Information security
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-02-03
- Publication Date
- 2026-08-13
Smart Images

Figure FI2026050047_13082026_PF_FP_ABST
Abstract
Description
INFORMATION SECURITYFIELD
[0001] The present disclosure relates to information security in automated systems.BACKGROUND
[0002] Networked applications have been used for various purposes for a long time. For example, airline tickets may be purchased using engines which retrieve ticket availability and price information from dozens of different providers. Likewise, generative artificial intelligence, Al, solutions have been provided with capability to call on tools external to the Al solutions as part of their processing of user-derived prompts.SUMMARY
[0003] According to some aspects, there is provided the subject-matter of the independent claims. Some embodiments are defined in the dependent claims.
[0004] According to a first aspect of the present disclosure, there is provided a computer-implemented method comprising obtaining, by an apparatus, data identifying an information element or comprising the information element in encrypted form, and providing to an automated query processing node a request and the data, the request referring to the information element and the request referring to a service node in a network domain, the apparatus being also comprised in the network domain and the automated query processing node comprised in a second network domain.
[0005] According to a second aspect of the present disclosure, there is provided a computer-implemented method comprising receiving, by an apparatus, from a node in a network domain, a request and data, the request referring to an information element and the request referring to a service node in the network domain, the apparatus being comprised in a second network domain, the data identifying the information element or comprising the information element in encrypted form, processing the request using an automated queryprocessing routine run by the apparatus, and providing, as part of the processing of the request, to the service node an instruction comprising the data.
[0006] According to a third aspect of the present disclosure, there is provided a non-transitory computer readable medium having stored thereon a set of computer readable instructions that, when executed by at least one processor, cause an apparatus to at least obtain data identifying an information element or comprising the information element in encrypted form, and provide to an automated query processing node a request and the data, the request referring to the information element and the request referring to a service node in a network domain, the apparatus being also comprised in the network domain and the automated query processing node comprised in a second network domain.
[0007] According to a fourth aspect of the present disclosure, there is provided a non-transitory computer readable medium having stored thereon a set of computer readable instructions that, when executed by at least one processor, cause an apparatus to at least receive, from a node in a network domain, a request and data, the request referring to an information element and the request referring to a service node in the network domain, the apparatus being comprised in a second network domain, the data identifying the information element or comprising the information element in encrypted form, process the request using an automated query processing routine run by the apparatus, and provide, as part of the processing of the request, to the service node an instruction comprising the data.
[0008] According to a fifth aspect of the present disclosure, there is provided an apparatus comprising means for obtaining, by the apparatus, data identifying an information element or comprising the information element in encrypted form, and providing to an automated query processing node a request and the data, the request referring to the information element and the request referring to a service node in a network domain, the apparatus being also comprised in the network domain and the automated query processing node comprised in a second network domain.
[0009] According to a sixth aspect of the present disclosure, there is provided an apparatus comprising means for receiving, by the apparatus, from a node in a network domain, a request and data, the request referring to an information element and the request referring to a service node in the network domain, the apparatus being comprised in a second network domain, the data identifying the information element or comprising the information element in encrypted form, processing the request using an automated query processingroutine run by the apparatus, and providing, as part of the processing of the request, to the service node an instruction comprising the data.
[0010] According to a seventh aspect of the present disclosure, there is provided an apparatus comprising at least one processing core and at least one memory storing instructions that, when executed by the at least one processing core, cause the apparatus at least to obtain data identifying an information element or comprising the information element in encrypted form, and provide to an automated query processing node a request and the data, the request referring to the information element and the request referring to a service node in a network domain, the apparatus being also comprised in the network domain and the automated query processing node comprised in a second network domain.
