Computer-implemented method, computer system, computer program, and computer-readable medium

The secure smart container system provides enhanced data access control by authenticating users, decrypting data based on behavior, and monitoring access to prevent unauthorized activities, addressing vulnerabilities in traditional access control methods.

JP7730237B2Active Publication Date: 2025-08-27INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2021178558
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-12-10
Filing Date
2021-11-01
Publication Date
2025-08-27
Estimated Expiration
2041-11-01

AI Technical Summary

Technical Problem

Traditional data access control methods, such as public key cryptography and user-based access control, fail to prevent unauthorized access and illicit activities by authorized users, necessitating a more robust security solution.

Method used

A secure smart container system that instantiates on a user's endpoint device, authenticates user credentials, decrypts data based on user behavior, and monitors access to prevent unauthorized activities.

Benefits of technology

Ensures secure and controlled access to data by encrypting unused data, monitoring user behavior, and preventing unauthorized access throughout the access period, enhancing data protection beyond initial authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007730237000002
    Figure 0007730237000002
  • Figure 0007730237000003
    Figure 0007730237000003
  • Figure 0007730237000004
    Figure 0007730237000004
Patent Text Reader

Abstract

To provide secure smart containers for controlling access to data.SOLUTION: A computer system controls access to data. A secure container that is based on an image file is instantiated at an endpoint of a user (410), where the secure container includes encrypted data corresponding to the user. An access request to the secure container is authenticated by verifying credentials of the user (420). In response to verifying (420) the credentials of the user, access to the data is granted (440). Access to the data is controlled by decrypting and enabling access to a portion of the data, where additional portions of the data are decrypted and made accessible based on user behavior.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to data access, and more particularly to a secure smart container for storing data and controlling access to the stored data. [Background technology]

[0002] Users often exchange data that is considered sensitive, confidential, or otherwise worth protecting from others. Traditional solutions for controlling access to data, such as public key cryptography and user-based access control, have varying strengths and vulnerabilities. However, traditional approaches cannot address security threats posed when unauthorized individuals gain access to data or when authorized users begin to engage in illicit activity. For example, a member of an organization may decide to reveal the organization's password-protected trade secrets, or a hacker may gain access to encrypted data through unauthorized means. Therefore, a method that extends protection to accessible data is required that not only prevents unauthorized access but also controls access to the data. Summary of the Invention [Problem to be solved by the invention]

[0003] The present invention aims to provide a secure smart container for controlling access to data. [Means for solving the problem]

[0004] According to one embodiment of the present disclosure, a computer system controls access to data. A secure container based on an image file is instantiated on a user's endpoint device, the secure container containing encrypted data corresponding to the user. A request for access to the secure container is authenticated by verifying the user's credentials. In response to verifying the user's credentials, access to the data is granted. Access to the data is controlled by decrypting and making accessible a portion of the data, and additional portions of the data are decrypted and made accessible based on user behavior.

[0005] Generally, like reference numbers in the various drawings are used to indicate like components. [Brief explanation of the drawings]

[0006] [Figure 1] FIG. 1 is a block diagram illustrating a computing environment for data access control according to one embodiment of the present disclosure. [Figure 2] FIG. 2 is a block diagram illustrating a computing system for data access control according to one embodiment of the present disclosure. [Figure 3] FIG. 3 is a flowchart illustrating a method for creating a data container according to one embodiment of the present disclosure. [Figure 4] FIG. 4 is a flow chart illustrating a method for accessing data stored in a data container according to one embodiment of the present disclosure. [Figure 5] FIG. 5 is a flowchart illustrating a method for detecting data access violations according to one embodiment of the present disclosure. [Figure 6] FIG. 6 is a block diagram illustrating a computing device according to one embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0007] FIELD OF THE DISCLOSURE Embodiments of the present disclosure relate to data access, and more particularly, to a secure smart container that stores data and controls access to the stored data. A container is a software package that can contain code for applications and other data. Designed for portability, containers typically contain dependencies for any included applications, allowing containerized applications to run quickly and reliably across various computing environments. In addition to supporting application execution, containers can also store any desired data. For example, a container can contain data in a proprietary format, allowing users to access the data in the proprietary format through applications included in the container.

[0008] A container can be instantiated from an image file, which can be transferred between computing devices, for example, via email. Instantiating a container on a computing device exposes a virtualized file system and virtualized file to a user. The virtualized file system can store any data desired to be protected in cryptographic form and includes executable code for an enforcement engine that allows authorized users to access the data while additionally monitoring access. The enforcement engine can control access to the data based on various factors, such as the nature of the access, the computing environment, the user's identity, or user behavior, or a combination of these.

[0009] Thus, embodiments of the present disclosure enable secure sharing and access of data while extending protection to the data during an access event. In particular, data not currently being accessed remains encrypted, and even authorized users can only access the portion of the data that the user is authorized to access at a time. Furthermore, as users access data, their behavior is monitored to identify any suspicious behavior, such as accessing more data than reasonably necessary at one time to support a specific use case or searching for suspicious keywords within the data. In other words, embodiments of the present disclosure improve data access control in practical applications by extending protection not only at the initial stage of access but throughout the entire period a user has access to data.

