RAG-Based System with Multi-Layered Security Features and Its Operation Method
Patent Information
- Application Number
- KR1020250016236
- Authority / Receiving Office
- KR · KR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2026-08-14
Smart Images

Figure PAT00001_ABST
Abstract
Description
Technology Field
[0001] The present invention belongs to the field of data management and retrieval technology, and in particular relates to a multi-protection function capable of securely enhancing the data input, storage, retrieval, and utilization processes in a RAG (Retrieval-Augmented Generation) based system. Background Technology
[0002] RAG-based systems have established themselves as a technology that enhances the efficiency of corporate data search and utilization. However, due to the nature of concentrated critical data, they are susceptible to security vulnerabilities, such as external hacking and unauthorized access by insiders. In particular, the file upload process is considered a critical moment where hackers can easily insert malware or gain unauthorized access. Existing security systems are unable to adequately prevent these threats, posing a risk of data leakage and loss. The problem to be solved
[0003] The present invention aims to provide a security technology that simultaneously resolves the problem of data leakage caused by external hacking attacks and insider errors or malicious behavior in RAG-based systems, maintains data integrity and security, and maximizes data utilization. means of solving the problem
[0004] The present invention proposes a multi-layer protection system composed of five major security functions.
[0005] 1. DataLock
[0006] Detects and blocks data tampering and unauthorized access attempts in real time, and maintains data integrity.
[0007] 2. HidingLock
[0008] Restrict access to sensitive data by hiding it based on position or authority.
[0009] Allow access with administrator approval.
[0010] 3. CenterLock
[0011] Provides USB connection blocking, clipboard copy prevention, and encrypted file download features to prevent data leakage.
[0012] 4. BackupLock
[0013] Prevent data loss from ransomware, etc. through multiple backups using cloud and physical servers.
[0014] 5.CipherLock
[0015] Encrypts data in real-time during file upload and download processes, and securely protects data through decryption during operations. Effects of the invention
[0016] Defense against external attacks: Protect data from ransomware and hacking attacks.
[0017] Enhanced internal security: Prevents internal leakage by restricting data access based on job title and authority.
[0018] Ensure data integrity: Prevent data corruption or loss through encryption and multiple backups.
[0019] Leakage Prevention: Completely blocks data copying outside the system. Brief explanation of the drawing
[0020] Figure 1 is a schematic diagram illustrating the data flow of a RAG-based system and the location of each protection layer. Figure 2 is a diagram showing the operation of DataLock and CipherLock during the file upload process. Figure 3 is a schematic diagram explaining the data leakage blocking mechanism of CenterLock. Specific details for implementing the invention
[0021] The present invention is implemented in the following manner:
[0023] Real-time virus scanning and malware blocking upon data upload.
[0024] Dynamically adjusts the list of accessible data based on the user's position and authority.
[0025] Minimize the possibility of loss by performing additional encryption and automatic backups of important data.
[0026] When a file is downloaded within the system, it remains encrypted and can be decrypted only under specified conditions. Explanation of the symbols
[0027] 10: RAG-based systems 20: Multiple Protection Layers 30 : DataLock section 40: BackupLock section 50 : CipherLock section 60 : CenterLock 70 : HidingLock section 80: Data Input Controller 90: Data storage controller 100: Data Retrieval and Utilization Controller 110: File upload process 120: File selection screen controller 130 : Data Upload Controller 140: Security layer 150 : Data Leakage Prevention Unit 160: Security blocking function controller 170: External leak blocking controller 180: Security Server
Claims
Claim 1 A data security system for protecting the data input, storage, retrieval, and utilization processes in a RAG-based system with multiple security layers, characterized by including DataLock, HidingLock, CenterLock, BackupLock, and CipherLock. Claim 2 A data security system according to claim 1, characterized by including a DataLock that detects data tampering during file upload and blocks it in real time. Claim 3 A data security system according to claim 1, characterized by including a HidingLock that restricts data access according to the user's position and authority and hides sensitive data. Claim 4 A data security system according to claim 1, characterized in that it includes a CenterLock that allows data to be downloaded only in an encrypted state and blocks clipboard copying and USB connection. Claim 5 A data security system according to claim 1, characterized by including a BackupLock that backs up data to the cloud and a physical server simultaneously. Claim 6 A data security system according to claim 1, characterized by including a CipherLock that performs real-time encryption and decryption during the data upload and download process.