Permission-Based Video Stream Redaction for Secure Screen Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing video sharing technologies lack the sophistication to automatically hide sensitive data from specific participants, making it difficult to secure screen sharing during presentations or video calls.

Innovation Solution

A method and system for classifying sensitive data in video streams into permission categories, providing sub-streams for different viewer categories, and redacting the original stream based on access permissions to create a combined stream for each endpoint.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual precautions are taken for data security during screen sharing, then user control over security is maintained, but security breaches can still occur due to human error

Engineering Contradiction:
Improvedata securityVSAvoidmanual security management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically classifies sensitive data components and manages security permissions without requiring manual user intervention. The classification system self-identifies sensitive information and applies appropriate security measures, eliminating human error in security management while maintaining reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual security management mechanisms with an automated computer-based classification and permission management system. The system uses automated data component classification and permission category assignment to substitute human-operated security controls, improving both reliability and ease of operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If all data components are shared in video streams, then complete information is transmitted, but sensitive information is exposed to unauthorized participants

Engineering Contradiction:
Improveinformation completenessVSAvoidinformation exposure
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system segments video stream data into distinct data components and classifies them by sensitivity. Each data component is assigned to a permission category, allowing selective sharing based on participant authorization. This segmentation enables complete information transmission to authorized users while protecting sensitive information from unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different data components within the video stream. Sensitive data components receive higher security protection with restricted access, while non-sensitive components are freely shared. This local quality differentiation allows complete information flow to authorized participants while preventing information exposure to unauthorized ones.

Inventive Principle:
Principle #3Local quality

3Reliability

If existing technology hides password fields, then basic security is improved, but sophisticated sensitive data classification and selective sharing is not achieved

Engineering Contradiction:
Improvebasic securityVSAvoidsensitive data classification capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts security measures based on the classification of each data component and the permission categories of participants. Rather than static password field hiding, the system flexibly applies security measures that adapt to different data types, participants, and contexts, achieving both basic security and sophisticated classification capability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal security system that handles multiple types of sensitive data across various permission categories. The classification system is versatile enough to manage different data components (not just passwords) and apply appropriate security measures based on participant authorization, achieving both basic and advanced security functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12356028B2Redacting information in video streams
Publication Date: 2025.07.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12356028B2 patent drawing
  • US12356028B2 patent drawing
  • US12356028B2 patent drawing

AI summary

A method, computer program product, and computer system for redacting information in a video stream. The method includes accessing content of an original video stream and classifying sensitive data within the original video stream as classified data components of one or more of multiple permission categories. The method provides sub-streams of the classified data components for one or more permission categories. The method redacts the classified data components in the original video stream and combines the redacted video stream with one or more of the sub-streams to output a combined video stream depending on the access permissions of an endpoint.