[0010] References to features, advantages, or similar language throughout this specification do not imply that all of the features and advantages realized in the embodiments disclosed herein are to be found in or inherent in any single embodiment disclosed. Rather, language referring to features and advantages is understood to mean that the particular feature, advantage, or characteristic disclosed in connection with an embodiment is included in at least one embodiment of the present disclosure. Thus, throughout this specification, discussions of features, advantages, and similar language may, but do not necessarily, refer to the same embodiment.

[0011] Furthermore, the described features, advantages, and characteristics of the present disclosure may be combined in any suitable manner in one or more embodiments. Those skilled in the relevant art will understand that the present disclosure can be practiced without one or more of the specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be realized in certain embodiments that may not appear in all embodiments of the present disclosure.

[0012] These features and advantages will become more fully apparent from the following drawings, description and appended claims, or may be learned by the practice of embodiments of the present disclosure as set forth below.

[0013] Embodiments of the present disclosure will now be described in detail with reference to the drawings. FIG. 1 is a block diagram illustrating a computing environment for controlling access to data according to an embodiment of the present disclosure. As shown, computing environment 100 includes a first client device 105A, one or more additional client devices 105B-105N, and a network 150. It should be understood that the functional division among the components of computing environment 100 has been selected for purposes of illustrating embodiments of the present disclosure and is not to be construed as a limiting example.

[0014] Each of client devices 105A-105N includes a network interface (I / F) 106, at least one processor 107, and memory 110 containing a host application 115. Client devices 105A-105N may include a laptop computer, a tablet computer, a netbook computer, a personal computer (PC), a desktop computer, a personal digital assistant (PDA), a smartphone, a thin client, or any programmable electronic device capable of executing computer-readable program instructions. Network interface 106 enables components of each of client devices 105A-105N to send and receive data over a network, such as network 150. Generally, client devices 105A-105N enable users to share data containers and access data in a controlled manner. For example, a user of client device 105A can add data to a container, which is securely stored as an image file and can be transferred to another device, such as client device 105B, for access by another user. Client devices 105A-105N each include internal and external hardware components as shown and described in more detail with reference to FIG.

[0015] The host application 115 may include one or more modules or units for performing various functions of the embodiments of the present disclosure, as described below. The host application 115 may be implemented by any number and combination of software modules, hardware modules or units, or both. The host application 115 may reside in memory 110 of any of the client devices 105A-105N for execution by a processor, such as processor 107.

[0016] In some embodiments, the host application 115 allows a user to create a secure container and add data to the container. A user of the client device 105A can define the container according to one or more parameters, such as the size of the container, the file system type of the container, and the data encryption type for the data to be securely stored within the container. Additionally, when a user creates a container through the host application 115, the user can select options to define which actions or occurrences constitute data access violations. For example, the container's enforcement engine can detect access violations and subsequently prevent the user from accessing the data if the container is instantiated in an unauthorized computing environment, if the user attempts to search for the data using specific words or phrases, or if the user attempts to access the data at a rate that exceeds any reasonable use case. Once the user finalizes the configuration for the container, data can be added to the container and user access permissions for the data can be defined. For example, the data can be encrypted so that different users can access different portions of the data using unique passwords or access keys. When a container is finalized, an image file corresponding to the container may be saved to a non-volatile storage medium, such as storage 120. Container creation is shown and described in more detail with respect to FIG.

[0017] Once a container image file is created, the user of client device 105A can share it with other users or devices, such as client devices 105B-105N, or both. The container image file can be transferred via conventional or other data transfer techniques, such as file transfer over a communications network (e.g., network 150) or physical transport of the image file using a removable storage device. When the image file is received by another computing device, such as client device 105B-105N, the image file is instantiated as a container, and once the user is authenticated, the secure data can be accessed on the computing device. Client devices 105B-105N can include other users' client devices, other client devices associated with the creator of the container (e.g., the user of client device 105A), or both. When a data access session is completed, any changes to the data can be saved to the image file, which can then be distributed to additional users and / or computing devices. In some embodiments, users can collaborate by sharing links to image files stored in network-accessible locations. Data access within a data container is illustrated and described in further detail below in connection with Figures 2 and 4.

[0018] Storage 120 may include any non-volatile storage medium known in the art, and may be implemented with a tape library, an optical library, one or more hard disk drives, or multiple disk drives in a redundant array of independent disks (RAID). Similarly, data in storage 120 may conform to any storage architecture known in the art, such as files, a relational database, an object-oriented database, one or more tables, or a combination thereof. In some embodiments, storage 120 stores data related to image files, computing environment data (e.g., operating system data, program data, metadata such as version information, etc.), data being added to or obtained from containers, etc.

[0019] Network 150 may include a local area network (LAN), a wide area network (WAN) such as the Internet, or a combination of the two, and may include wired, wireless, or fiber optic connections. In general, network 150 may be any combination of connections and protocols known in the art that support communication between client devices 105A-105N via their respective network interfaces, according to embodiments of the present disclosure.

[0020] 2 is a block diagram illustrating a computing system 200 for controlling access to data, according to an embodiment of the present disclosure. As shown, computing system 200 includes a client device 205, a network interface 206, a processor 207, memory 210, and storage 240. Memory 210 includes an operating system 212, a host application 215, a container 220 including an enhancement engine 225 and encrypted data 230, and accessible data 235. Storage 240 may include one or more image files, such as image file 245.

