Information processing device, data protection method by information processing device, and computer program

The information processing device detects fraudulent use and erases data based on usage status, enhancing data security by preventing unauthorized access and leakage.

JP7772524B2Active Publication Date: 2025-11-18HITACHI LTD
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
JP2021132913
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-17
Publication Date
2025-11-18
Estimated Expiration
2041-08-17

AI Technical Summary

Technical Problem

Existing technologies lack the ability to detect the usage status of an information processing device and erase data based on that status to prevent unauthorized access and data leakage.

Method used

An information processing device equipped with a processor that determines the usage status and erases data if it detects fraudulent use, utilizing components like a camera for user authentication, GPS for location tracking, and network connectivity checks to enforce data volatility levels.

Benefits of technology

Prevents data leakage by dynamically adjusting data erasure based on usage status, ensuring secure data protection even in unauthorized scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007772524000001
    Figure 0007772524000001
  • Figure 0007772524000002
    Figure 0007772524000002
  • Figure 0007772524000003
    Figure 0007772524000003
Patent Text Reader

Abstract

To allow for preventing leakage of data stored in an information processing device according to the usage state of the information processing device.SOLUTION: An information processing device 1 is provided, comprising a processor 10 and a storage unit 12 storing data including user data generated and used by a user, the processor 10 being configured to determine the state of usage of the information processing device 1 by the user, and erase the data in the storage unit 12 if it is determined that the information processing device 1 is being unauthorizedly used by someone other than the user.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device, a data protection method by the information processing device, and a computer program. [Background technology]

[0002] BACKGROUND ART There is known a technique for detecting that an information processing device has been stolen and erasing internal data from the information processing device in order to prevent user data from being leaked from the information processing device (for example, Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2014-149729 Summary of the Invention [Problem to be solved by the invention]

[0004] However, there is no known technology for detecting the usage status of an information processing device and erasing data stored in the information processing device in accordance with this usage status.

[0005] The present invention has been made in consideration of the above-mentioned problems, and its object is to provide an information processing device, a data protection method using an information processing device, and a computer program that can prevent leakage of data stored in the information processing device depending on the usage status of the information processing device. [Means for solving the problem]

[0006] In order to solve the above problem, an information processing device according to one aspect of the present invention is an information processing device having a processor and a storage device in which data including user data created and used by a user is stored, and the processor determines the usage status of the information processing device by the user, and erases the data in the storage device if it determines that the information processing device is being used fraudulently by someone other than the user. [Effects of the Invention]

[0007] According to the present invention, it is possible to realize an information processing device, a data protection method using an information processing device, and a computer program that can prevent leakage of data stored in the information processing device depending on the usage status of the information processing device. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a diagram illustrating a schematic configuration of an information processing apparatus according to an embodiment. [Figure 2] FIG. 2 is a diagram showing an overview of data stored in a storage device of the information processing apparatus according to the embodiment. [Figure 3] 10A and 10B are diagrams illustrating an example of classifications of unauthorized use states and a mode of data volatilization for each classification in the information processing device according to the embodiment. [Figure 4] 10 is a flowchart illustrating an example of the overall operation of the information processing apparatus according to the embodiment. [Figure 5] 10 is a flowchart illustrating an example of a network determination operation of the information processing device according to the embodiment. [Figure 6] 10 is a flowchart illustrating an example of an internet connection status determination operation of the information processing device according to the embodiment. [Figure 7] FIG. 10 is a diagram illustrating an example of an Internet connection status determination operation of the information processing apparatus according to the embodiment. [Figure 8] 10 is a flowchart showing an example of a GPS determination operation of the information processing device according to the embodiment. [Figure 9] FIG. 10 is a diagram illustrating an example of a GPS determination operation of the information processing device according to the embodiment. [Figure 10] 10 shows a table that serves as a criterion for determining whether or not data is to be volatilized in the information processing apparatus according to the embodiment. [Figure 11] 10 is a flowchart illustrating an example of a terminal user authority determination operation of the information processing device according to the embodiment. [Figure 12] 10 is a flowchart illustrating an example of a terminal state determination operation of the information processing device according to the embodiment. [Figure 13] 10 is a flowchart illustrating an example of a screen lock volatilization determination operation of the information processing device according to the embodiment. [Figure 14] 10 is a flowchart illustrating an example of a cover closure volatilization determination operation of the information processing apparatus according to the embodiment. [Figure 15] 10 is a flowchart illustrating an example of a user confirmation volatilization determination operation by a camera of the information processing device according to the embodiment. [Figure 16] FIG. 2 is a diagram showing an example of a volatility level table stored in the information processing apparatus according to the embodiment. [Figure 17] FIG. 10 is a diagram showing an example of a list of volatilization conditions used by the information processing apparatus according to the embodiment. [Figure 18] FIG. 10 is a diagram showing another example of a list of volatilization conditions used by the information processing apparatus according to the embodiment. [Figure 19] FIG. 2 is a diagram illustrating an example of a screen UI in the information processing device according to the embodiment. [Figure 20] FIG. 10 is a diagram showing another example of the screen UI in the information processing device according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] Hereinafter, embodiments of the present invention will be described with reference to the drawings. Note that the embodiments described below do not limit the scope of the invention as claimed, and not all of the elements and combinations thereof described in the embodiments are necessarily essential to the solution of the invention.

[0010] In the drawings explaining the embodiments, parts having the same functions are given the same reference numerals, and repeated explanations thereof will be omitted.