[0011] According to an eighth aspect of the present disclosure, there is provided an apparatus comprising at least one processing core and at least one memory storing instructions that, when executed by the at least one processing core, cause the apparatus at least to receive, from a node in a network domain, a request and data, the request referring to an information element and the request referring to a service node in the network domain, the apparatus being comprised in a second network domain, the data identifying the information element or comprising the information element in encrypted form, process the request using an automated query processing routine run by the apparatus, and provide, as part of the processing of the request, to the service node an instruction comprising the data.BRIEF DESCRIPTION OF THE DRAWINGS
[0012] FIGURE 1 illustrates an example system in accordance with at least some embodiments of the present invention;
[0013] FIGURE 2 illustrates an example system in accordance with at least some embodiments of the present invention;
[0014] FIGURE 3 illustrates an example apparatus capable of supporting at least some embodiments of the present invention;
[0015] FIGURE 4 illustrates signalling in accordance with at least some embodiments of the present invention;
[0016] FIGURE 5A is a flow graph of a method in accordance with at least some embodiments of the present invention;
[0017] FIGURE 5B is a flow graph of a method in accordance with at least some embodiments of the present invention;
[0018] FIGURE 6A is a flow graph of a method in accordance with at least some embodiments of the present invention, and
[0019] FIGURE 6B is a flow graph of a method in accordance with at least some embodiments of the present invention.EMBODIMENTS
[0020] Methods are herein disclosed which enable use of automated query processing nodes, such as large language model, LLM, small language model, SLM, or expert systems, of another domain without compromising information which is intended to be maintained in a first domain. In detail, the automated query processing node of the other domain is provided a request and data which identifies the information in the first domain, or alternatively the data may comprise the information in such an encrypted form, that it can be decrypted in the first domain but not in the domain of the automated query processing node. Thus benefits are obtained in that automated query processing node of the other domain may be used in a secure manner, without revealing the information which is intended to be maintained only in the first domain. The information may be in the form of information elements.
[0021] FIGURE 1 illustrates an example system in accordance with at least some embodiments of the present invention. First domain 101 comprises an agent 110, a service node 112, a second service node 114 and a database 116. The first domain is a network domain, by which it is meant an administrative grouping of multiple computer nodes within the same infrastructure. Network domains can be identified using a domain name, and domains which are accessible from the public Internet are assigned a globally unique name within the domain name system, DNS.
[0022] Service node 112 runs a computational tool which is configured to perform a limited service as a response to an instruction. For example, the computational tool may beconfigured to transmit short message service, SMS, messages, format data it receives into a new format or add to the instruction it receives data available in first domain 101 before passing the instruction, or parts of the instruction, onward. Second service node 114 runs a second computational tool, different from the computational tool run by service node 112. In some embodiments, second service node 114 is absent.
[0023] Database 116 is configured to store information elements and associations between the information elements and data, such that it may be said the data identifies the respective information element in first domain 101. Agent 110, service node 112, second service node 114 and database 116 are logical nodes, in other words, they may be run on one or more than one physical computing substrates. In some embodiments, each of agent 110, service node 112, second service node 114 and database 116 are run in physically separate nodes, interconnected with each other within first domain 101.
[0024] Second domain 102 is, like first domain 101, a network domain. Second domain 102 comprises automated query processing node 120 and, in some embodiments, third service node 122. The automated query processing node runs an automated query processing routine, such as an LLM, SLM or expert system. In some embodiments, third service node 122 is absent but where it is present, it runs a computational tool which automated query processing node can call when handling a request. First domain 101 and second domain 102 are communicatively coupled with each other, such that nodes of first domain 101 can transmit messages to nodes in second domain 102, and vice versa. Domain 102 may be a cloud, for example. There may exist restrictions as to communication between first domain 101 and second domain 102, for example, firewalls or edge nodes may be configured to reject certain kinds of messages arriving from outside the respective domain.
[0025] In certain artificial intelligence, Al, systems, such as LangChain, Haystack, or Semantic Kernel, a large language model, LLM, or other automated query processing node may use tools run by service nodes, these tools offering various functionalities the automated query processing node may invoke when needed. In other words, the automated query processing node may “decide” as part of its automatic processing of a request, to call on one or more such tool. In some cases, the request may itself instruct the automated query processing node, to call on a specific tool when processing the request. For example, an automated query processing node may invoke a tool which retrieves information from the web, examples of this being regular Internet search tools such as Qwant and Bing. Further,the tool may retrieve corporate data in real time, the automated query processing node may use a tool capable of performing mathematical computations, or a tool configured to post information onto social media, a website or generate a ticket into a customer service tool. When using the tools, the automated query processing node can decide how to act in terms of processing a request itself or processing the request by using tools external to the automated query processing node. When using tools, the automated query processing node may first select an appropriate tool, and then call the tool using suitable parameters. Calling a tool comprises providing an instruction to the tool.
