RAG-Based System with Multi-Layered Security Features and Its Operation Method

KR1020260123903APending Publication Date: 2026-08-14UNISWORD CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
KR1020250016236
Authority / Receiving Office
KR · KR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2026-08-14

Smart Images

  • Figure PAT00001_ABST
    Figure PAT00001_ABST
Patent Text Reader

Abstract

Retrieval-Augmented Generation (RAG)-based systems have established themselves as innovative tools for efficiently managing, searching, and utilizing critical data and files within enterprises. However, as these systems concentrate various types of data, they are highly susceptible to security vulnerabilities. In particular, security threats can arise as employees upload or modify various forms of files and data within the system, depending on their roles and positions. The moment of file upload is one of the most vulnerable points in time when hackers are most likely to insert malware into the system or gain access privileges. To address these issues, this invention proposes a technology capable of protecting the entire process of data input, storage, search, and utilization within a RAG-based system using multiple security functions.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present invention belongs to the field of data management and retrieval technology, and in particular relates to a multi-protection function capable of securely enhancing the data input, storage, retrieval, and utilization processes in a RAG (Retrieval-Augmented Generation) based system. Background Technology

[0002] RAG-based systems have established themselves as a technology that enhances the efficiency of corporate data search and utilization. However, due to the nature of concentrated critical data, they are susceptible to security vulnerabilities, such as external hacking and unauthorized access by insiders. In particular, the file upload process is considered a critical moment where hackers can easily insert malware or gain unauthorized access. Existing security systems are unable to adequately prevent these threats, posing a risk of data leakage and loss. The problem to be solved

[0003] The present invention aims to provide a security technology that simultaneously resolves the problem of data leakage caused by external hacking attacks and insider errors or malicious behavior in RAG-based systems, maintains data integrity and security, and maximizes data utilization. means of solving the problem

[0004] The present invention proposes a multi-layer protection system composed of five major security functions.

[0005] 1. DataLock

[0006] Detects and blocks data tampering and unauthorized access attempts in real time, and maintains data integrity.

[0007] 2. HidingLock

[0008] Restrict access to sensitive data by hiding it based on position or authority.

[0009] Allow access with administrator approval.

[0010] 3. CenterLock

[0011] Provides USB connection blocking, clipboard copy prevention, and encrypted file download features to prevent data leakage.

[0012] 4. BackupLock

[0013] Prevent data loss from ransomware, etc. through multiple backups using cloud and physical servers.

[0014] 5.CipherLock

[0015] Encrypts data in real-time during file upload and download processes, and securely protects data through decryption during operations. Effects of the invention

[0016] Defense against external attacks: Protect data from ransomware and hacking attacks.

[0017] Enhanced internal security: Prevents internal leakage by restricting data access based on job title and authority.

[0018] Ensure data integrity: Prevent data corruption or loss through encryption and multiple backups.

[0019] Leakage Prevention: Completely blocks data copying outside the system. Brief explanation of the drawing

[0020] Figure 1 is a schematic diagram illustrating the data flow of a RAG-based system and the location of each protection layer. Figure 2 is a diagram showing the operation of DataLock and CipherLock during the file upload process. Figure 3 is a schematic diagram explaining the data leakage blocking mechanism of CenterLock. Specific details for implementing the invention

[0021] The present invention is implemented in the following manner:

[0023] Real-time virus scanning and malware blocking upon data upload.

[0024] Dynamically adjusts the list of accessible data based on the user's position and authority.

[0025] Minimize the possibility of loss by performing additional encryption and automatic backups of important data.

[0026] When a file is downloaded within the system, it remains encrypted and can be decrypted only under specified conditions. Explanation of the symbols

[0027] 10: RAG-based systems 20: Multiple Protection Layers 30 : DataLock section 40: BackupLock section 50 : CipherLock section 60 : CenterLock 70 : HidingLock section 80: Data Input Controller 90: Data storage controller 100: Data Retrieval and Utilization Controller 110: File upload process 120: File selection screen controller 130 : Data Upload Controller 140: Security layer 150 : Data Leakage Prevention Unit 160: Security blocking function controller 170: External leak blocking controller 180: Security Server

Claims

Claim 1 A data security system for protecting the data input, storage, retrieval, and utilization processes in a RAG-based system with multiple security layers, characterized by including DataLock, HidingLock, CenterLock, BackupLock, and CipherLock. Claim 2 A data security system according to claim 1, characterized by including a DataLock that detects data tampering during file upload and blocks it in real time. Claim 3 A data security system according to claim 1, characterized by including a HidingLock that restricts data access according to the user's position and authority and hides sensitive data. Claim 4 A data security system according to claim 1, characterized in that it includes a CenterLock that allows data to be downloaded only in an encrypted state and blocks clipboard copying and USB connection. Claim 5 A data security system according to claim 1, characterized by including a BackupLock that backs up data to the cloud and a physical server simultaneously. Claim 6 A data security system according to claim 1, characterized by including a CipherLock that performs real-time encryption and decryption during the data upload and download process.