It is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] It is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] It is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] It is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] It is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] It shows an emotion map to which a plurality of emotions are mapped. [Figure 10] It shows an emotion map to which a plurality of emotions are mapped. [Figure 11] It is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] It is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] It is a sequence diagram showing the processing flow of the data processing system in Example 2 when an emotion engine is combined. [Figure 14] It is a sequence diagram showing the processing flow of the data processing system in Application Example 2 when an emotion engine is combined.
Embodiments for Carrying Out the Invention
[0015] An example of an embodiment of the system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.
[0016] First, the terms used in the following description will be explained.
[0017] In the following embodiments, a labeled processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Also, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), and the like.
[0018] In the following embodiments, a labeled RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a work memory by the processor.
[0019] In the following embodiments, a labeled storage is one or more non-volatile storage devices that store various programs, various parameters, and the like. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes, and the like.
[0020] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).
[0021] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."
[0022] [First Embodiment]
[0023] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.
[0024] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0025] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0026] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.
[0027] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0028] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0029] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0030] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0031] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0032] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0033] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0034] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0035] This invention provides a system for effectively addressing email-based security threats faced by businesses and organizations. Specific embodiments of this system are described below.
[0036] This system primarily consists of a server, terminals, and users. First, the server monitors email communications via the network. Upon receiving a new electronic message, the server analyzes the message in real time using an information processing device and evaluates the email's content using natural language processing technology. If the analysis detects suspicious content, the server isolates the email and provides a warning to the user.
[0037] Furthermore, users can inquire about the security of emails. In this case, the server utilizes a generation mechanism to generate an appropriate response to the inquiry in real time and provide it to the user. For example, if a user inquires, "Is this email safe?", the server will return specific instructions such as, "This email requires caution. Do not click on any links."
[0038] Furthermore, the server shares detected threat information with other organizations through global information exchange channels, constantly updating its analysis based on the latest threat intelligence. This information sharing function allows other users and organizations to utilize the latest security intelligence.
[0039] In addition, administrators can monitor the overall security system status using on-device displays. These displays real-time statistics on detected threats and email filtering results, enabling administrators to take quick and appropriate action.
[0040] As a concrete example, consider the case of receiving a phishing email. The server analyzes the email's unusual link structure and fraudulent sender information to determine if it is a phishing attempt. As a result, the email is quarantined, and the user is notified of a security warning. In this way, this system can comprehensively enhance the security of email usage within a company.
[0041] The following describes the processing flow.
[0042] Step 1:
[0043] The server receives new electronic messages over the network. Upon receipt, it temporarily stores the email header information to check the sender's domain and whether or not there are attachments.
[0044] Step 2:
[0045] The server uses an information processing device to analyze received electronic messages in real time. Natural language processing techniques are used for analysis, including keyword detection and contextual analysis of the email body.
[0046] Step 3:
[0047] The server evaluates the presence of threats such as phishing, malware, and spam based on the analysis results from the AI agent. Based on this evaluation, it determines the security of the email.
[0048] Step 4:
[0049] The server moves emails deemed suspicious or dangerous to a quarantine folder. Users are notified of quarantined emails with a warning message.
[0050] Step 5:
[0051] If a user is concerned about the security of a particular email, they can send a query to the server asking, "Is this email secure?"
[0052] Step 6:
[0053] The server generates a response to the user's inquiry using a generation mechanism. The response includes instructions such as whether the email is secure and whether the user should not click on any links.
[0054] Step 7:
[0055] The server shares detected threat information with other organizations via a global information exchange network, keeping threat intelligence constantly up-to-date.
[0056] Step 8:
[0057] Administrators use a management dashboard to monitor the status of the server's email security system in real time. The dashboard displays detected threats and filtering results, allowing administrators to take swift action as needed.
[0058] (Example 1)
[0059] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0060] Currently, many companies and organizations face various security risks through email. To respond quickly and effectively to threats such as phishing, spam, and malware, advanced analytical techniques and appropriate information sharing are required. However, existing systems struggle to identify suspicious emails and effectively utilize threat intelligence.
[0061] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0062] In this invention, the server includes an electronic computing device that monitors email communications and analyzes received electronic data in real time, data processing means that evaluates the content of the electronic data using natural language processing, and protective means that identify and isolate suspicious electronic data based on the analysis results. This makes it possible to respond quickly to various security threats and enhance the security of information within companies and organizations.
[0063] "Email communication" refers to the process of sending and receiving electronic messages via the internet.
[0064] "Electronic computing equipment" refers to computer devices that process data and perform calculations.
[0065] "Natural language processing" refers to the technology of analyzing, understanding, and generating human language using computers.
[0066] "Data processing means" refers to a method or function for analyzing input data and generating a specific output.
[0067] "Analysis results" refer to the conclusions and insights obtained from data analysis.
[0068] "Electronic data" refers to information in digital format handled by computer systems.
[0069] "Protective measures" refer to measures and methods to prevent unauthorized access and data loss.
[0070] "Generating means" refers to a method or device for generating new data or information based on specific data.
[0071] "Information exchange methods" refer to methods or processes for sharing information between different systems or organizations.
[0072] "Display means" refers to devices or technologies for visually presenting data or information.
[0073] "User" refers to an individual or organization that uses the system or service.
[0074] "Threat intelligence" refers to information about potential risks and security issues.
[0075] A "generative AI model" refers to an artificial intelligence model that uses machine learning algorithms to create new data.
[0076] This invention provides an email security system in which a server, terminal, and user work together.
[0077] The server monitors electronic data received via the mail server in real time. For this purpose, it can utilize mail filtering software such as "SpamAssassin" and antivirus software such as "ClamAV". When an email is received, the server analyzes its content using natural language processing libraries such as "spaCy" or "NLTK" to assess its potential as phishing or spam.
[0078] If suspicious electronic data is detected, the server will quarantine the email and take appropriate action. Email forwarding agents such as "Postfix" can be used for email quarantine. Afterward, the server utilizes a generative AI model to generate a response for the user. This response includes points the user should be aware of and specific security recommendations.
[0079] As a concrete example, consider a case where a user inquires about the security of an incoming email. The server can use a generative AI model such as "OpenAI® GPT" to provide a real-time response to the prompt "Is this email secure?" such as "Caution is advised. Do not click the link."
[0080] Furthermore, the server shares detected threat information with other organizations using information exchange mechanisms. This makes it possible to constantly update the system's analysis data based on the latest threat information. Server administrators can monitor the security system status in real time on their terminals, track suspicious activity, and take immediate action.
[0081] This invention allows companies and organizations to significantly reduce security risks arising from email and improve the safety and reliability of information.
[0082] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0083] Step 1:
[0084] The server monitors electronic data on the network through the mail server. It receives electronic messages via mail protocols (IMAP and SMTP) as input. It obtains the results of basic spam filtering as output. During this process, tools such as "SpamAssassin" are used to identify emails that may be classified as spam.
[0085] Step 2:
[0086] The server analyzes received electronic data using natural language processing techniques. Input includes email body, links, and sender information. Data processing involves tokenization and semantic analysis using "spaCy" or "NLTK" to identify traces of phishing and malware. Output includes an analysis score and a list of detected threats.
[0087] Step 3:
[0088] The server isolates suspicious electronic data based on its analysis score. It uses the analysis results obtained in the previous step as input. Its operation involves using a mail forwarding agent such as "Postfix" to move emails deemed suspicious to a quarantine folder. As output, it creates a log of the quarantined emails and records it for later analysis.
[0089] Step 4:
[0090] The server uses a generative AI model to generate responses for the user. It generates prompts based on the user's inquiry and email analysis results as input. For output, it uses "OpenAI GPT" to provide specific responses to the user in real time, such as "Is this email safe?" followed by "Caution is advised. Do not click the link."
[0091] Step 5:
[0092] The server shares threat intelligence with other organizations. It uses detected threat intelligence and analysis results as input. Its operation involves uploading information to a global threat database via an information sharing platform. As output, the information sharing history with other organizations is updated, ensuring that the latest security information is always available.
[0093] Step 6:
[0094] The terminal provides administrators with a system-wide monitoring screen. Inputs include real-time collected security data and email filtering results. Operationally, it uses data visualization technology to visualize the situation, allowing administrators to immediately understand the system status and potential threats. Outputs include threat statistics and filtering results, providing information for management.
[0095] (Application Example 1)
[0096] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0097] In modern society, security threats via email are increasing, with many emails received by businesses and individuals containing phishing or malware. Such threats are serious problems that can lead to the leakage of important information and system breaches. Furthermore, conventional email security systems are insufficient for real-time security assessment, and have particular challenges in responding quickly when users are on the go using smartphones. Therefore, there is a need for a system that enhances the ability to monitor and analyze email communications in real time, and to immediately assess security and issue warnings.
[0098] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0099] In this invention, the server includes an information processing means for monitoring email communications and analyzing received electronic messages in real time, an information processing device for evaluating the content of electronic messages using natural language processing, and a notification means for analyzing electronic messages in real time in the background on a mobile terminal and notifying a warning if suspicious content is detected. This makes it possible to immediately evaluate the security of emails and provide users with quick and appropriate warnings.
[0100] An "information processing device" is a device that monitors and analyzes electronic messages over a network in real time and processes the obtained data.
[0101] "Information processing means" refers to a function that uses natural language processing technology to analyze the content of electronic messages and evaluate their security.
[0102] "Protection measures" refer to the function of identifying suspicious electronic messages based on analysis results and isolating them to protect users from danger.
[0103] "Generation means" refers to a device or function for generating a response regarding the security of an electronic message in response to an inquiry from a user.
[0104] "Information exchange means" refers to communication methods that allow organizations to exchange threat information with other organizations through a global information sharing network, and to constantly reflect the latest security information in their systems.
[0105] A "display means" is a screen or interface that allows administrators to visualize, monitor, and operate the overall system status.
[0106] The "analysis means" refers to a function that operates on a mobile terminal, performs background analysis of electronic messages, and conducts security assessments in real time.
[0107] A "notification means" is a device or function that immediately notifies the user of a warning when suspicious content is detected.
[0108] The system implementing the present invention mainly consists of a server, a terminal, and a user. The server monitors email communications and analyzes received electronic messages in real time. For analysis, it evaluates the security of messages using natural language processing technologies such as Google's Natural Language API and Microsoft's Cognitive Services. Based on the analysis results, the server has a protection function to identify suspicious messages and isolate them. In addition, the user can inquire about the security of received messages via the terminal. In this case, the server uses a generation means and a generation AI model to provide the user with appropriate security instructions in real time.
[0109] Furthermore, the server shares threat information detected through analysis with other organizations via a global network, accumulating and reflecting the latest threat intelligence. On the terminal, emails are analyzed in the background on the user's mobile device, and if security concerns are raised, a warning is displayed to the user via a notification system. For example, if a user receives an email containing a suspicious link from an unverified sender while on the move, the terminal analyzes the anomaly of this link and sends a warning notification to the user.
[0110] A concrete example of a prompt message would be: "Design a program for an application that scans new emails, analyzes links and sender information within the emails, and assesses the likelihood of phishing in real time." This would allow the server to efficiently evaluate the security of emails received by users and support quick and appropriate responses.
[0111] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0112] Step 1:
[0113] The server monitors the network and receives electronic messages, including email header information and content. This information is taken as input and prepared for analysis.
[0114] Step 2:
[0115] The server sends the content of the acquired electronic message to a natural language processing API for analysis. Text analysis is performed to identify suspicious behavior in the message (e.g., phishing links or suspicious sender information). Based on this analysis, the server evaluates the degree of suspiciousness and outputs the evaluation result.
[0116] Step 3:
[0117] The server identifies suspicious messages based on the evaluation results. These identified messages are moved to a quarantine folder. This process prevents direct access from the user's mailbox.
[0118] Step 4:
[0119] The user uses their device to query the server about the security of a specific email. A generative AI model is used to receive the user's query as input and generate a response to that query.
[0120] Step 5:
[0121] The server uses a generative AI model to create an immediate response to a user inquiry. This response includes specific instructions, such as, "This email requires caution. Do not click the link." The generated response is sent to the user and is output as the result of the email's security assessment.
[0122] Step 6:
[0123] The server shares the threat information obtained through analysis with other organizations via an information exchange network. This information sharing ensures that the system is constantly updated with new threat intelligence, and that other users and organizations can also utilize this information.
