Data Masking System
The data masking system addresses the inadequacies of existing technologies by converting and masking multimedia data, ensuring confidential information remains secure even if leaked, with enhanced management features.
Patent Information
- Application Number
- JP2024094654
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2016-06-29
- Filing Date
- 2024-06-11
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2037-06-29
AI Technical Summary
Existing data masking technologies are inadequate for multimedia data, and encrypted data can be decrypted to reveal confidential information, posing a risk of leakage.
A data masking system that converts and masks confidential data into viewable/listenable data, applies encryption, and stores masked data securely, with additional features like data linking and shredding to prevent unauthorized access.
Effectively conceals confidential information, making it impossible to view or listen to even if data is leaked, while enhancing data management convenience and security.
Smart Images

Figure 0007777353000001 
Figure 0007777353000002 
Figure 0007777353000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a data masking system that, when various data including confidential information is made available for viewing or viewing, makes it easy to view or listen to the portion of the data to be viewed or listened to, while reliably concealing the confidential information. [Background technology]
[0002] In recent years, with the spread of digitalization due to advances in digital technology and from the perspective of resource conservation, efforts are being made to go paperless. In other words, the storage of documents and other information is shifting from analog formats such as paper, photographs, and drawings to digital formats in which documents are digitized and stored in databases.
[0003] Furthermore, public institutions and companies that are obligated to disclose information are required to take into consideration personal information and some confidential information. Therefore, there is a demand for a data processing method (masking method) that can separate data into confidential information and information that can be disclosed and then display it.
[0004] Furthermore, data containing confidential information has become more diverse, including not only traditional documents and images but also music, videos, and other media, and with the spread of multimedia data, the importance of masking methods for this data is also increasing. Furthermore, with the spread of high-definition 4K and 8K video cameras, images captured on video are not only viewed, but also increasingly viewed as still images (photographs) of individual frames captured at 60 to 120 frames per second.
[0005] However, data is at risk of being leaked when sending and receiving information over communication networks, or of being intercepted or attacked by third parties during transmission. Other major issues include data being copied and leaked from within a company, or data being left behind when data is taken out. Furthermore, with the development of cloud servers and other technologies, the operation of information stored and utilized on external storage devices always carries the risk of information leaks from within or outside the company. Therefore, data management that minimizes damage even in the unlikely event of a data leak is necessary.
[0006] Individuals also face challenges in terms of both the benefits of digitalization and the risk of personal information leaks. For example, in recent years, the number of cloud server-based browsing and storage services has increased, but the damage caused by information leaks, such as the invasion of privacy, has become a major issue. The damage caused by information leaks varies depending on the content of the data, i.e., whether or not it contains confidential information, and its importance, but there is a concern that it could sometimes cause enormous damage.
[0007] Therefore, if the data to be distributed for viewing is encrypted and transmitted over a communication network, or if the data to be distributed is encrypted and recorded on an external storage device, the above-mentioned risk can be significantly reduced, but if the encrypted data is decrypted, all of the information contained in the data can be viewed, and therefore the information can be leaked.If encrypted data is decrypted and displayed, related information will also be displayed, so there is a risk that the information will be known to people who do not need to know it after decryption.
[0008] Additionally, methods for preventing information leaks or minimizing damage in the event of a leak include, for example, encrypting data multiple times or using more complex encryption. However, such methods would significantly increase the effort, skill, and cost required to store data, and would be less convenient for users. Furthermore, even if data is encrypted multiple times, related information can still be seen if it is decrypted and displayed, as mentioned above, and this does not fundamentally solve the problem.
[0009] Various technologies have been proposed to ensure that such digitized data can be both confidential and accessible. For example, Patent Document 1 discloses a medical image processing device that aims to prevent leakage of patient information contained in medical images as text images, and to allow only the medical images to be viewed by concealing the patient information at the output destination of the medical images.
[0010] Specifically, based on the selected image output format, the input medical image is arranged to create an output format image, the patient information area is extracted from the created output format image, and masking processing based on reversible conversion is performed on only the data and thumbnail image in accordance with the input encryption key.
[0011] Furthermore, Patent Document 2 discloses an information transmission device that can automatically perform mask processing on not only character string elements but also image elements and transmit the masked information.
[0012] Specifically, in Patent Document 2, content information is separated into a text area and an image area, and image elements extracted from the image area are compared with an NG image. If the two are similar, the rectangular area of the content information that contains the NG image is filled in and displayed.
[0013] Furthermore, Patent Document 3 discloses a content portion concealment device that enables a content provider to easily specify a portion of content that the provider wishes to conceal.
[0014] Specifically, the system accepts keywords and confidential part extraction conditions from the user, analyzes the sentence structure of the text part of the content, and extracts parts of the content that match the confidential part extraction conditions and encrypts them. [Prior art documents] [Patent documents]
[0015] [Patent Document 1] Japanese Patent Application Laid-Open No. 2007-319342 [Patent Document 2] Japanese Patent Application Laid-Open No. 2012-238222 [Patent Document 3] Japanese Patent Application Laid-Open No. 2004-287566 Summary of the Invention [Problem to be solved by the invention]
[0016] However, the techniques described in the above Patent Documents 1 to 3 all apply masking processing to documents or images, and are unable to apply masking processing to music, video, or multimedia data.
[0017] In addition, in both technologies, encryption is only temporary, so the confidential information is still viewable at the masking stage, and it is not possible to completely prevent information leakage or viewing by third parties.
[0018] In light of the above, there is a need for a method for easily and quickly masking various types of data, including confidential information, so that it is easy to use and, in the unlikely event that it is leaked, it can minimize damage.
[0019] The object of the present invention is to provide a data masking system that can mask confidential information contained in various data to be viewed or listened to, concealing the confidential information portion and allowing only other general data to be viewed or listened to, and that can make it impossible to actually view or listen to the confidential information even if the final unmasked data is leaked or compromised. [Means for solving the problem]
[0020] In order to solve the above problems, the present invention provides a data masking system that includes a data conversion unit that converts all or part of first data including information to be concealed, the part including the information to be concealed, into second data for viewing or listening, a masking processing unit that performs a masking process on the second data to create masked data, a storage unit that stores the masked data, and an output unit that outputs the masked data stored in the storage unit.
[0021] The device may further include an encryption processing unit that performs encryption processing on the first data to create encrypted data, the storage unit stores the encrypted data, and the output unit outputs the encrypted data stored in the storage unit.
[0022] The data link unit may further comprise a data link unit that links the encrypted data with the second data.
[0023] The data processing device may further include a concealment portion selection unit that selects an area to be concealed that includes information to be concealed that is included in the second data, and the masking process may include a first masking process that is applied to the area to be concealed selected by the concealment portion selection unit.
[0024] The masking process may further include a second masking process that is performed on an area other than the area to be concealed in the second data.
[0025] The second data may be plural, the second masking process may be applied to the whole of the plural second data, and the first masking process may be applied to a part of the plural second data.