[0021] The client device 205 can be implemented by any of the client devices 105A-105N of the computing environment 100, as shown and described in more detail with reference to FIG. 1. The client device 205 can include a laptop computer, a tablet computer, a netbook computer, a personal computer (PC), a desktop computer, a personal digital assistant (PDA), a smartphone, a thin client, or any programmable electronic device capable of executing computer-readable program instructions. The network interface 206 enables components of the client device 205 to send and receive data over a network. In general, the client device 205 allows a user to access a secure data container. The client device 205 includes internal and external hardware components, as shown and described in more detail with reference to FIG. 6.

[0022] The operating system 212, the host application 215, the container 220, and the enhancement engine 225 may include one or more modules or units for performing various functions of the embodiments of the present disclosure, as described below. The operating system 212, the host application 215, the container 220, and the enhancement engine 225 may be implemented by any number or combination of software modules, hardware modules or units, or both, and may reside in the memory 210 of any client device 205 for execution by a processor, such as the processor 207.

[0023] Operating system 212 may include any conventional or other operating system for a computing device, such as a Microsoft® Windows® or Linux® distribution. Host application 215 is installed within operating system 212 to integrate instantiated containers into operating system 212 and provide them as a virtualized file system.

[0024] The host application 215 enables the creation of image files and the instantiation of image files as containers. The host application 215 can be a daemon process that uses one or more application programming interfaces (APIs) to allow the containerized application to interact with software outside the container, such as the operating system 212 of the client device 205, any applications installed on the client device 205, or both. When the host application 215 instantiates a container, such as container 220, the container is integrated into the operating system 212 of the client device 205 as a virtualized file system, virtualized folder, network drive, or any conventional or other form of data medium. In some embodiments, accessible data is presented to the user of the client device 205 using operating system integration components, such as drivers (e.g., FUSE for macOS®) or virtualized file systems.

[0025] Container 220 is a secure data container instantiated in memory 210 of client device 205 by host application 215, allowing users to access executable files and data stored within container 220. Container 220 is instantiated based on an image file, such as image file 245. Container 220 can include encrypted data 230 and portions that are unencrypted and include hardening engine 225. In some embodiments, container 220 includes an operating system separate from operating system 212 and / or any protected areas necessary for hardening engine 225 to perform aspects of embodiments of the present disclosure. For example, container 220 can include a lightweight operating system such as CentOS™, Amazon® Elastic File System, VeraCrypt, or a combination thereof.

[0026] The enforcement engine 225 resides in the unencrypted portion of the container 220 and includes executable code for verifying user access to data present in the encrypted data 230. Additionally, the enforcement engine 225 monitors user access control to the data and performs security operations as necessary. The enforcement engine 225 can access components of the client device 205 outside of the container 220 via the host application 215. For example, the enforcement engine 225 can access peripherals of the client device 205 to track user input, access other portions of the memory 210 to detect malicious or other software running on the client device 205, access the storage 240 to identify stored data, etc.

[0027] When an authenticated user registers a key to access the encrypted data, the enhancement engine 225 can verify the key, process the encrypted data 230, decrypt some or all of the data, and provide the decrypted data to memory as accessible data 235. In some embodiments, the accessible data 235 is provided to the operating system 212 of the client device 205 by visualizing the accessible data 235 as a network connection or data stream. The accessible data 235 can be presented as a virtualized drive separate from the virtualized drive of the container 220, or the accessible data 235 can be presented within the same virtualized drive as the container 220. The enhancement engine 225 can place only a portion of the encrypted data 230 as accessible data 235 at a time, thereby preventing a user from accessing the entire data contained within the encrypted data 230. When the user finishes accessing the current portion of data, the accessible data 235 can be refreshed with the next portion of data by decrypting the next portion from the encrypted data 230 and converting it into accessible data 235.

[0028] When a user registers a key to request access to data, the enforcement engine 225 can verify other aspects of the access request. In some embodiments, the enforcement engine 225 authenticates the request based on the computing environment of the client device 205. For example, access control settings for a container can dictate that the container can only be accessed from certain devices, which can be defined by a host name, Media Access Control (MAC) address, Internet Protocol (IP) address, or other unique software- or hardware-based identifier. In some embodiments, the enforcement engine 225 can grant access to secure data based on the geographic location of the client device 205, which can be obtained using a Global Positioning System (GPS), radio tower triangulation, or the like. For example, if a user can access data within a container only if they are located in a particular city, state, or country, the presence of the client device 205 in a certain location can prevent data access. In some embodiments, the reinforcement engine 225 compares the current access location with a previous access location, which may include comparing a geographic location, a logical location (e.g., a computing environment), or both. Thus, for example, the reinforcement engine 225 may block access if the current access location exceeds a threshold amount of distance from the previous access location, or if the container was previously accessed using a different operating system, or both.

[0029] The reinforcement engine 225 can monitor user interaction with accessible data 235 to control access to the data. If the reinforcement engine 225 determines that an access violation has occurred (e.g., any unauthorized access to data), the reinforcement engine 225 can take action to prevent subsequent user access to accessible data 235. In various embodiments, the reinforcement engine 225 can determine that an access violation has occurred if a user searches for a particular word or phrase included in a list, if the user attempts to access data too quickly, etc. The reinforcement engine 225 can use rules-based scoring of user behavior to determine that an access violation has occurred if the user's behavior generates a total risk score above a predetermined threshold.

