A security system based on concealed information for the security of electronic documents.
The security system maintains security levels and log information for electronic documents by using a hidden information module to embed and verify authorization and log data, addressing execution errors and exposure issues in conventional systems.
Patent Information
- Application Number
- JP2021207787
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-12-30
- Filing Date
- 2021-12-22
- Publication Date
- 2026-08-26
- Estimated Expiration
- 2041-12-22
AI Technical Summary
Conventional security systems for electronic documents fail to maintain security levels and log-related information when data is modified, leading to execution errors and exposure of sensitive information, especially when accessed by legacy systems that cannot recognize security headers.
A security system that utilizes a security agent with a hidden information module to analyze electronic document data, generate and conceal authorization and log information using steganography, and restrict access based on policy-compliant execution through a security module.
Maintains security levels and log-related information even with data modifications, ensuring continuous policy-based security by verifying and limiting access rights and execution history.
Smart Images

Figure 0007911370000001 
Figure 0007911370000002 
Figure 0007911370000003
Abstract
Description
Technical Field
[0005]
[0001] The present invention relates to a security system based on hidden information for electronic document security that can maintain security levels and log-related information in data transformation of electronic documents and sustain a security process according to policies.
Background Art
[0002] Generally, in order to secure an electronic document, access by a user is restricted by restricting the user's login to a security system storing the electronic document or by setting a security level for the electronic document itself. The former security method classifies many electronic documents by level and secures them collectively, so it is efficient for security by level of electronic documents, but there is a limit to the detailed right restrictions for each electronic document. The latter method enables detailed right restrictions for each electronic document, but since the access right for security has to be set for each electronic document, there is a burden on the security processing of the security system for each electronic document.
[0003] Therefore, the above security technologies are used in combination according to the security purpose of electronic documents.
[0004] On the other hand, for setting the security level of an electronic document itself, conventionally, the electronic document was encrypted and a header in which security levels such as access rights and logs regarding access history were recorded was further generated. Eventually, the security system confirmed the header to confirm the security level and log of the electronic document, and restricted others' access to the electronic document based on the confirmed security level and log to enhance security.
[0005] Incidentally, when the aforementioned conventional electronic documents were attempted to be read by a legacy system that could not recognize the header containing the security rating and log, the legacy system could not recognize the header of the electronic document, resulting in an execution error. In other words, electronic documents with security features in a dedicated security word processing program would fail to execute at all in older versions of existing word processing programs that lacked security features, resulting in errors.
[0006] Furthermore, if the header containing security ratings and log-related information is compromised by a malicious user, the electronic document itself may lose its security. This means that conventional security systems are unable to protect such electronic documents, leaving the sensitive information exposed.
[0007] Therefore, a technology was required that could support and execute the legacy system without errors even when a security level was set, and that the security system could recognize the security level of the electronic document after decryption and restrict access rights by the user. [Prior art documents] [Patent Documents]
[0008] [Patent Document 1] Korean Published Patent Publication No. 10-2016-0121248 [Overview of the Initiative] [Problems that the invention aims to solve]
[0009] The present invention was devised to solve the aforementioned problems and aims to provide a security system for electronic document security based on concealed information that maintains security levels and log-related information even when electronic documents are data-modified, thereby ensuring the continuation of policy-based security processes. [Means for solving the problem]
[0010] To achieve the objectives of the present invention, the present invention provides a security system based on hidden information for electronic document security, comprising a security agent that includes: a hidden information module that analyzes the source code of electronic document data executed by a word processing unit based on an OS (Operating System) to search for custom.xml, which is hidden information with fmtID (format identifier) as its identification value, and confirms authorization information; a content execution module that adjusts the content execution of electronic document data by the word processing unit under the control of a security module; and a security module that hides custom.xml, which contains authorization information for the security of electronic document data, at a specific location in the source code of the electronic document data using steganography techniques, generates it as hidden information with a security agent-specific fmtID, and limits the acceptable range of content by comparing the authorization information confirmed by the hidden information module with reference information. [Effects of the Invention]
[0011] As described above, the present invention has the effect of maintaining security ratings and log-related information even when electronic documents are modified, thereby sustaining security processes based on policy. Furthermore, since the concealed information of electronic documents is maintained even when the format of the data file is modified, it has the effect of continuously verifying and utilizing access rights and log information for electronic documents for security purposes. [Brief explanation of the drawing]
[0012] [Figure 1] This is a block diagram showing a security system based on concealed information for electronic document security according to a preferred embodiment of the present invention. [Figure 2] This flowchart sequentially illustrates the process of securely processing electronic document data, authenticating the user, and outputting the content of the electronic document data based on a security system according to a preferred embodiment of the present invention. [Figure 3] This is an illustrative diagram showing, as one example, the concealed information of securely processed electronic document data. [Modes for carrying out the invention]
[0013] Various "Embodiments" or "Examples" are described below based on the details discussed, and the accompanying drawings illustrate these various embodiments. The following description and drawings are illustrative and should not be construed as restrictive. Numerous specific details are described to provide a complete understanding of the various embodiments of the present invention. However, in certain embodiments, widely known or prior details are not described in order to provide a concise description of the embodiments of the present invention.