[0026] Different architectural solutions exist for situating the automated query processing node, the calling agent, and the service nodes running the tools. Examples are situating all in a same warehouse and in a same public cloud. The locations may be relevant in terms of privacy and regulations, as handling of personal information is restricted in several jurisdictions. An example of regulation affecting handling of personal information is the GDPR regulation in force in Europe. Further, natural persons and businesses have interest in protecting their private information also in the absence of jurisdictional requirements in this regard. Safety of natural persons is enhanced when e.g. their addresses are protected from disclosure.
[0027] A request provided to an automated query processing node may comprise, for example, one or more of: a system prompt with instructions to the automated query processing node concerning how to handle the request, a user request from a user, source data based on which the automated query processing node is to produce a response, or a chat history. The request may refer to the information element which relates to the request.
[0028] In certain situations, it is not desired or allowed to give an automated query processing node, such as an LLM or SLM, all the information elements needed to completely process the query. For example, as discussed herein above, some information elements may have personal information, such as a telephone number, email address, passport number or vaccination status.
[0029] To avoid providing the information elements to an automated query processing node of another domain, solutions are herein described. In detail, the agent 110 may store the information element in a database in a same domain 101 as the agent 110, and provide to the automated query processing node 120 data identifying the information element in the domain 101 of the agent 110. Alternatively to this, the information element may be providedto the automated query processing node 120 in encrypted form, such that the encryption is reversible by service nodes 112, 114 in the domain 101 of the agent 110. The data identifying the information element may identify more than one information element, for example if the data is a session identifier wherein the request to the automated query processing node 120 is comprised in the session identified by the session identifier.
[0030] In operation, agent 110 obtains a request, such as from a user or from an automated system. For example, a weather sensor or triggered smoke alarm may produce sensor data which triggers sending of a request to agent 110 are examples of automated systems generating requests to agent 110.
[0031] Agent 110 then compiles a request to be provided to automated query processing node 120 in domain 102. Since the request is comprised in a session involving at least one information element that should not be disclosed to nodes outside domain 101, agent 110 refrains from disclosing this at least one information element to automated query processing node 120, and instead stores this at least one information element in database 116, associated therein with data which identifies the at least one information element via this association. For example, database may store a look-up table which enables retrieving the information element with the data in domain 101. Database 116 may be configured to not respond to requests for the information element which originate from outside domain 101, even if the requests comprise the data. The data itself may be, for example, randomly or pseudo-randomly generated and the information element cannot be inferred from the data.
[0032] Agent 110 provides to automated query processing node 120 a request and the data identifying the information element(s) in phase 1 A. The request refers to service node 112 in domain 101, instructing automated query processing node 120 to call a tool provided by service node 112 when processing the request of phase 1 A.
[0033] Automated query processing node 120 begins processing the request of phase 1A, optionally calling on a tool provided by third service node 122 in domain 102, this optional call is illustrated in FIGURE 1 as phases IB and 1C. Based on the request of phase 1A, automated query processing node calls service node 112 in phase ID, the call of phase ID comprising an instruction for service node 112 to perform, and the call of phase ID also comprises the data identifying the information element(s). The call of phase ID may also comprise a partially complete response to the request of phase 1 A.
[0034] Service node 112 receives call ID, and retrieves the information element(s) from database 116 in call IE and response IF. Service node 112 now being in possession of the information element(s), it may perform its processing to produce an output, such as output 1G. As a specific example, where the information element retrieved from database 116 comprises a telephone number or email address, call ID from automated query processing node 120 may comprise an instruction to transmit text included in call ID to the identified telephone number as an SMS, or to the identified email address as an email. Service node 112 will then provide the information it received from automated query processing node 120 to the telephone number or email address, completing the processing of the request of phase 1 A without revealing the telephone number or email address to any node in domain 102.
[0035] Another example of what service node 112 may do in response to call ID, is to remove a subscriber identified by the telephone number identified by the data from a database of active subscribers of a cellular communication network, expelling this subscriber from the cellular communication network. This may be needed as a response to spam messaging, for example. In this case, phase 1G is directed at a subscriber information repository of the cellular communication network.