[0030] Storage 240 can include any non-volatile storage medium known in the art. For example, storage 240 can be implemented with a tape library, an optical library, one or more hard disk drives, or multiple hard disks in a redundant array of independent disks (RAID). Similarly, data in storage 240 can follow any suitable storage architecture known in the art, such as a file, a relational database, an object-oriented database, or one or more tables. In some embodiments, storage 240 stores data associated with one or more image files, such as image file 245. When a user unmounts container 220, any changes to the protected data are saved, and image file 245 is updated accordingly. When a user unmounts container 220, an access log containing timestamps of any read and write operations corresponding to the protected data is updated. Version control can be implemented by providing version numbers for changes to the container.

[0031] FIG. 3 is a flow chart illustrating a method 300 for creating a data container according to one embodiment of the present disclosure.

[0032] Image file generation begins at operation 310. A user can request a new image file to be generated by defining the characteristics of the resulting container, such as the container's data size, encryption settings for the encrypted data portion of the container, operating system settings for the container, a name for the container if possible, and other settings such as any executable files to be included in the container. The user can also define file system settings for any virtualized file systems provided by the container.

[0033] Data is added to the image file in operation 320. A user can include any data they wish to protect in an image file. In some embodiments, a user can add data organized into directories that can contain multiple files and folders.

[0034] Access control settings, including user credentials, user permissions, or access violation settings, or a combination thereof, are configured in operation 330. The image file creator can add user accounts that can access the container, along with a corresponding access key for each account. In some embodiments, each user account can include one or more of the user's account name, username (e.g., legal name or nickname), job or role within the organization, data access time limit or expiration date, and unique access key. Rules can be established for user account permissions on a file-by-file basis. For example, if a container contains 200 sequentially numbered files, a first user can access files 1 through 100, a second user can only access files 6 through 9, and a third user can access all 200 files. In some embodiments, rules can be established taking into account the nature of access to files. For example, a first user can have read access, and a second user can have read and write access. In some embodiments, documents can be tiered according to increasing levels of sensitivity, and access levels can be defined for each user account, allowing users to access any data at or below their access level.

[0035] The data is encrypted and the finalized image is saved in operation 340. Any data for which protection is desired is encrypted and the image is finalized by adding executable code, such as code for the hardening engine 225, any protected areas, operating system modes, etc. The resulting image file can be saved in non-volatile storage for subsequent transmission and / or use.

[0036] FIG. 4 is a flow chart illustrating a method 400 for accessing data stored in a data container, according to one embodiment of the present disclosure.

[0037] The container is instantiated in operation 410. A user of a computing device, such as client device 105A-105N, obtains or receives an image file to be instantiated into the container through a host application installed on the user's computing device. In some embodiments, the image file is stored locally on the computing device, and in other embodiments, the image file may be located in a network-accessible location.

[0038] An access key is received in operation 420. Initially, an access key can be created when a new image file is created, when a new authorized user is added to the container, or both. The creator or another authorized individual can issue the access key to an authorized user. For example, a user can be provided with their access key through a different communication channel than the way the user accesses the image file. When a user instantiates a container, the virtualized file system is mounted on the user's computing device, and the enforcement engine 225 begins execution and notifies the user to provide an access key. Additionally or alternatively, the enforcement engine 225 can obtain details related to the local environment of the computing device where the access request originates, such as the operating system of the computing device or the geographic location of the computing device.

[0039] Operation 430 determines whether the access request satisfies all access requirements. In some embodiments, the user's access key is validated. Additionally, or alternatively, information collected about the local environment can be validated by the enforcement engine 225. For example, the enforcement engine 225 can verify that the container was instantiated on the same computing device on which the container was previously accessed, or that the container was instantiated on a computing device in another country.

[0040] If the access request, including the access key and any other requirements, satisfies the access requirements, access to the data is granted in operation 440. The enforcement engine 225 decrypts portions or all of the encrypted data and makes the data available to authorized users. Accessible data can be created in an ad-hoc manner as files presented in a virtualized file system. While the data is accessible to the user, computing device activity and user behavior can be monitored and analyzed by the enforcement engine 225 to protect the protected data.

[0041] In some embodiments, multiple portions of encrypted data are accessible at one time, and when a user finishes a particular portion, subsequent portions are made available. Thus, the entirety of the protected data is never exposed to memory at any given time. For example, a user reading or editing a text file may reach the end of a portion of the file and be instructed to close and reopen the file. When the user closes the file, the hardening engine 225 can overwrite the file in the virtualized file system with data corresponding to the subsequent portion of the protected data. In some embodiments, the hardening engine 225 virtualizes the source of the data accessible as a stream of network data, allowing applications to access and present data without otherwise being able to open the missing file.

[0042] If the access requirements are not met, access to the data is denied in operation 450. In some embodiments, a user may be blocked from attempting to access the data after one or more failed attempts. In some embodiments, if access to the data is denied, the container may be unmounted from the computing device. The hardening engine 225 may perform additional security operations, such as deleting encrypted data or deleting image files upon unmounting the container. In this manner, the container may self-destruct to protect the data.

[0043] In some embodiments, the user may provide an alternative key at operation 420 that is not an access key but is an anomaly code or other anomaly indicator. For example, instead of the user entering an access key, the user may enter a string of zeros indicating that the user is under duress. When an anomaly indicator is received, the enforcement engine 225 may display counterfeit data that appears authentic but is not the actual data to be protected by the container. The counterfeit data may be completely different from the actual data or may be based on the actual data. The counterfeit data may be uniquely identified by the insertion of a secret phrase or watermark so that if the counterfeit data is leaked, the identity of the source, the perpetrator, or both, may be identified.

