Method for controlling external access to security information
The method addresses the risk of security information exposure in remote control by controlling and authenticating external access to sensitive data, thereby enhancing security and protecting personal and business secrets.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- JIRANDATA CO LTD
- Filing Date
- 2025-05-30
- Publication Date
- 2026-07-29
AI Technical Summary
Existing remote control technologies risk the unprotected exposure of security information, such as personal or business secrets, during computer-to-computer remote control due to unprocessed screen transmission.
A method for controlling external access to security information involves searching for and setting security data, monitoring access, blocking unauthorized access, and requiring authentication through a user interface with password entry and selective display based on internal access control.
Enhances security by preventing unauthorized access and protecting sensitive information during remote control operations.
Smart Images

Figure 2026525139000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an external access control method for security information.
Background Art
[0002] Security solutions are provided for a wide range of enterprise applications for Internet security, and the security solutions are used in a wide range of fields such as web security, email security, remote connection, electronic documents, and e-commerce applications.
[0003] Particularly, as computer and communication technologies have developed, the use of computers has expanded not only in various industrial fields but also in daily life. As a means of assisting not only general users who are inexperienced in using computers and the Internet but also industrial workers who handle a significant portion of their work using computers, computer-to-computer remote control technology has been developed and widely used.
[0004] Remote control is an operation in which a user of a control computer at a remote location operates a controlled computer connected to the Internet via the Internet. In this process, the screen information of the controlled computer is transmitted to the control computer, and the controlled computer is operated so that the user of the control computer can directly operate it. Naturally, the computer itself and peripheral devices including various output devices are caused to operate.
[0005] At this time, as the remote control progresses, the screen output to the monitor of the controlled computer is transmitted to the control computer, so that the user of the control computer can confirm the screen of the controlled computer in real time. Thus, in computer-to-computer remote control, since the screen of the controlled computer is transmitted to the control computer without being processed, there is a risk of leakage of security information such as personal information or business secrets of the user of the controlled computer output to the screen of the control computer.
Summary of the Invention
[0006] Therefore, the present invention was devised to solve the aforementioned problems and provides a method for controlling external access to security information that can prevent the unprotected exposure of security information during remote control.
[0007] Other objects of the present invention will become more apparent from the preferred embodiments described below. [Means for solving the problem]
[0008] According to one aspect of the present invention, a method for controlling external access to security information performed on a computing device is provided, which includes the steps of: searching for a file or program containing security information and setting it as security data when external control for maintenance is required; monitoring external access to the security data when the external control is performed; and blocking any attempted external access to the security data according to a predetermined criterion.
[0009] Here, the step of setting the security data includes the steps of searching for a file or program containing security information, displaying a security data setting interface screen containing the searched information, and setting the security data by user selection.
[0010] Additionally, security data is searched for in the current screen and running windows.
[0011] Furthermore, the security data will only be displayed if the external control is required under the control of the internal access performed after login.
[0012] Furthermore, under the control of internal access, a first user interface screen is displayed in which security data can be set, and under the control of external access, a second user interface screen is displayed in which the security data is specifically displayed and which includes an interface for accessing the security data with the permission of the internal access user.
[0013] Furthermore, when access to security data is requested through the second user interface screen, access is granted only if security authentication is successful, based on whether or not a pre-set password can be entered via the keyboard using the internal access.
[0014] Furthermore, monitoring images are saved through capture of the second user interface screen via external access, the monitoring images of the external access are displayed on the user interface screen for password input, and only monitoring images from a certain period of time prior to an external access request to security data are extracted and displayed.
[0015] Furthermore, in the second user interface screen, the security data is concealed only when the mouse is operated.
[0016] Furthermore, as the second interface screen, a dialogue window between an internal access user and an external access user is displayed in one area.
[0017] Other aspects, features, and advantages not mentioned above will become apparent from the following drawings, claims, and detailed description of the invention. [Effects of the Invention]
[0018] According to the present invention, security can be enhanced by monitoring and controlling external connections to security information, thereby blocking unprotected access by external users. [Brief explanation of the drawing]
[0019] [Figure 1] A configuration diagram schematically showing an overall system for external access control of security information during remote control according to an embodiment of the present invention.
[0020] [Figure 2] A flowchart showing an external access control process for security information performed by a computing device according to an embodiment of the present invention.
[0021] [Figure 3] A flowchart showing an external access processing process for security data during remote control according to an embodiment of the present invention.
[0022] [Figure 4] An exemplary diagram showing a second user interface screen for remote control according to each embodiment of the present invention. [Figure 5] An exemplary diagram showing a second user interface screen for remote control according to each embodiment of the present invention.
Mode for Carrying Out the Invention
[0023] The present invention can be modified in various ways and can have various embodiments. Therefore, specific embodiments are illustrated in the drawings and described in detail in the detailed description. However, this is not intended to limit the present invention to specific embodiments, and it should be understood that it includes all modifications, equivalents, or alternatives included in the spirit and technical scope of the present invention.