[0036] FIGURE 2 illustrates an example system in accordance with at least some embodiments of the present invention. Like numbering denotes like structure as in FIGURE 1. The system of FIGURE 2 differs from that of FIGURE 1 in that there is no database node in domain 101. Here, in the request of phase 1A the data in fact comprises the information element(s) to be concealed from nodes of domain 102, in encrypted form. The encryption prevents nodes of domain 102 from accessing the information element(s) in plaintext form. As was the case in FIGURE 1, the request may instruct the automated query processing node to use a tool provided by service node 112 in the processing of the request. Automated query processing node 120 may, optionally, as in the system of FIGURE 1, call on third service node 122, phases IB and 1C, in the processing of the request of phase 1A.
[0037] Automated query processing node 120 calls on service node 112 in phase ID, this call comprising the encrypted information element(s). Service node 112 obtains decryption of the information element(s) and acts on the call of phase ID. Then service node 112 completes, phase 2E, the processing of the request of phase 1 A, as was discussed herein above in connection with phase 1G.
[0038] For the mechanism of FIGURE 2 to work, agent 110 needs to encrypt the information element(s) in a way that service node 112 is capable of performing the decrypting. For example, agent 110 may use an encryption key of domain 101 in a symmetric encryption algorithm, enabling service node 112 to decrypt the data using the same encryption key which it will have, or can retrieve, as service node 112 is in domain 101, like agent 110. As another example, agent 110 may obtain, directly or via a key repository of domain 101, a public key of service node 112 and perform the encrypting using this public key and an asymmetric encryption algorithm. Service node 112 can then reverse this encryption using its corresponding private key, which it holds. A key repository may also be referred to as a key management node.
[0039] In some embodiments, agent 110 is configured to generate an encryption key for the encrypting of the information element(s) dynamically, and store this encryption key in a key repository of domain 101 together with a randomly or pseudo-randomly generated identifier of this encryption key. This encryption key identifier may then be included in the request of phase 1 A, and also by automated query processing node 120 in call ID, enabling service node 112 to retrieve the encryption key from the key repository using the key identifier, for performing the decryption in service node 112. As a further variant, service node 112 may be configured to provide the encrypted information element(s) to a further node of domain 101, together with the key identifier, and to receive the decrypted information element(s) from the further node after the further node has retrieved the encryption key using the key identifier and performed the decrypting.
[0040] Once service node 112 has completed its processing of call ID, it will complete the processing of the request of phase 1 A. Phase 2E thus corresponds functionally to phase 1G of FIGURE 1.
[0041] FIGURE 3 illustrates an example apparatus capable of supporting at least some embodiments of the present invention. Illustrated is device 300, which may comprise, for example, a computer running agent 110 or automated query processing node 120 of FIGURE 1 or FIGURE 2. Comprised in device 300 is processor 310, which may comprise, for example, a single- or multi-core processor wherein a single-core processor comprises one processing core and a multi-core processor comprises more than one processing core. Processor 310 may comprise, in general, a control device. Processor 310 may comprise more than one processor. When processor 310 comprises more than one processor, device 300may be a distributed device wherein processing of tasks takes place in more than one physical unit. Processor 310 may be a control device. A processing core may comprise, for example, a Cortex- A8 processing core manufactured by ARM Holdings or a Zen processing core designed by Advanced Micro Devices Corporation. A processing core or processor may be, or may comprise, at least one qubit. Processor 310 may comprise at least one Qualcomm Snapdragon and / or Intel Atom processor. Processor 310 may comprise at least one application-specific integrated circuit, ASIC. Processor 310 may comprise at least one field-programmable gate array, FPGA. Processor 310, optionally together with memory and computer instructions, may be means for performing method steps in device 300. Processor 310 may be configured, at least in part by computer instructions, to perform actions.
[0042] Device 300 may comprise memory 320. Memory 320 may comprise randomaccess memory and / or permanent memory. Memory 320 may comprise at least one RAM chip. Memory 320 may be a computer readable medium. Memory 320 may comprise solid-state, magnetic, optical and / or holographic memory, for example. Memory 320 may be at least in part accessible to processor 310. Memory 320 may be at least in part comprised in processor 310. Memory 320 may be means for storing information. Memory 320 may comprise computer instructions that processor 310 is configured to execute. When computer instructions configured to cause processor 310 to perform certain actions are stored in memory 320, and device 300 overall is configured to run under the direction of processor 310 using computer instructions from memory 320, processor 310 and / or its at least one processing core may be considered to be configured to perform said certain actions. Memory 320 may be at least in part external to device 300 but accessible to device 300. Memory 320 may be transitory or non-transitory. The term “non-transitory”, as used herein, is a limitation of the medium itself (that is, tangible, not a signal) as opposed to a limitation on data storage persistency (for example, RAM vs. ROM).