[0044] FIG. 5 is a flow chart illustrating a method 500 for detecting data access violations, according to one embodiment of the present disclosure.

[0045] In operation 510, access to data is monitored. If the user's access to the container is verified, the enforcement engine 225 monitors user behavior by tracking the user's read and / or write operations on the operating system of the user's computing device or on the accessible data. The enforcement engine 225 can continuously monitor for any suspicious or potentially suspicious activity as long as the protected data is accessible to the user.

[0046] Operation 520 determines whether an unauthorized access event has occurred. Using a rules-based approach, the enrichment engine 225 can determine when an unauthorized event has occurred. Rules can be defined for the creation of an image file and can include rules for any activity, such as a user searching for a word or phrase that appears in a suspicious search list, a copy-and-paste operation, saving accessed data to a hard drive, or transferring accessed data via email. In some embodiments, traditional or other machine learning techniques can be applied by training a model to detect suspicious user behavior and generate rules for detecting unauthorized access events accordingly. If no unauthorized access has occurred, the enrichment engine continues monitoring at operation 510.

[0047] A risk subscore corresponding to the access event is determined in operation 530. In some embodiments, events can be scored according to their severity, such that different risk subscore values ​​are associated with different unauthorized access events. For example, risk subscores can be provided according to Table 1.

[0048] [Table 1]

[0049] Operation 540 determines whether the total risk score meets a predetermined threshold. In particular, the total risk score is calculated by summing each of the risk subscores and comparing the total risk score to a predetermined threshold. If the total risk score does not meet the threshold, then the enrichment engine 225 continues to monitor data access and, in the event that further unauthorized access is detected, updates the total risk score again after each unauthorized access event. In some embodiments, the total risk score decays over time.

[0050] In the event that the total risk score meets a threshold, further access to the data is prevented in operation 550. In various embodiments, falsified data can be presented to the user, the container can be unmounted, and the user's access key can be revoked or the image file can be automatically deleted.

[0051] 6 is a block diagram illustrating components of a computer 10 suitable for implementing the methods disclosed herein. The computer 10 may be implemented as a client device 105A-105N, a client device 205, or both, according to embodiments of the present disclosure. FIG. 6 is illustrative of only one embodiment and is not intended to imply any limitation with respect to the environments in which different embodiments may be implemented. Many modifications to the illustrated embodiment are possible.

[0052] As shown, computer 10 includes a communications mechanism 12 that provides communication between computer processor(s) 14, memory 16, persistent storage 18, communications unit 20, and input / output (I / O) interface(s) 22. Communications mechanism 12 may be implemented as any architecture designed to pass data and / or information between processors (such as multiple microprocessors, communications processors, and network processors), system memory, peripheral devices, and any other hardware components within a system. For example, communications mechanism 12 may be implemented with one or more buses.

[0053] Memory 16 and persistent storage 18 are computer-readable storage media. In the illustrated embodiment, memory 16 includes random access memory (RAM) 24 and cache memory 26. In general, memory 16 may include any suitable volatile or non-volatile computer-readable storage media.

[0054] One or more programs may be stored in persistent storage 18 for execution by one or more respective computer processors 14 via one or more memories 16. Persistent storage 18 may be a magnetic hard disk, solid state hard drive, semiconductor storage device, read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, or any other computer-readable recording medium capable of storing program instructions or digital information.

[0055] The media used by persistent storage 18 can also be removable. For example, a removable hard drive can be used as persistent storage 18. Other examples include optical and magnetic disks, thumb drives, and smart cards that are inserted into a drive for transfer onto another computer-readable recording medium that is also part of persistent storage 18.

[0056] Communications unit 20, in these embodiments, provides for communications with other data processing systems or devices. In these embodiments, communications unit 20 includes one or more network interface cards. Communications unit 20 may provide communications through either or both physical or wireless communications links.

[0057] I / O interface(s) 22 allow for the input and output of data to and from other devices that may be connected to computer 10. For example, I / O interface 22 may provide connection to external devices 28, such as a keyboard, keypad, touch screen, or some other suitable input device. External devices 28 may also include, for example, thumb drives, portable optical or magnetic disks, and memory cards.

[0058] Software and data used to implement embodiments of the present disclosure may be stored on a portable computer-readable recording medium such as those described above and may be loaded into persistent storage 18 via I / O interface 22. The I / O interface may also connect to a display 30. Display 30 provides functionality for displaying data to a user and may be, for example, a computer monitor.

[0059] The programs described herein are identified based on the application in which they are implemented in a particular embodiment of the present disclosure. However, it should be recognized that any specific program terminology herein is used merely for convenience, and thus the present disclosure should not be limited to any particular application designated and / or implied by such terminology.

[0060] Data associated with secure smart containers that control access to data (e.g., image file data, protected data, user permission data, rules for suspicious access events, access history data, etc.) can be stored in any conventional or other data structure (e.g., file, array, list, stack, queue, record, etc.) and in any desired storage unit (e.g., database, data or other storage means, queue, etc.). Data transmitted between client devices 105A-105N can include any desired format and organization and can contain any amount of any size and type of field for storing data. The definition and data model for any data set can indicate the overall structure in any preferred manner (e.g., computer-related language, graphical representation, list, etc.).

