Method for controlling external access to security information

The method addresses the risk of unauthorized access to security information during remote control by implementing a system to search, monitor, and block external access, ensuring secure transmission of sensitive data.

WO2025263874A1PCT designated stage Publication Date: 2025-12-26JIRANDATA CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/007442
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-20
Filing Date
2025-05-30
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

The transmission of screen information during remote control between computers poses a risk of exposing sensitive security information, such as personal or trade secrets, to unauthorized access.

Method used

A method and program for controlling external access to security information by searching for and setting security data, monitoring access, and blocking unauthorized access based on preset criteria, including authentication and interface management.

Benefits of technology

Strengthened security by preventing unprotected exposure of sensitive information during remote control sessions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025007442_26122025_PF_FP_ABST
    Figure KR2025007442_26122025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed is a method for controlling external access to security information. A method for controlling external access to security information, performed in a computing device, according to one aspect of the present invention, comprises the steps of: when external control for maintenance is requested, searching for a file or program containing security information and setting the file or program as security data; when external control is performed, monitoring external access to the security data; and , blocking the security data according to a preset criterion when external access to the security data is attempted.
Need to check novelty before this filing date? Find Prior Art

Description

Methods for controlling external access to security information

[0001] The present invention relates to a method for controlling external access to security information.

[0002]

[0003] We provide security solutions for a wide range of corporate applications for Internet security, and our security solutions are used in a wide variety of fields, including web security, e-mail security, remote access, electronic documents, and e-commerce applications.

[0004] In particular, with the development of computer and communication technology, the use of computers is expanding in various industrial fields as well as in daily life, and remote control technology between computers is being developed and widely used as a means to support not only general users who are not familiar with using computers and the Internet, but also industrial workers who handle a significant portion of their work with computers.

[0005] Remote control is a method in which a user of a remote control computer operates a controlled computer connected to the Internet through the Internet. In this process, the screen information of the controlled computer is transmitted to the control computer, and the controlled computer is operated as if the user of the control computer were directly operating it, so that the computer itself as well as peripheral devices including various output devices are operated.

[0006] At this time, as remote control proceeds, the screen output on the monitor of the controlled computer is transmitted to the control computer, and the user of the control computer can check the screen of the controlled computer in real time. As such, in remote control between computers, the screen of the controlled computer is transmitted to the control computer without any addition or subtraction, and there is a concern that security information such as personal information or trade secrets of the user of the controlled computer that is output on the screen of the control computer may be leaked.

[0007]

[0008] Accordingly, the present invention has been devised to solve the above-described problem, and to provide a method for controlling external access to security information that can block unprotected exposure of security information during remote control.

[0009] Other objects of the present invention will become more apparent through the preferred embodiments described below.

[0010]

[0011] According to one aspect of the present invention, a method for controlling external access to security information and a program for executing the method are provided, the method comprising: when external control for maintenance is requested, searching for a file or program containing security information and setting it as security data; when the external control is performed, monitoring external access to the security data; and when external access to the security data is attempted, blocking it according to preset criteria.

[0012] Here, the step of setting the security data includes the step of searching for a file or program containing security information; the step of displaying a security data setting interface screen containing the searched information; and the step of setting the security data according to a user selection.

[0013] Additionally, it searches for security data targeting the current screen and execution window.

[0014] Additionally, the security data is displayed only when the external control is requested under the control of internal access performed by the login.

[0015] In addition, under the control of the internal access, a first user interface screen capable of setting security data is displayed, and under the external control, a second user interface screen is displayed in which the security data is specifically displayed and which includes an interface for accessing the security data with the permission of the internal access user.

[0016] In addition, when access to security data is requested through the second user interface screen, access is permitted only when security authentication is successful based on whether a preset password is entered through the keyboard for internal access.

[0017] In addition, the monitoring video is saved by capturing the second user interface screen according to external access, the monitoring video for the external access is displayed on the user interface screen for entering the password, and only the monitoring video for a certain period of time prior to the request for external access to the security data is extracted and displayed.