[0124] Step 7:
[0125] The device re-analyzes emails received on the user's mobile device in the background and displays the results of the security assessment to the user as a notification. For example, if it determines that an email contains a suspicious link, a warning notification is sent to the user. This process allows the user to immediately recognize the risk.
[0126] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0127] This invention provides an improved email security system that incorporates an emotion engine to recognize user emotions and provide more personalized security responses. Specific embodiments are described below.
[0128] This system consists of a server, terminals, and users, with the server playing a central role in monitoring and analyzing email communications. Upon receiving a new electronic message, the server analyzes the message in real time using an information processing device and evaluates its content using natural language processing. This process determines the security of the email and isolates suspicious emails. The server also monitors users' email operations and can recognize user emotions using an emotion engine.
[0129] If a user feels uneasy or suspicious about a particular email, they can query the server about the email's security. The server uses an emotion engine to analyze the user's emotions and generates and provides an appropriate response based on that analysis. For example, if the server detects that the user is feeling uneasy, it will send specific, emotion-sensitive advice such as, "This email is suspicious. Do not open it and consult your administrator."
[0130] Furthermore, the servers share detected threat information through a global information network to maintain up-to-date threat intelligence. Administrators can monitor the overall system status in real time through on-device displays and take additional security measures based on the user's emotional state.
[0131] For example, if a user receives a suspicious email and the emotion engine detects tension as the user attempts to open it, the server immediately issues a warning and notifies the administrator. This allows relevant parties to respond immediately. In this way, the system can further enhance email security through emotion recognition and improve the quality of responses provided to users.
[0132] The following describes the processing flow.
[0133] Step 1:
[0134] The server receives new electronic messages via the network. Upon receiving a message, it analyzes the email header information to check for sender information and whether or not there are attachments.
[0135] Step 2:
[0136] The server uses an information processing device to analyze received electronic messages in real time. It uses natural language processing technology to evaluate the content of emails and determine if they are phishing or spam.
[0137] Step 3:
[0138] Based on the analysis results, the server quarantines emails deemed suspicious or dangerous. For quarantined emails, a warning message is sent to the user.
[0139] Step 4:
[0140] If a user has concerns or questions about the content of an email, they can send a query to the server asking, "Is this email safe?" The server will then receive this query.
[0141] Step 5:
[0142] The server uses an emotion engine to monitor the user's emotional state. It analyzes the user's actions and inquiries to recognize their emotions (e.g., anxiety, tension).
[0143] Step 6:
[0144] The server generates an appropriate response using a generation mechanism based on the user's perceived emotions. For example, if the user indicates anxiety, it might send a response such as, "Please do not open this email. Our support team will contact you later."
[0145] Step 7:
[0146] The server transmits detected threat intelligence and information about users' emotional states to a global information sharing network. This information is shared with other organizations and contributes to strengthening security.
[0147] Step 8:
[0148] Administrators can use on-device displays to monitor system status and user sentiment in real time. Additional security measures can be implemented as needed.
[0149] (Example 2)
[0150] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0151] Modern email communication faces increasing security risks such as phishing and spam, leading to heightened user anxiety when encountering suspicious emails. In this context, security measures must go beyond mere technical security, taking into account user emotions. It's crucial to enable users to react appropriately to email content and prevent them from making incorrect judgments.
[0152] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0153] In this invention, the server includes information processing means for monitoring email communications and analyzing received electronic messages in real time, emotion recognition means for monitoring user operations and analyzing emotional states, and generation means for generating responses corresponding to the user's emotional state. This enables users to use email in a more secure environment. Furthermore, receiving personalized advice based on the user's emotions facilitates appropriate responses to security risks.
[0154] "Email communication" refers to the sending and receiving of information via email, and is a means of transmitting messages in digital format.
[0155] "Information processing means" refers to hardware or software functions for analyzing received electronic messages and evaluating their content and metadata.
[0156] "Natural language processing" is a technology that enables computers to understand, analyze, and generate human language, and is primarily used for analyzing string data.
[0157] "Electronic processing means" refers to a device or program that uses computing resources to process and analyze data.
[0158] "Protective measures" refer to security features that identify suspicious electronic messages based on analysis results and isolate or delete them.
[0159] "Emotion recognition means" refers to methods and technologies for monitoring and analyzing emotional states from user interactions, and is particularly used for monitoring operational status.
[0160] "Generation means" refers to technology that has the function of automatically creating appropriate responses and advice to provide to the user based on the processing results.
[0161] "Information exchange means" refers to the ability to send and receive security-related information with other organizations via a global information sharing network.
[0162] "Display means" refers to devices or interfaces that visually show the real-time status of the system to the administrator and assist in its operation.
[0163] This invention is an improved email security system that supports users in using email with peace of mind. The system is realized through the collaboration of the server, terminal, and user.
[0164] The server uses an information processing device that monitors email communications to analyze received electronic messages in real time. This analysis employs natural language processing technology, enabling evaluation of the content of electronic messages and suspicious patterns. Furthermore, the server utilizes various protective measures to isolate suspicious emails, thereby enhancing security.
[0165] To recognize the user's emotional state, the server utilizes an emotion recognition engine. This engine analyzes user interaction data, such as mouse movements, click frequency, and keyboard input speed, to determine the user's emotional state.
[0166] Furthermore, the server can use generation methods to create personalized responses based on the user's emotional state. For example, if the server determines that the user is stressed, it may provide a message such as, "This email is suspicious. Do not open it and contact your administrator."
[0167] Through information exchange via a global network, servers share threat information with other systems and maintain access to the latest security information at all times.
[0168] Administrators can monitor the system status in real time using terminal displays and adjust security settings as needed. Furthermore, they can devise personalized security measures based on user sentiment data to provide even stronger protection.
[0169] An example of a prompt message is, "Perform sentiment analysis on a newly received email, assess the user's level of anxiety, and generate appropriate security advice." Through this prompt message, the generating AI model can respond flexibly and appropriately to the situation.
[0170] In this way, the present invention aims to improve user safety and reduce anxiety associated with using email.
[0171] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0172] Step 1:
[0173] When the server receives an email, an information processing device performs real-time analysis. The input is the data of the received email. The server uses natural language processing technology to analyze the email's content, sender, links, attachments, etc., to check for any suspicious patterns. The output is information indicating whether the email is safe or not.
[0174] Step 2:
[0175] The server collects user interaction data and analyzes it using an emotion recognition engine. The input is user interaction data (mouse movements, click frequency, keyboard input, etc.). The server processes this data and applies an emotion model to recognize the user's emotional state. The output is the result of the user's emotional state.
[0176] Step 3:
[0177] The server generates a response to the user based on the analysis results. The inputs are information regarding the security of the email and the user's emotional state. The server utilizes a generative AI model to generate appropriate security advice for the user using this data. The output is a specific response message provided to the user.
[0178] Step 4:
[0179] The server shares threat intelligence via a global information network. Inputs include characteristics of suspicious emails identified through analysis and user response data. Outputs are threat intelligence shared with other systems and organizations, thereby improving the overall security level.
[0180] Step 5:
[0181] The administrator monitors the system status using a terminal and adjusts settings as needed. Input is real-time log information generated within the system. Output is the adjusted security settings and the latest security status on the dashboard. Based on this, the administrator can take further security enhancements.
[0182] (Application Example 2)
[0183] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0184] Traditional email security systems could analyze the security of electronic messages received by users, but they lacked the nuanced approach that considered the emotions users felt towards emails. This made it difficult to implement specific security measures that addressed user anxieties and doubts, and there was a need for a system that could recognize users' emotions upon receiving emails and respond quickly.
[0185] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0186] In this invention, the server includes information processing means for monitoring email communications and analyzing received electronic messages in real time, emotion recognition means for monitoring user actions and recognizing emotional states, and response generation means for generating responses based on emotional states in response to user inquiries regarding the security of electronic messages. This makes it possible to quickly implement specific and appropriate security measures that take into account the user's emotions.
[0187] "Email communication" refers to the flow of messages sent and received electronically between users.
[0188] "Electronic messages" refer to information content transmitted in digital format, including email.
[0189] An "information processing device" refers to hardware or software used to analyze and process digital data and derive specific results.
[0190] "Natural language processing" refers to the technology that enables computers to understand, analyze, and generate human language.
[0191] A "suspicious electronic message" refers to an electronic message that the recipient deems potentially dangerous or fraudulent.
[0192] "Emotion recognition means" refers to technology or devices that detect and recognize emotional states from the user's actions, facial expressions, etc.
[0193] "Response generation means" refers to a technology or program for creating an appropriate response based on input information.
[0194] "Information exchange means" refers to communication methods or devices used to share data and information among multiple organizations.
[0195] "Display means" refers to output devices such as screens and projectors used to visually display information and data.
[0196] The system of this invention mainly consists of three elements: a server, a terminal, and a user. The server is equipped with an information processing device that monitors email communications and analyzes received electronic messages in real time. The server evaluates the content of electronic messages using natural language processing and determines security risks to the user. As a result, it identifies suspicious electronic messages and isolates them as necessary.
[0197] Furthermore, the server is equipped with emotion recognition capabilities, which analyze the user's actions and facial expressions to recognize their emotional state. Specifically, it uses the camera and sensors of smartphones and tablet devices to analyze emotions using generative AI models such as TENSORFLOW®. Based on the emotional state, the server uses response generation capabilities to provide the user with appropriate security responses and advice.
[0198] Furthermore, the server shares threat information with other organizations through a global information sharing network via information exchange mechanisms, thereby improving the overall security level of the system. Administrators can monitor the system status and take action as needed through on-screen displays.
[0199] As a concrete example, when a user receives an unread email with the subject "Important Security Notice," the server analyzes the email's text content and uses emotion recognition to detect the user's fears and anxieties. Based on the results, a prompt appears on the user's screen stating, "This email may be suspicious. Please check the sender before opening."
[0200] Examples of prompt messages include: "Analyze the following email content and assess the security risks. If sentiment analysis reveals anxiety, provide a proposed response to the user."
[0201] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0202] Step 1:
[0203] The server monitors email communications and receives new electronic messages. At this point, the server extracts the email metadata and records basic information such as the sender, recipient, and subject. It takes received emails as input and prepares metadata information as output.
[0204] Step 2:
[0205] The server analyzes the body of electronic messages using natural language processing (NLP) techniques. Specifically, it uses an NLP library to input the email body as text data and performs analysis for risk assessment. As a result, it outputs an evaluation indicating whether the email content is safe or suspicious.
[0206] Step 3:
[0207] The server activates the emotion recognition system and collects user interaction data and facial expression data. It inputs data from the device's camera, microphone, and touch inputs into an emotion analysis model, which then outputs the analyzed emotional state. This model utilizes a generative AI model such as TensorFlow.
[0208] Step 4:
[0209] Based on the analyzed emotional state and email content evaluation, the server uses a response generation mechanism to create a message to be provided to the user. Specifically, if user anxiety is detected, it generates a warning message corresponding to that emotion and provides a user notification as output.
[0210] Step 5:
[0211] The server shares threat information with other organizations via information exchange mechanisms. It inputs data on email risk assessment and user sentiment, exchanges information with other systems in real time, and outputs an updated threat database.
[0212] Step 6:
[0213] The terminal displays the response message generated by the server to the user. For example, the prompt message "This email may be suspicious. Please verify the sender before opening it." is displayed on the screen to encourage the user to take appropriate action.
[0214] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0215] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0216] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.
[0217] [Second Embodiment]
[0218] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0219] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0220] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0221] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0222] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0223] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0224] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0225] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0226] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0227] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0228] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0229] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0230] This invention provides a system for effectively addressing email-based security threats faced by businesses and organizations. Specific embodiments of this system are described below.
[0231] This system primarily consists of a server, terminals, and users. First, the server monitors email communications via the network. Upon receiving a new electronic message, the server analyzes the message in real time using an information processing device and evaluates the email's content using natural language processing technology. If the analysis detects suspicious content, the server isolates the email and provides a warning to the user.
[0232] Furthermore, users can inquire about the security of emails. In this case, the server utilizes a generation mechanism to generate an appropriate response to the inquiry in real time and provide it to the user. For example, if a user inquires, "Is this email safe?", the server will return specific instructions such as, "This email requires caution. Do not click on any links."