[0026] The second data may be plural, and the second masking process may be commonly performed on the same region of each of the plural second data.
[0027] The masking process may involve removing the second masking process to create restored or decoded third data, and then performing the first masking process on the third data.
[0028] The second masking process may be removed from a portion of the second data.
[0029] The third data may be copied, and the copied third data may be made unoutputtable and stored in the storage unit.
[0030] The encryption device may further include an encryption history recording unit that records the history of the encryption process and the masking process.
[0031] The output unit may further have an authentication input unit into which an authentication key can be input, and may request authentication when outputting masked data.
[0032] The data processing device may further include a keyword assigning unit that can assign search keywords to the encrypted data and the masked data.
[0033] The storage unit may include a first storage unit that stores the encrypted data and a second storage unit that stores the masking data.
[0034] The masked data may be temporarily restored or decrypted using a password or decryption key so that it returns to the masked state when a predetermined condition is met.
[0035] The apparatus may further include a communication unit capable of communicating with a network, and the output unit may output the encrypted data and the masked data to an external device via the network.
[0036] When discarding either or both of the encrypted data and the viewing / listening masked data, the data may be subjected to a second masking process by adding non-periodic data, and then the data may be subjected to a data shredding process by dividing the data into multiple unrecoverable data pieces before being discarded.
[0037] The image processing device may further include a viewing / viewing history recording unit that records the viewing / viewing history and / or feedback when the masked data output from the output unit is viewed / viewed.
[0038] The data conversion unit may further have a function of specifying a resolution when the second data is an image, and a function of specifying a viewing accuracy when the second data is video or music. [Effects of the Invention]
[0039] This invention masks confidential information contained in various data to be viewed and listened to, concealing the confidential information portion and allowing only other general data to be viewed and listened to, while also making it practically impossible to view and listen to the confidential information even if the final unmasked data is leaked or divulged. Furthermore, by performing data link processing such as adding commands to the original data, it becomes possible to link the encrypted data that encrypts the original data with the masked data that has been masked for viewing and listening, which makes it possible to greatly improve the convenience of management. [Brief explanation of the drawings]
[0040] [Figure 1] 1 is a system diagram showing the overall configuration of a data masking system according to a first embodiment. [Figure 2] 1 shows various masking states when masking an image file using the data masking system according to the present invention. [Figure 3] 1 is a system correlation diagram showing the overall configuration when the data masking system according to the present invention is used in combination with the Internet. [Figure 4] 1 is a system correlation diagram showing the overall configuration when the data masking system according to the present invention is used in combination with the Internet. [Figure 5] FIG. 10 is a system diagram showing the overall configuration of a data masking system according to a second embodiment. [Figure 6] FIG. 10 is a diagram illustrating a concealment area when there is a plurality of data to be concealed. DETAILED DESCRIPTION OF THE INVENTION
[0041] Below, a data masking system according to an embodiment of the present invention (hereinafter referred to as "this system"; the same applies to other embodiments, operation and use cases, etc.) will be described in detail with reference to the attached drawings.
[0042] As shown in Figure 1, the system is configured to include a data conversion unit that converts all or part of the data, including information to be kept secret, into viewing / viewing data for viewing or viewing; a masking processing unit (a batch masking processing unit and an individual masking processing unit) that performs a masking process on the viewing / viewing data to create masked data; an encryption processing unit that performs an encryption process on data including information to be kept secret to create encrypted data; a final storage unit that stores the encrypted data and masked data; and an output unit that outputs the encrypted data and masked data.
[0043] Furthermore, this system includes a concealment portion selection unit that selects a concealment target area containing concealment target information included in the data. The masking processing unit is composed of an individual masking processing unit and a batch masking processing unit. The individual masking processing unit performs masking processing on the concealment target area selected by the concealment portion selection unit in the data for viewing / viewing. The batch masking processing unit also performs masking processing on areas of the data for viewing / viewing other than the concealment target area. For example, when the data for viewing / viewing is an image, this masking processing can employ various methods such as striped filling, checkered filling, full filling, blurring, adding patterns, blacking out, whitening out, and adding dummy data. Furthermore, color conversion of the concealment target area is defined as part of the masking processing, from the perspective of hiding the original.
[0044] The system also includes a keyword assignment unit that assigns search keywords to the original data. This keyword assignment ensures that the same keywords are assigned to both encrypted data and masked data in a later process, improving operational management convenience.
[0045] This system includes a data link unit. The data link unit assigns a command such as #01# to the original data. By assigning this command, the command #01# is also assigned to the encrypted data and the masked data. As a result, the encrypted data and the masked data to which the same command is assigned are linked to each other.
[0046] The data conversion unit in this system converts each piece of data, including confidential information, into viewing / viewing data that shows a portion of the data's contents and allows users to view or listen to it. Specifically, examples include thumbnail images if the original data is an image, a partial page or region of a document if the original data is a document, or a selected portion if the original data is music or video. However, the data to be converted is not limited to these, and the data may be converted into a different type of data from the original data. Furthermore, if the viewing / viewing data is an image, the data conversion unit may further have a function to specify the resolution. Alternatively, if the data is video or music, the data conversion unit may further have a function to specify the viewing accuracy (bandwidth and number of gradations).
[0047] This system also includes an encryption processing unit. The encryption processing unit performs various encryption processes on data received from the data link unit. Examples of encryption processes include password protection, disguising by changing the file extension, changing the security level, changing the algorithm, and commonly used encryption processes such as the common key method (AES) that encrypts by entering a password, and the method that uses a private key and public key (RSA). Note that the encryption processing unit may not perform encryption processes at all.
[0048] The system also includes an encryption history recording unit that includes a medium capable of recording the history of encryption and / or masking processes performed in the encryption processing unit or masking processing unit (collectively masking processing unit and individual masking processing unit).
[0049] Furthermore, this encryption history recording unit can be configured to record not only the encryption / masking history, but also the history of each file being saved to removable media such as USB, and the history of data being sent externally via wired or wireless connections. This makes it possible to reliably identify the source of data leakage by checking the history in the event of data leakage or leak.
[0050] In this way, by keeping a history of encryption / masking, there is an operational advantage in that it becomes easier to manage files that have been encrypted and masked, and the details of that encryption / masking.
[0051] The system also includes a temporary storage unit that temporarily stores the browsing / audio data that has been subjected to the batch masking process, and transmits the data to the batch unmasking unit via a LAN or the Internet.
[0052] The batch unmasking unit unmasks the received viewing / listening data and connects and transmits it to the individual masking processing unit. Note that this batch unmasking unit may be integrated with the individual masking processing unit so that the individual masking processing is performed simultaneously with the batch unmasking.
[0053] The individual masking processing unit performs a masking process on the area to be concealed in the viewing / listening data. This generates individual masked data. The generated individual masked data is sent to the final storage unit and stored in the final storage unit, or is temporarily stored directly on a storage medium in the individual masking processing unit. As with bulk masking, various methods can be used for this individual masking. To release bulk masking or individual masking, a masking tool that can be peeled and re-masked multiple times as needed, such as a re-peelable sticker, may have a temporary release function. In addition, masking processes can be added or changed.