[0018] Additionally, in the second user interface screen, the security data is hidden only when the mouse is operated.

[0019] Additionally, as the second interface screen, a dialogue window between an internal access user and an external access user is displayed in one area.

[0020] Other aspects, features and advantages other than those described above will become apparent from the following drawings, claims and detailed description of the invention.

[0021] According to the present invention, by monitoring and controlling external access to security information, security can be strengthened by blocking unprotected access by external users.

[0022]

[0023] FIG. 1 is a schematic diagram of an entire system for controlling external access to security information during remote control according to one embodiment of the present invention.

[0024] FIG. 2 is a flowchart illustrating an external access control process for security information performed in a computing device according to one embodiment of the present invention.

[0025] FIG. 3 is a flowchart illustrating an external access processing process for security data during remote control according to one embodiment of the present invention.

[0026] FIGS. 4 and 5 are exemplary diagrams showing a second user interface screen for remote control according to each embodiment of the present invention.

[0027]

[0028] The present invention is susceptible to various modifications and embodiments. Specific embodiments are illustrated in the drawings and described in detail in the detailed description. However, this is not intended to limit the present invention to specific embodiments, but rather to encompass all modifications, equivalents, and alternatives falling within the spirit and technical scope of the present invention.

[0029] When a component is referred to as being "connected" or "connected" to another component, it should be understood that it may be directly connected or connected to that other component, but that there may be other components intervening. Conversely, when a component is referred to as being "directly connected" or "connected" to another component, it should be understood that there are no other components intervening.

[0030] Terms such as "first" and "second" may be used to describe various components, but these components should not be limited by these terms. These terms are used solely to distinguish one component from another. For example, terms such as "first threshold" and "second threshold" described below may be predefined as thresholds that are substantially different or partially identical in value. However, since there is room for confusion when expressed using the same word "threshold," terms such as "first" and "second" will be used together for convenience of distinction.

[0031] The terminology used herein is merely used to describe specific embodiments and is not intended to limit the present invention. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this specification, it should be understood that the terms "comprises" or "has" indicate the presence of a feature, number, step, operation, component, part, or combination thereof described in the specification, but do not exclude in advance the possibility of the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.

[0032] In addition, it is to be understood that the components of the embodiments described with reference to each drawing are not limited to the specific embodiments, but may be implemented to be included in other embodiments within the scope in which the technical idea of ​​the present invention is maintained, and that multiple embodiments may be re-implemented as a single integrated embodiment even if a separate description is omitted.

[0033] In addition, when describing with reference to the attached drawings, identical components will be assigned identical or related reference numerals regardless of the drawing reference numbers, and redundant descriptions thereof will be omitted. When describing the present invention, if a detailed description of a related known technology is judged to unnecessarily obscure the gist of the present invention, the detailed description thereof will be omitted.

[0034]

[0035] FIG. 1 is a schematic diagram illustrating an entire system for controlling external access to security information during remote control according to one embodiment of the present invention, and FIG. 2 is a flowchart illustrating a process for controlling external access to security information performed in a computing device according to one embodiment of the present invention.

[0036] Referring to FIG. 1, the entire system includes a target computer (10) and a remote control computer (30), and a security agent (12) for controlling access to security information from the remote control computer (30) is installed in the form of an application program on the target computer (10).

[0037] Access by remote control users must be controlled for files or programs containing security information (hereinafter referred to as “security data”) that is accessible only to authorized users, such as personal information or confidential information.

[0038] A remote control computer (30) connects to a target computer (10) via a communication network such as the Internet and controls it remotely. In other words, a remote user other than an internal user of the target computer (10) uses the target computer (10). Typically, a remote control program periodically captures the screen of the target computer (10) and transmits it to the remote control computer (30), and the remote control computer (30) controls the target computer (10) by remotely manipulating the mouse pointer or inputting through the keyboard while viewing the received screen. Of course, this is just one example, and any method for remote control may be used.