[0011] In the following description, expressions such as "xxx data" may be used as an example of information, but the data structure of the information may be any. In other words, to indicate that the information does not depend on the data structure, "xxx data" may be referred to as "xxx table." Furthermore, "xxx data" may be simply referred to as "xxx." In the following description, the structure of each piece of information is an example, and the information may be stored divided or combined.

[0012] In the following explanation, processing may be described using a "program" as the subject, but since a program is executed by a processor (e.g., a CPU (Central Processing Unit)) to perform a predetermined process using storage resources (e.g., memory) and / or communication interface devices (e.g., ports) as appropriate, the subject of the processing may also be the program. Processing described using a program as the subject may also be processing performed by a processor or a computer having that processor.

[0013] In the following explanation, when the subject of an operation is described as "the ○○ unit," it means that the processor of the information processing device reads and loads the processing contents of the ○○ unit, which is a program stored in memory, and then realizes the function of the ○○ unit (details described below).

[0014] The program may be installed in a device such as a computer, or may be stored in, for example, a program distribution server or a computer-readable (e.g., non-transitory) recording medium. Also, in the following description, two or more programs may be realized as one program, or one program may be realized as two or more programs.

[0015] In this specification, "volatilization" of data means erasing the data, and in particular, logically deleting the data. Therefore, even if data is volatilized by an information processing device, the data itself is not necessarily physically deleted.

[0016] FIG. 1 is a diagram showing a schematic configuration of an information processing apparatus according to an embodiment. The information processing device 1 of this embodiment has a processor 10, a memory 11, a storage device 12, a camera 13, an input device 14, an open / close detection switch 15, a GPS module 16, a display device 17, and a network module 18.

[0017] The information processing device 1 of this embodiment is a device capable of performing various types of information processing, such as a computer.

[0018] The processor 10 is, for example, a central processing unit (CPU), a graphics processing unit (GPU), or a field-programmable gate array (FPGA). The memory 11 and storage device 12 include, for example, a magnetic storage medium such as a hard disk drive (HDD), or a semiconductor storage medium such as a random access memory (RAM), a read-only memory (ROM), or a solid state drive (SSD). A combination of an optical disk such as a digital versatile disk (DVD) and an optical disk drive can also be used as the memory and storage. Other known storage media such as magnetic tape media can also be used as the memory and storage.

[0019] Programs such as firmware are stored in the storage device 12. When the information processing device 1 starts operating (for example, when the power is turned on), the programs such as firmware are read from the storage device 12 and executed in the memory 11 to perform overall control of the information processing device 1. In addition to the programs, the storage device 12 also stores data and the like required for each process of the information processing device 1.

[0020] The processor 10 has a terminal usage state determination unit 19, a volatilization level determination unit 20, and a data volatilization processing unit 21 as function realization means.

[0021] The terminal usage status determination unit 19 determines the usage status of the user who uses the information processing device 1, and determines whether the information processing device 1 is being used fraudulently by someone other than the user. More specifically, the terminal usage status determination unit 19 determines whether the information processing device 1 is being used fraudulently by someone other than the user by checking whether the terminal is left unused, whether the screen lock is not released for a certain period of time, whether the cover remains closed for a certain period of time without being connected to a power source, whether the terminal is offline, whether the terminal user is authenticated by the camera, whether the terminal is connected to a normal network, whether the NIC (Network Interface Controller) is enabled, and whether communication with a specific server is possible. An overview of the determination made by the terminal usage status determination unit 19 is shown in FIG. 3. Details of the operation of the terminal usage status determination unit 19 will be described later.

[0022] In addition, in the information processing device 1 of this embodiment, as described below, the terminal usage status determination unit 19 has a face authentication function, as it determines whether the user of the information processing device 1 captured by the camera 13 provided in the information processing device 1 is an authenticated person.

[0023] The volatility level determination unit 20 determines whether or not the data stored in the storage medium (mainly the storage device 12) of the information processing device 1 corresponds to one of the volatility levels that determine when and how the data is to be volatilized, based on the determination by the terminal usage state determination unit 19. The volatility level determination unit 20 makes the determination based on a volatility level table 24, which will be described later. The volatility levels will also be described later in detail.

[0024] The data volatilization processing unit 21 volatilizes the data stored in the storage medium of the information processing device 1 based on the determination results of the terminal usage state determination unit 19 and the volatilization level determination unit 20.

[0025] The storage device 12 stores terminal usage status data 22, NW connection status data 23, and a volatile level table 24.

[0026] The terminal usage state data 22 stores data for determining whether or not the information processing device 1 is being used by a user, as determined by the terminal usage state determination unit 19, and the determination result. The NW connection state data 23 stores data for determining whether or not the information processing device 1 is connected to an appropriate network, as determined by the terminal usage state determination unit 19, and the determination result. The volatility level table 24 is a table that defines volatility levels, which are the basis for determining the volatility level by the volatility level determination unit 20. Details of the volatility level table 24 will be described later with reference to FIG. 16.

[0027] Camera 13 is attached to the housing of information processing device 1, captures an image of an area including the face of a user using information processing device 1, and sends the captured image to processor 10. Information processing device 1 of this embodiment is a so-called notebook computer, and its housing has a main body, a lid (cover) covering the top surface of the main body, and a hinge that rotatably secures the lid to the main body. When using information processing device 1, the user lifts the lid upward and adjusts the display (constituting display device 17) provided on the backside of the lid to a position facing the user's face. Camera 13 is provided somewhere on the backside of the lid (usually above the display), and is positioned so that it can capture an image of an area including the user's face when information processing device 1 is in use.