[0061] Data associated with a secure smart container that controls access to data (e.g., image file data, protected data, user permission data, rules for suspicious access events, access history data, etc.) can include any information provided to or generated by a client device 105A-105N. Data associated with a secure smart container that controls access to data can include any desired format and organization and can include any size, quantity, and type of fields for storing data. Data associated with a secure smart container that controls access to data can include any data collected about an entity by any collection mechanism, any combination of collected information, and any information derived from analysis of collected information.

[0062] Embodiments of the present disclosure can utilize any number and type of interfaces (e.g., graphical user interfaces (GUIs), command lines, prompts, etc.) to obtain or provide information (e.g., data related to a secure smart container that provides access control to the data), and such interfaces can include any information organized in any manner. Interfaces can include any number and type of input or activation mechanisms (e.g., buttons, icons, fields, boxes, links, etc.) located in any location for entering / viewing information and initiating desired actions via any suitable input device (e.g., mouse, keyboard, etc.). Interface screens can include any suitable actuators (e.g., links, tabs, etc.) for navigating between screens in any manner.

[0063] It should be recognized that the embodiments described above and illustrated in the drawings represent only a few of the many ways to improve data security by preventing unauthorized data access and to extend protection during legitimate or other access events.

[0064] The environment for embodiments of the present disclosure can include any number of computers or other processor systems (e.g., client or end-user systems, server systems, etc.) and databases or other storage means organized in any desired manner, and embodiments of the present disclosure can be applied to any desired type of computing environment (e.g., cloud computing, client-server, network computing, mainframe, standalone systems, etc.). Computers or other processing systems used with embodiments of the present disclosure can be implemented by any number of personal or other types of computers or processing systems (e.g., desktops, laptops, PDAs, mobile devices, etc.). Computers or other processing systems used with embodiments of the present disclosure can include any commercially available operating system and any combination of commercially available and custom software (e.g., communications software, operating system software, host application 115, host application 215, enrichment engine 225, etc.). These systems can include any type of monitor and input device (eg, keyboard, mouse, voice recognition, etc.) for entering information, viewing, or both.

[0065] Software of embodiments of the present disclosure (e.g., communications software, operating system software, host application 115, host application 215, enhancement engine 225, etc.) can be implemented in any desired computer language and can be developed by one of ordinary skill in the computer arts based on the functional descriptions contained in the specification and the flowcharts illustrated in the drawings. Furthermore, any references herein to software performing various functions generally refer to a computer system or processor that performs those functions under software control. Computer systems of embodiments of the present disclosure can alternatively be implemented by any type of hardware or other processing circuitry, or both.

[0066] Various functions of a computer or other processing system may be distributed in any manner among any number of software or hardware modules, units, processing systems, computer systems, circuits, or combinations thereof, and the computers or processing systems may be located locally or remotely from one another via any suitable communications medium (e.g., LAN, WAN, intranet, Internet, hardwired, modem connection, wireless, etc.). For example, functions of embodiments of the present disclosure may be distributed in any manner among various end-user / client and server systems, or any other intermediary processing device, or combinations thereof. The software and / or algorithms described above and illustrated in flowcharts may be modified in any manner with the functions disclosed herein. Additionally, functions in the flowcharts or illustrations may be performed in any order consistent with desired operation.

[0067] The software of embodiments of the present disclosure (e.g., communications software, operating system software, host application 115, host application 215, enhancement engine 225, etc.) may be available as a non-transitory computer-usable medium (e.g., magnetic or optical media, magneto-optical media, floppy diskettes, CD-ROMs, DVDs, memory devices, etc.) in a fixed or portable program product apparatus or device for a stand-alone system or for system(s) connected by a network or other communications medium.

[0068] The communications network can be implemented by any number and type of communications network (e.g., KAN, WAN, intranet, Internet, VPN, etc.). The computer or other processing system of embodiments of the present disclosure can include any conventional or other communications device for communicating over the network via any conventional or other protocol. The computer or other processing system can use any type of connection (e.g., wired, wireless, etc.) to access the network. The local communications medium can be implemented by any suitable communications medium (e.g., local area network (LAN), hardwired or wireless link, intranet, etc.).

[0069] The system may utilize any number of conventional or other databases, data stores, or storage structures (e.g., files, databases, data structures, data, or other storage means, etc.) to store information (e.g., data related to the secure smart container that controls access to data). The database system may be implemented with any number of conventional or other databases, data stores, or storage structures to store information (e.g., data related to the secure smart container that controls access to data). The database system may be within or coupled to a server or client system, or both. The database system or storage structure may be implemented remotely or locally from a computer or other processing system and may store any desired data (e.g., data related to the secure smart container that controls access to data).

[0070] Embodiments of the present disclosure can utilize any number and type of interfaces (e.g., graphical user interfaces (GUIs), command lines, prompts, etc.) to obtain or provide information (e.g., data related to a secure smart container that provides access control to the data), and such interfaces can include any information organized in any manner. Interfaces can include any number and type of input or activation mechanisms (e.g., buttons, icons, fields, boxes, links, etc.) located in any location for entering / viewing information and initiating desired actions via any suitable input device (e.g., mouse, keyboard, etc.). Interface screens can include any suitable actuators (e.g., links, tabs, etc.) for navigating between screens in any manner.