[0039] However, the security agent (12) installed on the target computer (10) controls (blocks or allows use with the permission of the user of the target computer (10)) the remote control computer (30) from accessing the security data.

[0040] Referring to Figure 2, which illustrates an external access control process performed on a target computer (10), when external control is requested for purposes such as maintenance, a file or program containing security information is searched for and set as security data (S210).

[0041] In one example, the setting of security data can be automatically set by searching for files or applications containing personal information such as resident registration numbers and addresses. In another example, a file or program containing security information can be searched for, a security data setting interface screen including the searched information can be displayed, and the security data can be set according to the user's selection. That is, the target computer (10) allows the user to directly select and set security data based on the searched information determined to be security data, or provides a user interface screen that allows the user to directly search and set security data. The user interface that allows the user to set a specific file or installed program stored on the target computer (10) as security data will be apparent to those skilled in the art, and therefore, a detailed description thereof will be omitted.

[0042] And, according to an example, the target computer (10) may determine whether all files or applications are secure data, but for efficient processing, it determines whether only files and applications existing on the current screen and in the running window are secure data, and this may be performed periodically or whenever a change occurs in the screen or the running window.

[0043] When the security data is set, external control is performed and a second user interface screen on which the security data is specifically displayed is displayed (S220). In other words, the target computer (10) displays a first user interface screen under control by internal access, and when external control is performed, a second user interface screen on which the security data is specifically displayed is displayed. Referring to Fig. 4, for example, on the second user interface screen, the security data (security file 1) is externally processed with a red block so that the target computer user (hereinafter referred to as an internal user) and the remote control user recognize that it is security data.

[0044] And, according to an example, the security data is displayed only when external control is requested under the control of internal access where the login procedure is performed. In other words, the target computer (10) hides all security data when external control is performed without an internal login procedure, rather than when external control is requested while the user is logged in and under control. This prevents indiscriminate leakage of security data when external control is performed without an internal user, and only shows the security data to the remote control user when an internal user is present. In order for the remote control user to access the security data, an authorization procedure for the internal user must be performed. This will be explained in detail later.

[0045] Monitor external access based on external control (S230). For example, periodically capture and save screens and monitor whether remote control users attempt to access secure data.

[0046] When external access to security data is recognized, control processing such as blocking or inquiry to internal users is performed (S240).

[0047]

[0048] FIG. 3 is a flowchart illustrating an external access processing process for security data during remote control according to one embodiment of the present invention, and FIGS. 4 and 5 are exemplary diagrams illustrating a second user interface screen for remote control according to each embodiment of the present invention.

[0049] Referring to FIG. 3, when external control is performed and access to secure data is recognized by the external control (S310), authentication is requested from the internal access user (S320). Referring to FIG. 4, when external access is requested for secure data, security file 1 (e.g., a mouse click by external control on security file 1), an authentication window (430) that the internal access user can confirm is displayed.

[0050] At this time, according to an example, a monitoring video (440) for external access is displayed on the user interface screen for password input. That is, the stored monitoring video is provided as a video so that the internal access user can immediately check what kind of history the external access user has when attempting to access the security data. Here, for quick confirmation, only the monitoring video for a certain period of time (e.g., 20 seconds or 1 / 3 of the total length, etc.) prior to the external access request for the security data is extracted and displayed, and the playback speed is varied according to the playback time of the video (e.g., the longer the playback time, the faster the playback speed).

[0051] Authentication is processed (S330) by determining whether a password is entered through an internal keyboard (i.e., the keyboard of the target computer (10)) through an authentication window (430).

[0052] If authentication is successful, external access to the security data is permitted (S340), and if authentication fails, access is denied (S350, for example, an access denied message is displayed on the screen).