[0233] Furthermore, the server shares detected threat information with other organizations through global information exchange channels, constantly updating its analysis based on the latest threat intelligence. This information sharing function allows other users and organizations to utilize the latest security intelligence.
[0234] In addition, administrators can monitor the overall security system status using on-device displays. These displays real-time statistics on detected threats and email filtering results, enabling administrators to take quick and appropriate action.
[0235] As a concrete example, consider the case of receiving a phishing email. The server analyzes the email's unusual link structure and fraudulent sender information to determine if it is a phishing attempt. As a result, the email is quarantined, and the user is notified of a security warning. In this way, this system can comprehensively enhance the security of email usage within a company.
[0236] The following describes the processing flow.
[0237] Step 1:
[0238] The server receives new electronic messages over the network. Upon receipt, it temporarily stores the email header information to check the sender's domain and whether or not there are attachments.
[0239] Step 2:
[0240] The server uses an information processing device to analyze received electronic messages in real time. Natural language processing techniques are used for analysis, including keyword detection and contextual analysis of the email body.
[0241] Step 3:
[0242] The server evaluates the presence of threats such as phishing, malware, and spam based on the analysis results from the AI agent. Based on this evaluation, it determines the security of the email.
[0243] Step 4:
[0244] The server moves emails deemed suspicious or dangerous to a quarantine folder. Users are notified of quarantined emails with a warning message.
[0245] Step 5:
[0246] If a user is concerned about the security of a particular email, they can send a query to the server asking, "Is this email secure?"
[0247] Step 6:
[0248] The server generates a response to the user's inquiry using a generation mechanism. The response includes instructions such as whether the email is secure and whether the user should not click on any links.
[0249] Step 7:
[0250] The server shares detected threat information with other organizations via a global information exchange network, keeping threat intelligence constantly up-to-date.
[0251] Step 8:
[0252] Administrators use a management dashboard to monitor the status of the server's email security system in real time. The dashboard displays detected threats and filtering results, allowing administrators to take swift action as needed.
[0253] (Example 1)
[0254] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0255] Currently, many companies and organizations face various security risks through email. To respond quickly and effectively to threats such as phishing, spam, and malware, advanced analytical techniques and appropriate information sharing are required. However, existing systems struggle to identify suspicious emails and effectively utilize threat intelligence.
[0256] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0257] In this invention, the server includes an electronic computing device that monitors email communications and analyzes received electronic data in real time, data processing means that evaluates the content of the electronic data using natural language processing, and protective means that identify and isolate suspicious electronic data based on the analysis results. This makes it possible to respond quickly to various security threats and enhance the security of information within companies and organizations.
[0258] "Email communication" refers to the process of sending and receiving electronic messages via the internet.
[0259] "Electronic computing equipment" refers to computer devices that process data and perform calculations.
[0260] "Natural language processing" refers to the technology of analyzing, understanding, and generating human language using computers.
[0261] "Data processing means" refers to a method or function for analyzing input data and generating a specific output.
[0262] "Analysis results" refer to the conclusions and insights obtained from data analysis.
[0263] "Electronic data" refers to information in digital format handled by computer systems.
[0264] "Protective measures" refer to measures and methods to prevent unauthorized access and data loss.
[0265] "Generating means" refers to a method or device for generating new data or information based on specific data.
[0266] "Information exchange methods" refer to methods or processes for sharing information between different systems or organizations.
[0267] "Display means" refers to devices or technologies for visually presenting data or information.
[0268] "User" refers to an individual or organization that uses the system or service.
[0269] "Threat intelligence" refers to information about potential risks and security issues.
[0270] A "generative AI model" refers to an artificial intelligence model that uses machine learning algorithms to create new data.
[0271] This invention provides an email security system in which a server, terminal, and user work together.
[0272] The server monitors electronic data received via the mail server in real time. For this purpose, it can utilize mail filtering software such as "SpamAssassin" and antivirus software such as "ClamAV". When an email is received, the server analyzes its content using natural language processing libraries such as "spaCy" or "NLTK" to assess its potential as phishing or spam.
[0273] If suspicious electronic data is detected, the server will quarantine the email and take appropriate action. Email forwarding agents such as "Postfix" can be used for email quarantine. Afterward, the server utilizes a generative AI model to generate a response for the user. This response includes points the user should be aware of and specific security recommendations.
[0274] As a concrete example, consider a scenario where a user inquires about the security of an incoming email. The server can use a generative AI model such as "OpenAI GPT" to provide a real-time response to the prompt "Is this email secure?" such as "Caution advised. Do not click the link."
[0275] Furthermore, the server shares detected threat information with other organizations using information exchange mechanisms. This makes it possible to constantly update the system's analysis data based on the latest threat information. Server administrators can monitor the security system status in real time on their terminals, track suspicious activity, and take immediate action.
[0276] This invention allows companies and organizations to significantly reduce security risks arising from email and improve the safety and reliability of information.
[0277] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0278] Step 1:
[0279] The server monitors electronic data on the network through the mail server. As input, it receives electronic messages received using mail protocols (such as IMAP and SMTP). As output, it obtains the result of performing preliminary spam filtering. In this process, tools such as "SpamAssassin" are used to identify emails that may be determined as spam.
[0280] Step 2:
[0281] The server analyzes the received electronic data using natural language processing technology. The input includes the email body, links, sender information, etc. For data processing, tokenization and semantic analysis are performed using "spaCy" or "NLTK" to identify traces of phishing and malware. As output, an analysis score and a list of detected threats are obtained.
[0282] Step 3:
[0283] The server isolates suspicious electronic data based on the analysis score. As input, the analysis results obtained in the previous step are used. As an operation, a mail transfer agent such as "Postfix" is used to move the emails determined to be suspicious to an isolation folder. As output, a log of the isolated emails is created and recorded for later analysis.
[0284] <F000899>Step 4:
[0285] The server uses a generative AI model to generate a response to the user. As input, a prompt text is generated based on the user's inquiry content and the analysis results of the email. As output, using "OpenAI GPT", specific responses such as "This email is safe?" and "Caution is required. Do not click on the link." are provided to the user in real time for an inquiry.
[0286] Step 5:
[0287] The server shares threat intelligence with other organizations. It uses detected threat intelligence and analysis results as input. Its operation involves uploading information to a global threat database via an information sharing platform. As output, the information sharing history with other organizations is updated, ensuring that the latest security information is always available.
[0288] Step 6:
[0289] The terminal provides administrators with a system-wide monitoring screen. Inputs include real-time collected security data and email filtering results. Operationally, it uses data visualization technology to visualize the situation, allowing administrators to immediately understand the system status and potential threats. Outputs include threat statistics and filtering results, providing information for management.
[0290] (Application Example 1)
[0291] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0292] In modern society, security threats via email are increasing, with many emails received by businesses and individuals containing phishing or malware. Such threats are serious problems that can lead to the leakage of important information and system breaches. Furthermore, conventional email security systems are insufficient for real-time security assessment, and have particular challenges in responding quickly when users are on the go using smartphones. Therefore, there is a need for a system that enhances the ability to monitor and analyze email communications in real time, and to immediately assess security and issue warnings.
[0293] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0294] In this invention, the server includes an information processing means for monitoring email communications and analyzing received electronic messages in real time, an information processing device for evaluating the content of electronic messages using natural language processing, and a notification means for analyzing electronic messages in real time in the background on a mobile terminal and notifying a warning if suspicious content is detected. This makes it possible to immediately evaluate the security of emails and provide users with quick and appropriate warnings.
[0295] An "information processing device" is a device that monitors and analyzes electronic messages over a network in real time and processes the obtained data.
[0296] "Information processing means" refers to a function that uses natural language processing technology to analyze the content of electronic messages and evaluate their security.
[0297] "Protection measures" refer to the function of identifying suspicious electronic messages based on analysis results and isolating them to protect users from danger.
[0298] "Generation means" refers to a device or function for generating a response regarding the security of an electronic message in response to an inquiry from a user.
[0299] "Information exchange means" refers to communication methods that allow organizations to exchange threat information with other organizations through a global information sharing network, and to constantly reflect the latest security information in their systems.
[0300] A "display means" is a screen or interface that allows administrators to visualize, monitor, and operate the overall system status.
[0301] The "analysis means" refers to a function that operates on a mobile terminal, performs background analysis of electronic messages, and conducts security assessments in real time.
[0302] The "notification means" is a device or function for immediately notifying a user of a warning when suspicious content is detected.
[0303] The system for implementing the present invention mainly has a configuration consisting of a server, a terminal, and a user. The server monitors email communication and analyzes the received electronic messages in real time. For the analysis, natural language processing technologies such as Google's Natural Language API and Microsoft's Cognitive Services are used to evaluate the security of the messages. Based on the analysis results, the server identifies suspicious messages and has a protection function for isolating them. In addition, the user can inquire about the security of the received messages via the terminal. In this case, the server uses the generation means, utilizes the generation AI model, and provides appropriate security instructions to the user in real time.
[0304] Furthermore, the server shares the threat information detected by the analysis with other organizations through the global network and accumulates and reflects the latest threat intelligence. On the terminal, the mobile device owned by the user analyzes emails in the background, and when there are concerns about security, a warning to the user is displayed via the notification means. As a specific example, when the user receives an email containing a suspicious link from an unconfirmed sender during movement, the terminal analyzes the abnormality of this link and sends a warning notification to the user.
[0305] Specific examples of the prompt text include content such as "Please design a program for an application that scans new emails, analyzes the links and sender information in the emails, and evaluates the possibility of phishing in real time." Thereby, the server can efficiently evaluate the security of the emails received by the user and support prompt and appropriate responses.
[0306] The flow of the specific process in Application Example 1 will be described using FIG. 12.
[0307] Step 1:
[0308] The server monitors the network and receives electronic messages, including email header information and content. This information is taken as input and prepared for analysis.
[0309] Step 2:
[0310] The server sends the content of the acquired electronic message to a natural language processing API for analysis. Text analysis is performed to identify suspicious behavior in the message (e.g., phishing links or suspicious sender information). Based on this analysis, the server evaluates the degree of suspiciousness and outputs the evaluation result.
[0311] Step 3:
[0312] The server identifies suspicious messages based on the evaluation results. These identified messages are moved to a quarantine folder. This process prevents direct access from the user's mailbox.
[0313] Step 4:
[0314] The user uses their device to query the server about the security of a specific email. A generative AI model is used to receive the user's query as input and generate a response to that query.
[0315] Step 5:
[0316] The server uses a generative AI model to create an immediate response to a user inquiry. This response includes specific instructions, such as, "This email requires caution. Do not click the link." The generated response is sent to the user and is output as the result of the email's security assessment.
[0317] Step 6:
[0318] The server shares the threat information obtained through analysis with other organizations via an information exchange network. This information sharing ensures that the system is constantly updated with new threat intelligence, and that other users and organizations can also utilize this information.
[0319] Step 7:
[0320] The device re-analyzes emails received on the user's mobile device in the background and displays the results of the security assessment to the user as a notification. For example, if it determines that an email contains a suspicious link, a warning notification is sent to the user. This process allows the user to immediately recognize the risk.
[0321] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0322] This invention provides an improved email security system that incorporates an emotion engine to recognize user emotions and provide more personalized security responses. Specific embodiments are described below.
[0323] This system consists of a server, terminals, and users, with the server playing a central role in monitoring and analyzing email communications. Upon receiving a new electronic message, the server analyzes the message in real time using an information processing device and evaluates its content using natural language processing. This process determines the security of the email and isolates suspicious emails. The server also monitors users' email operations and can recognize user emotions using an emotion engine.
[0324] If a user feels uneasy or suspicious about a particular email, they can query the server about the email's security. The server uses an emotion engine to analyze the user's emotions and generates and provides an appropriate response based on that analysis. For example, if the server detects that the user is feeling uneasy, it will send specific, emotion-sensitive advice such as, "This email is suspicious. Do not open it and consult your administrator."
[0325] Furthermore, the servers share detected threat information through a global information network to maintain up-to-date threat intelligence. Administrators can monitor the overall system status in real time through on-device displays and take additional security measures based on the user's emotional state.
[0326] For example, if a user receives a suspicious email and the emotion engine detects tension as the user attempts to open it, the server immediately issues a warning and notifies the administrator. This allows relevant parties to respond immediately. In this way, the system can further enhance email security through emotion recognition and improve the quality of responses provided to users.
[0327] The following describes the processing flow.