[0028] The input device 14 is, for example, a keyboard, a touchpad, etc., and accepts user operation input and sends an input signal to the processor 10. The open / close detection switch 15 detects the fixed position of the hinge described above and sends a signal indicating the position of the lid to the processor 10. The GPS module 16 receives information from GPS satellites and sends the position (latitude, longitude, etc.) of the information processing device 1 to the processor 10. The display device 17 is, for example, a display, and as already explained, is provided on the back surface of the lid of the housing of the information processing device 1.

[0029] The network module 18 communicates with an in-house server 40 or the like via a network 30. In the information processing device 1 of this embodiment, the information processing device 1 is not directly connected to a WAN such as the Internet, but is connected to the in-house server 40 via a secure network 30 that can be considered equivalent to an in-house LAN including a VPN connection or the like. The information processing device 1 can then connect to the WAN such as the Internet via this in-house server 40 or under the control of the in-house server 40. The network 30 complies with protocols such as TCP / IP, and a DNS server and the like are also provided in the in-house server 40.

[0030] FIG. 2 is a diagram showing an overview of data stored in the storage device 12 of the information processing device 1 according to the embodiment.

[0031] The information processing device 1 of this embodiment uses Windows (registered trademark) as its OS, and the file system and folder structure are also defined by Windows (prepared and created by Windows). As shown in Fig. 2, the storage device 12 stores data generated, acquired, etc. by users in folders provided for each user and in folders subordinate to those folders (e.g., desktop folders).

[0032] In this specification, data stored in the Users folder and folders under it (including folders here) is referred to as user data, and this user data is subject to volatilization at volatility level 1. Data other than user data (such as setting data, but not limited to this, is listed in FIG. 2) is also stored in the storage device 12, and this data other than user data is subject to volatilization at volatility level 2.

[0033] Next, the operation of the information processing device 1 of this embodiment will be described with reference to FIGS.

[0034] FIG. 4 is a flowchart showing an example of the overall operation of the information processing device 1 according to the embodiment.

[0035] The operation shown in the flowchart of Fig. 4 is started when the information processing device 1 is started. First, the terminal usage state determination unit 19 performs a NW determination operation (step S401). The NW determination operation will be described in detail later. Then, if the information processing device 1 is connected to an in-house network (i.e., an in-house server, etc. 40) and if it is determined by GPS that the information processing device 1 is located inside the company, the terminal usage state determination unit 19 performs a non-volatilization target determination operation (step S402), and if it is determined otherwise, the terminal usage state determination unit 19 performs a terminal user authority determination operation (step S403). Furthermore, even if it is determined by GPS in the non-volatilization target determination operation (step S402) that the information processing device 1 is located outside the company, the terminal usage state determination unit 19 also performs the terminal user authority determination operation (step S403).

[0036] After the terminal user authority determination operation (step S403), the terminal usage state determination unit 19 performs a terminal state determination operation (step S404). Thereafter, the volatilization level determination unit 20 determines the volatilization level based on the determination results of steps S401 to S404 (step S405). If the volatilization level determined by the volatilization level determination unit 20 is level 1, the data volatilization processing unit 21 performs volatilization processing of the specified data, and then the terminal usage state determination unit 19 performs the terminal state determination operation again (step S404). On the other hand, if the volatilization level determined by the volatilization level determination unit 20 is level 2 or 3, the data volatilization processing unit 21 performs volatilization processing of the specified data, and then shuts down the information processing device 1.

[0037] 5 is a flowchart showing an example of the NW determination operation of the information processing device 1 according to the embodiment. The NW determination operation shown in the flowchart of FIG. 5 corresponds to step S401 in FIG.

[0038] First, the terminal usage status determination unit 19 determines whether the information processing device 1 is online, that is, whether it is connected to a WAN such as the Internet (regardless of whether it is inside or outside the company) (step S501). If it determines that the information processing device 1 is online (YES in step S501), the terminal usage status determination unit 19 performs the process of step S502, and if it determines that the information processing device 1 is offline (NO in step S501), the terminal usage status determination unit 19 performs the terminal user authority determination process shown in step S403 in FIG. 4 (step S503).

[0039] In step S502, the terminal usage status determination unit 19 determines whether or not the information processing device 1 is connected to an in-house network (i.e., an in-house server, etc. 40). If it is determined that the information processing device 1 is connected to the in-house network (YES in step S502), the terminal usage status determination unit 19 performs the process of step S504, and if it is determined that the information processing device 1 is not connected to the in-house network (NO in step S502), the terminal usage status determination unit 19 performs the terminal user authority determination process shown in step S403 of Fig. 4 (step S505). The determination in step S502 is performed, for example, by issuing a communication from the information processing device 1 to a DNS server, which is the in-house server, etc. 40, and determining that the information processing device 1 is in-house if an expected response is confirmed from the DNS server.

[0040] In step S504, the terminal usage state determination unit 19 determines whether or not the information processing device 1 is located within a geographical range recognized as being within the company, based on the measurement results from the GPS module 16. If it is determined that the information processing device 1 is located within the company (YES in step S504), the terminal usage state determination unit 19 performs the non-volatilization target determination process shown in step S402 of Fig. 4 (step S506), and if it is determined that the information processing device 1 is located outside the company (NO in step S504), the volatility level determination unit 20 performs the terminal user authority determination process shown in step S403 of Fig. 4 (step S507).

[0041] Fig. 6 is a flowchart showing an example of the Internet connection status determination operation of the information processing device 1 according to the embodiment, and Fig. 7 is a diagram showing an example of the Internet connection status determination operation of the information processing device according to the embodiment. The Internet connection status determination operation shown in the flowchart of Fig. 6 corresponds to step S501 in Fig. 5.