[0071] Embodiments of the present disclosure are not limited to the specific tasks or algorithms described above, but may be utilized for any number of applications in related fields, including, but not limited to, controlling data access to prevent unauthorized access.

[0072] The terminology used herein is for the purpose of describing particular embodiments and is not intended to be limiting of the disclosure. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. Furthermore, when used herein, the terms "comprise," "comprising," "includes," "including," "has," "have," "having," "with," and the like, specify the presence of a stated feature, integer, step, operation, element, or component, or combination thereof, but should be understood as not excluding the presence or addition of one or more other features, integers, steps, operations, elements, components, or groups, or combinations thereof.

[0073] All equivalents of corresponding structure, material, acts, and means- or step-plus-function elements in the following claims are intended to include any structure, material, or act that performs that function in combination with other claim elements, particularly as recited in that claim. The description of the present disclosure has been presented for purposes of illustration and description, but is not intended to be an exclusive or limited disclosure in the form described. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the present disclosure. The embodiments have been chosen and described to best explain the principles and practical application of the disclosure and to enable others skilled in the art to understand the disclosure for various embodiments, with various modifications to adapt them to particular uses envisioned.

[0074] The description of various embodiments of the present disclosure has been presented for illustrative purposes, but is not intended to be exclusive or limited to the disclosed embodiments. Many modifications or variations will be apparent to those skilled in the art without departing from the scope and spirit of the present disclosure. The terms used herein have been selected to best explain the principles, practical applications, or technical improvements of the present embodiments beyond those found in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.

[0075] The present disclosure discloses a system, a computer-implemented method, a computer-executable computer program, or a computer-readable recording medium that is at such a state-of-the-art level of integration. A computer program including computer-readable program instructions for a processor to carry out aspects of the present disclosure can be included on a computer-readable recording medium (or media) and cause a computer to implement the means of the present embodiments.

[0076] A computer-readable storage medium may be any tangible device capable of holding and storing instructions for use by an instruction execution device. The computer-readable storage medium may be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electro-magnetic storage device, a semiconductor storage device, or any suitable combination thereof. More specific examples of computer-readable storage media include the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile diskette (DVD), a memory stick, a floppy disk, a punch card, or a mechanically encoded device having protruding structures within grooves that record instructions, and any suitable combination thereof. As used herein, a computer-readable recording medium is not to be construed as a transitory signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave such as a wave guide or other communication medium (e.g., light pulses passing through a fiber optic cable), or an electrical signal communicated through a wire.

[0077] The computer programs described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or can be downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network can include copper communication cables, fiber optic communication cables, wireless communication routers, firewalls, switches, gateway computers, and edge servers, or a combination thereof. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions to a computer-readable storage medium within the computing / processing device for storage.

[0078] Computer-readable program instructions for carrying out the operations of the present invention can be either source code or object code written in any combination of programming languages, including assembler instructions, instruction set architecture (ISA) instructions, machine language instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for integrated circuits, or one or more procedural programming languages, such as object-oriented programming languages ​​like Smalltalk®, C++, the "C" programming language, or similar programming languages. The computer-readable program instructions can execute entirely on the user computer, partially on the user computer as a stand-alone software package, partially on the user computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer can be connected to the user computer through any type of network, including a local area network (LAN), a wide area network (WAN), or the connection can be to an external computer (e.g., through an Internet service provider). In some embodiments, computer-readable program instructions can be executed by electrical circuitry, including, for example, programmable logic circuitry, field programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), using state information from the computer-readable program instructions to personalize the electrical circuitry to perform features of the present invention.

[0079] Aspects of the invention described herein have been described with reference to flowchart instructions and / or block diagrams of methods, apparatus (systems), and computer-readable storage media and computer program products according to embodiments of the invention. It will be understood that any combination of flowchart illustrations and / or block diagrams and / or blocks in flowchart illustrations and / or block diagrams can be implemented by computer-readable program instructions.

[0080] The computer-readable program instructions can be provided to a computer processor or other programmable data processing device to create a machine, which, when executed by the computer processor or other programmable data processing device, generates means for implementing the functions / acts specified in the block or blocks of the flowcharts and block diagrams, or a combination thereof. These computer-readable program instructions, which direct a computer, programmable data processing device, or other device, or a combination thereof, to function in a particular manner, can also be stored on a computer-readable recording medium, and the computer-readable recording medium having the instructions stored thereon constitutes an article of manufacture containing instructions that implement the functional / actual features specified in the block or blocks of the flowcharts and block diagrams, or a combination thereof.

[0081] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device and cause a computer-implemented process to execute a series of operational steps on the computer, other programmable apparatus, or other device to implement the functions / acts specified in a block or blocks of the flowcharts and block diagrams, or a combination thereof, on the computer, other programmable apparatus, or other device.