[0328] Step 1:
[0329] The server receives new electronic messages via the network. Upon receiving a message, it analyzes the email header information to check for sender information and whether or not there are attachments.
[0330] Step 2:
[0331] The server uses an information processing device to analyze received electronic messages in real time. It uses natural language processing technology to evaluate the content of emails and determine if they are phishing or spam.
[0332] Step 3:
[0333] Based on the analysis results, the server quarantines emails deemed suspicious or dangerous. For quarantined emails, a warning message is sent to the user.
[0334] Step 4:
[0335] If a user has concerns or questions about the content of an email, they can send a query to the server asking, "Is this email safe?" The server will then receive this query.
[0336] Step 5:
[0337] The server uses an emotion engine to monitor the user's emotional state. It analyzes the user's actions and inquiries to recognize their emotions (e.g., anxiety, tension).
[0338] Step 6:
[0339] The server generates an appropriate response using a generation mechanism based on the user's perceived emotions. For example, if the user indicates anxiety, it might send a response such as, "Please do not open this email. Our support team will contact you later."
[0340] Step 7:
[0341] The server transmits detected threat intelligence and information about users' emotional states to a global information sharing network. This information is shared with other organizations and contributes to strengthening security.
[0342] Step 8:
[0343] Administrators can use on-device displays to monitor system status and user sentiment in real time. Additional security measures can be implemented as needed.
[0344] (Example 2)
[0345] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0346] Modern email communication faces increasing security risks such as phishing and spam, leading to heightened user anxiety when encountering suspicious emails. In this context, security measures must go beyond mere technical security, taking into account user emotions. It's crucial to enable users to react appropriately to email content and prevent them from making incorrect judgments.
[0347] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0348] In this invention, the server includes information processing means for monitoring email communications and analyzing received electronic messages in real time, emotion recognition means for monitoring user operations and analyzing emotional states, and generation means for generating responses corresponding to the user's emotional state. This enables users to use email in a more secure environment. Furthermore, receiving personalized advice based on the user's emotions facilitates appropriate responses to security risks.
[0349] "Email communication" refers to the sending and receiving of information via email, and is a means of transmitting messages in digital format.
[0350] "Information processing means" refers to hardware or software functions for analyzing received electronic messages and evaluating their content and metadata.
[0351] "Natural language processing" is a technology that enables computers to understand, analyze, and generate human language, and is primarily used for analyzing string data.
[0352] "Electronic processing means" refers to a device or program that uses computing resources to process and analyze data.
[0353] "Protective measures" refer to security features that identify suspicious electronic messages based on analysis results and isolate or delete them.
[0354] "Emotion recognition means" refers to methods and technologies for monitoring and analyzing emotional states from user interactions, and is particularly used for monitoring operational status.
[0355] "Generation means" refers to technology that has the function of automatically creating appropriate responses and advice to provide to the user based on the processing results.
[0356] "Information exchange means" refers to the ability to send and receive security-related information with other organizations via a global information sharing network.
[0357] "Display means" refers to devices or interfaces that visually show the real-time status of the system to the administrator and assist in its operation.
[0358] This invention is an improved email security system that supports users in using email with peace of mind. The system is realized through the collaboration of the server, terminal, and user.
[0359] The server uses an information processing device that monitors email communications to analyze received electronic messages in real time. This analysis employs natural language processing technology, enabling evaluation of the content of electronic messages and suspicious patterns. Furthermore, the server utilizes various protective measures to isolate suspicious emails, thereby enhancing security.
[0360] To recognize the user's emotional state, the server utilizes an emotion recognition engine. This engine analyzes user interaction data, such as mouse movements, click frequency, and keyboard input speed, to determine the user's emotional state.
[0361] Furthermore, the server can use generation methods to create personalized responses based on the user's emotional state. For example, if the server determines that the user is stressed, it may provide a message such as, "This email is suspicious. Do not open it and contact your administrator."
[0362] Through information exchange via a global network, servers share threat information with other systems and maintain access to the latest security information at all times.
[0363] Administrators can monitor the system status in real time using terminal displays and adjust security settings as needed. Furthermore, they can devise personalized security measures based on user sentiment data to provide even stronger protection.
[0364] An example of a prompt message is, "Perform sentiment analysis on a newly received email, assess the user's level of anxiety, and generate appropriate security advice." Through this prompt message, the generating AI model can respond flexibly and appropriately to the situation.
[0365] In this way, the present invention aims to improve user safety and reduce anxiety associated with using email.
[0366] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0367] Step 1:
[0368] When the server receives an email, an information processing device performs real-time analysis. The input is the data of the received email. The server uses natural language processing technology to analyze the email's content, sender, links, attachments, etc., to check for any suspicious patterns. The output is information indicating whether the email is safe or not.
[0369] Step 2:
[0370] The server collects user interaction data and analyzes it using an emotion recognition engine. The input is user interaction data (mouse movements, click frequency, keyboard input, etc.). The server processes this data and applies an emotion model to recognize the user's emotional state. The output is the result of the user's emotional state.
[0371] Step 3:
[0372] The server generates a response to the user based on the analysis results. The inputs are information regarding the security of the email and the user's emotional state. The server utilizes a generative AI model to generate appropriate security advice for the user using this data. The output is a specific response message provided to the user.
[0373] Step 4:
[0374] The server shares threat intelligence via a global information network. Inputs include characteristics of suspicious emails identified through analysis and user response data. Outputs are threat intelligence shared with other systems and organizations, thereby improving the overall security level.
[0375] Step 5:
[0376] The administrator monitors the system status using a terminal and adjusts settings as needed. Input is real-time log information generated within the system. Output is the adjusted security settings and the latest security status on the dashboard. Based on this, the administrator can take further security enhancements.
[0377] (Application Example 2)
[0378] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the smart glasses 214 as the "terminal".
[0379] Traditional email security systems could analyze the security of electronic messages received by users, but they lacked the nuanced approach that considered the emotions users felt towards emails. This made it difficult to implement specific security measures that addressed user anxieties and doubts, and there was a need for a system that could recognize users' emotions upon receiving emails and respond quickly.
[0380] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0381] In this invention, the server includes information processing means for monitoring email communications and analyzing received electronic messages in real time, emotion recognition means for monitoring user actions and recognizing emotional states, and response generation means for generating responses based on emotional states in response to user inquiries regarding the security of electronic messages. This makes it possible to quickly implement specific and appropriate security measures that take into account the user's emotions.
[0382] "Email communication" refers to the flow of messages sent and received electronically between users.
[0383] "Electronic messages" refer to information content transmitted in digital format, including email.
[0384] An "information processing device" refers to hardware or software used to analyze and process digital data and derive specific results.
[0385] "Natural language processing" refers to the technology that enables computers to understand, analyze, and generate human language.
[0386] A "suspicious electronic message" refers to an electronic message that the recipient deems potentially dangerous or fraudulent.
[0387] "Emotion recognition means" refers to technology or devices that detect and recognize emotional states from the user's actions, facial expressions, etc.
[0388] "Response generation means" refers to a technology or program for creating an appropriate response based on input information.
[0389] "Information exchange means" refers to communication methods or devices used to share data and information among multiple organizations.
[0390] "Display means" refers to output devices such as screens and projectors used to visually display information and data.
[0391] The system of this invention mainly consists of three elements: a server, a terminal, and a user. The server is equipped with an information processing device that monitors email communications and analyzes received electronic messages in real time. The server evaluates the content of electronic messages using natural language processing and determines security risks to the user. As a result, it identifies suspicious electronic messages and isolates them as necessary.
[0392] Furthermore, the server is equipped with emotion recognition capabilities, which analyze the user's actions and facial expressions to recognize their emotional state. Specifically, it uses the camera and sensors of smartphones and tablet devices to analyze emotions using generative AI models such as TensorFlow. Based on the emotional state, the server uses response generation capabilities to provide the user with appropriate security responses and advice.
[0393] Furthermore, the server shares threat information with other organizations through a global information sharing network via information exchange mechanisms, thereby improving the overall security level of the system. Administrators can monitor the system status and take action as needed through on-screen displays.
[0394] As a concrete example, when a user receives an unread email with the subject "Important Security Notice," the server analyzes the email's text content and uses emotion recognition to detect the user's fears and anxieties. Based on the results, a prompt appears on the user's screen stating, "This email may be suspicious. Please check the sender before opening."
[0395] Examples of prompt messages include: "Analyze the following email content and assess the security risks. If sentiment analysis reveals anxiety, provide a proposed response to the user."
[0396] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0397] Step 1:
[0398] The server monitors email communications and receives new electronic messages. At this point, the server extracts the email metadata and records basic information such as the sender, recipient, and subject. It takes received emails as input and prepares metadata information as output.
[0399] Step 2:
[0400] The server analyzes the body of electronic messages using natural language processing (NLP) techniques. Specifically, it uses an NLP library to input the email body as text data and performs analysis for risk assessment. As a result, it outputs an evaluation indicating whether the email content is safe or suspicious.
[0401] Step 3:
[0402] The server activates the emotion recognition system and collects user interaction data and facial expression data. It inputs data from the device's camera, microphone, and touch inputs into an emotion analysis model, which then outputs the analyzed emotional state. This model utilizes a generative AI model such as TensorFlow.
[0403] Step 4:
[0404] Based on the analyzed emotional state and email content evaluation, the server uses a response generation mechanism to create a message to be provided to the user. Specifically, if user anxiety is detected, it generates a warning message corresponding to that emotion and provides a user notification as output.
[0405] Step 5:
[0406] The server shares threat information with other organizations via information exchange mechanisms. It inputs data on email risk assessment and user sentiment, exchanges information with other systems in real time, and outputs an updated threat database.
[0407] Step 6:
[0408] The terminal displays the response message generated by the server to the user. For example, the prompt message "This email may be suspicious. Please verify the sender before opening it." is displayed on the screen to encourage the user to take appropriate action.
[0409] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0410] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0411] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.
[0412] [Third Embodiment]
[0413] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0414] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0415] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0416] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0417] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0418] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0419] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0420] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0421] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0422] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0423] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0424] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".
[0425] This invention provides a system for effectively addressing email-based security threats faced by businesses and organizations. Specific embodiments of this system are described below.
[0426] This system primarily consists of a server, terminals, and users. First, the server monitors email communications via the network. Upon receiving a new electronic message, the server analyzes the message in real time using an information processing device and evaluates the email's content using natural language processing technology. If the analysis detects suspicious content, the server isolates the email and provides a warning to the user.
[0427] Furthermore, users can inquire about the security of emails. In this case, the server utilizes a generation mechanism to generate an appropriate response to the inquiry in real time and provide it to the user. For example, if a user inquires, "Is this email safe?", the server will return specific instructions such as, "This email requires caution. Do not click on any links."
[0428] Furthermore, the server shares detected threat information with other organizations through global information exchange channels, constantly updating its analysis based on the latest threat intelligence. This information sharing function allows other users and organizations to utilize the latest security intelligence.
[0429] In addition, administrators can monitor the overall security system status using on-device displays. These displays real-time statistics on detected threats and email filtering results, enabling administrators to take quick and appropriate action.
[0430] As a concrete example, consider the case of receiving a phishing email. The server analyzes the email's unusual link structure and fraudulent sender information to determine if it is a phishing attempt. As a result, the email is quarantined, and the user is notified of a security warning. In this way, this system can comprehensively enhance the security of email usage within a company.
[0431] The following describes the processing flow.
[0432] Step 1:
[0433] The server receives new electronic messages over the network. Upon receipt, it temporarily stores the email header information to check the sender's domain and whether or not there are attachments.
[0434] Step 2:
[0435] The server uses an information processing device to analyze received electronic messages in real time. Natural language processing techniques are used for analysis, including keyword detection and contextual analysis of the email body.
[0436] Step 3:
[0437] The server evaluates the presence of threats such as phishing, malware, and spam based on the analysis results from the AI agent. Based on this evaluation, it determines the security of the email.
[0438] Step 4:
[0439] The server moves emails deemed suspicious or dangerous to a quarantine folder. Users are notified of quarantined emails with a warning message.
[0440] Step 5:
[0441] If a user is concerned about the security of a particular email, they can send a query to the server asking, "Is this email secure?"
[0442] Step 6:
[0443] The server generates a response to the user's inquiry using a generation mechanism. The response includes instructions such as whether the email is secure and whether the user should not click on any links.
