Content Approval Apparatus Using Hash Data for Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies cannot prevent intentional information leakage, as they do not manage which contents are permitted to be taken out, allowing encrypted information to be decrypted and shared with unauthorized parties, and mail filtering technologies struggle to determine if sensitive information is being transmitted.

Innovation Solution

A content approving apparatus that generates and manages 'taking-out-permitted-content identification data' to determine whether content is allowed to be transmitted, using a system that includes a storage means for this data and a generating means to create it, ensuring only permitted content is shared.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption technology is used to protect information, then information security is improved, but intentional information leakage cannot be prevented

Engineering Contradiction:
Improveinformation securityVSAvoidintentional information leakage
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary registration of content identification data (such as hash values) for all content permitted to be taken out before the actual content transfer occurs. This preliminary action creates a reference database that enables automatic approval or rejection of content transfer requests without requiring decryption or manual review, thus preventing intentional information leakage while maintaining information security.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If mail filtering technology is used to detect sensitive information, then transmission control is improved, but it cannot determine if encrypted sensitive information is being transmitted

Engineering Contradiction:
Improvetransmission controlVSAvoidencrypted sensitive information transmission
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

Instead of attempting to decrypt and analyze the actual content of emails or attachments, the system uses copying of content identification data (hash values) to determine whether sensitive information is being transmitted. The filtering apparatus compares the hash value of the content to be transmitted against registered hash values of permitted content, enabling effective filtering without compromising encryption.

Inventive Principle:
Principle #26Copying

3Reliability

If content approval management is implemented, then information leakage prevention is improved, but system complexity increases

Engineering Contradiction:
Improveinformation leakage preventionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential identifying features of content (such as hash values or metadata) and stores them separately from the actual content. This extraction approach allows the approval management system to operate on lightweight identification data rather than complex content analysis, reducing system complexity while maintaining effective information leakage prevention.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8271756B2Content approving apparatus
Publication Date: 2012.09.18 HITACHI SOFTWARE ENG
  • US8271756B2 patent drawing
  • US8271756B2 patent drawing
  • US8271756B2 patent drawing

AI summary

The present invention aims to provide an apparatus capable of determining whether or not content is permitted to be taken out, by managing contents permitted to be taken out. One aspect of the invention is characterized by comprising: a storage means that stores therein taking-out-permitted-content identification data which is data generated on the basis of a part or entirety of each content permitted to be taken out; and a generating means that generates the taking-out-permitted-content identification data. Another aspect of the present invention is characterized by comprising: a storage means that stores therein taking-out-permitted-content identification data which is data generated on the basis of a part or entirety of each content permitted to be taken out to the outside; and an approving means that determines whether a content is permitted to be taken out, with reference to the taking-out-permitted-content identification data.