[0014] In the specification, any reference to “one embodiment” or “an embodiment” means that a particular feature, structure, or characteristic described based on the embodiment may be included in at least one embodiment. In many parts of the specification, the phrase “one embodiment” does not necessarily refer to the same embodiment in all instances.
[0015] Embodiments of the present invention may include special-purpose or general-purpose computers, including a variety of computer hardware, as will be described in more detail below. Figure 1 shows a schematic diagram of an exemplary computer system that can be used to embody the features of the present invention, and is referred to as a client. The client described herein is merely an example of such a suitable computer environment and is not intended to imply any limitation on the scope of the uses or functionality of the present invention. The present invention should not be construed as having any dependence or requirements relating to any one of the components shown in Figure 1 or any combination thereof.
[0016] This document defines terms used to describe the “Security System Based on Concealed Information for Electronic Document Security” according to the present invention. The “Security System Based on Concealed Information for Electronic Document Security” according to the present invention refers to software or a device that restricts the reading, number of readings, editing, decryption, export, output, print marking, validity period, automatic destruction, permission changes, content duplication, etc., of the content of an electronic document by the user or the executing PC. The “Security System Based on Concealed Information for Electronic Document Security” is embedded in the client and operates in conjunction with the software that executes the electronic document. Hereinafter, the “Security System Based on Concealed Information for Electronic Document Security” will be referred to as the “Security System”.
[0017] In this invention, "electronic document" is defined as "Electronic document" in English, and is a standardized document format created and transmitted or stored in electronic form by a device with information processing capabilities, such as a computer. This document may include content such as text, images, and graphs. Supported file extensions for electronic document-related software for computer execution include versions such as doc, ppt, docx, xlsx, and pptx supported by MS Office, as well as versions such as HWP and PDF, and many other extensions. A "word processing unit" refers to office software that can read, correct, or create electronic documents. A "security agent" in this invention refers to software that generates and inputs hidden information into an electronic document, searches for and verifies the hidden information configured in the electronic document, and reads the security level and log information of the electronic document. "Authority information" refers to rights granted to a user or execution PC, such as content reading, number of readings, editing, decryption, export, output, print marking, validity period, automatic destruction, authority change, and content copying for an electronic document. Therefore, the scope of use for electronic documents differs depending on who the user is and what kind of PC is running it on.
[0018] An embodiment according to the present invention will describe a security system based on hidden information for electronic document security.
[0019] According to an embodiment of the present invention, a security system based on hidden information for electronic document security analyzes the source code of electronic document data executed by a word processing unit based on an OS (Operating System) to search for custom.xml with fmtID (format identifier) as an identification value, and a hidden information module that checks the authority information and log information configured in custom.xml, an information confirmation module that grasps and outputs the execution history of an electronic document from the log information confirmed by the hidden information module, a content execution module that adjusts the content execution of the electronic document by the word processing unit under the control of a security module, and custom.xml containing authority information for electronic document security and log information about the execution history of the electronic document is generated in the source code of the electronic document by a steganography technique and a security agent专用 fmtID is specified, and a security module that compares the authority information confirmed by the hidden information module and the execution history confirmed by the information confirmation module with reference information to limit the allowable range of content. Further, the security system according to the present invention further includes a decryption module that decrypts all or the content of electronic document data under the control of the security module, and the security module controls the decryption module in conjunction with the word processing unit. Here, the security module can generate authority information corresponding to the input command value.
[0020] Hereinafter, a security system according to a preferred embodiment of the present invention will be described in more detail based on the accompanying drawings.
[0021] FIG. 1 is a block diagram showing a security system based on hidden information for electronic document security according to a preferred embodiment of the present invention.