[0444] Step 7:
[0445] The server shares detected threat information with other organizations via a global information exchange network, keeping threat intelligence constantly up-to-date.
[0446] Step 8:
[0447] Administrators use a management dashboard to monitor the status of the server's email security system in real time. The dashboard displays detected threats and filtering results, allowing administrators to take swift action as needed.
[0448] (Example 1)
[0449] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0450] Currently, many companies and organizations face various security risks through email. To respond quickly and effectively to threats such as phishing, spam, and malware, advanced analytical techniques and appropriate information sharing are required. However, existing systems struggle to identify suspicious emails and effectively utilize threat intelligence.
[0451] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0452] In this invention, the server includes an electronic computing device that monitors email communications and analyzes received electronic data in real time, data processing means that evaluates the content of the electronic data using natural language processing, and protective means that identify and isolate suspicious electronic data based on the analysis results. This makes it possible to respond quickly to various security threats and enhance the security of information within companies and organizations.
[0453] "Email communication" refers to the process of sending and receiving electronic messages via the internet.
[0454] "Electronic computing equipment" refers to computer devices that process data and perform calculations.
[0455] "Natural language processing" refers to the technology of analyzing, understanding, and generating human language using computers.
[0456] "Data processing means" refers to a method or function for analyzing input data and generating a specific output.
[0457] "Analysis results" refer to the conclusions and insights obtained from data analysis.
[0458] "Electronic data" refers to information in digital format handled by computer systems.
[0459] "Protective measures" refer to measures and methods to prevent unauthorized access and data loss.
[0460] "Generating means" refers to a method or device for generating new data or information based on specific data.
[0461] "Information exchange methods" refer to methods or processes for sharing information between different systems or organizations.
[0462] "Display means" refers to devices or technologies for visually presenting data or information.
[0463] "User" refers to an individual or organization that uses the system or service.
[0464] "Threat intelligence" refers to information about potential risks and security issues.
[0465] A "generative AI model" refers to an artificial intelligence model that uses machine learning algorithms to create new data.
[0466] This invention provides an email security system in which a server, terminal, and user work together.
[0467] The server monitors electronic data received via the mail server in real time. For this purpose, it can utilize mail filtering software such as "SpamAssassin" and antivirus software such as "ClamAV". When an email is received, the server analyzes its content using natural language processing libraries such as "spaCy" or "NLTK" to assess its potential as phishing or spam.
[0468] If suspicious electronic data is detected, the server will quarantine the email and take appropriate action. Email forwarding agents such as "Postfix" can be used for email quarantine. Afterward, the server utilizes a generative AI model to generate a response for the user. This response includes points the user should be aware of and specific security recommendations.
[0469] As a concrete example, consider a scenario where a user inquires about the security of an incoming email. The server can use a generative AI model such as "OpenAI GPT" to provide a real-time response to the prompt "Is this email secure?" such as "Caution advised. Do not click the link."
[0470] Furthermore, the server shares detected threat information with other organizations using information exchange mechanisms. This makes it possible to constantly update the system's analysis data based on the latest threat information. Server administrators can monitor the security system status in real time on their terminals, track suspicious activity, and take immediate action.
[0471] This invention allows companies and organizations to significantly reduce security risks arising from email and improve the safety and reliability of information.
[0472] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0473] Step 1:
[0474] The server monitors electronic data on the network through the mail server. It receives electronic messages via mail protocols (IMAP and SMTP) as input. It obtains the results of basic spam filtering as output. During this process, tools such as "SpamAssassin" are used to identify emails that may be classified as spam.
[0475] Step 2:
[0476] The server analyzes received electronic data using natural language processing techniques. Input includes email body, links, and sender information. Data processing involves tokenization and semantic analysis using "spaCy" or "NLTK" to identify traces of phishing and malware. Output includes an analysis score and a list of detected threats.
[0477] Step 3:
[0478] The server isolates suspicious electronic data based on its analysis score. It uses the analysis results obtained in the previous step as input. Its operation involves using a mail forwarding agent such as "Postfix" to move emails deemed suspicious to a quarantine folder. As output, it creates a log of the quarantined emails and records it for later analysis.
[0479] Step 4:
[0480] The server uses a generative AI model to generate responses for the user. It generates prompts based on the user's inquiry and email analysis results as input. For output, it uses "OpenAI GPT" to provide specific responses to the user in real time, such as "Is this email safe?" followed by "Caution is advised. Do not click the link."
[0481] Step 5:
[0482] The server shares threat intelligence with other organizations. It uses detected threat intelligence and analysis results as input. Its operation involves uploading information to a global threat database via an information sharing platform. As output, the information sharing history with other organizations is updated, ensuring that the latest security information is always available.
[0483] Step 6:
[0484] The terminal provides administrators with a system-wide monitoring screen. Inputs include real-time collected security data and email filtering results. Operationally, it uses data visualization technology to visualize the situation, allowing administrators to immediately understand the system status and potential threats. Outputs include threat statistics and filtering results, providing information for management.
[0485] (Application Example 1)
[0486] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0487] In modern society, security threats via email are increasing, with many emails received by businesses and individuals containing phishing or malware. Such threats are serious problems that can lead to the leakage of important information and system breaches. Furthermore, conventional email security systems are insufficient for real-time security assessment, and have particular challenges in responding quickly when users are on the go using smartphones. Therefore, there is a need for a system that enhances the ability to monitor and analyze email communications in real time, and to immediately assess security and issue warnings.
[0488] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0489] In this invention, the server includes an information processing means for monitoring email communications and analyzing received electronic messages in real time, an information processing device for evaluating the content of electronic messages using natural language processing, and a notification means for analyzing electronic messages in real time in the background on a mobile terminal and notifying a warning if suspicious content is detected. This makes it possible to immediately evaluate the security of emails and provide users with quick and appropriate warnings.
[0490] An "information processing device" is a device that monitors and analyzes electronic messages over a network in real time and processes the obtained data.
[0491] "Information processing means" refers to a function that uses natural language processing technology to analyze the content of electronic messages and evaluate their security.
[0492] "Protection measures" refer to the function of identifying suspicious electronic messages based on analysis results and isolating them to protect users from danger.
[0493] "Generation means" refers to a device or function for generating a response regarding the security of an electronic message in response to an inquiry from a user.
[0494] "Information exchange means" refers to communication methods that allow organizations to exchange threat information with other organizations through a global information sharing network, and to constantly reflect the latest security information in their systems.
[0495] A "display means" is a screen or interface that allows administrators to visualize, monitor, and operate the overall system status.
[0496] The "analysis means" refers to a function that operates on a mobile terminal, performs background analysis of electronic messages, and conducts security assessments in real time.
[0497] A "notification means" is a device or function that immediately notifies the user of a warning when suspicious content is detected.
[0498] The system implementing the present invention mainly consists of a server, a terminal, and a user. The server monitors email communications and analyzes received electronic messages in real time. For analysis, it uses natural language processing technologies such as Google's Natural Language API and Microsoft's Cognitive Services to evaluate the security of messages. Based on the analysis results, the server has a protection function to identify suspicious messages and isolate them. In addition, the user can inquire about the security of received messages via the terminal. In this case, the server uses a generation means and a generation AI model to provide the user with appropriate security instructions in real time.
[0499] Furthermore, the server shares threat information detected through analysis with other organizations via a global network, accumulating and reflecting the latest threat intelligence. On the terminal, emails are analyzed in the background on the user's mobile device, and if security concerns are raised, a warning is displayed to the user via a notification system. For example, if a user receives an email containing a suspicious link from an unverified sender while on the move, the terminal analyzes the anomaly of this link and sends a warning notification to the user.
[0500] A concrete example of a prompt message would be: "Design a program for an application that scans new emails, analyzes links and sender information within the emails, and assesses the likelihood of phishing in real time." This would allow the server to efficiently evaluate the security of emails received by users and support quick and appropriate responses.
[0501] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0502] Step 1:
[0503] The server monitors the network and receives electronic messages, including email header information and content. This information is taken as input and prepared for analysis.
[0504] Step 2:
[0505] The server sends the content of the acquired electronic message to a natural language processing API for analysis. Text analysis is performed to identify suspicious behavior in the message (e.g., phishing links or suspicious sender information). Based on this analysis, the server evaluates the degree of suspiciousness and outputs the evaluation result.
[0506] Step 3:
[0507] The server identifies suspicious messages based on the evaluation results. These identified messages are moved to a quarantine folder. This process prevents direct access from the user's mailbox.
[0508] Step 4:
[0509] The user uses their device to query the server about the security of a specific email. A generative AI model is used to receive the user's query as input and generate a response to that query.
[0510] Step 5:
[0511] The server uses a generative AI model to create an immediate response to a user inquiry. This response includes specific instructions, such as, "This email requires caution. Do not click the link." The generated response is sent to the user and is output as the result of the email's security assessment.
[0512] Step 6:
[0513] The server shares the threat information obtained through analysis with other organizations via an information exchange network. This information sharing ensures that the system is constantly updated with new threat intelligence, and that other users and organizations can also utilize this information.
[0514] Step 7:
[0515] The device re-analyzes emails received on the user's mobile device in the background and displays the results of the security assessment to the user as a notification. For example, if it determines that an email contains a suspicious link, a warning notification is sent to the user. This process allows the user to immediately recognize the risk.
[0516] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0517] This invention provides an improved email security system that incorporates an emotion engine to recognize user emotions and provide more personalized security responses. Specific embodiments are described below.
[0518] This system consists of a server, terminals, and users, with the server playing a central role in monitoring and analyzing email communications. Upon receiving a new electronic message, the server analyzes the message in real time using an information processing device and evaluates its content using natural language processing. This process determines the security of the email and isolates suspicious emails. The server also monitors users' email operations and can recognize user emotions using an emotion engine.
[0519] If a user feels uneasy or suspicious about a particular email, they can query the server about the email's security. The server uses an emotion engine to analyze the user's emotions and generates and provides an appropriate response based on that analysis. For example, if the server detects that the user is feeling uneasy, it will send specific, emotion-sensitive advice such as, "This email is suspicious. Do not open it and consult your administrator."
[0520] Furthermore, the servers share detected threat information through a global information network to maintain up-to-date threat intelligence. Administrators can monitor the overall system status in real time through on-device displays and take additional security measures based on the user's emotional state.
[0521] For example, if a user receives a suspicious email and the emotion engine detects tension as the user attempts to open it, the server immediately issues a warning and notifies the administrator. This allows relevant parties to respond immediately. In this way, the system can further enhance email security through emotion recognition and improve the quality of responses provided to users.
[0522] The following describes the processing flow.
[0523] Step 1:
[0524] The server receives new electronic messages via the network. Upon receiving a message, it analyzes the email header information to check for sender information and whether or not there are attachments.
[0525] Step 2:
[0526] The server uses an information processing device to analyze received electronic messages in real time. It uses natural language processing technology to evaluate the content of emails and determine if they are phishing or spam.
[0527] Step 3:
[0528] Based on the analysis results, the server quarantines emails deemed suspicious or dangerous. For quarantined emails, a warning message is sent to the user.
[0529] Step 4:
[0530] If a user has concerns or questions about the content of an email, they can send a query to the server asking, "Is this email safe?" The server will then receive this query.
[0531] Step 5:
[0532] The server uses an emotion engine to monitor the user's emotional state. It analyzes the user's actions and inquiries to recognize their emotions (e.g., anxiety, tension).
[0533] Step 6:
[0534] The server generates an appropriate response using a generation mechanism based on the user's perceived emotions. For example, if the user indicates anxiety, it might send a response such as, "Please do not open this email. Our support team will contact you later."
[0535] Step 7:
[0536] The server transmits detected threat intelligence and information about users' emotional states to a global information sharing network. This information is shared with other organizations and contributes to strengthening security.
[0537] Step 8:
[0538] Administrators can use on-device displays to monitor system status and user sentiment in real time. Additional security measures can be implemented as needed.
[0539] (Example 2)
[0540] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0541] Modern email communication faces increasing security risks such as phishing and spam, leading to heightened user anxiety when encountering suspicious emails. In this context, security measures must go beyond mere technical security, taking into account user emotions. It's crucial to enable users to react appropriately to email content and prevent them from making incorrect judgments.