[0082] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and possible implementations of systems, methods, and computer programs according to various embodiments of the present invention. In this regard, the flowcharts or block diagrams may represent modules, segments, or portions of instructions, which contain one or more executable instructions for implementing a specific logical function(s). In some alternative implementations, the functions described in the blocks may be performed other than as illustrated. For example, two blocks shown in succession may actually be performed as a single step, or may be performed simultaneously, substantially simultaneously, or partially or completely overlapping in time, depending on the functionality involved, or the blocks may sometimes be performed in reverse order. Furthermore, block diagram and / or flowchart illustrations and / or combinations of the blocks in the block diagrams and flowchart illustrations indicate that the blocks may be implemented by special-purpose hardware-based systems that perform specific functions or operations or execute specific-purpose hardware and computer instructions. [Explanation of symbols]

[0083] 10: Computer 12: Communication mechanism 14: Processor 16: Memory 18: Persistent Storage 20: Communication unit 22: I / O interface 26: Cache memory 28: External device 30: Display 106: Network Interface 107: Processor 110: Memory 115: Host Application 120: Storage 150: Network 200: System 205 :Device 206: Network Interface 207: Processor 210: Memory 212: System 215: Application 220: Container 225: Enhanced Engine 230: Encrypted data 235: Data 245: Image file

Claims

1. 1. A computer-implemented method for controlling access to a secure container, the method comprising: instantiating, at a user's endpoint device based on the image file, a secure container containing encrypted data corresponding to the user, wherein the secure container contains encrypted data corresponding to a plurality of users, including the user and an enhancement engine, and the encrypted data is encrypted to allow different users to access different portions of the data; verifying the request for access to the secure container by verifying the user's credentials; permitting access to data in response to verifying the credentials of the user; controlling access to the data by decrypting and making accessible portions of the encrypted data using the enhanced engine stored in the secure container, wherein additional portions of the data are decrypted and made accessible based on user behavior, each additional portion of the data being provided by providing a command from the user to close a file containing the portion of data, overwriting the file with the additional portion of data in response to the user closing the file, providing a command to the user to reopen the file, and providing the additional portion of data to the user in response to the user's command to reopen the file; receiving one or more edits by said user to said data that said user is authorized to access; providing a modified image file containing the one or more edits made by the user; and transmitting the modified image file to a device of a user having different access permissions to the data compared to the user; Contains Computer-implemented methods.

2. moreover, analyzing the user's behavior to determine that an access violation has occurred; and suspending the user's access to the data in response to determining that the access violation has occurred. The computer-implemented method of claim 1 , comprising:

3. The user's behavior is analyzed to identify one or more events, and the access violation is: calculating a total risk score based on one or more risk subscores corresponding to the identified one or more events; and determining that the total risk score meets a predetermined threshold; The computer-implemented method of claim 2 , wherein the determination is made by:

4. The computer-implemented method of any one of claims 1 to 3, wherein the user behavior includes an access rate to the data.

5. The computer-implemented method of any one of claims 1 to 4, wherein the user behavior includes user searches using one or more unauthorized search terms.

6. 6. The computer-implemented method of claim 1, wherein verifying the access request is further performed based on one or more selected from the group consisting of: a computing environment of the endpoint device, a current location of the endpoint device, and a previous access location to the secure container.

7. moreover, 7. The computer-implemented method of claim 1, further comprising submitting fake data in response to an access violation occurring or in response to the access request including an anomaly indicator.

8. 1. A computer system for controlling access to a secure container, the computer system comprising: means for instantiating, at a user's endpoint device based on an image file, a secure container containing encrypted data corresponding to the user, wherein the secure container contains encrypted data corresponding to a plurality of users, including the user and an enhancement engine, and the encrypted data is encrypted to allow different users to access different portions of the data; means for verifying a request for access to the secure container by verifying a credential of the user; means for permitting access to data in response to validation of said credentials of said user; means for controlling access to the data by decrypting and making accessible portions of the encrypted data using the enhanced engine stored in the secure container, wherein additional portions of the data are decrypted and made accessible based on user behavior, each additional portion of the data being provided by providing a command from the user to close a file containing the portion of data, overwriting the file with the additional portion of data in response to the user closing the file, providing a command to the user to reopen the file, and providing the additional portion of data to the user in response to the user commanding the reopening of the file; means for receiving one or more edits by said user to said data that said user is authorized to access; means for providing a modified image file containing the one or more edits made by the user; and means for transmitting the modified image file to a device of a user having different access permissions to the data compared to the user; Including, Computer systems.

9. moreover, means for analyzing the user's behavior to determine that an access violation has occurred; and means for terminating said user's access to said data in response to determining that said access violation has occurred; 9. The computer system of claim 8, comprising:

10. The user's behavior is analyzed to identify one or more events, and the access violation is: calculating a total risk score based on one or more risk subscores corresponding to the identified one or more events; and determining that the total risk score meets a predetermined threshold; 10. The computer system of claim 9, wherein the determination is made by:

11. The computer system according to any one of claims 8 to 10, wherein the user behavior includes an access rate to the data.

12. The computer system of any one of claims 8 to 11, wherein the user behavior includes user searches using one or more unauthorized search terms.

13. 13. The computer system of claim 8, wherein verifying the access request is further performed based on one or more selected from the group consisting of: a computing environment of an endpoint device, a current location of the endpoint device, and a previous access location to the secure container.

14. moreover, 14. The computer system of claim 8, wherein counterfeit data is presented in response to an access violation occurring or in response to the access request including an anomaly indicator.

15. A computer-executable computer program for causing a computer to carry out the computer-implemented method according to any one of claims 1 to 7.

16. A computer-readable recording medium having recorded thereon a computer program for causing a computer to execute the computer-implemented method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • System for processing administration document

    JP2002032523A

  • Security container for document component

    JP2005056418A

  • Failure analysis support terminal and failure analysis support information providing device

    JP2006120081A

  • Content providing management device, content distribution system, and program

    JP2007081918A

  • Secure public communication environment for remote access

    JP2012512573A