[0054] The final storage unit stores the encrypted data received from the encryption processing unit and the masked data received from the masking processing unit. The final storage unit also functions as an output unit that outputs the stored data to the outside via a LAN or the Internet. In other words, the final storage unit also functions as a communication unit. Naturally, the final storage unit and the communication unit may be arranged separately. The final storage unit transmits the viewing data to a general-purpose viewing viewer or a dedicated viewing viewer via an output unit connected to a LAN or the Internet. Furthermore, if the data is video or music, it is transmitted as general-purpose viewing data or dedicated viewing data.
[0055] The general-purpose viewing viewer and general-purpose viewing data are in a state where anyone can freely view and view them, and it is possible to freely view and view masked data without using a password, etc. However, viewing and viewing may be restricted by setting viewing and viewing conditions (age, membership, etc.) as well as by limiting the viewing and viewing period and the number of times the data can be viewed and viewed.
[0056] Only specific individuals are permitted to access the dedicated viewing viewer and dedicated viewing data, and access to the data requires authentication such as a dedicated authorization ID, password, or personal authentication.
[0057] In addition, the general-purpose viewing viewer, dedicated viewing viewer, and viewing data may have the aforementioned temporary release function when viewing or watching using these. Furthermore, the general-purpose or dedicated viewing viewer and viewing data may also be equipped with a viewing / viewing history recording unit and a medium capable of recording the viewing / viewing history of the viewers. It is also preferable that the viewing / viewing history recording unit be equipped with a feedback function that allows the viewers' impressions and opinions, i.e., reactions, to be recorded. This makes it possible to grasp the viewers' level of interest based on the viewing / viewing history records and the viewers' impressions and opinions. This feedback can also be sent to information terminals such as PCs via a cloud server.
[0058] For example, in the case of official documents, there are cases where the documents are not stored for viewing but are required to be stored for a long period of time by law, etc., and therefore the data is not sent to either a general-purpose viewer or a dedicated viewer. In such cases, the final storage unit continues to store the documents in a confidential state, and further encrypts them, and then discards them after the storage period has elapsed.
[0059] In addition, as mentioned above, the viewing and viewing masking data linked to the encrypted data When discarding either or both of the data, the data is shredded and divided into smaller pieces using the data shredding function, and the shredded data is then scrambled and discarded. At this time, the link data is also disassembled and decrypted. Furthermore, when discarding the data, it may be further encrypted to make it difficult to decrypt before discarding.
[0060] At this time, for the viewing image masking data, the masking data is divided into a matrix of any size, and the data is averaged either as a whole or in units of divisions. It is then further shredded using the aforementioned data shredding function, and the shredded data is scrambled (a process of further shuffling the shredded data) before being discarded. The data averaging method involves tallying all the colors (RGB, CMYK, etc.) of all pixels in each block of the image divided into a matrix, and replacing the averaged color with the color of all pixels in the block, creating a mosaic-like image for the entire image. For text data, dummy data is randomly added to the text data, which is then divided into data of any size, and each division is scrambled and discarded.
[0061] The masked data for viewing can be obscured by white-out exposure, color conversion, distortion, or the addition of noise or dummy data. The data can then be subdivided into the number of frames or playback time required for the video, and then scrambled and discarded. In these cases, it is even better to encrypt the data before or after the subdivision process. Another method is to overlay this irreversible masking image on top of the confidential data, masking it to prevent the underlying data from being leaked. The decryption key is a hash of a long password, which is used to remove the masking of this irreversible image overlaid on top of the confidential data. Since the hash data is indecipherable, if the lossy masking needs to be removed, it can be done by selecting a password with a matching hash value from among multiple passwords stored on a PC. Alternatively, to permanently prevent the confidential data from being viewed or played, the masking can be deleted and replaced with unrelated dummy data.
[0062] If you want to discard masked data, you can safely discard it by performing the following additional processing. Specifically, when erasing data stored in a PC's storage device, external storage devices including cloud servers, or storage devices such as smartphones, erasure generally only involves erasing the data header. Therefore, using application software specifically designed for data masking, dummy data is added to the data for masking purposes. In the case of image data, further matrix division processing is performed, image averaging is performed for each matrix division, and then the matrix division array is scrambled for safe disposal. At this point, the data can be further processed and discarded using an existing data erasure program.
[0063] Figure 2 shows specific examples of each masking method. The original data 10 is an unpublished photograph of a new prototype car manufactured by an automobile manufacturer, and this data must be kept secret. Therefore, the concealment portion selection unit selects the concealment target region 11, which contains information about the car that must be kept secret.
[0064] Then, an individual masking process (checkered pattern in FIG. 2) is performed by the individual masking processing unit, thereby generating masking data 20.
[0065] Furthermore, before the individual masking process, the collective masking processing unit may generate collective masking data 30. In this state, the collective masking data 30 is stored in the temporary storage unit, sent to the collective masking release unit, the collective masking is released, and sent to the individual masking processing unit.
[0066] In this way, the data to be sent to the individual masking processing unit is Since the data is not data 10 containing the information to be concealed but is instead batch masked data 30, even if information is leaked or hacked during the process from the data conversion unit to the individual masking processing unit, the confidential information cannot be easily viewed or listened to. Also, adding dummy data during batch masking provides a safer solution even if the information is disclosed. Of course, as mentioned above, the masked data may be further encrypted.
[0067] (Second embodiment) Next, the system according to the second embodiment will be described with reference to Fig. 5. The overall configuration of the system according to the second embodiment is similar to that of the first embodiment. Therefore, the following description will focus on the differences from the first embodiment, and some parts that have already been described may be omitted.
[0068] In the second embodiment, the final storage unit includes a first data storage unit (first storage unit) that stores encrypted data encrypted by the encryption processing unit, and a second masking data storage unit (second storage unit) that stores masked data. Note that, as shown in Fig. 5, the output unit in this embodiment is integrated with the final storage unit.
[0069] The first data storage unit (first storage unit) and the second masking data storage unit (second storage unit) are equipped with different recording media that are isolated from each other, and data cannot be moved between them. However, as described above, the data stored in each is linked by commands or the like. They are also not accessible at the same time. In this way, by separating and isolating the first data storage unit and the second masking data storage unit, it is possible to prevent the two data from being leaked or leaked at the same time, compared to when the encrypted data and masking data are stored in a single storage unit.
[0070] Furthermore, in this embodiment, a viewing / viewing restriction unit is provided. The viewing / viewing restriction unit may request information about the viewer before disclosing the viewing / viewing. Furthermore, the viewing / viewing restriction unit may limit the viewing / viewing period and the number of times the content can be viewed / viewed.