[0542] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0543] In this invention, the server includes information processing means for monitoring email communications and analyzing received electronic messages in real time, emotion recognition means for monitoring user operations and analyzing emotional states, and generation means for generating responses corresponding to the user's emotional state. This enables users to use email in a more secure environment. Furthermore, receiving personalized advice based on the user's emotions facilitates appropriate responses to security risks.
[0544] "Email communication" refers to the sending and receiving of information via email, and is a means of transmitting messages in digital format.
[0545] "Information processing means" refers to hardware or software functions for analyzing received electronic messages and evaluating their content and metadata.
[0546] "Natural language processing" is a technology that enables computers to understand, analyze, and generate human language, and is primarily used for analyzing string data.
[0547] "Electronic processing means" refers to a device or program that uses computing resources to process and analyze data.
[0548] "Protective measures" refer to security features that identify suspicious electronic messages based on analysis results and isolate or delete them.
[0549] "Emotion recognition means" refers to methods and technologies for monitoring and analyzing emotional states from user interactions, and is particularly used for monitoring operational status.
[0550] "Generation means" refers to technology that has the function of automatically creating appropriate responses and advice to provide to the user based on the processing results.
[0551] "Information exchange means" refers to the ability to send and receive security-related information with other organizations via a global information sharing network.
[0552] "Display means" refers to devices or interfaces that visually show the real-time status of the system to the administrator and assist in its operation.
[0553] This invention is an improved email security system that supports users in using email with peace of mind. The system is realized through the collaboration of the server, terminal, and user.
[0554] The server uses an information processing device that monitors email communications to analyze received electronic messages in real time. This analysis employs natural language processing technology, enabling evaluation of the content of electronic messages and suspicious patterns. Furthermore, the server utilizes various protective measures to isolate suspicious emails, thereby enhancing security.
[0555] To recognize the user's emotional state, the server utilizes an emotion recognition engine. This engine analyzes user interaction data, such as mouse movements, click frequency, and keyboard input speed, to determine the user's emotional state.
[0556] Furthermore, the server can use generation methods to create personalized responses based on the user's emotional state. For example, if the server determines that the user is stressed, it may provide a message such as, "This email is suspicious. Do not open it and contact your administrator."
[0557] Through information exchange via a global network, servers share threat information with other systems and maintain access to the latest security information at all times.
[0558] Administrators can monitor the system status in real time using terminal displays and adjust security settings as needed. Furthermore, they can devise personalized security measures based on user sentiment data to provide even stronger protection.
[0559] An example of a prompt message is, "Perform sentiment analysis on a newly received email, assess the user's level of anxiety, and generate appropriate security advice." Through this prompt message, the generating AI model can respond flexibly and appropriately to the situation.
[0560] In this way, the present invention aims to improve user safety and reduce anxiety associated with using email.
[0561] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0562] Step 1:
[0563] When the server receives an email, an information processing device performs real-time analysis. The input is the data of the received email. The server uses natural language processing technology to analyze the email's content, sender, links, attachments, etc., to check for any suspicious patterns. The output is information indicating whether the email is safe or not.
[0564] Step 2:
[0565] The server collects user interaction data and analyzes it using an emotion recognition engine. The input is user interaction data (mouse movements, click frequency, keyboard input, etc.). The server processes this data and applies an emotion model to recognize the user's emotional state. The output is the result of the user's emotional state.
[0566] Step 3:
[0567] The server generates a response to the user based on the analysis results. The inputs are information regarding the security of the email and the user's emotional state. The server utilizes a generative AI model to generate appropriate security advice for the user using this data. The output is a specific response message provided to the user.
[0568] Step 4:
[0569] The server shares threat intelligence via a global information network. Inputs include characteristics of suspicious emails identified through analysis and user response data. Outputs are threat intelligence shared with other systems and organizations, thereby improving the overall security level.
[0570] Step 5:
[0571] The administrator monitors the system status using a terminal and adjusts settings as needed. Input is real-time log information generated within the system. Output is the adjusted security settings and the latest security status on the dashboard. Based on this, the administrator can take further security enhancements.
[0572] (Application Example 2)
[0573] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0574] Traditional email security systems could analyze the security of electronic messages received by users, but they lacked the nuanced approach that considered the emotions users felt towards emails. This made it difficult to implement specific security measures that addressed user anxieties and doubts, and there was a need for a system that could recognize users' emotions upon receiving emails and respond quickly.
[0575] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0576] In this invention, the server includes information processing means for monitoring email communications and analyzing received electronic messages in real time, emotion recognition means for monitoring user actions and recognizing emotional states, and response generation means for generating responses based on emotional states in response to user inquiries regarding the security of electronic messages. This makes it possible to quickly implement specific and appropriate security measures that take into account the user's emotions.
[0577] "Email communication" refers to the flow of messages sent and received electronically between users.
[0578] "Electronic messages" refer to information content transmitted in digital format, including email.
[0579] An "information processing device" refers to hardware or software used to analyze and process digital data and derive specific results.
[0580] "Natural language processing" refers to the technology that enables computers to understand, analyze, and generate human language.
[0581] A "suspicious electronic message" refers to an electronic message that the recipient deems potentially dangerous or fraudulent.
[0582] "Emotion recognition means" refers to technology or devices that detect and recognize emotional states from the user's actions, facial expressions, etc.
[0583] "Response generation means" refers to a technology or program for creating an appropriate response based on input information.
[0584] "Information exchange means" refers to communication methods or devices used to share data and information among multiple organizations.
[0585] "Display means" refers to output devices such as screens and projectors used to visually display information and data.
[0586] The system of this invention mainly consists of three elements: a server, a terminal, and a user. The server is equipped with an information processing device that monitors email communications and analyzes received electronic messages in real time. The server evaluates the content of electronic messages using natural language processing and determines security risks to the user. As a result, it identifies suspicious electronic messages and isolates them as necessary.
[0587] Furthermore, the server is equipped with emotion recognition capabilities, which analyze the user's actions and facial expressions to recognize their emotional state. Specifically, it uses the camera and sensors of smartphones and tablet devices to analyze emotions using generative AI models such as TensorFlow. Based on the emotional state, the server uses response generation capabilities to provide the user with appropriate security responses and advice.
[0588] Furthermore, the server shares threat information with other organizations through a global information sharing network via information exchange mechanisms, thereby improving the overall security level of the system. Administrators can monitor the system status and take action as needed through on-screen displays.
[0589] As a concrete example, when a user receives an unread email with the subject "Important Security Notice," the server analyzes the email's text content and uses emotion recognition to detect the user's fears and anxieties. Based on the results, a prompt appears on the user's screen stating, "This email may be suspicious. Please check the sender before opening."
[0590] Examples of prompt messages include: "Analyze the following email content and assess the security risks. If sentiment analysis reveals anxiety, provide a proposed response to the user."
[0591] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0592] Step 1:
[0593] The server monitors email communications and receives new electronic messages. At this point, the server extracts the email metadata and records basic information such as the sender, recipient, and subject. It takes received emails as input and prepares metadata information as output.
[0594] Step 2:
[0595] The server analyzes the body of electronic messages using natural language processing (NLP) techniques. Specifically, it uses an NLP library to input the email body as text data and performs analysis for risk assessment. As a result, it outputs an evaluation indicating whether the email content is safe or suspicious.
[0596] Step 3:
[0597] The server activates the emotion recognition system and collects user interaction data and facial expression data. It inputs data from the device's camera, microphone, and touch inputs into an emotion analysis model, which then outputs the analyzed emotional state. This model utilizes a generative AI model such as TensorFlow.
[0598] Step 4:
[0599] Based on the analyzed emotional state and email content evaluation, the server uses a response generation mechanism to create a message to be provided to the user. Specifically, if user anxiety is detected, it generates a warning message corresponding to that emotion and provides a user notification as output.
[0600] Step 5:
[0601] The server shares threat information with other organizations via information exchange mechanisms. It inputs data on email risk assessment and user sentiment, exchanges information with other systems in real time, and outputs an updated threat database.
[0602] Step 6:
[0603] The terminal displays the response message generated by the server to the user. For example, the prompt message "This email may be suspicious. Please verify the sender before opening it." is displayed on the screen to encourage the user to take appropriate action.
[0604] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0605] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0606] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.
[0607] [Fourth Embodiment]
[0608] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0609] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0610] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0611] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0612] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0613] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0614] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0615] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0616] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0617] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0618] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0619] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0620] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0621] This invention provides a system for effectively addressing email-based security threats faced by businesses and organizations. Specific embodiments of this system are described below.
[0622] This system primarily consists of a server, terminals, and users. First, the server monitors email communications via the network. Upon receiving a new electronic message, the server analyzes the message in real time using an information processing device and evaluates the email's content using natural language processing technology. If the analysis detects suspicious content, the server isolates the email and provides a warning to the user.
[0623] Furthermore, users can inquire about the security of emails. In this case, the server utilizes a generation mechanism to generate an appropriate response to the inquiry in real time and provide it to the user. For example, if a user inquires, "Is this email safe?", the server will return specific instructions such as, "This email requires caution. Do not click on any links."
[0624] Furthermore, the server shares detected threat information with other organizations through global information exchange channels, constantly updating its analysis based on the latest threat intelligence. This information sharing function allows other users and organizations to utilize the latest security intelligence.
[0625] In addition, administrators can monitor the overall security system status using on-device displays. These displays real-time statistics on detected threats and email filtering results, enabling administrators to take quick and appropriate action.
[0626] As a concrete example, consider the case of receiving a phishing email. The server analyzes the email's unusual link structure and fraudulent sender information to determine if it is a phishing attempt. As a result, the email is quarantined, and the user is notified of a security warning. In this way, this system can comprehensively enhance the security of email usage within a company.
[0627] The following describes the processing flow.
[0628] Step 1:
[0629] The server receives new electronic messages over the network. Upon receipt, it temporarily stores the email header information to check the sender's domain and whether or not there are attachments.
[0630] Step 2:
[0631] The server uses an information processing device to analyze received electronic messages in real time. Natural language processing techniques are used for analysis, including keyword detection and contextual analysis of the email body.
[0632] Step 3:
[0633] The server evaluates the presence of threats such as phishing, malware, and spam based on the analysis results from the AI agent. Based on this evaluation, it determines the security of the email.
[0634] Step 4:
[0635] The server moves emails deemed suspicious or dangerous to a quarantine folder. Users are notified of quarantined emails with a warning message.
[0636] Step 5:
[0637] If a user is concerned about the security of a particular email, they can send a query to the server asking, "Is this email secure?"
[0638] Step 6:
[0639] The server generates a response to the user's inquiry using a generation mechanism. The response includes instructions such as whether the email is secure and whether the user should not click on any links.
[0640] Step 7:
[0641] The server shares detected threat information with other organizations via a global information exchange network, keeping threat intelligence constantly up-to-date.
[0642] Step 8:
[0643] Administrators use a management dashboard to monitor the status of the server's email security system in real time. The dashboard displays detected threats and filtering results, allowing administrators to take swift action as needed.
[0644] (Example 1)
[0645] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0646] Currently, many companies and organizations face various security risks through email. To respond quickly and effectively to threats such as phishing, spam, and malware, advanced analytical techniques and appropriate information sharing are required. However, existing systems struggle to identify suspicious emails and effectively utilize threat intelligence.
[0647] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0648] In this invention, the server includes an electronic computing device that monitors email communications and analyzes received electronic data in real time, data processing means that evaluates the content of the electronic data using natural language processing, and protective means that identify and isolate suspicious electronic data based on the analysis results. This makes it possible to respond quickly to various security threats and enhance the security of information within companies and organizations.
[0649] "Email communication" refers to the process of sending and receiving electronic messages via the internet.
[0650] "Electronic computing equipment" refers to computer devices that process data and perform calculations.
[0651] "Natural language processing" refers to the technology of analyzing, understanding, and generating human language using computers.
[0652] "Data processing means" refers to a method or function for analyzing input data and generating a specific output.
[0653] "Analysis results" refer to the conclusions and insights obtained from data analysis.
[0654] "Electronic data" refers to information in digital format handled by computer systems.
[0655] "Protective measures" refer to measures and methods to prevent unauthorized access and data loss.
[0656] "Generating means" refers to a method or device for generating new data or information based on specific data.
[0657] "Information exchange methods" refer to methods or processes for sharing information between different systems or organizations.
[0658] "Display means" refers to devices or technologies for visually presenting data or information.
[0659] "User" refers to an individual or organization that uses the system or service.