[0022] Referring to Figure 1, a security system according to a preferred embodiment of the present invention includes a security agent 30 which includes: a hidden information module 31 that analyzes the source code of electronic document data executed by a word processing unit 40 based on an OS (Operating System) 10 to search for custom.xml with fmtID (format identifier) as the identification value and confirms the authorization information and log information configured in custom.xml; an information confirmation module 32 that grasps and outputs the execution history of the electronic document from the log information confirmed by the hidden information module 31; a content execution module 33 that adjusts the execution of the electronic document content by the word processing unit 40 under the control of the security module 34; and a security module 34 which generates custom.xml containing authorization information for the security of the electronic document and log information about the execution history of the electronic document at a specific location in the source code of the electronic document using a steganography technique, specifies a dedicated fmtID for the security agent 30, and limits the acceptable range of content by comparing the authorization information confirmed by the hidden information module 31 and the execution history confirmed by the information confirmation module 32 with reference information.
[0023] The concealment information module 31 analyzes the source code of the electronic document data executed by the word processing unit 40 based on the OS to search for custom.xml with fmtID as the identification value, and checks the authority information and log information configured in custom.xml. As described above, since the security module 34 generates concealment information with authority information and log information configured in the electronic document, the concealment information module 31 searches for fmtID generated as the identification value of the concealment information to check the concealment information in the custom.xml format. Since the concealment information according to the present invention is generated by steganography techniques, the word processing unit 40 cannot recognize the concealment information in the custom.xml format, and only the concealment information module 31 checks and recognizes the fmtID. On the other hand, the log information is updated during the storage process such as data replication and name change of the electronic document. The history configured in the log information can be information such as the open time, close time, save time, save location, ID of the current version newly generated during the save process, and ID of the previous version of the electronic document.
[0024] The information confirmation module 32 grasps the execution history of the electronic document from the log information confirmed by the concealment information module 31. To explain this more specifically, the history of the log information configured in the concealment information can be information such as the open time, close time, save time, save location, ID of the current version newly generated during the save process, and ID of the previous version of the electronic document, as exemplified above, and the information confirmation module 32 can grasp the execution history and distribution route of the electronic document by grasping the history.
[0025] The content execution module 33 adjusts the execution of electronic documents by the word processing unit 40 under the control of the security module 34. More specifically, since the concealed information includes authorization information for the electronic document, the scope of execution of the electronic document must be restricted by the authorization information. Therefore, once the security module 34 confirms the authorization information and specifies the permissible scope, the content execution module 33, in conjunction with the word processing unit 40, forcibly restricts the execution of the electronic document to only within the permissible scope. That is, if the permissible scope of the electronic document is restricted to content reading only, the content execution module 33 checks the word processing unit 40's approach to the electronic document and forcibly stops any attempt at editing.
[0026] The security module 34 generates concealed information in the electronic document that the word processing unit 40 cannot recognize, so that only the security agent 30 can recognize it. This concealed information is generated and inserted into a specific location in the source code of the electronic document using steganography techniques. The concealed information is configured in the electronic document in custom.xml format, and the fmtID (format identifier) is set as the identification value of custom.xml. custom.xml contains authorization information and log information for the electronic document, and the concealed information module 31 can be independently located at a specific location in the source code of the electronic document. In short, the concealed information is configured in the electronic document as data that the word processing unit 40 cannot recognize or ignore, similar to steganography techniques, and only the concealed information module 31 can recognize the specified fmtID to confirm the concealed information and read the authorization information and log information. Furthermore, since the concealed information contained within an electronic document is an object independent of the electronic document itself, even if the content or attributes of the electronic document are changed or the file extension of the electronic document is changed, the concealed information maintains its original form, and the concealed information module 31 can search for and recognize the authorization information and log information. For reference, steganography is a data concealment technique that involves embedding data into other data or the research thereof. To add to that, while cryptography is a means of making it impossible to read the contents of a message, steganography hides its very existence.
[0027] Next, the security module 34 compares the authorization information confirmed by the concealed information module 31 and the execution history confirmed by the information verification module 32 with the reference information to restrict the permissible range of content. As mentioned above, the authorization information concerns the permissible range for the execution of the electronic document, so the content execution module 33 determines the permissible range from the authorization information configured in the concealed information and restricts the word processing unit 40 to execute the electronic document only for permissible execution content.
[0028] The technique for comparing the aforementioned authorization information and execution history with the reference information will be explained again below.