[0043] Device 300 may comprise a transmitter 330. Device 300 may comprise a receiver 340. Transmitter 330 and receiver 340 may be configured to transmit and receive, respectively, information in accordance with at least one suitable standard.
[0044] Device 300 may comprise user interface, UI, 360. UI 360 may comprise at least one of a display, a keyboard, a touchscreen, a vibrator arranged to signal to a user by causing device 300 to vibrate, a speaker or a microphone. A user may be able to operate device 300 via UI 360, for example to configure agent, LLM or SLM parameters.
[0045] Processor 310 may be furnished with a transmitter arranged to output information from processor 310, via electrical leads internal to device 300, to other devices comprised in device 300. Such a transmitter may comprise a serial bus transmitter arranged to, for example, output information via at least one electrical lead to memory 320 for storage therein. Alternatively to a serial bus, the transmitter may comprise a parallel bus transmitter. Likewise processor 310 may comprise a receiver arranged to receive information in processor 310, via electrical leads internal to device 300, from other devices comprised in device 300. Such a receiver may comprise a serial bus receiver arranged to, for example, receive information via at least one electrical lead from receiver 340 for processing in processor 310. Alternatively to a serial bus, the receiver may comprise a parallel bus receiver.
[0046] Device 300 may comprise further devices not illustrated in FIGURE 3. For example, where device 300 comprises a smartphone, it may comprise at least one digital camera. Some devices 300 may comprise a back-facing camera and a front-facing camera, wherein the back-facing camera may be intended for digital photography and the frontfacing camera for video telephony. Device 300 may comprise a fingerprint sensor arranged to authenticate, at least in part, a user of device 300. In some embodiments, device 300 lacks at least one device described above.
[0047] Processor 310, memory 320, transmitter 330, receiver 340, and / or UI 360 may be interconnected by electrical leads internal to device 300 in a multitude of different ways. For example, each of the aforementioned devices may be separately connected to a master bus internal to device 300, to allow for the devices to exchange information. However, as the skilled person will appreciate, this is only one example and depending on the embodiment various ways of interconnecting at least two of the aforementioned devices may be selected without departing from the scope of the present invention.
[0048] FIGURE 4 illustrates signalling in accordance with at least some embodiments of the present invention. On the vertical axes are disposed, from the left to the right, database 116, service node 112, agent 110, automated query processing node 120 and third service node 122. Time advances from the top toward the bottom.
[0049] Initially, in phase 410, agent 110 sends its request to automated query processing node 120, as was discussed herein above in connection with phase 1 A of FIGURE 1. For example, the agent may be triggered by automated sensor data, or a human calling anautomated chatbot to request changes to a technical system, such as a manufacturing facility or a cellular communication network. The hot or sensor may trigger agent 110 with a query or request, initiating the signalling flow illustrated in FIGURE 4. The request of phase 410 comprises the data identifying the information element(s) retained in domain 101 and not shared with nodes of domain 102. In phase 420 automated query processing node 120 processes the request, and determines, in this example, to invoke third service node 122 as part of the processing, which is illustrated as phases 430 and 435, which correspond to phases IB and 1C of FIGURE 1, respectively.
[0050] Automated query processing node 120 continues processing of the request of phase 410 in phase 440. The request of phase 410 comprises an instruction to use a tool provided by service node 112 in the processing of the request, wherefore automated query processing node 120 calls, phase 450, service node 112 as part of its processing of the request of phase 410. Phase 450 corresponds to phase ID of FIGURE 1. The call of phase 450 comprises the data identifying the information element(s) obtained in automated query processing node 120 in phase 410 from agent 110.