[0660] "Threat intelligence" refers to information about potential risks and security issues.
[0661] A "generative AI model" refers to an artificial intelligence model that uses machine learning algorithms to create new data.
[0662] This invention provides an email security system in which a server, terminal, and user work together.
[0663] The server monitors electronic data received via the mail server in real time. For this purpose, it can utilize mail filtering software such as "SpamAssassin" and antivirus software such as "ClamAV". When an email is received, the server analyzes its content using natural language processing libraries such as "spaCy" or "NLTK" to assess its potential as phishing or spam.
[0664] If suspicious electronic data is detected, the server will quarantine the email and take appropriate action. Email forwarding agents such as "Postfix" can be used for email quarantine. Afterward, the server utilizes a generative AI model to generate a response for the user. This response includes points the user should be aware of and specific security recommendations.
[0665] As a concrete example, consider a scenario where a user inquires about the security of an incoming email. The server can use a generative AI model such as "OpenAI GPT" to provide a real-time response to the prompt "Is this email secure?" such as "Caution advised. Do not click the link."
[0666] Furthermore, the server shares detected threat information with other organizations using information exchange mechanisms. This makes it possible to constantly update the system's analysis data based on the latest threat information. Server administrators can monitor the security system status in real time on their terminals, track suspicious activity, and take immediate action.
[0667] This invention allows companies and organizations to significantly reduce security risks arising from email and improve the safety and reliability of information.
[0668] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0669] Step 1:
[0670] The server monitors electronic data on the network through the mail server. It receives electronic messages via mail protocols (IMAP and SMTP) as input. It obtains the results of basic spam filtering as output. During this process, tools such as "SpamAssassin" are used to identify emails that may be classified as spam.
[0671] Step 2:
[0672] The server analyzes received electronic data using natural language processing techniques. Input includes email body, links, and sender information. Data processing involves tokenization and semantic analysis using "spaCy" or "NLTK" to identify traces of phishing and malware. Output includes an analysis score and a list of detected threats.
[0673] Step 3:
[0674] The server isolates suspicious electronic data based on its analysis score. It uses the analysis results obtained in the previous step as input. Its operation involves using a mail forwarding agent such as "Postfix" to move emails deemed suspicious to a quarantine folder. As output, it creates a log of the quarantined emails and records it for later analysis.
[0675] Step 4:
[0676] The server uses a generative AI model to generate responses for the user. It generates prompts based on the user's inquiry and email analysis results as input. For output, it uses "OpenAI GPT" to provide specific responses to the user in real time, such as "Is this email safe?" followed by "Caution is advised. Do not click the link."
[0677] Step 5:
[0678] The server shares threat intelligence with other organizations. It uses detected threat intelligence and analysis results as input. Its operation involves uploading information to a global threat database via an information sharing platform. As output, the information sharing history with other organizations is updated, ensuring that the latest security information is always available.
[0679] Step 6:
[0680] The terminal provides administrators with a system-wide monitoring screen. Inputs include real-time collected security data and email filtering results. Operationally, it uses data visualization technology to visualize the situation, allowing administrators to immediately understand the system status and potential threats. Outputs include threat statistics and filtering results, providing information for management.
[0681] (Application Example 1)
[0682] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0683] In modern society, security threats via email are increasing, with many emails received by businesses and individuals containing phishing or malware. Such threats are serious problems that can lead to the leakage of important information and system breaches. Furthermore, conventional email security systems are insufficient for real-time security assessment, and have particular challenges in responding quickly when users are on the go using smartphones. Therefore, there is a need for a system that enhances the ability to monitor and analyze email communications in real time, and to immediately assess security and issue warnings.
[0684] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0685] In this invention, the server includes an information processing means for monitoring email communications and analyzing received electronic messages in real time, an information processing device for evaluating the content of electronic messages using natural language processing, and a notification means for analyzing electronic messages in real time in the background on a mobile terminal and notifying a warning if suspicious content is detected. This makes it possible to immediately evaluate the security of emails and provide users with quick and appropriate warnings.
[0686] An "information processing device" is a device that monitors and analyzes electronic messages over a network in real time and processes the obtained data.
[0687] "Information processing means" refers to a function that uses natural language processing technology to analyze the content of electronic messages and evaluate their security.
[0688] "Protection measures" refer to the function of identifying suspicious electronic messages based on analysis results and isolating them to protect users from danger.
[0689] "Generation means" refers to a device or function for generating a response regarding the security of an electronic message in response to an inquiry from a user.
[0690] "Information exchange means" refers to communication methods that allow organizations to exchange threat information with other organizations through a global information sharing network, and to constantly reflect the latest security information in their systems.
[0691] A "display means" is a screen or interface that allows administrators to visualize, monitor, and operate the overall system status.
[0692] The "analysis means" refers to a function that operates on a mobile terminal, performs background analysis of electronic messages, and conducts security assessments in real time.
[0693] A "notification means" is a device or function that immediately notifies the user of a warning when suspicious content is detected.
[0694] The system implementing the present invention mainly consists of a server, a terminal, and a user. The server monitors email communications and analyzes received electronic messages in real time. For analysis, it uses natural language processing technologies such as Google's Natural Language API and Microsoft's Cognitive Services to evaluate the security of messages. Based on the analysis results, the server has a protection function to identify suspicious messages and isolate them. In addition, the user can inquire about the security of received messages via the terminal. In this case, the server uses a generation means and a generation AI model to provide the user with appropriate security instructions in real time.
[0695] Furthermore, the server shares threat information detected through analysis with other organizations via a global network, accumulating and reflecting the latest threat intelligence. On the terminal, emails are analyzed in the background on the user's mobile device, and if security concerns are raised, a warning is displayed to the user via a notification system. For example, if a user receives an email containing a suspicious link from an unverified sender while on the move, the terminal analyzes the anomaly of this link and sends a warning notification to the user.
[0696] A concrete example of a prompt message would be: "Design a program for an application that scans new emails, analyzes links and sender information within the emails, and assesses the likelihood of phishing in real time." This would allow the server to efficiently evaluate the security of emails received by users and support quick and appropriate responses.
[0697] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0698] Step 1:
[0699] The server monitors the network and receives electronic messages, including email header information and content. This information is taken as input and prepared for analysis.
[0700] Step 2:
[0701] The server sends the content of the acquired electronic message to a natural language processing API for analysis. Text analysis is performed to identify suspicious behavior in the message (e.g., phishing links or suspicious sender information). Based on this analysis, the server evaluates the degree of suspiciousness and outputs the evaluation result.
[0702] Step 3:
[0703] The server identifies suspicious messages based on the evaluation results. These identified messages are moved to a quarantine folder. This process prevents direct access from the user's mailbox.
[0704] Step 4:
[0705] The user uses their device to query the server about the security of a specific email. A generative AI model is used to receive the user's query as input and generate a response to that query.
[0706] Step 5:
[0707] The server uses a generative AI model to create an immediate response to a user inquiry. This response includes specific instructions, such as, "This email requires caution. Do not click the link." The generated response is sent to the user and is output as the result of the email's security assessment.
[0708] Step 6:
[0709] The server shares the threat information obtained through analysis with other organizations via an information exchange network. This information sharing ensures that the system is constantly updated with new threat intelligence, and that other users and organizations can also utilize this information.
[0710] Step 7:
[0711] The device re-analyzes emails received on the user's mobile device in the background and displays the results of the security assessment to the user as a notification. For example, if it determines that an email contains a suspicious link, a warning notification is sent to the user. This process allows the user to immediately recognize the risk.
[0712] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0713] This invention provides an improved email security system that incorporates an emotion engine to recognize user emotions and provide more personalized security responses. Specific embodiments are described below.
[0714] This system consists of a server, terminals, and users, with the server playing a central role in monitoring and analyzing email communications. Upon receiving a new electronic message, the server analyzes the message in real time using an information processing device and evaluates its content using natural language processing. This process determines the security of the email and isolates suspicious emails. The server also monitors users' email operations and can recognize user emotions using an emotion engine.
[0715] If a user feels uneasy or suspicious about a particular email, they can query the server about the email's security. The server uses an emotion engine to analyze the user's emotions and generates and provides an appropriate response based on that analysis. For example, if the server detects that the user is feeling uneasy, it will send specific, emotion-sensitive advice such as, "This email is suspicious. Do not open it and consult your administrator."
[0716] Furthermore, the servers share detected threat information through a global information network to maintain up-to-date threat intelligence. Administrators can monitor the overall system status in real time through on-device displays and take additional security measures based on the user's emotional state.
[0717] For example, if a user receives a suspicious email and the emotion engine detects tension as the user attempts to open it, the server immediately issues a warning and notifies the administrator. This allows relevant parties to respond immediately. In this way, the system can further enhance email security through emotion recognition and improve the quality of responses provided to users.
[0718] The following describes the processing flow.
[0719] Step 1:
[0720] The server receives new electronic messages via the network. Upon receiving a message, it analyzes the email header information to check for sender information and whether or not there are attachments.
[0721] Step 2:
[0722] The server uses an information processing device to analyze received electronic messages in real time. It uses natural language processing technology to evaluate the content of emails and determine if they are phishing or spam.
[0723] Step 3:
[0724] Based on the analysis results, the server quarantines emails deemed suspicious or dangerous. For quarantined emails, a warning message is sent to the user.
[0725] Step 4:
[0726] If a user has concerns or questions about the content of an email, they can send a query to the server asking, "Is this email safe?" The server will then receive this query.
[0727] Step 5:
[0728] The server uses an emotion engine to monitor the user's emotional state. It analyzes the user's actions and inquiries to recognize their emotions (e.g., anxiety, tension).
[0729] Step 6:
[0730] The server generates an appropriate response using a generation mechanism based on the user's perceived emotions. For example, if the user indicates anxiety, it might send a response such as, "Please do not open this email. Our support team will contact you later."
[0731] Step 7:
[0732] The server transmits detected threat intelligence and information about users' emotional states to a global information sharing network. This information is shared with other organizations and contributes to strengthening security.
[0733] Step 8:
[0734] Administrators can use on-device displays to monitor system status and user sentiment in real time. Additional security measures can be implemented as needed.
[0735] (Example 2)
[0736] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0737] Modern email communication faces increasing security risks such as phishing and spam, leading to heightened user anxiety when encountering suspicious emails. In this context, security measures must go beyond mere technical security, taking into account user emotions. It's crucial to enable users to react appropriately to email content and prevent them from making incorrect judgments.
[0738] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0739] In this invention, the server includes information processing means for monitoring email communications and analyzing received electronic messages in real time, emotion recognition means for monitoring user operations and analyzing emotional states, and generation means for generating responses corresponding to the user's emotional state. This enables users to use email in a more secure environment. Furthermore, receiving personalized advice based on the user's emotions facilitates appropriate responses to security risks.
[0740] "Email communication" refers to the sending and receiving of information via email, and is a means of transmitting messages in digital format.
[0741] "Information processing means" refers to hardware or software functions for analyzing received electronic messages and evaluating their content and metadata.
[0742] "Natural language processing" is a technology that enables computers to understand, analyze, and generate human language, and is primarily used for analyzing string data.
[0743] "Electronic processing means" refers to a device or program that uses computing resources to process and analyze data.
[0744] "Protective measures" refer to security features that identify suspicious electronic messages based on analysis results and isolate or delete them.
[0745] "Emotion recognition means" refers to methods and technologies for monitoring and analyzing emotional states from user interactions, and is particularly used for monitoring operational status.
[0746] "Generation means" refers to technology that has the function of automatically creating appropriate responses and advice to provide to the user based on the processing results.
[0747] "Information exchange means" refers to the ability to send and receive security-related information with other organizations via a global information sharing network.
[0748] "Display means" refers to devices or interfaces that visually show the real-time status of the system to the administrator and assist in its operation.
[0749] This invention is an improved email security system that supports users in using email with peace of mind. The system is realized through the collaboration of the server, terminal, and user.
[0750] The server uses an information processing device that monitors email communications to analyze received electronic messages in real time. This analysis employs natural language processing technology, enabling evaluation of the content of electronic messages and suspicious patterns. Furthermore, the server utilizes various protective measures to isolate suspicious emails, thereby enhancing security.
[0751] To recognize the user's emotional state, the server utilizes an emotion recognition engine. This engine analyzes user interaction data, such as mouse movements, click frequency, and keyboard input speed, to determine the user's emotional state.