[0071] Furthermore, this embodiment includes a re-encryption unit and a decryption unit. The re-encryption unit applies a different type of encryption process to the encrypted data or masked data stored in the final storage unit than the encryption or masking applied to them. The re-encryption unit can then be configured to discard the data after a predetermined period of time has passed. Alternatively, before sending the data to a general-purpose or dedicated viewer, the data can be sent again to the decryption unit for decryption and then sent to the respective viewer. This further increases the security level.
[0072] (Encryption process procedure) Here, an example of the procedure of the encryption process performed in the encryption processing unit of this system will be described. First, we developed an encryption GUI that allows encryption and decryption to be performed using normal file operations, making it easy for anyone to use. In addition, encrypted files will have a different icon, making them easier to understand visually and helping to prevent missing encryption files.
[0073] Specifically, the procedure is as follows: (1) First, select the file (or folder) of data to be encrypted. (2) When you place a file in the encrypted folder, it is automatically encrypted on a file-by-file basis and the file icon changes. (3) Enter the decryption key and click to decrypt and display the contents (plain text). The file icon will also return. (4) If you view the decrypted file, edit it, and save it, it will be automatically re-encrypted and saved. It can also remain. (5) You can also display the decrypted file, specify masking, and save it, which will automatically mask the file and save it.
[0074] (Encryption unit) With file or folder encryption, you select the file or folder you want to encrypt and enter a password to encrypt it. Decryption is also done by selecting the file or folder. You can create a file, folder, or virtual drive, encrypt only the contents, and output them as a regular file on your computer. Encrypting files is quick and easy when attaching them to an email or encrypting them for transport, while encrypting folders is convenient for storing frequently used files or large numbers of files.
[0075] Encrypting the entire hard disk (HDD) also makes it possible to prevent information leaks due to theft or loss of a laptop. Normally, all data is protected unless the password and decryption key entered when starting up the PC are known, but once the password and decryption key are entered and the PC is started up, the data becomes defenseless. This system is primarily implemented by corporations to protect against theft and loss of laptops, and encryption can be performed via command processing, and applications can be automatically launched at the same time as decryption.
[0076] Storage media such as HDDs (Hard Disk Drives) and flash memory are managed using cryptographic processes that encrypt and decrypt data. AES (Advanced Encryption Standard)-XTS is becoming the standard method for encryption of storage media. AES-XTS encrypts or decrypts sector numbers, which identify the location on the disk of the storage media.
[0077] (Operational overview by data) The following describes the operation of each data type common to the present system according to each embodiment. (1) For text data When masking text data such as diaries, reports, development project progress management information, slips, and personal information on application forms, the individual masking process involves keyword searching for the text to be masked, or detecting fields or items that require masking, such as address fields, name fields, and amount fields, and then selecting and masking them all at once or sequentially. Of course, no masking is required for pages that do not require masking, or the bulk masking process described above can be performed. In this case, even pages that do not require masking may be masked as a feint process to confuse the other party as a leak prevention measure. Adding dummy data provides a double level of security, preventing leaks by preventing the password from being leaked unless a recovery process for the dummy data is performed, since the dummy data remains mixed in even if the password is leaked.
[0078] In addition, for individual masking processing, when the original text data has been converted into a PDF image format, OCR processing is performed on the PDF image, and when text is obtained, the text to be masked can be searched for by keyword, and the text can be selected all at once or sequentially, and the masking processing can be performed, or the text can be added freely.
[0079] (2) In the case of image data When masking data such as photographs and illustrations, individual masking is performed on images that are searched for by image location search, and the original data is in image format, and the text and image parts are individually separated using a function related to OCR processing. In the case of data that can be searched for by image search, masking is performed on images that are searched for by image location search. For example, in the case of masking medical MRI images, masking is performed on names, disease names, imaging dates, disease conditions, etc. The keyword assignment unit assigns keywords for search.
[0080] Individual masking is performed when the original data is in image format and a part or all of the image is masked. Furthermore, when the original data is in image format, it is also possible to process the image by performing color conversion on a part or all of the image as part of the masking process, changing part of the image to dummy data that can be reversibly converted, or inserting a digital watermark.
[0081] (3) In the case of video, music, audio recordings, and conversations When masking data such as movies, music, audio, recorded conversations, and real-time conversations, individual masking can be performed by converting the data into image data for viewing or by converting the data into data for viewing. When converting to image data for viewing, the image can be selected from template images pre-registered and stored in the data conversion unit or an external cloud server. For viewing data, for example, data for a certain period of time from the beginning of the data or data that intermittently connects multiple segments can be used. Then, a batch masking process is performed on the image data or viewing data to create batch masked data. The masking of this batch masked data is then released, and individual masking is performed on some or all of the data. The released data may be made uncopyable or deleted. In the case of real-time conversations, batch continuous masking is performed using sound effects (SE), music, silence, noise, etc.
[0082] In addition, for individual masking processing, if the original data is in the MIDI code format of music, masking image display data for the image display data of the note face is created, the code to be masked is searched for, selected all at once or sequentially, and image display masking processing of the note face is performed. Alternatively, the MIDI code is converted into sound source data, and a portion is masked to make it possible to listen to it.
[0083] For music data such as MP3 (MPEG1 Audio layer 3) and AAC (Advanced Audio Coding), masking can be performed by filtering noise and sound effects or by silencing audio so that the secret portion can be restored based on the progression code and time. Masking can also be performed by changing the compression algorithm for the audio portion that cannot be played during the secret processing.
[0084] (4) CAD data and other graphic data formats If the data is two-dimensional or three-dimensional CAD data or graphic data in other formats, commands such as #start# and #end# may be inserted before and after the part of the data program that you want to keep secret, thereby concealing it. Graphic data may also be encrypted and then subjected to image processing and masking. The masking process in this case is the same as that for image data (2) above.
[0085] (5) Other data When the data is a program, metadata, mathematical formula, game, quiz, etc., the individual masking process involves creating batch masking data from the original program or metadata, and then individually masking some or all of the data. In this case, as with the graphic data described above, commands such as #start# and #end# may be inserted before and after the part of the data program that you want to keep secret, to keep it secret.