[0029] Meanwhile, client C1, which has the security agent 30 installed, can connect to the communication network via the web browser 20 and communicate data with other clients C2. If a security-configured electronic document is received by the web browser 20 during the data communication, the security agent 30 searches for hidden information in the electronic document, and checks and updates the log information from the found hidden information. As mentioned above, the log information may include the storage time and version of the electronic document, so the security module 34 adds the storage time and version of the electronic document to the log information once the electronic document is received and saved.
[0030] Furthermore, the security agent 30 according to the present invention further includes a decryption module 35 that decrypts the entire electronic document data or its contents under the control of a security module 34, and the security module 34 controls the decryption module 35 in conjunction with the word processing unit 40. More specifically, in order to enhance the security of electronic documents, the security agent 30 can encrypt the data of an electronic document that has finished executing and save it to client C1. To this end, when the security module 34 recognizes the completion process of an electronic document in the word processing unit 40, it controls the decryption module 35 to encrypt the electronic document data saved by the word processing unit 40. The decryption module 35 generates and places a temporary file with a name and extension matching the electronic document data in the storage path of the encrypted electronic document data so that the word processing unit 40 can recognize and load the encrypted electronic document data, and the actual electronic document data with content can be saved as an encrypted file. However, this encryption procedure is merely one embodiment of the present invention, and the word processing unit 40's saving process can also be performed in conjunction with the security module 34 so that the security module 34 can encrypt the electronic document data.
[0031] Subsequently, if the user attempts to execute the encrypted electronic document data by the word processing unit 40, the security module 34 recognizes the execution process of the word processing unit 40 and controls the decryption module 35 to decrypt the encrypted electronic document data. Of course, the decryption module 35 decrypts the specified data under the control of the security module 34, and once the security module 34 confirms the decryption, it processes the electronic document data so that it is executed by the word processing unit 40.
[0032] Figure 2 is a flowchart illustrating the process of securely processing electronic document data, authenticating the user, and outputting the content of the electronic document data based on a preferred embodiment of the present invention. Figure 3 is an illustrative diagram showing the concealed information of the securely processed electronic document data as one embodiment.
[0033] Referring to Figures 1 to 3, the security method based on the security system according to the present invention is as follows.
[0034] S10: Concealed Information Setting Stage When the word processing unit 40 generates and saves an electronic document data file, the security module 34 of the security agent 30 allows the author who created the electronic document or the rights holder who owns the rights to the electronic document (hereinafter referred to as the 'configurator') to set the authorization information for the electronic document. For this purpose, the security agent 30 generates a security setting menu key (not shown) in the word processing unit 40's menu using a GUI (Graphical User Interface) or general UI. When the configurator clicks the security setting menu key, the security module 34 of the security agent 30 is executed and outputs a setting layer (not shown) in which the scope of execution can be entered.
[0035] The user inputs the execution range into the outputted configuration layer, and the security module 34 generates permission information for the execution range as concealed information based on the input command value. The concealed information is generated in custom.xml format using steganography techniques, and the security module 34 places it at a specific location in the source code of the electronic document. Furthermore, the custom.xml file, which contains the concealed information, is identified by an fmtID that can be recognized by the concealed information module 31.
[0036] The security module 34 may further include log information that stores information about the execution history of electronic documents in the concealed information. The history configured in the log information may include information such as the open time, close time, storage time, storage location of the electronic document, the ID of the current version created during the storage process, and the ID of previous versions.
[0037] S20: Information Discovery Phase If the word processing unit 40 attempts to execute a specific electronic document through user input, the concealed information module 31 of the security agent 30 searches for concealed information in the electronic document and confirms the authorization information and log information.
[0038] If the concealed information module 31 checks the authorization information, it calls the security module 34; if it checks the log information, it calls the information verification module 32.
[0039] S30: Stage for verifying the execution history of electronic documents Upon calling the concealed information module 31, the information verification module 32 checks the log information of the concealed information to understand the execution history of the electronic document. As mentioned above, the execution history can include information such as the open time, close time, save time, save location, ID of the current version created during the save process, and ID of previous versions of the electronic document, and the information verification module 32 can understand the execution history and distribution route of the electronic document based on this history.
[0040] For reference, the execution history of an electronic document as determined by the information verification module 32 can be output through a separate settings window (not shown), thereby allowing the distribution route of the electronic document to be tracked.