[0051] In phase 460 service node 112 requests from database 116 to be provided the information element(s), providing the data to database 116. In phase 465 the database looks up which information element(s) service node 112 is requesting, using the data and a lookup table, and in phase 470 database 116 provides the information element(s) to service node 112. In phase 480 service node 112 processes the call of phase 450, using the information element(s) withheld from nodes of domain 102, and in phase 490 service node provides an output as response to call 450, completing the processing of the request of phase 410. In some embodiments, the message of phase 490 is delivered from service node 112 to agent 110.
[0052] In a variant of the signalling flow of FIGURE 4, automated query processing node 120 may provide a textual answer to the request of phase 410 directly to agent 110, which may forward the textual answer to a user who triggered the request of phase 410. Additionally, in this variant, automated query processing node 120 may decide, as part of processing the request of phase 410, to transmit an SMS to the user, which automated query processing node 120 may accomplish via service node 112, which in this variant has an SMS transmission portal. The user’s telephone number is thus concealed from automated queryprocessing node 120, even if automated query processing node 120 successfully uses it to send the SMS. The SMS may comprise a link the user can use, for example.
[0053] The herein described mechanism was tested using a Python code. The test relied on a LangChain based agent using an LLM as the automated query processing node in another domain. The agent had access to four tools: firstly, a Bing web search, secondly, a tool configured to fetch data from an Azure Al search, thirdly, a tool which returns the current date and time, and fourthly, a tool simulating SMS transmission. As this was a test, no actual SMS was sent.
[0054] In the test, a session identifier is generated as a response to a caller’s telephone number. The session identifier is here the data which identifies the information element, the caller’s telephone number, which is withheld from the LLM. A user poses a question using natural language, which the agent will respond to and the LLM should send a reply to the user using SMS. The prompt used was:
[0055] ’’You are an assistant that help customers by answering their questions. If you are asked about Elisa (a Finnish telco and IT company). You can use the elisa search tool. If you need to get A) realtime information or B) Elisa related information that is not found from elisa search tool or C) information that you do not have, you can use bing search tool to request a web search in order to get more information. If you think that you need to perform web search just do it without asking the user. If a web search does not give the required information, you can try again with a modified query. If you need to get the current date and time, you can use now tool. Finally please always send your answer as an SMS using the send sms tool! It is important that you send the answer as an SMS! You find the session ID below with the user query. Please use that session ID if you call the send sms tool! . IT IS IMPORTANT THAT YOU USE THE sessionld VALUE PROVIDED IN THE USER PART AND YOU DO NOT INVENT YOURSELF ITS VALUE! ! "
[0056] An example test used with the Python code was the question “Where is the headquarters of Elisa?” ” MODIFIED QUERY: Where is the headquarters of Elisa? The session ID (sessionld) to use for this query is 1724904647.741767.” Here the user prompt is modified by adding the session Id for the LLM. ” Invoking: 'elisa search' with '{'query1: 'Elisa HQ location', 'top': 1}'”, the LLM decides to use the elisa-search tool to find the information.
[0057] ’’Invoking: 'send_sms' with ' {'sessionld': '1724904647.741767', 'content': 'Elisa headquarters is located at address Kutomotie 18, Helsinki, Finland.'}'” Here the LLM decides to use a send sms tool with the procided session-ID:lla and content it has formed.
[0058] SMS sent to the number 0101234567 with the content Elisa headquarters is at address Kutomotie 18, Helsinki, Finland.” The send sms tool acknowledged having performed the transmission.
[0059] FIGURE 5A is a flow graph of a method in accordance with at least some embodiments of the present invention. Phase 510 corresponds to startup of an agent-based service, for example as a response to a telephone call arriving at a voicebot and initialization of a dialogue between a user and the voicebot. Phase 520 corresponds to generation of pairs of information elements and their corresponding identifying data, for example pairs of telephone numbers and their associated session identifiers. Phase 530 corresponds to provision of the identifying data to an automated query processing node, such as an LLM, SLM or expert system. Phase 540 corresponds to the automated query processing node deciding to call a tool provided by a service node. The automated query processing node provides one or more data to the tool. Phase 560 corresponds to the tool retrieving one or more information element identified by the data received in the tool from the automated query processing node. Finally, phase 570 comprises the tool completing its task. Thus the flow of FIGURE 5 A corresponds to the system of FIGURE 1.