[0024] When one component is said to be "connected" or "linked" to another component, it should be understood that it is either directly connected to the other component, or may be connected to it, but there may be other components in between. On the other hand, when one component is said to be "directly connected" or "directly linked" to another component, it should be understood that there are no other components in between.
[0025] Terms such as "first," "second," etc., can be used to describe various components, but the components should not be limited by such terms. The terms are used solely for the purpose of distinguishing one component from another. For example, terms such as "first threshold" and "second threshold," described later, may be substantially different or partially the same threshold value, but because there is room for confusion when expressed with the same word "threshold," terms such as "first," "second," etc., will be used together for the sake of distinction.
[0026] The terms used herein are used solely to describe specific embodiments and are not intended to limit the invention. A singular expression includes plural expressions unless the context clearly indicates otherwise. In this specification, terms such as “includes” or “having” are intended to indicate the presence of features, figures, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood not to preemptively exclude the possibility of the presence or addition of one or more other features, figures, steps, actions, components, parts, or combinations thereof.
[0027] Furthermore, the components of the embodiments described with reference to each drawing are not limited to those embodiments, and may be implemented in a manner that is included in other embodiments as long as the technical idea of the present invention is maintained. It is also natural that multiple embodiments may be reimplemented into a single integrated embodiment, even if a separate explanation is omitted.
[0028] In the description with reference to the attached drawings, identical components will be given the same or related reference numerals regardless of the numerals used in the drawings, and redundant explanations will be omitted. In the description of the present invention, if it is determined that a specific explanation of related prior art may unnecessarily obscure the gist of the present invention, such detailed explanation will be omitted.
[0029] Figure 1 is a schematic diagram showing the overall system for controlling external access to security information during remote control according to one embodiment of the present invention, and Figure 2 is a flowchart showing the process of controlling external access to security information performed by a computing device according to one embodiment of the present invention.
[0030] Referring to Figure 1, the entire system includes a target computer 10 and a remote control computer 30. The target computer 10 has a security agent 12 installed in the form of an application program to control access to security information from the remote control computer 30.
[0031] Remote access by users must be controlled to files or programs containing security information, such as personal information and confidential information, that should only be accessible to authorized users (hereinafter referred to as security data).
[0032] The remote control computer 30 connects to the target computer 10 via a communication network such as the Internet and controls it remotely. In other words, another user, not an internal user of the target computer 10, uses the target computer 10 remotely. Generally, the remote control program periodically captures the screen of the target computer 10 and transmits it to the remote control computer 30, which then controls the target computer 10 by remotely manipulating the mouse pointer while viewing the received screen or by input via the keyboard. Of course, this is just one example, and any method of remote control can be used.
[0033] However, the security agent 12 installed on the target computer 10 controls (blocks or allows access to security data with the permission of the target computer 10 user) the remote control computer 30.
[0034] Referring to Figure 2, which shows the external access control process performed on the target computer 10, when external control is requested for purposes such as maintenance, S210 searches for files or programs containing security information and sets them as security data.
[0035] For example, security data can be automatically configured by searching for files or application programs containing personal information such as My Number (Japanese social security number) and address. For another example, files or programs containing security information can be searched for, a security data setting interface screen containing the searched information can be displayed, and the security data can be set by the user's selection. In other words, the target computer 10 provides a user interface screen that allows the user to directly select and set security data based on information that has been searched for and identified as security data, or allows the user to directly search for and set security data. A user interface that allows a user to set any specific file stored on the target computer 10 or installed program as security data is obvious to those skilled in the art, so a more detailed explanation is omitted.
[0036] For example, the target computer 10 can determine whether all files or applications are security data, but for efficient processing, it can determine whether only files and applications present on the current screen and running windows are security data, which can be done periodically or whenever a change in the screen or running window occurs.
[0037] When security data is set, S220 proceeds with external control and displays a second user interface screen that specifically displays the security data. In other words, the target computer 10 displays the first user interface screen under internal access control, and when external control is performed, it displays a second user interface screen that specifically displays the security data. Referring to Figure 4, for example, on the second user interface screen, the security data (security file 1) is visually processed with a red block so that the target computer user (hereinafter referred to as the internal user) and the remote control user recognize that it is security data.
[0038] For example, security data is only displayed when external control is requested under the control of internal access after a login procedure has been performed. In other words, when external control is performed without an internal login procedure, rather than when external control is requested while the target computer 10 is under control after a user has logged in, all security data is hidden. This prevents the indiscriminate leakage of security data from occurring when external control is performed without an internal user, and security data is only visible to the remote control user when an internal user is present. For the remote control user to access security data, permission procedures must be performed for the internal user. This will be explained in detail later.
[0039] The S230 monitors external access via external control. For example, it periodically captures and saves screens to monitor whether remote users attempt to access security data.
[0040] When external access to security data is detected, S240 performs control actions such as blocking the access or querying the internal user.