[0042] In the drawings, numbers in circles (numbers in circles) are represented in the specification as numbers in parentheses (for example, (1)) for display purposes.

[0043] First, the terminal usage status determination unit 19 attempts to connect to the Internet via the network module 18 (step S601, (1) in FIG. 7)) and determines whether the information processing device 1 is connected to the Internet (step S602). The determination of whether the information processing device 1 is connected to the Internet in step S602 may be based on, for example, whether a server identified by a predetermined URL is connectable. However, in the information processing device 1 of this embodiment, this determination is made by determining both the presence or absence of an Internet connection (communication) using the NCSI (Network Connection Status Indicator) provided in Windows and the presence or absence of communication with the DNS server and NTP server provided in the in-house server 40. By determining the presence or absence of an Internet connection using two means in this way, unexpected data loss can be prevented even if one of the means is damaged or malfunctions due to an external attack.

[0044] If it is determined that the information processing device 1 has been able to connect to the Internet (YES in step S602), the terminal usage status determination unit 19 performs processing in step S604, and if it is determined that it has not been able to connect to the Internet (NO in step S602), the terminal usage status determination unit 19 performs processing in step S603.

[0045] In step S603, the terminal usage status determination unit 19 counts up using a counter (not shown) to measure the time during which the terminal is not connected to the Internet. Based on the result of counting up in step S603, the terminal usage status determination unit 19 determines whether the time during which the terminal is not connected to the Internet has lasted for 5, 10, or 15 minutes (step S605). If the terminal usage status determination unit 19 determines that the time during which the terminal is not connected to the Internet has lasted for 5, 10, or 15 minutes (YES in step S605), the terminal usage status determination unit 19 performs the process of step S606. If the terminal usage status determination unit 19 determines that the time during which the terminal is not connected to the Internet has lasted for more than 5, 10, or 15 minutes (NO in step S605), the terminal usage status determination unit 19 returns to step S601 and continues the process.

[0046] In step S606, it is determined whether the time without connection to the Internet has continued for 15 minutes. If it is determined that the time without connection to the Internet has continued for 15 minutes (YES in step S606), the terminal usage status determination unit 19 performs the process of step S607, and if it is determined that the time without connection to the Internet has not continued for 15 minutes (NO in step S606), the terminal usage status determination unit 19 performs the process of step S608.

[0047] In step S607, the terminal usage status determination unit 19 performs a terminal user authority determination process, and then the volatility level determination unit 20 performs a volatility level determination operation (4). Meanwhile, in step S608, the terminal usage status determination unit 19 displays a warning message on the display device 17 of the information processing device 1 (FIGS. 7(2) and (3)), and then returns to step S601 to continue the process.

[0048] On the other hand, in step S604, the terminal usage state determination unit 19 resets the counter that counts the time during which the terminal is not connected to the Internet. After that, the terminal usage state determination unit 19 returns to step S601 and continues the process.

[0049] Fig. 8 is a flowchart showing an example of the GPS determination operation of the information processing device 1 according to the embodiment, and Fig. 9 is a diagram showing an example of the GPS determination operation of the information processing device 1 according to the embodiment. The GPS determination operation shown in the flowchart of Fig. 8 corresponds to step S504 in Fig. 5.

[0050] First, the terminal usage status determination unit 19 acquires the location information of the information processing device 1 via the GPS module 16 (step S801, (1) in FIG. 9). Alternatively, if the network module 18 included in the information processing device 1 has a so-called Wi-Fi (registered trademark) function, the terminal usage status determination unit 19 may acquire the location information from the network module 18. When the location information of the information processing device 1 is acquired using the GPS module 16, accurate location information can be obtained, but the GPS determination operation shown in FIG. 8 can only be performed on information processing devices 1 that have the GPS module 16. In contrast, since the majority of recent information processing devices 1 have a Wi-Fi function, the GPS determination operation can be performed on almost all information processing devices 1. However, since location information based on the Wi-Fi function is subject to significant inaccuracies, it is preferable to set the location information by prefecture in advance. Note that the data volatility level can also be varied depending on the location information acquisition method used by the information processing device 1.

[0051] Next, the terminal use state determining unit 19 determines whether the position of the information processing device 1 specified by the position information acquired in step S801 is within a predetermined set range determined to be inside a company (step S802).

[0052] If it is determined that the information processing device 1 is located within the company (YES in step S802), the terminal usage status determination unit 19 performs processing in step S804, and if it is determined that the information processing device 1 is not located within the company (NO in step S802), the terminal usage status determination unit 19 performs processing in step S803.

[0053] In step S803, the terminal usage status determination unit 19 counts up using a counter (not shown) to measure the time that exists outside the set range. Then, as a result of the counting up in step S803, it determines whether the time that exists outside the range has continued for 5, 10, or 15 minutes (step S805). If it determines that the time that exists outside the range has continued for 5, 10, or 15 minutes (YES in step S805), the terminal usage status determination unit 19 performs the process of step S806. If it determines that the time that exists outside the range is not 5, 10, or 15 minutes (NO in step S805), the terminal usage status determination unit 19 returns to step S601 and continues the process.

[0054] In step S806, it is determined whether the time outside the range has continued for 15 minutes. If it is determined that the time outside the range has continued for 15 minutes (YES in step S806), the terminal usage state determination unit 19 performs the process of step S807, and if it is determined that the time outside the range has not continued for 15 minutes (NO in step S806), the terminal usage state determination unit 19 performs the process of step S808.

[0055] In step S807, the terminal usage status determination unit 19 performs a terminal user authority determination process, and then the volatility level determination unit 20 performs a volatility level determination operation (4). Meanwhile, in step S808, the terminal usage status determination unit 19 displays a warning message on the display device 17 of the information processing device 1 (FIGS. 9(2) and (3)), and then returns to step S801 to continue the process.