[0086] (Masking process procedure) The specific masking process procedures for each type of data are explained below. Note that the numbers assigned to the following processes are for convenience and do not necessarily mean that the processes are performed in numerical order. The same applies to other data described below. (A) In the case of document data 1. From the document data, select the pages or parts you want to make viewable / confidential (confidentiality selection section), then select and copy the corresponding document data for viewing. 2. A common keyword is assigned to the document data and the viewing data copied for masking (keyword assignment section). 3. When a code such as a book title is assigned to the document data and the viewing data copied for masking, this becomes a link code (data link section). 4. The original document data is encrypted in units of all pages or chapters (encryption processing unit). 5. The encrypted document data is stored in a storage device (first storage unit). 6. The copied document data is processed into an image PDF and converted into image data for viewing (data conversion section). 7. If individual masking is not possible immediately, select a masking pattern for bulk masking and perform automatic processing (bulk masking processing unit). 8. When the masking is completed, the data is temporarily stored (temporary storage section). 9. The temporarily saved batch masked data is retrieved from the temporary storage unit and individual masking processing is performed. For individual masking, individual masking functions such as pattern masking and blurring functions are called up and selected from pre-registered and saved template images. In the case of pattern masking, the image is registered in the system in advance, and the image is selected and masked to process the parts to be kept secret. Note that individual masking may also be performed directly after creating the viewing data in 6 (individual masking processing unit). 10. If it is necessary to impose viewing restrictions on the individually masked masked data, select the content of the restrictions (viewing / viewing restriction section). 11. After checking the viewing restrictions, the individual masked data is saved in a storage device (final saving section). 12. The data is made public so that it can be viewed on the viewing date (general viewing viewer, dedicated viewing viewer). 13. If necessary, re-encrypt the stored data and masked data to strengthen the encryption strength (re-encryption unit). 14. The data is decrypted in the decryption section and saved so that it can be viewed in the viewing viewer on the viewing date (decryption section).
[0087] (B) In the case of image data 1. From the image data, select the image data you want to view and duplicate it at the required resolution. At this time, it is a good idea to lower the resolution of the duplicate to reduce the amount of data you want to view. Then, select the pages or parts of the image data you want to make viewable / confidential (confidentiality selection section). Generally, documents, drawings, etc. are scanned at the required resolution, and the image data is then captured and processed in one go to create thumbnail images (typically around 50-200 dpi). At this time, for paged documents, only the cover and important pages are used as thumbnail images. 2. to 14. These processes are the same as those in the procedure for document data (A) above, except that "document data" is replaced with "image data" and "viewing data" is replaced with "thumbnail image."
[0088] (B') In the case of PDF images For PDF images, thumbnail images of all pages are displayed and masking is performed according to the following rules. 1. Display thumbnail images of all pages and use the system's masking software to specify the data to be masked. PDF data that has already been filed can also be specified using the specified software. 2. An automatic masking processing server is selected and the specified masking process is performed automatically. 3. After the masking process, the masked data is saved, but it can also be saved on a cloud server for use. 4. Restoring and decrypting masked data may require a password or decryption key.
[0089] (C) For audio, music, and video data Hereinafter, the portion of the audio, music, and video data that is selected from the entire original viewing data as data to be made available for viewing will be referred to as viewing data. 1. From the original viewing data, select the part you want to make public / private (private part selection section), select the corresponding viewing data, and copy it. In principle, the data to be made public will remain the original data, and you will select the viewing part. 2. to 5. These processes are the same as those in 2. to 5. of the procedure for document data in (A) above, except that "viewing" is replaced with "viewing", "document data" with "viewing data", and "viewing data" with "viewing data". 6. The copied viewing data is edited and converted into viewing data to be made public (data conversion unit). 7. to 14. These processes are the same as those in steps 7. to 14. of (A) Document Data above, except that "document data" is replaced with "viewing data" and "viewing data" is replaced with "viewing data."
[0090] (D) CAD data (vector data) 1. From the CAD data, select the drawings or completed drawings you want to make viewable / confidential (confidentiality selection section), then select and copy the corresponding CAD data for viewing. 2. to 14. These processes are the same as those in the procedure for document data (A) above, except that "document data" is replaced with "CAD data" and "document data for viewing" is replaced with "CAD data for viewing."
[0091] (E) Metadata such as programs, codes, and numerical tables 1. From the metadata, select the data content or parts you want to make visible / confidential (confidential part selection section), then select and copy the corresponding viewing metadata. 2. to 14. These processes are the same as those in the procedure for document data (A) above, except that "document data" is replaced with "metadata" and "document data for viewing" is replaced with "metadata for viewing."
[0092] Furthermore, as a common item for each data, a two-dimensional barcode or cloud server code can be assigned to the masking sticker. The cloud server code is an access code for connecting to the cloud server. A one-time password can also be issued to enable viewing using the viewing software required for viewing. Search keywords can be registered for the original data and the viewing / viewing data. Of course, viewing / viewing can also be restricted, or discarded after a certain period of time.
[0093] (Example of use) Below, we will explain a specific example of how this system is operated.
[0094] (Public Document Disclosure) The confidential portions of official document data are individually masked, and the data is made public electronically, allowing access without the masked portions. When the number of years for information confidentiality has passed, the individually masked portions are removed (decrypted). Similarly, official documents are disclosed by partially removing the individual masking depending on the importance of the confidential data. However, if there are remaining portions that have not been individually masked prior to disclosure, the remaining portions are subjected to a second overall masking process and provisionally released. Furthermore, for those who cannot see or read, official documents may be released as first masked data by creating viewing data in Braille or audio data. The same applies to documents created by schools, companies, etc. in addition to official documents.
[0095] (Personal information management) All personal information, such as city and ward registries, student information at schools, customer information at companies, and electronic medical records at hospitals, is masked and used, including names, parts of addresses, and contact information. When information managers, such as resident registry operators, school teachers, company representatives, and hospital doctors, need this personal information, they can temporarily unlock it with a password or decryption key to enable viewing, and the viewing viewer program can be set to automatically return to the masked state after viewing. The text information in question can also be made available to those who cannot see or read characters by creating braille viewing data or audio audio data as the first masked data. Furthermore, a GPS code can be added as viewing permission information, allowing access to specific locations only.
[0096] (Multiple passwords) Additionally, if there are particularly important confidential parts, multiple passwords should be set. Also, different passwords should be set for each piece of data (for example, for each page). Those who are permitted to view the data should be notified of the password by phone or by email sent to a separate address. Furthermore, to check whether the masked data has been tampered with, hash data of the data before and after disclosure should be created and compared. It is also possible to add a certificate from a certification authority to authenticate the date and time.
[0097] (Application of masked data display method) Related data that can be simultaneously viewed or played on a PC can also be linked to the masked data. For example, photo portions of document data can be masked, allowing photos to be displayed or video to be played during viewing. Audio data can also be linked to portions of a document and played for the visually impaired. In the case of video data, text data related to the video can also be displayed. Link information can be triggered by the viewer's will or by a sensor such as a motion sensor. Furthermore, while the data remains fully or partially masked for display or playback, a password function can be added to a "viewing card," for example. Holding the "viewing card" over a card reader and entering the correct password launches and displays the display or playback application software on the PC. Decrypted display can also be enabled for a limited time, such as while a specific key is pressed or for a specified number of seconds. Furthermore, the decrypted display and playback of the original encrypted text or video can also be linked.
[0098] (Online ordering printing) When a print orderer (customer) places a printing order over the Internet, they send the print data, color-managed color sample print, and color chart data scanned into a printing company. At this time, the 1-bit print data is encrypted, and the 8-bit scanned data of the color sample print is masked to hide confidential parts. The scanned data of the color chart is also sent to the printing company. The printing company is notified of the encryption key (using a public key system) or a masking password in advance or via a separate communication. At the printing company, the print data is decrypted using a (private key) encryption key, and the color chart data and color sample print data have the masking of confidential parts removed using a password. A color management profile is then created using the color chart data. The color sample print data is then used by the design department to output a print color proof using the profile.