[0060] FIGURE 5B is a flow graph of a method in accordance with at least some embodiments of the present invention. Phase 580 corresponds to startup of an agent-based service, for example as a response to a telephone call arriving at a voicebot and initialization of a dialogue between a user and the voicebot. Phase 590 corresponds to provision of the information element} s) in encrypted form to the automated query processing node. In phase 5100 the automated query processing node decides to call a tool run in the same domain as the agent which called the automated query processing node, and phase 5110 corresponds to the automated query processing node providing the encrypted information element} s) to the tool. In phase 5120 the tool decrypts the information element} s), as described herein above, and finally phase 5130 corresponds to the tool performing its task, using the decrypted information element} s).
[0061] Technical effects are thus obtained in terms of information security, as automated query processing nodes in foreign, untrusted domains may be used whileconcealing from these automated query processing nodes information elements which are considered sensitive. For example, the information elements may identify persons.
[0062] FIGURE 6A is a flow graph of a method in accordance with at least some embodiments of the present invention. The phases of the illustrated method may be performed in agent 110, for example, or in a control device configured to control the functioning thereof, when installed therein
[0063] Phase 610 comprises obtaining, by an apparatus, data identifying an information element or comprising the information element in encrypted form. Phase 620 comprises providing to an automated query processing node a request and the data, the request referring to the information element and the request referring to a service node in a network domain, the apparatus being also comprised in the network domain and the automated query processing node comprised in a second network domain.
[0064] FIGURE 6B is a flow graph of a method in accordance with at least some embodiments of the present invention. The phases of the illustrated method may be performed in automated query processing node 120, for example, or in a control device configured to control the functioning thereof, when installed therein
[0065] Phase 630 comprises receiving, by an apparatus, from a node in a network domain, a request and data, the request referring to an information element and the request referring to a service node in the network domain, the apparatus being comprised in a second network domain, the data identifying the information element or comprising the information element in encrypted form. Phase 640 comprises processing the request using an automated query processing routine run by the apparatus. Finally, phase 650 comprises providing, as part of the processing of the request, to the service node an instruction comprising the data.
[0066] It is to be understood that the embodiments of the invention disclosed are not limited to the particular structures, process steps, or materials disclosed herein, but are extended to equivalents thereof as would be recognized by those ordinarily skilled in the relevant arts. It should also be understood that terminology employed herein is used for the purpose of describing particular embodiments only and is not intended to be limiting.
[0067] Reference throughout this specification to one embodiment or an embodiment means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present invention. Thus,appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Where reference is made to a numerical value using a term such as, for example, about or substantially, the exact numerical value is also disclosed.
[0068] As used herein, a plurality of items, structural elements, compositional elements, and / or materials may be presented in a common list for convenience. However, these lists should be construed as though each member of the list is individually identified as a separate and unique member. Thus, no individual member of such list should be construed as a de facto equivalent of any other member of the same list solely based on their presentation in a common group without indications to the contrary. In addition, various embodiments and example of the present invention may be referred to herein along with alternatives for the various components thereof. It is understood that such embodiments, examples, and alternatives are not to be construed as de facto equivalents of one another, but are to be considered as separate and autonomous representations of the present invention.
[0069] Furthermore, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the preceding description, numerous specific details are provided, such as examples of lengths, widths, shapes, etc., to provide a thorough understanding of embodiments of the invention. One skilled in the relevant art will recognize, however, that the invention can be practiced without one or more of the specific details, or with other methods, components, materials, etc. In other instances, well-known structures, materials, or operations are not shown or described in detail to avoid obscuring aspects of the invention.
[0070] While the forgoing examples are illustrative of the principles of the present invention in one or more particular applications, it will be apparent to those of ordinary skill in the art that numerous modifications in form, usage and details of implementation can be made without the exercise of inventive faculty, and without departing from the principles and concepts of the invention. Accordingly, it is not intended that the invention be limited, except as by the claims set forth below.
[0071] The verbs “to comprise” and “to include” are used in this document as open limitations that neither exclude nor require the existence of also un-recited features. The features recited in depending claims are mutually freely combinable unless otherwise explicitly stated. Furthermore, it is to be understood that the use of "a" or "an", that is, asingular form, throughout this document does not exclude a plurality.