[0056] On the other hand, in step S604, the terminal usage state determination unit 19 resets the counter that counts the time that the device is outside the range. After that, the terminal usage state determination unit 19 returns to step S601 and continues the process.

[0057] Fig. 10 shows a table that is used as a criterion for determining whether a device is not a target for volatilization in the information processing device 1 according to the embodiment. The table shown in Fig. 10 is used when the terminal usage state determination unit 19 performs the operation of determining whether a device is not a target for volatilization in step S402 in Fig. 4.

[0058] 4, the information processing device 1 is connected to the in-house network and has already been determined to be located within the company by GPS. Therefore, regardless of whether the user of the information processing device 1 is a general user or an administrator, whether the screen lock state has continued for a predetermined time, whether the cover has been closed for a predetermined time, and whether the user authenticated by the camera 13 is anyone, the information processing device 1 is determined to be in a safe state, and the data volatilization processing unit 21 will not perform data volatilization processing as long as this state continues.

[0059] 11 is a flowchart showing an example of the terminal user authority determination operation of the information processing device 1 according to the embodiment. The terminal user authority determination process shown in the flowchart of FIG.

[0060] First, the terminal usage state determination unit 19 determines whether the user of the information processing device 1 is a general user (step S1101). That is, when the information processing device 1 is started (logged in), the terminal usage state determination unit 19 refers to whether the user account used to log in is used, and determines whether the user logged in is used an administrator account.

[0061] If it is determined that the login has been made using an administrator account (NO in step S1101), the terminal usage status determination unit 19 stores this login information in memory 11 and then performs a terminal status determination operation (step S1102, step S404 in FIG. 4). On the other hand, if it is determined that the login has been made by a general user (YES in step S1101), the terminal usage status determination unit 19 stores this login information in memory 11 and then performs a terminal status determination operation (step S1103, step S404 in FIG. 4).

[0062] 12 is a flowchart showing an example of the terminal state determination operation of the information processing device 1 according to the embodiment. The terminal state determination operation shown in the flowchart of FIG.

[0063] First, the terminal usage state determination unit 19 determines the usage state of the information processing device 1 based on the screen lock state (step S1201). If it is determined that data needs to be volatilized based on the screen lock state (YES in step S1201), the volatilization level determination unit 20 performs a volatilization level determination operation (step S1203, step S405 in FIG. 4), and if it is determined that data does not need to be volatilized based on the screen lock state (NO in step S1201), the terminal usage state determination unit 19 performs the process of step S1202.

[0064] In step S1202, terminal usage state determination unit 19 determines the usage state of information processing device 1 based on the open / close state of the lid (cover). If it is determined that data needs to be volatilized based on the open / close state of the lid (YES in step S1202), volatilization level determination unit 20 performs a volatilization level determination operation (step S1205, step S405 in FIG. 4), and if it is determined that data does not need to be volatilized based on the open / close state of the lid (NO in step S1202), terminal usage state determination unit 19 performs the process of step S1204.

[0065] In step S1204, terminal usage state determination unit 19 determines the usage state of information processing device 1 based on user confirmation by camera 13. If it is determined that data needs to be volatilized based on user confirmation by camera 13 (YES in step S1204), volatilization level determination unit 20 performs a volatilization level determination operation (step S1207, step S405 in FIG. 4), and if it is determined that data does not need to be volatilized based on user confirmation by camera 13 (NO in step S1204), terminal usage state determination unit 19 performs a non-volatilization target determination process (FIG. 10, step S1206).

[0066] 13 is a flowchart showing an example of a screen lock volatilization determination operation of the information processing device 1 according to the embodiment. The screen lock volatilization determination operation shown in the flowchart of FIG. 13 corresponds to step S1201 in FIG.

[0067] The terminal use state determination unit 19 executes a lock state change event at predetermined time intervals while the information processing device 1 is running (step S1301), and changes a variable LockState indicating the screen lock state of the information processing device 1 based on the result of the event (step S1302). As an example, the terminal use state determination unit 19 performs the determination process shown in steps S1301 and S1302 every second. The variable LockState is stored in the storage device 12 as terminal use state data 22.

[0068] When step S1201 is executed, the terminal use state determination unit 19 determines the value of the variable LockState (step S1303). If it is determined that the value of the variable LockState is Lock, the terminal use state determination unit 19 performs the process of step S1304, and if it is determined that the value of the variable LockState is Unlock, the terminal use state determination unit 19 performs the process of step S1305.

[0069] In step S1304, the terminal use state determination unit 19 counts up using a counter (not shown) to measure the time the screen has been locked. Then, as a result of the counting up in step S1304, it determines whether the time the screen has been locked has lasted for 60 minutes (step S1306). If it determines that the time the screen has been locked has lasted for 60 minutes (YES in step S1306), the terminal use state determination unit 19 performs the process of step S1307, and if it determines that the time the screen has been locked has not lasted for 60 minutes (NO in step S1306), the terminal use state determination unit 19 returns to step S1303 and continues the process.

[0070] In step S1307, the volatilization level determination unit 20 determines the volatilization level, and the data volatilization processing unit 21 performs volatilization processing of the data based on the determined volatilization level.

[0071] On the other hand, in step S1305, the terminal use state determination unit 19 resets the counter that counts the time that the screen is in the locked state. After that, the terminal use state determination unit 19 returns to step S1303 and continues the process.