[0099] This print color proof print is shown to the print client and color proof instructions are received, but this work may be done over the Internet. When color proofing or text proofing is done over the Internet, confidential parts are masked and set to be viewable with a password. This prevents information leaks over the Internet, between the printing company and the print client. Furthermore, as mentioned above, the printing company creates and encrypts 1-bit output data for the printing plate from the printing data in the prepress department, and then masks the confidential parts of the 8-bit color sample data and sends both to the printing factory. At the printing factory, the encrypted 1-bit print output data is decrypted using a separately sent encryption key, and the printing plate is output using an imagesetter. The masked color sample data can be made viewable again with a password and displayed as print color sample data. When necessary, the print data of the print orderer can be safely handled by printing it as a color sample through color management print output.
[0100] For example, to prevent the leakage of personal information such as the policyholder's name and address printed on printed materials such as insurance, first masking data is provided to a printing company. When printing the personal information using a digital printer such as a print-on-demand (POD) printer that can replace the address, name, etc., the data containing the masked personal information is sent to the POD digital printer, and the masked portion is temporarily decrypted just before printing, and the print data is created and printed. This method is also applicable to offset printing. Furthermore, during the masking process, an encryption or masking deletion key that is triggered by the print execution button can be assigned, and after printing, the temporarily decrypted data can be forcibly deleted using dedicated software.
[0101] (Create software for temporary decryption of masking) Regarding the decoding of the individually masked images, videos, and data obtained by the first masking, software is developed and incorporated into the viewing device that performs decryption only temporarily, and immediately after viewing and displaying, forcibly erases only the decrypted data, returning to individual masking. Also, after a limited number of data copies are made during temporary decryption, only the decrypted data is forcibly erased, returning to displaying only the individually masked data. For decryption, temporary decryption version and continuous decryption version software are developed and provided.
[0102] (Input device with masking function) It is also possible to provide input devices and systems that perform a second simple masking process after or simultaneously with input. For example, the first individual masking function software may be bundled with or set up on a computer, so that individual masking is enabled when the purchaser presses a license request confirmation button. A temporary release version and a continuous release version may be provided for individual masking release. Alternatively, a device capable of encryption or masking may be attached as an external connection to the aforementioned device. With these functions, input data can be directly or copied for masking purposes simultaneously with input operations such as input by a scanner or photographing with a digital camera, and then encrypted or masked before being stored or securely transmitted via communication.
[0103] (Masking and filing of scanning data) Until now, companies have saved copies of documents, but with the shift to digitization, these documents can now be scanned and saved using masking technology. For example, an A4-sized document is scanned with a continuous-reading scanner and saved as an electronic image file. Next, data masking application software is launched on a PC, and full-page masking processing is performed in a short time. In addition, in the case of PDF data, reversible full-page masking processing can be applied directly to the data before saving.
[0104] After that, the full masking is removed for each page, and if there are parts of the page that require confidentiality processing, partial masking is performed and saved, and this process is then repeated for each page in turn. Also, if you want to link additional commands such as GPS data, sensor information from the ID card of the individual masking work permit holder, or other viewing date and time restrictions for each page, you can link them and save them. For example, information with GPS location information attached can be saved as a file containing the GPS location information. It may not be viewable, or you may link to a GPS map.
[0105] (Photo Masking Net Album; photo sharing site) When uploading photos to a sharing site, some parts of the photo, such as the background, are masked to conceal parts that should not be shown, such as to protect the privacy of others, or to hide the location where the photo was taken, before uploading the photo to the site. Furthermore, when disclosing a personal album to specific family members, masking is also performed to prevent information leaks. A separate unmasking key or a password for one-time disclosure is sent to those who are permitted to view the photo. Furthermore, when posting, masked photos can be made so that they cannot be copied, or a program that automatically deletes them after a certain period of time can be linked to the masked photo.
[0106] (Report submitted online) When sending and receiving data such as various reports from government agencies and companies over the Internet, important content is masked individually or entirely, and if necessary, further encrypted before being sent, received, and stored over communication lines such as LANs, dedicated lines, and the Internet. Authorized personnel at government agencies and companies send dedicated viewing software over the Internet that limits the viewing date and time and disclosure and recovery to those who are authorized to view the data, and send the password for viewing by a separate means. In addition, dedicated viewing software is set up with functions to allow output and to prevent output, and those authorized to view the data can view it. Furthermore, if necessary, data can be sent and received encrypted with a common key and then further encrypted with a public key.
[0107] (Voucher) When sending or saving various slips, the parts that need to be kept secret are subjected to a first masking process, and then the slip is sent or saved via a communication line such as a LAN, dedicated line, or the Internet. The slip creator sends a separate viewing password for dedicated viewing software for disclosure with a limited viewing date and time to the person who is giving permission for viewing. Furthermore, the person viewing the slip sets up the dedicated viewing software, which has functions for allowing output and disabling output, and allows the user to view the slip.
[0108] (Time Letter Service) For personal use, a sender can deposit an electronic letter on a cloud server to be sent to a PC or smartphone after a certain period of time, such as on anniversaries like birth, or one or ten years from now. The confidential parts of the text, voice, video, music, etc. that need to be kept confidential can be masked and saved, and the email can be decrypted and displayed when the disclosure date arrives, or messages can be sent to the future. For business use, pre-created invitations, new product announcements, company information, and other emails or electronic letters that need to be kept confidential can be saved and the confidential parts of the text, voice, video, music, etc. that need to be kept confidential can be saved, and the email can be decrypted and displayed when the disclosure date arrives, or messages can be sent to the future.
[0109] (Digital Diary) Digital diaries (including personal diaries and diaries shared with friends with whom you want to share private information) and contact sites can be masked to hide any parts of the data that need to be kept secret, such as photos, text, voice, video, and music that you don't want anyone to see, and saved on your own computer or cloud server, and then decrypted when necessary with a decryption key or password. At this time, it is advisable for the poster to be able to change the password at any time of their own volition to prevent leaks to third parties. A password entry box for temporarily disabling masking is also provided. When the password for temporarily disabling masking is entered, it is displayed temporarily only while the user is operating the site. Furthermore, for example, if the posted data is copied and leaked, it can be set so that it cannot be opened with a password even if it is leaked. Diaries and private information can be made so that they cannot be copied, and a program that automatically deletes them after a certain period of time can be linked to the masked data. Furthermore, it can also be used for business sharing sites. In this case, further encryption processing can be added. It would also be better to add a device ID to the data to identify the PC that is viewing or playing it.
[0110] (Electronic message board) For electronic message boards that are made public online, you can register the message board by providing the internet address and message board masking disclosure password to the person you want to contact, and then masking the photos, text, voice, and video before registering the message board. This is also useful for contacting people in emergencies and disasters.