[0041] Figure 3 is a flowchart showing the external access processing process for security data during remote control according to one embodiment of the present invention, and Figures 4 and 5 are illustrative diagrams showing the second user interface screen for remote control according to each embodiment of the present invention.
[0042] Referring to Figure 3, external control is performed, and when access to security data is recognized by the external control, S310 requests authentication from the internal access user, S320. Referring to Figure 5, when external access is requested to security file 1, which is security data (for example, a mouse click on security file 1 by external control), an authentication window 430 is displayed that can be verified by the internal access user.
[0043] In this case, for example, a monitoring image 440 of external access is displayed on the user interface screen for password entry. That is, the internal access user is provided with saved monitoring images as a video so that they can immediately see what kind of history the external access user has when attempting to access security data. Here, for quick verification, only monitoring images from a certain period of time before the external access request to the security data (e.g., 20 seconds or 1 / 3 of the total length) are extracted and displayed, but the playback speed is varied according to the video playback time (e.g., the longer the playback time, the faster the playback speed).
[0044] S330 performs authentication by determining whether or not a password is entered via the internal keyboard (i.e., the keyboard of the target computer 10) through the authentication window 430.
[0045] If authentication is successful, S340 will allow external access to the security data; if authentication fails, S350 will deny access (for example, by displaying an access denied message on the screen).
[0046] Furthermore, referring to Figure 5, in the second user interface screen, security data is hidden when the mouse is being operated. That is, when the mouse pointer is being moved by external control, the security data is hidden, and the security data is only displayed when the mouse pointer is not being operated. Of course, this is just one example, and it is also possible to display the security data only when the mouse pointer is being operated.
[0047] Furthermore, a second interface screen, a dialogue window 510 between internal and external access users, is displayed in one area, allowing for dialogue between the two parties, such as inquiring about the permission to access security data.
[0048] A computer program stored on a computer-readable medium that executes the external access control method for security information according to the present invention described above can be provided.
[0049] Furthermore, the aforementioned external access control methods for security information can be implemented as computer-readable code on computer-readable recording media. Computer-readable recording media include all types of recording media that store data that can be deciphered by a computer system. Examples include ROM (Read Only Memory), RAM (Random Access Memory), magnetic tape, magnetic disks, flash memory, and optical data storage devices. Moreover, computer-readable recording media can be distributed across computer systems connected by a computer communication network and stored as distributed readable code.
[0050] Furthermore, although preferred embodiments of the present invention have been described above with reference to those described above, a person with ordinary skill in the art will understand that the present invention can be modified and altered in various ways without departing from the spirit and scope of the invention as described in the claims below.
Claims
1. In an external access control method performed on a computing device, When external control is required for maintenance, the process involves searching for files or programs containing security information and setting them as security data. Once the aforementioned external control is performed, the steps include monitoring external access to the security data, The step includes blocking any attempts to access the security data externally based on pre-configured criteria, The security data is displayed only when the external control is required under the control of the internal access performed by the login. Under the control of the internal access, a first user interface screen is displayed in which security data can be set; under the control of the external access, a second user interface screen is displayed in which the security data is specifically displayed and which includes an interface for accessing the security data with the permission of the internal access user. The second user interface screen provides an external access control method for security information in which the security data is concealed only when the mouse is operated.
2. The step of setting the aforementioned security data is: The steps include searching for files or programs that contain security information, The steps include: displaying the searched information as the first user interface screen; A method for controlling external access to security information according to claim 1, comprising the step of setting security data by user selection.
3. A method for controlling external access to security information according to claim 2, which searches for security data targeting the current screen and execution window.
4. The method for controlling external access to security information according to claim 1, wherein when access to security data is requested through the second user interface screen, access is permitted only if security authentication is successful by determining whether or not a pre-set password can be entered via the keyboard through internal access.
5. The monitoring image is saved through capture of the second user interface screen via external access. The method for controlling external access to security information according to claim 4, which displays a monitoring image of the external access on the user interface screen for password input.
6. The method for controlling external access to security information according to claim 5, which extracts and displays only monitoring images taken during a certain period of time prior to an external access request to security data.
7. The method for controlling external access to security information according to claim 1, wherein a dialogue window between an internal access user and an external access user is displayed in one area as the second user interface screen.
8. A computer program stored on a computer-readable medium that causes a computer to perform an external access control method for security information, wherein the computer program causes the computer to perform the following steps, the steps being: When external control is required for maintenance, the process involves searching for files or programs containing security information and setting them as security data. Once the aforementioned external control is performed, the steps include monitoring external access to the security data, The step includes blocking any attempts to access the security data externally based on pre-configured criteria, The security data is displayed only when the external control is required under the control of the internal access performed by the login. Under the control of the internal access, a first user interface screen is displayed in which security data can be set; under the control of the external access, a second user interface screen is displayed in which the security data is specifically displayed and which includes an interface for accessing the security data with the permission of the internal access user. The second user interface screen includes a computer program stored on a computer-readable medium in which the security data is concealed only when the mouse is operated.