[0072] 14 is a flowchart showing an example of the cover closure volatilization determination operation of the information processing device 1 according to the embodiment. The cover closure volatilization determination operation shown in the flowchart of FIG. 14 corresponds to step S1202 in FIG.

[0073] The terminal usage state determination unit 19 executes a power management event at predetermined time intervals while the information processing device 1 is running (step S1401), and changes a variable LidState indicating the cover closed state of the information processing device 1 based on the result of the event (step S1402). This variable LidState is based on the detection result of the open / close detection switch 15.

[0074] In addition, the terminal usage state determination unit 19 executes a cover closed state event at predetermined time intervals while the information processing device 1 is running (step S1403), and changes the power state of the information processing device 1, that is, the variable PowerState, which indicates whether the information processing device 1 is powered by its own battery (not shown) or an external power source, based on the result of the event (step S1404).

[0075] As an example, the terminal usage state determination unit 19 performs the determination process shown in steps S1401 and S1402 every second, and the determination process shown in steps S1403 and S1404 every 10 seconds. The variables LidState and PowerState are stored in the storage device 12 as terminal usage state data 22.

[0076] When step S1202 is executed, the terminal usage state determination unit 19 determines the values ​​of the variables LidState and PowerState (step S1405). If it is determined that the value of the variable LidState is Close and the value of PowerState is Offline, the terminal usage state determination unit 19 performs the process of step S1406, and if it is determined that the value of the variable LidState is not Close or the value of PowerState is not Offline, the terminal usage state determination unit 19 performs the process of step S1407.

[0077] In step S1406, terminal use state determination unit 19 counts up using a counter (not shown) to measure the time the cover is closed and the device is powered by the battery. Then, as a result of the counting up in step S1406, it determines whether the time the cover is closed and the device is powered by the battery has continued for 15 minutes (step S1408). If it determines that the time the cover is closed and the device is powered by the battery has continued for 15 minutes (YES in step S1408), terminal use state determination unit 19 performs the process of step S1409. If it determines that the time the cover is closed and the device is powered by the battery has not continued for 15 minutes (NO in step S1408), terminal use state determination unit 19 returns to step S1405 and continues the process.

[0078] In step S1409, the volatilization level determination unit 20 determines the volatilization level, and the data volatilization processing unit 21 performs volatilization processing of the data based on the determined volatilization level.

[0079] On the other hand, in step S1407, the terminal use state determination unit 19 resets the counter that counts the time when the cover is closed and the device is battery-powered. After that, the terminal use state determination unit 19 returns to step S1405 and continues the process.

[0080] 15 is a flowchart showing an example of a user confirmation volatility determination operation by a camera of the information processing device 1 according to the embodiment. The user confirmation volatility determination operation by a camera shown in the flowchart of FIG. 15 corresponds to step S1204 in FIG.

[0081] First, the terminal usage state determination unit 19 uses a face authentication function to confirm who is currently using the information processing device 1 based on the image capture result by the camera 13 (step S1501). Next, the terminal usage state determination unit 19 determines whether the user of the information processing device 1 authenticated in step S1501 is a user who has already been linked to (pre-registered in advance) this information processing device 1 (step S1502).

[0082] If it is determined that the user is a registered user (YES in step S1502), the terminal usage status determination unit 19 performs the processing of step S1504, and if it is determined that the user is not a registered user (NO in step S1502), the terminal usage status determination unit 19 performs the processing of step S1503.

[0083] In step S1503, the terminal usage status determination unit 19 counts up using a counter (not shown) to measure the elapsed time since it was determined that a user who is not a registered user is using the information processing device 1. Then, as a result of the counting up in step S1503, it is determined whether the elapsed time since it was determined that a user who is not a registered user is using the information processing device 1 is 5 minutes, 10 minutes, or 15 minutes (step S1505). If it is determined that the elapsed time since it was determined that a user who is not a registered user is using the information processing device 1 is 5 minutes, 10 minutes, or 15 minutes (YES in step S1505), the terminal usage status determination unit 19 performs the process of step S1506. If it is determined that the elapsed time since it was determined that a user who is not a registered user is using the information processing device 1 is not 5 minutes, 10 minutes, or 15 minutes (NO in step S1505), the terminal usage status determination unit 19 returns to step S1501 and continues the process.

[0084] In step S1506, it is determined whether 15 minutes have elapsed since it was determined that a user who is not a registered user is using the information processing device 1. If it is determined that 15 minutes have elapsed since it was determined that a user who is not a registered user is using the information processing device 1 (YES in step S1506), the terminal usage status determination unit 19 performs the process of step S1507, and if it is determined that 15 minutes have elapsed since it was determined that a user who is not a registered user is using the information processing device 1 (NO in step S1506), the terminal usage status determination unit 19 performs the process of step S1508.

[0085] In step S1507, the volatilization level determination unit 20 determines the volatilization level, and the data volatilization processing unit 21 performs data volatilization processing based on the determined volatilization level. Meanwhile, in step S1508, the terminal usage state determination unit 19 displays a warning message on the display device 17 of the information processing device 1, and then returns to step S1501 to continue processing.

[0086] On the other hand, in step S1504, the terminal usage status determination unit 19 resets a counter that counts the elapsed time since it was determined that a user who is not a registered user is using the information processing device 1. Thereafter, the terminal usage status determination unit 19 returns to step S1501 and continues the process.

[0087] 16 is a diagram showing an example of the volatility level table 24 stored in the information processing device 1 according to the embodiment. The volatility level table 24 shown in FIG. 16 is the basis for the volatility level determination operation performed by the volatility level determination unit 20 in step S405 of FIG.