[0111] (email, attachments) Furthermore, even if email text and attachments are strictly speaking encrypted, they are still a means of transmitting information that can be decrypted by the administrator of the email service. To make email communication more secure and confidential, data masking is performed on the parts of the email text and attachments that you want to keep secret before sending them. The password required for the recipient to decrypt the email is then communicated via a separate communication line.
[0112] (Electronic surveys, electronic voting) When answering an electronic survey, private information such as addresses, names, audio, photos, and videos are masked so that only those who need to view or listen to it can do so, providing peace of mind that even if the electronic survey information is leaked, it will not be leaked. It can also be used for handwritten electronic voting in elections. This is a voting method in which voters handwrite the names of candidates on ballot papers, input the information into a small scanner, and store it in a memory device. The image data of the electronically voted ballots can be completely masked, and when the electronic votes are tallied, the masking can be removed and dedicated software developed to perform OCR processing of the handwritten names and check the images of the handwritten candidate names, and tallies the votes by candidate.
[0113] (Turning over subtitles on a TV program) In TV programs, portions of bulletin board displays are hidden with peelable paper, allowing for a flip-through display. This can then be displayed as a digital bulletin board on a tablet screen or PC monitor, where the hidden portions are replaced with different images or image text. Depending on the content, the images can be peeled off sequentially on the touchscreen. If necessary, audio, video, or music files can also be linked, enabling multimedia linking effects not previously possible with bulletin boards. For example, in television news programs and programs, overlapping areas are created in advance to display data on top of PDF data, allowing masked images or other related data to be displayed for concealment. For display or video playback, the screen display is created by processing the image as if peeling off the masked image. During the program, anchors and others can activate and display the masked data displayed on a large touchscreen display by touching the display directly or indirectly using a small touchscreen. By peeling off the masked image sticker over a specific concealed portion of the screen, different PDF data or video to be played will be displayed underneath the image that was peeled off. You can overlap multiple images to process them like peeling off stickers, or display a different image. This not only reduces the time and printing costs required to actually create panels, but also creates new expressive effects.
[0114] (Masking Reference Book) In the content of viewing and listening to a digital reference book, the parts that need to be memorized are masked, or masking of hints for learning and memory is added and multiple masking is performed, thereby performing masking processing as a digital reference book that is effective for answering and memorizing.
[0115] (Big file transfer service) There is a big file transfer service, but I am concerned about the possibility of information leakage from the site administrator. Therefore, the data transferred for big files is masked before being sent via a transfer service. The security of the transferred file data is maintained by sending a separate decryption password to the destination.
[0116] (Adding information to masked data) For masked data, GPS location restrictions may be set for the masking process or to limit viewing locations. GPS location information and restriction information (such as PC ID) limited to the viewer, for example, the PC of the person authorized to view, may be added to part of the masked data, and disclosure may be made possible by verifying the PC and GPS location, the viewer's password, and the PC ID. It may also be possible to make the data viewable only during certain time periods, or to use IoT (Internet of Things) Things) Notifies the connected PC of the ON or OFF state of specific sensors (temperature sensors, human presence sensors, ID cards, etc.). Commands to detect these sensors and edit, view, or play can be added to part of the masking data and linked to the PC. In other words, editing or viewing permission can be turned ON or OFF only when a certain condition value is met. In addition, viewing under specific sensor conditions can also be turned ON or OFF.
[0117] (Image of masking data. Video processing) In photographs and printed images, there are cases where parts of the photograph or printed image contain information that must be kept secret, and that part must be kept secret in order for the image to be viewed. Furthermore, print clients and printing companies have a duty to maintain the confidentiality of customer information, which must be made available only to select personnel. It is common for specialized personnel other than the designated personnel to perform tasks such as cutting out photographs and images to be used in printing or online content. When such personnel are performing the work, they individually mask the parts that must be kept secret to the extent that it does not interfere with the image cutting process, and then perform related tasks such as image cutting. Additionally, there are parts of video, audio, music, etc. that must be kept secret until they are released or reported. In such cases, when editing video, audio, music, etc., the parts to be kept secret are masked, blurred, blinded, or processed in a reversible manner, or the audio is processed using a voice changer or other reversible audio processing, and the parts to be kept secret are masked to the extent that it does not interfere with other editing work, and editing is carried out by a specialist other than the person in charge. When the content is released, the masking, blurring, blinding, audio processing, etc. that can be removed from the parts that have been kept secret are removed.
[0118] (1) Electronic submission and online proofreading (Electronic submission) Figure 3 is a system diagram showing an overview of electronic manuscript transmission, which is a one-way process for data transfer. Here, electronic manuscript transmission is defined as "one-way data transfer between related parties." For example, in the case of magazine or newspaper advertisements, it is a one-way process between the upstream parties in the advertising production flow: (1) client or advertising agency, (2) design production company, (3) magazine company, (4) platemaking company, and (5) printing company. In this case, a system is created that can prevent information leaks by masking the image data in case of an information leak.
[0119] (2) Data handled in the advertising and printing industries (Online proofreading) Figure 4 is a system diagram showing an overview of online proofreading electronic manuscript transmission, which is a two-way process of data operation. Here, online proofreading is defined as "manuscript data transmission in a two-way process" between the parties involved. The person ordering the print and the parties involved mask data and image data that must be kept secret and not shown to third parties until printing is complete, set a password for confidentiality and viewing, and send it to those who need it. For security reasons, it is best to change the password for confidentiality and viewing each time between the parties involved.
[0120] For example, this refers to a system in which advertising documents or print proofing image data stored on a server are shared among relevant parties, such as clients, advertising agencies, design companies, and printing companies, along with proofing instruction information and its history. The final step in online proofreading is a final online check of the printed material just before printing. The printed material just before printing is input using a scanner or other device, and the input image is sent to relevant parties as masked print data. The print orderer or other relevant parties then restore the masking process using a password to confirm the final proofread. Text and color proofs are input using image input devices such as cameras and scanners for character and smudge inspection and color proof evaluation devices, and confidential parts are masked, passwords are set for restoration, and the data is sent over the internet to various facilities, such as headquarters, the design department, and the printing factory.
[0121] The passwords mentioned above are communicated by a different phone number or, if possible, encrypted and sent via email. At each facility, the confidential portion is temporarily restored by entering a decryption key or password, and text and smudge inspections and color evaluations are performed. If any abnormalities are found, the confidential portion is masked again, the temporary restoration is released, and a change password is entered as necessary, before the document is sent online to the required location. The same password is used, or if it is changed, it is communicated via a different phone number or email. This temporary masking and restoration function and encryption process create a system that prevents information leaks, since the decryption key and password are not known, even in the unlikely event of a data leak of the image data being sent or received. This secure online proofreading eliminates the need for physical movement of people and proofs, and significantly reduces the need for on-site supervision during printing, offering significant benefits to both print clients and printing companies.