[0752] Furthermore, the server can use generation methods to create personalized responses based on the user's emotional state. For example, if the server determines that the user is stressed, it may provide a message such as, "This email is suspicious. Do not open it and contact your administrator."
[0753] Through information exchange via a global network, servers share threat information with other systems and maintain access to the latest security information at all times.
[0754] Administrators can monitor the system status in real time using terminal displays and adjust security settings as needed. Furthermore, they can devise personalized security measures based on user sentiment data to provide even stronger protection.
[0755] An example of a prompt message is, "Perform sentiment analysis on a newly received email, assess the user's level of anxiety, and generate appropriate security advice." Through this prompt message, the generating AI model can respond flexibly and appropriately to the situation.
[0756] In this way, the present invention aims to improve user safety and reduce anxiety associated with using email.
[0757] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0758] Step 1:
[0759] When the server receives an email, an information processing device performs real-time analysis. The input is the data of the received email. The server uses natural language processing technology to analyze the email's content, sender, links, attachments, etc., to check for any suspicious patterns. The output is information indicating whether the email is safe or not.
[0760] Step 2:
[0761] The server collects user interaction data and analyzes it using an emotion recognition engine. The input is user interaction data (mouse movements, click frequency, keyboard input, etc.). The server processes this data and applies an emotion model to recognize the user's emotional state. The output is the result of the user's emotional state.
[0762] Step 3:
[0763] The server generates a response to the user based on the analysis results. The inputs are information regarding the security of the email and the user's emotional state. The server utilizes a generative AI model to generate appropriate security advice for the user using this data. The output is a specific response message provided to the user.
[0764] Step 4:
[0765] The server shares threat intelligence via a global information network. Inputs include characteristics of suspicious emails identified through analysis and user response data. Outputs are threat intelligence shared with other systems and organizations, thereby improving the overall security level.
[0766] Step 5:
[0767] The administrator monitors the system status using a terminal and adjusts settings as needed. Input is real-time log information generated within the system. Output is the adjusted security settings and the latest security status on the dashboard. Based on this, the administrator can take further security enhancements.
[0768] (Application Example 2)
[0769] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0770] Traditional email security systems could analyze the security of electronic messages received by users, but they lacked the nuanced approach that considered the emotions users felt towards emails. This made it difficult to implement specific security measures that addressed user anxieties and doubts, and there was a need for a system that could recognize users' emotions upon receiving emails and respond quickly.
[0771] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0772] In this invention, the server includes information processing means for monitoring email communications and analyzing received electronic messages in real time, emotion recognition means for monitoring user actions and recognizing emotional states, and response generation means for generating responses based on emotional states in response to user inquiries regarding the security of electronic messages. This makes it possible to quickly implement specific and appropriate security measures that take into account the user's emotions.
[0773] "Email communication" refers to the flow of messages sent and received electronically between users.
[0774] "Electronic messages" refer to information content transmitted in digital format, including email.
[0775] An "information processing device" refers to hardware or software used to analyze and process digital data and derive specific results.
[0776] "Natural language processing" refers to the technology that enables computers to understand, analyze, and generate human language.
[0777] A "suspicious electronic message" refers to an electronic message that the recipient deems potentially dangerous or fraudulent.
[0778] "Emotion recognition means" refers to technology or devices that detect and recognize emotional states from the user's actions, facial expressions, etc.
[0779] "Response generation means" refers to a technology or program for creating an appropriate response based on input information.
[0780] "Information exchange means" refers to communication methods or devices used to share data and information among multiple organizations.
[0781] "Display means" refers to output devices such as screens and projectors used to visually display information and data.
[0782] The system of this invention mainly consists of three elements: a server, a terminal, and a user. The server is equipped with an information processing device that monitors email communications and analyzes received electronic messages in real time. The server evaluates the content of electronic messages using natural language processing and determines security risks to the user. As a result, it identifies suspicious electronic messages and isolates them as necessary.
[0783] Furthermore, the server is equipped with emotion recognition capabilities, which analyze the user's actions and facial expressions to recognize their emotional state. Specifically, it uses the camera and sensors of smartphones and tablet devices to analyze emotions using generative AI models such as TensorFlow. Based on the emotional state, the server uses response generation capabilities to provide the user with appropriate security responses and advice.
[0784] Furthermore, the server shares threat information with other organizations through a global information sharing network via information exchange mechanisms, thereby improving the overall security level of the system. Administrators can monitor the system status and take action as needed through on-screen displays.
[0785] As a concrete example, when a user receives an unread email with the subject "Important Security Notice," the server analyzes the email's text content and uses emotion recognition to detect the user's fears and anxieties. Based on the results, a prompt appears on the user's screen stating, "This email may be suspicious. Please check the sender before opening."
[0786] Examples of prompt messages include: "Analyze the following email content and assess the security risks. If sentiment analysis reveals anxiety, provide a proposed response to the user."
[0787] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0788] Step 1:
[0789] The server monitors email communications and receives new electronic messages. At this point, the server extracts the email metadata and records basic information such as the sender, recipient, and subject. It takes received emails as input and prepares metadata information as output.
[0790] Step 2:
[0791] The server analyzes the body of electronic messages using natural language processing (NLP) techniques. Specifically, it uses an NLP library to input the email body as text data and performs analysis for risk assessment. As a result, it outputs an evaluation indicating whether the email content is safe or suspicious.
[0792] Step 3:
[0793] The server activates the emotion recognition system and collects user interaction data and facial expression data. It inputs data from the device's camera, microphone, and touch inputs into an emotion analysis model, which then outputs the analyzed emotional state. This model utilizes a generative AI model such as TensorFlow.
[0794] Step 4:
[0795] Based on the analyzed emotional state and email content evaluation, the server uses a response generation mechanism to create a message to be provided to the user. Specifically, if user anxiety is detected, it generates a warning message corresponding to that emotion and provides a user notification as output.
[0796] Step 5:
[0797] The server shares threat information with other organizations via information exchange mechanisms. It inputs data on email risk assessment and user sentiment, exchanges information with other systems in real time, and outputs an updated threat database.
[0798] Step 6:
[0799] The terminal displays the response message generated by the server to the user. For example, the prompt message "This email may be suspicious. Please verify the sender before opening it." is displayed on the screen to encourage the user to take appropriate action.
[0800] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0801] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0802] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.
[0803] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0804] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[0805] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[0806] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[0807] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[0808] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[0809] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[0810] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.
[0811] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.
[0812] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[0813] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0814] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[0815] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[0816] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[0817] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[0818] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[0819] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[0820] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.
[0821] The following is further disclosed regarding the embodiments described above.
[0822] (Claim 1)
[0823] An information processing device that monitors email communications and analyzes received electronic messages in real time,
[0824] An electronic processing means that evaluates the content of an electronic message using natural language processing,
[0825] Based on the analysis results, protective measures are in place to identify and isolate suspicious electronic messages.
[0826] A generation means for generating a response to an inquiry from a user regarding the security of electronic messages,
[0827] A means of exchanging information to share threat intelligence with other organizations via a global information sharing network,
[0828] A display means for administrators to monitor and operate the system status,
[0829] A system that includes this.
[0830] (Claim 2)
[0831] The system according to claim 1, characterized in that the information processing device has a function to extract metadata when it receives an electronic message and record the analysis results as a log.
[0832] (Claim 3)
[0833] The system according to claim 1, characterized in that the generation means includes security recommendations to the user in the generated response.
[0834] "Example 1"
[0835] (Claim 1)
[0836] An electronic computing device that monitors email communications and analyzes received electronic data in real time,
[0837] A data processing means for evaluating the content of electronic data using natural language processing,
[0838] Based on the analysis results, protective measures are in place to identify and isolate suspicious electronic data.
[0839] A generation means for generating responses to inquiries from users regarding the security of electronic data,
[0840] A means of exchanging information to share threat intelligence with other organizations via a global information sharing network,
[0841] A display means for administrators to monitor and operate the system status,
[0842] An analytical method that uses natural language processing technology and generative AI models to quantify and identify potential threats in received emails,
[0843] A generation means that generates a response including security recommendations for the user based on a generation AI model,
[0844] A system that includes this.
[0845] (Claim 2)
[0846] The system according to claim 1, characterized in that the information processing device has a function to extract metadata when it receives electronic data and to store the analysis results as a record.
[0847] (Claim 3)
[0848] The system according to claim 1, characterized in that the generation means includes security recommendations for the user in the generated response.
[0849] "Application Example 1"
[0850] (Claim 1)
[0851] An information processing device that monitors email communications and analyzes received electronic messages in real time,
[0852] Information processing means for evaluating the content of electronic messages using natural language processing,
[0853] Based on the analysis results, protective measures are in place to identify and isolate suspicious electronic messages.
[0854] A generation means for generating a response to an inquiry from a user regarding the security of electronic messages,
[0855] A means of exchanging information to share threat intelligence with other organizations via a global information sharing network,
[0856] A display means for administrators to monitor the system status,
[0857] An analysis means for analyzing electronic messages in real time in the background on a mobile terminal and evaluating their security, and a notification means for issuing a warning when suspicious content is detected,
[0858] A system that includes this.
[0859] (Claim 2)
[0860] The system according to claim 1, characterized in that the information processing device has a function to extract metadata when it receives an electronic message and to save the analysis results as a log in a recording device.
[0861] (Claim 3)
[0862] The system according to claim 1, characterized in that the generation means includes safety recommendations to the user in the generation response.
[0863] "Example 2 of combining an emotion engine"
[0864] (Claim 1)
[0865] An information processing means that monitors email communications and analyzes received electronic messages in real time,
[0866] An electronic processing means that evaluates the content of an electronic message using natural language processing,
[0867] Based on the analysis results, protective measures are in place to identify and isolate suspicious electronic messages.
[0868] An emotion recognition means that monitors user actions and analyzes emotional states,
[0869] A generation means for generating responses based on emotional states in response to user inquiries regarding the security of electronic messages,
[0870] A means of exchanging information to share threat intelligence with other organizations via a global information sharing network,
[0871] A display means for administrators to monitor and operate the system status,
[0872] A system that includes this.
[0873] (Claim 2)
[0874] The system according to claim 1, characterized in that the information processing means has a function to extract metadata when an electronic message is received and record the analysis results as a log.
[0875] (Claim 3)
[0876] The system according to claim 1, characterized in that the generation means includes security recommendations for the user in the generated response and provides personalized advice in accordance with the sentiment analysis results based on the user's actions.
[0877] "Application example 2 when combining with an emotional engine"
[0878] (Claim 1)
[0879] An information processing device that monitors email communications and analyzes received electronic messages in real time,
[0880] A processing means for evaluating the content of an electronic message using natural language processing,
[0881] Based on the analysis results, protective measures are in place to identify and isolate suspicious electronic messages.
[0882] An emotion recognition means that monitors the user's actions and recognizes their emotional state,
[0883] A response generation means that generates a response based on emotional state in response to a user's inquiry regarding the security of electronic messages,
[0884] A means of exchanging information to share threat intelligence with other organizations via a global information sharing network,
[0885] A display means for administrators to monitor and operate the system status,
[0886] A system that includes this.
[0887] (Claim 2)
[0888] The system according to claim 1, characterized in that the information processing device has a function to extract metadata when it receives an electronic message and to record the analysis results and emotional state as a log.
[0889] (Claim 3)
[0890] The system according to claim 1, characterized in that the generation means includes security recommendations and emotion-based advice to the user in the generated response. [Explanation of Symbols]
[0891] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>
Claims
1. An information processing device that monitors email communications and analyzes received electronic messages in real time, Information processing means for evaluating the content of electronic messages using natural language processing, Based on the analysis results, protective measures are in place to identify and isolate suspicious electronic messages. A generation means for generating a response to an inquiry from a user regarding the security of electronic messages, A means of exchanging information to share threat intelligence with other organizations via a global information sharing network, A display means for administrators to monitor the system status, An analysis means for analyzing electronic messages in real time in the background on a mobile terminal and evaluating their security, and a notification means for issuing a warning when suspicious content is detected, A system that includes this.
2. The system according to claim 1, characterized in that the information processing device has a function to extract metadata when it receives an electronic message and to save the analysis results as a log in a recording device.
3. The system according to claim 1, characterized in that the generation means includes safety recommendations to the user in the generation response.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A