[0088] 16 corresponds to one of level 1 to level 3 based on the determination result by the terminal usage state determination unit 19. Then, the data volatilization processing unit 21 performs data volatilization processing based on the volatilization level determined by the volatilization level determination unit 20. Note that level 3 is assumed to be the volatilization level when the information processing device 1 is lost, and an in-house information terminal administrator remotely volatilizes the OS data upon contact by the user of the information processing device 1.

[0089] 17 and 18 are diagrams showing an example of a list of volatilization conditions for the information processing device 1 according to the embodiment. The volatilization conditions shown in Fig. 17 are volatilization conditions when the user authority of the information processing device 1 is that of a general user, and the volatilization conditions shown in Fig. 18 are volatilization conditions when the user authority of the information processing device 1 is that of an administrator. The data volatilization processing unit 21 volatilizes data stored in the storage device 12 in accordance with the volatilization conditions, examples of which are shown in Fig. 17 and Fig. 18.

[0090] Fig. 19 is a diagram showing an example of a screen UI in the information processing device 1 according to the embodiment. The screen UI shown in Fig. 19 is intended for an administrator of the information processing device 1, and is a screen that allows the administrator to change the details (such as time) of the volatilization level determination by the volatilization level determination unit 20.

[0091] Fig. 20 is a diagram showing another example of a screen UI in the information processing device according to the embodiment. The screen UI shown in Fig. 20 is intended for general users of the information processing device 1. This screen is displayed prior to the data volatilization process by the volatilization level determination unit 20 in order to prevent unintended data volatilization process from being performed, for example, if the user has been engaged in work that does not involve the use of the information processing device 1 for a long period of time.

[0092] For example, data volatilization may occur when a user is traveling by train or other means of transportation, when working in an environment where they cannot connect to the corporate network, such as a reception room, or when they are traveling between locations and are unable to connect to the corporate network. Furthermore, when a user is connected to the corporate network using the tethering function of a company-issued smartphone or other device, data volatilization may also occur if the tethering is disconnected due to the user leaving the office or other reasons. Furthermore, data volatilization may also occur if the network device used to connect to the corporate network fails. It is preferable to inform users of the possibility of such unintended data volatilization, and to display a message such as that shown in FIG. 20 on the screen of the user's smartphone.

[0093] Alternatively, if the information processing device 1 has already been misused, a screen such as that shown in FIG. 20 can be displayed on the smartphone of the user of the information processing device 1 to notify the user of the possibility of misuse of the information processing device 1 at an early stage.

[0094] As described above, according to the information processing device 1 of this embodiment, it is possible to prevent leakage of data stored in the storage device 12 of the information processing device 1 depending on the usage state of the information processing device 1. Moreover, it is possible to perform data volatilization processing in stages depending on the usage state of the information processing device 1.

[0095] The above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to those including all of the described components. Furthermore, some of the components of each embodiment can be added to, deleted from, or replaced with other components.

[0096] Furthermore, the above-described configurations, functions, processing units, processing means, etc. may be partially or entirely implemented in hardware, for example, by designing them as integrated circuits. The present invention can also be realized by software program code that implements the functions of the embodiments. In this case, a storage medium on which the program code is recorded is provided to a computer, and a processor included in the computer reads the program code stored in the storage medium. In this case, the program code itself read from the storage medium implements the functions of the above-described embodiments, and the program code itself and the storage medium on which it is stored constitute the present invention. Examples of storage media for providing such program code include flexible disks, CD-ROMs, DVD-ROMs, hard disks, solid-state drives (SSDs), optical disks, magneto-optical disks, CD-Rs, magnetic tapes, non-volatile memory cards, and ROMs.

[0097] Furthermore, the program code for realizing the functions described in this embodiment can be implemented in a wide range of program or script languages, such as assembler, C / C++, perl, Shell, PHP, Java (registered trademark), and Python.

[0098] Furthermore, all or part of the program code of the software that realizes the functions of each embodiment may be stored in advance in the storage of the machine learning system, or, if necessary, may be stored in the storage from a non-temporary storage medium from a non-temporary storage device of another device connected to the network, or via an external I / F (not shown) provided by the machine learning system.

[0099] Furthermore, the program code of the software that realizes the functions of the embodiments may be distributed via a network and stored in a storage means such as a computer's hard disk or memory, or in a storage medium such as a CD-RW or CD-R, and the processor of the computer may read and execute the program code stored in the storage means or storage medium.

[0100] In the above-described embodiment, the control lines and information lines are shown as those considered necessary for the explanation, and not all control lines and information lines are necessarily shown in the product. All components may be interconnected. (Appendix 1) An information processing device having a processor and a storage device storing data including user data created and used by a user, The processor: determining a usage state of the information processing device by the user; If it is determined that the information processing device is being used illegally by someone other than the user, the data in the storage device is erased. 1. An information processing device comprising: (Appendix 2) The information processing device according to (Supplementary Note 1), wherein the processor differentiates the timing of erasing the user data stored in the storage device from the other data. (Appendix 3) The information processing device according to claim 2, wherein the processor erases the data other than the user data if it determines that the data has been used fraudulently after erasing the user data. (Appendix 4) The information processing device according to claim 1, wherein the processor erases the data if the unauthorized use state continues for a predetermined period of time. (Appendix 5) The information processing device according to (Supplementary Note 4), wherein the processor sets the predetermined time period in accordance with the usage state. (Appendix 6) A data protection method for an information processing device having a processor and a storage device storing data including user data created and used by a user, determining a usage state of the information processing device by the user; If it is determined that the information processing device is being used illegally by someone other than the user, the data in the storage device is erased. 2. A data protection method for an information processing device. (Appendix 7) A computer program executed by a computer having a processor and a storage device storing data including user data created and used by a user, When this computer program is executed, the computer determining a usage status of the computer by the user; If it is determined that the computer is being used illegally by someone other than the user, the data in the storage device is erased. This computer program is characterized by: [Explanation of symbols]

[0101] 1...information processing device 10...processor 11...memory 12...storage device 13...camera 14...input device 15...open / close detection switch 16...GPS module 17...display device 18...network module 19...terminal usage state determination unit 20...volatility level determination unit 21...data volatility processing unit 22...terminal usage state data 23...NW connection state data 24...volatility level table 30...network 40...in-house server, etc.