[0053] Also, referring to Figure 5, in the second user interface screen, security data is hidden when the mouse is operated. That is, when the mouse pointer is moved by external control, security data is hidden, and is displayed only when the mouse pointer is not operated. Of course, this is merely an example, and conversely, security data can be displayed only when the mouse pointer is operated.

[0054] And, as a second interface screen, a dialogue window (510) between an internal access user and an external access user is displayed in one area, so that a dialogue can be performed between the two, such as asking whether or not to access security data.

[0055]

[0056] A computer program stored in a computer-readable medium that performs the method for controlling external access to security information according to the present invention described above may be provided.

[0057] Additionally, the method for controlling external access to the aforementioned security information can be implemented as computer-readable code on a computer-readable storage medium. Computer-readable storage media include all types of storage media that store data decipherable by a computer system. Examples include read-only memory (ROM), random access memory (RAM), magnetic tape, magnetic disks, flash memory, and optical data storage devices. Furthermore, the computer-readable storage media can be distributed across computer systems connected via a computer communications network, and stored and executed as readable code in a distributed manner.

[0058] In addition, although the above has been described with reference to preferred embodiments of the present invention, it will be understood by those skilled in the art that various modifications and changes can be made to the present invention without departing from the spirit and scope of the present invention as set forth in the claims below.

Claims

1. In a method for controlling external access performed in a computing device, When external control for maintenance is requested, a step of searching for a file or program containing security information and setting it as security data; A step of monitoring external access to the security data when the above external control is performed; and Including a step of blocking an attempt at external access to the above security data according to preset criteria, The above security data is displayed only when the above external control is requested under the control of internal access performed by login. Under the control by the internal access, a first user interface screen capable of setting security data is displayed, and under the external control, a second user interface screen is displayed in which the security data is specifically displayed and which includes an interface for accessing the security data with the permission of the internal access user. A method for controlling external access to security information, in which the security data is hidden only when the mouse is operated on the second user interface screen.

2. In claim 1, The steps for setting the above security data are: Steps to browse files or programs containing security information; A step of displaying the searched information as the first user interface screen; and A method for controlling external access to security information, comprising a step of setting security data according to user selection.

3. In claim 2, A method for controlling external access to security information by searching for security data targeting the current screen and execution window.

4. In claim 1, A method for controlling external access to security information, in which, when access to security data is requested through the second user interface screen, access is permitted only when security authentication is successful based on whether a preset password is entered through the keyboard through the internal access.

5. In claim 4, The monitoring video is saved by capturing the second user interface screen according to external access. A method for controlling external access to security information, which displays a monitoring image for the external access on a user interface screen for entering the above password.

6. In claim 5, A method for controlling external access to security information by extracting and displaying only monitoring images taken during a certain period of time prior to a request for external access to security data.

7. In claim 1, A method for controlling external access to security information, wherein a dialogue window between an internal access user and an external access user is displayed in one area as the second user interface screen.

8. A computer program stored in a computer-readable medium that causes a computer to perform an external access control method for security information, wherein the computer program causes a computer to perform the following steps, wherein the steps are: When external control for maintenance is requested, a step of searching for a file or program containing security information and setting it as security data; A step of monitoring external access to the security data when the above external control is performed; and Including a step of blocking an attempt at external access to the above security data according to preset criteria, The above security data is displayed only when the above external control is requested under the control of internal access performed by login. Under the control by the internal access, a first user interface screen capable of setting security data is displayed, and under the external control, a second user interface screen is displayed in which the security data is specifically displayed and which includes an interface for accessing the security data with the permission of the internal access user. A computer program stored in a computer-readable medium, wherein the security data is hidden only when the mouse is operated on the second user interface screen.

Citation Information

Patent Citations

  • Method and system for security materialization of remote connection for the same

    KR100733476B1

  • Pairing digital system for smart security and method for providing same

    KR1020140007303A

  • System and Method for controlling remote device

    KR1020140067186A

  • Virtual fields driving related operations

    KR1020240024735A

  • External access control method for security information

    KR102744986B1