[0041] S40: Electronic Document Execution Decision Stage The security module 34 restricts the permissible scope of content by comparing the authorization information for the security of the electronic document and the execution history of the log information with reference information. More specifically, the authorization information is the permissible scope for the execution of the electronic document and is entered as a security grade code. That is, when setting security for an electronic document, if the user sets only content reading as the permissible scope for that electronic document, only the security grade code for content reading will be set in the authorization information. On the other hand, the security module 34 stores the permissible scope content for each security grade code as reference information. Therefore, the security module 34 checks the security grade code set in the authorization information and searches the reference information for the permissible scope content of that security grade code to understand what the permitted scope is for the electronic document. After the permissible scope is confirmed, the security module 34 transmits the relevant data to the content execution module 33.
[0042] Furthermore, the log information pertains to the execution history of electronic documents. If a harmful URL or user's path is found to have passed through the path specified in the reference information within the execution history of an electronic document, the execution of that electronic document will be restricted.
[0043] S50: Electronic document execution stage The word processing unit 40 executes the electronic document based on the user's operation, and the content execution module 33, which is controlled by the security module 34, adjusts the execution of the electronic document in conjunction with the word processing unit 40. In other words, if the security module 34 determines from the authorization information that the scope of the electronic document is limited to content reading, the content execution module 33, upon receiving a content reading signal from the security module 34, restricts the execution of the process so that the word processing unit 40 does not perform any functions other than the user's content reading of the electronic document.
[0044] Furthermore, if the security module 34 checks the execution history of the electronic document from the log information and confirms that the execution history is the same as a harmful route registered in the reference information, the content execution module 33, having received an execution restriction signal from the security module 34, transmits a stop signal to prevent the word processing unit 40 from executing the electronic document.
[0045] S60: Electronic document preservation stage If the security module 34 confirms the termination process of an electronic document in the word processing unit 40, it updates one or more selected pieces of the access information and log information configured in the concealed information and saves them to the client C1's storage means.
[0046] As described above, the security system according to the present invention has been explained with more detailed illustrations, but this should be understood as being for the convenience of explaining and understanding the security system according to the present invention. Furthermore, the rights should not be interpreted restrictively by limiting them to the configuration of the above-described embodiment, the data storage location, etc., nor should they be interpreted restrictively by using other documents contrary to the description of the present invention. The scope of rights for the security system according to the present invention should be determined by the attached claims. [Explanation of symbols]
[0047] 10 OS 20 Web browsers 31. Concealed Information Module 32 Information Verification Module 33 Content Execution Modules 34 Safety Module 35. Decryption Module 40 word processing units
Claims
1. A hidden information module analyzes the source code of electronic document data executed by a word processing unit based on the OS (Operating System) to search for custom.xml, which is hidden information with fmtID (format identifier) as the identification value, and confirms authorization information related to security level and log information related to the execution history of the electronic document data. An information verification module that obtains and outputs the execution history of the electronic document data from the log information confirmed by the concealed information module, It is a safety module, The custom.xml file, which contains authorization information and log information for the security of the electronic document data, is concealed using steganography techniques at a specific location in the source code of the electronic document data in a form that is not recognized by the word processing unit and is not affected by the word processing unit's saving and editing processes of the electronic document data, thereby generating concealed information with a specified fmtID. The permission information confirmed by the aforementioned concealed information module is compared with the standard information where the acceptable range for each security class code is registered, thereby restricting the acceptable range of content. A security module that compares the log information relating to the execution history with reference information in which harmful paths are registered, and if the log information relating to the execution history includes paths registered in the reference information, restricts the execution of the electronic document data. A content execution module that adjusts the content execution of the electronic document data by the word processing unit through the control of the security module, A security system for electronic document security based on concealed information, characterized by including the following:
2. The system further includes an encryption / decryption module that decrypts the entire electronic document data or its contents under the control of the security module, The security system for electronic document security based on concealed information according to claim 1, characterized in that the security module controls the encryption / decryption module in conjunction with the word processing unit.
3. The security module generates authorization information corresponding to the input command value, characterized in that it is a security system based on concealed information for electronic document security according to claim 1.
Citation Information
Patent Citations
Document distribution method and document management method
JP2003228560A
Document security system
JP2005065209A
Document leakage detection management system, its method, and program
JP2005130214A
Data use restricting system, data use restricting method, and data use restricting program
JP2007179087A
Security apparatus, tracking server and method for detecting distribution channel of security document
KR1020160121248A