Claims

1. An information processing device having a processor and a storage device storing data including user data created and used by a user, The processor: determining a usage state of the information processing device by the user; If it is determined that the information processing device is being used fraudulently by a person other than the user, the data in the storage device is erased. the information processing device includes a camera and a display device; the information processing device includes a GPS module or a network module having a wireless LAN function, The processor: Based on the result of the photographing by the camera, a face authentication function is used to identify the person using the information processing device at the time of the photographing; determining whether the person identified by the face authentication function is a user already associated with the information processing device; measuring a duration of a determination result that the person confirmed by the face authentication function is not a user already linked to the information processing device; When the measured duration reaches a first predetermined time, a warning is displayed on the display device; When the measured duration reaches a second predetermined time that is longer than the first predetermined time, the data in the storage device is erased.

1. An information processing device comprising:

2. An information processing device having a processor and a storage device storing data including user data created and used by a user, The processor: determining a usage state of the information processing device by the user; If it is determined that the information processing device is being used fraudulently by a person other than the user, the data in the storage device is erased. the information processing device includes a camera; The processor: Based on the result of the photographing by the camera, a face authentication function is used to identify the person using the information processing device at the time of the photographing; determining whether the person identified by the face authentication function is a user already associated with the information processing device; If a predetermined time has passed with the determination result that the person confirmed by the face authentication function is not a user already linked to the information processing device, the data in the storage device is erased.

1. An information processing device comprising:

3. An information processing device having a processor and a storage device storing data including user data created and used by a user, The processor: determining a usage state of the information processing device by the user; If it is determined that the information processing device is being used fraudulently by a person other than the user, the data in the storage device is erased. the information processing device includes a GPS module or a network module having a wireless LAN function, The processor: acquiring location information of the information processing device via the GPS module or the network module having the wireless LAN function; determining whether the position of the information processing device specified by the position information is within a predetermined set range; determining whether the information processing device is connected to a secure network rather than directly connected to a WAN; When the location of the information processing device is within the predetermined setting range and the information processing device is connected to the secure network, the data in the storage device is not erased even if it is determined that the information processing device is being used fraudulently by someone other than the user.

1. An information processing device comprising:

4. A data protection method for an information processing device having a processor and a storage device in which data including user data created and used by a user is stored, comprising: The data protection method includes: determining a usage state of the information processing device by the user; If it is determined that the information processing device is being used fraudulently by a person other than the user, the data in the storage device is erased. the information processing device includes a camera and a display device; the information processing device includes a GPS module or a network module having a wireless LAN function, The data protection method includes: Based on the result of the photographing by the camera, a face authentication function is used to identify the person using the information processing device at the time of the photographing; determining whether the person identified by the face authentication function is a user already associated with the information processing device; measuring a duration of a determination result that the person confirmed by the face authentication function is not a user already linked to the information processing device; When the measured duration reaches a first predetermined time, a warning is displayed on the display device; When the measured duration reaches a second predetermined time that is longer than the first predetermined time, the data in the storage device is erased.

2. A data protection method for an information processing device.

5. A data protection method for an information processing device having a processor and a storage device in which data including user data created and used by a user is stored, comprising: The data protection method includes: determining a usage state of the information processing device by the user; If it is determined that the information processing device is being used fraudulently by a person other than the user, the data in the storage device is erased. the information processing device includes a camera; The data protection method includes: Based on the result of the photographing by the camera, a face authentication function is used to identify the person using the information processing device at the time of the photographing; determining whether the person identified by the face authentication function is a user already associated with the information processing device; If a predetermined time has passed with the determination result that the person confirmed by the face authentication function is not a user already linked to the information processing device, the data in the storage device is erased.

2. A data protection method for an information processing device.

6. A data protection method for an information processing device having a processor and a storage device in which data including user data created and used by a user is stored, comprising: The data protection method includes: determining a usage state of the information processing device by the user; If it is determined that the information processing device is being used fraudulently by a person other than the user, the data in the storage device is erased. the information processing device includes a GPS module or a network module having a wireless LAN function, The data protection method includes: acquiring location information of the information processing device via the GPS module or the network module having the wireless LAN function; determining whether the position of the information processing device specified by the position information is within a predetermined set range; determining whether the information processing device is connected to a secure network rather than directly connected to a WAN; When the location of the information processing device is within the predetermined setting range and the information processing device is connected to the secure network, the data in the storage device is not erased even if it is determined that the information processing device is being used fraudulently by someone other than the user.

2. A data protection method for an information processing device.

7. 7. A computer program for causing the information processing device to execute the data protection method according to claim 4, 5 or 6.

Citation Information

Patent Citations

  • Portable data recording terminal

    JP2002216099A

  • Terminal device, secret information management method and program

    JP2005339255A

  • Client system, server system, their control method, control program, data erasure system and method

    JP2007316789A

  • Device for preventing outflow of information for portable terminal

    JP2008181467A

  • Thin client system

    JP2009181460A