[0072] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.INDUSTRIAL APPLICABILITY
[0073] At least some embodiments of the present invention find industrial application in information security.REFERENCE SIGNS LIST
Claims
CLAIMS:
1. A computer-implemented method comprising:- obtaining (610), by an apparatus (110), data identifying an information element or comprising the information element in encrypted form, and- providing (620 to an automated query processing node (120) a request (1 A) and the data,wherein- the request (1A) refers to the information element and the request instructs the automated query processing node to request (ID), using the data, a service from a service node (112) in a network domain (101) in processing the request (1A), the apparatus (110) being also comprised in the network domain (101) and the automated query processing node (120) comprised in a second network domain (102).
2. The computer-implemented method according to claim 1, further comprising storing the information element in a database (116) located in the network domain (101), such that the data identifies the information element in the database (116).
3. The computer-implemented method according to claim 2, wherein the data comprises a session identifier, the request (1A) being comprised in a session identified by the session identifier.
4. The computer-implemented method according to claim 1, further comprising encrypting, using an encryption key, the information element to obtain the data, and to exactly one of: a) providing the encryption key to the service node (112), b) obtaining the encryption key from the service node (112), c) obtaining the encryption key from a key management node in the network domain (101), or d) providing the encryption key to the key management node in the network domain (101).
5. A computer-implemented method comprising:- receiving (630), by an apparatus (120), from a node (110) in a network domain (101), a request (1A) and data, the data identifying an information element or comprising the information element in encrypted form;- processing (640) the request (1A) using an automated query processing routine run by the apparatus (120),wherein- the request (1 A) refers to the information element and the request refers to a service node (112) in the network domain (101), the apparatus (120) being comprised in a second network domain (102), and- providing (650), as part of the processing of the request (1A), to the service node (112) an instruction (ID) comprising the data, wherein the request (1 A) instructs the automated query processing routine to request a service from the service node (112) in processing the request (1A), wherein the method comprises responsively requesting (1 A) the service from the service node (112) as part of the processing of the request (1A), wherein the method comprises providing the data to the service node (112) when requesting the service from the service node (112).
6. The computer-implemented method according to claim 5, wherein the automated query processing routine comprises a large language model, LLM, or a small language model, SLM.
7. The computer-implemented method according to claim 5 or 6, wherein the automated query processing routine is configured to decide based at least in part on the request (1 A), which service node (112) or service nodes it invokes as part of the processing of the request (1A).
8. An apparatus (110, 120, 300) comprising at least one processing core (310) and at least one memory (320) storing instructions that, when executed by the at least one processing core (310), cause the apparatus (110, 120, 300) at least to perform a method according to one of claims 1 - 4 or one of claims 5 - 7.
9. A non-transitory computer readable medium having stored thereon a set of computer readable instructions that, when executed by at least one processor (310), cause an apparatus (110, 300) to at least:- obtain (610) data identifying an information element or comprising the information element in encrypted form, and- provide (620) to an automated query processing node (120) a request (1A) and the data,wherein- the request (1A) refers to the information element and the request instructs the automated query processing node (120) to request, using the data, a service from a service node (112) in a network domain (101) in processing the request (1A), the apparatus (110, 300) being also comprised in the network domain (101) and the automated query processing node (120) comprised in a second network domain (102).
10. A non-transitory computer readable medium having stored thereon a set of computer readable instructions that, when executed by at least one processor (310), cause an apparatus (120, 300) to at least:- receive (630), from a node (110) in a network domain (101), a request (1 A) and data, the data identifying an information element or comprising the information element in encrypted form;- process (640) the request (1 A) using an automated query processing routine run by the apparatus (120, 300),- wherein- the request (1A) refers to the information element and the request (1A) refers to a service node (112) in the network domain (101), the apparatus (120, 300) being comprised in a second network domain (102), and the set of computer readable instructions is further configured to cause the apparatus (120, 300) to:- provide (650), as part of the processing of the request (1 A), to the service node (112) an instruction (ID) comprising the data, wherein the request (1A) instructs the automated query processing routine to request a service from the service node (112) in processing the request (1 A), and wherein the set of computer readable instructions are configured to cause the apparatus (120, 300) to responsively request (ID) theservice from the service node (112) as part of the processing (640) of the request, and to provide the data to the service node (112) when requesting the service from the service node (112).