[0122] The data handled in the advertising industry is DTP (Desk Top Publishing) data, which is so-called PS (PostScript) data, and in the platemaking and printing industry, this DTP data is subjected to raster image processing using a RIP device and converted into the following two types of Tiff data for printing: (2) and (3) (advertising and design companies) (1) PS data for DTP design (platemaking and printing company); (2) 8-bit Tiff data for printing proofs; (3) 1-bit 4-tone (C, M, YK) data for printing plate output; it is necessary to send, receive, store, and operate the above advertising and printing data safely.
[0123] (Inspection just before printing) In addition, the prepress department, which creates printing plate data at a printing company, uses a RIP (Rastar Image Processor) to convert outline data created by the printing DTP equipment into image data. The RIP-processed 1-bit image data for printing is then encrypted. The RIP-processed 8-bit image data for inspection and color samples, approximately 200 to 400 dpi, is also RIP-processed from the print data, and confidential areas are masked. These two sets of data are sent from the prepress department to the vicinity of the plate setter at the printing factory. The confidential parts of the aforementioned color sample image data are then restored using a password at the printing factory, and a proof print (also simply called a proof) is output. The 1-bit image data for printing is then decrypted using a decryption key, and the printing plates output as printing plates are then run on the printing press to produce a test print. These are then compared for print color inspection and character / smudge detection.
[0124] (others) The present invention can include many modifications and other operational examples in addition to the embodiments and operational examples described above. As shown in FIG. 6, when there are multiple pieces of image data 40 (50) to be concealed, the area 41 (51) to be concealed may be an area common to each piece of data. For example, when the data is image data 40 relating to a person, the area 41 to be concealed may be the face of the person included in each piece of data. Also, when the data is document data 51 including personal information, the area to be concealed may be the upper area where personal information such as address and name is written. In addition, video data containing personal information of people is also treated in the same way.
[0125] Even in such a case, the present system can appropriately set a confidentiality target area (common confidentiality area) for each piece of data and perform appropriate encryption and masking processes. While Fig. 6 illustrates a case where the confidentiality target data is an image or document, the present system is not limited to this and can, of course, be applied to various types of data, such as video, music, programs, and metadata. Furthermore, the common confidentiality area is not limited to that shown in Fig. 6, and can be freely set, for example, for video or music, to a certain time range from the start, or to a certain time range from an arbitrarily set timing. Furthermore, for documents, it is also possible to set words or phrases that are common to multiple pieces of data as the common confidentiality area.
[0126] Although several embodiments have been described above with reference to the drawings, the present invention is not limited to these embodiments, and the components used in each embodiment can be combined or deleted for application. Furthermore, the operational examples of this system are not limited to those described above, and it goes without saying that the system can be applied to various businesses that require data encryption or masking.
[0127] (Addendum) Supplementary notes regarding the above-described embodiments, including those already mentioned, are listed below. Masking designs and patterns can be selected from a cloud server that provides at least some of the functions of this system, or from template images registered and saved in the worker's storage device. Types of masking designs and patterns include those described in the above examples and operational examples, such as stripe, checker, center, square, blur, wave, pattern, blackout, whiteout, the addition of dummy data, and photos, illustrations, designs, and patterns registered by the worker on their PC. Furthermore, a temporary simplified and rapid masking method is used. In other words, any of the masking methods described above is selected, and data is processed in bulk. After bulk processing, the data is temporarily unmasked using a password or decryption key, and individual masking is performed. A log of the masking process is kept.
[0128] Regarding masking of input data with a scanner, if you have written with a pen using erasable ink, or made marks with a stamp or temporary erasable marker (e.g., marks that disappear when oxidized in air or with a different erasing material), when scanning, the same part of the scanned data can be automatically masked.
[0129] Furthermore, keywords can be added to the masked data to provide search functionality. If the image data is PDF data, for example, OCR functionality can also be used. These keywords can also be encrypted, and can be temporarily decrypted using multiple passwords. After the data is saved in the final storage unit, when it is output, an output password, the password of the outputter, or a decryption key can be required.
[0130] Dummy data may be added to the masked and unmasked display portions of the viewing / viewing data. Viewing or viewing restrictions such as start date and time, number of times, date, duplication, and output may be added to the viewing / viewing data. The viewing / viewing data may also have a function to record viewers' reactions to the viewing or viewing interest, or to record audio or video. After restricting the number of times and date of viewing or viewing, dummy data may be added to the viewing image or images, and the viewing image or images may be shredded and rearranged to make them undecryptable without generating a decryption key, and the data may be erased. [Explanation of symbols]
[0131] 1. Data Masking System 10, 40, 50 Confidential data 11, 21 Confidentiality Area 20 Individually masked data 30 Bulk Masked Data 41, 51 Common Confidentiality Area
Claims
1. a batch masking processing unit that performs batch masking processing on the viewing / viewing data to be viewed or listened to by a user; a temporary storage unit that temporarily stores the browsing / viewing data that has been subjected to the collective masking process by the collective masking processing unit; a batch unmasking unit that unmasks the browsing / viewing data that has been subjected to the batch masking and that is stored in the partial storage unit; a concealment portion selection unit that accepts a selection of a region to be concealed in the viewing / listening data; an individual masking processing unit that performs individual masking processing on the concealment target area selected by the concealment portion selection unit in the viewing / viewing data to create masked data; a storage unit for storing masking data created by the individual masking processing unit; an output unit that outputs the masked data stored in the storage unit for viewing or listening; a viewing / viewing history recording unit that records a history and / or feedback of the viewing / viewing when the masked data output from the output unit is viewed / viewed; Equipped with Data masking system.
2. The batch masking processing unit and the batch unmasking unit transmit the browsing / viewing data that has been subjected to the batch masking processing via a communication line. The data masking system of claim 1 .
3. the viewing / listening data is document data including multiple pages, the batch masking processing unit performs the batch masking process on the entire document data, the collective masking removal unit removes the collective masking process on a page-by-page basis from the document data; The individual masking processing unit performs individual masking processing on the concealment target area selected by the concealment portion selecting unit for each page of the document data from which the collective masking processing has been released. The data masking system of claim 1 .
4. a discarding unit that subdivides the masked data stored in the storage unit, further scrambles the data, and discards the data; The data masking system of claim 1 .
5. a display unit that displays the masking data output from the output unit; a touch panel that accepts a sticker peeling operation to sequentially make the concealment target area of the masked data displayed on the display unit viewable or viewable; Equipped with The concealment target areas are sequentially made viewable or viewable based on the sticker peeling operation and are displayed on the display unit. The data masking system of claim 1 .
6. An audio, video or music file is linked to the area to be concealed, The audio, video or music file is played when the concealment target area is made viewable or audible. The data masking system of claim 1 .
Citation Information
Patent Citations
Device for concealing part of content and content circulation system using it
JP2004287566A
System for protecting cellular telephone mail, and cellular telephone server
JP2007233983A
Medical image processor
JP2007319342A
Imaging apparatus, imaging system, and image browsing system
JP2009044311A
Image processing apparatus and image processing system
JP2010199967A