Screen Sharing Data Privacy Masking via Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current screen sharing technologies in Web conferences fail to ensure data privacy, as they transmit images of display screens without regard to access rights, potentially sharing confidential information with all attendees, thereby circumventing access control rules.

Innovation Solution

A method and system that select a third-party application for screen sharing, query access control interfaces for attendees, identify protected data fields, and mask them for attendees prohibited from viewing, while displaying the rest of the screen, using access control rules based on attendee credentials and organizational affiliations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If screen sharing transmits images of display screens to all attendees, then the illusion of live display is maintained and all content is visible, but access control rules are circumvented and confidential information is shared with unauthorized attendees

Engineering Contradiction:
Improveaccess control enforcementVSAvoidscreen sharing system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer between the screen sharing system and the display screen. This intermediary queries access control rules before transmitting images to attendees, acting as a mediator that filters content based on user authorization. The intermediary receives the display screen image, checks access control data, and only transmits the image to attendees who are authorized to view it, thereby preventing unauthorized access while maintaining the screen sharing functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If continuous images are generated and transmitted to maintain live display illusion, then viewing experience is improved, but processing time and computational resources are consumed

Engineering Contradiction:
Improvelive display viewing experienceVSAvoidimage processing and transmission time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

Instead of continuously generating and transmitting complete images to all attendees, the system applies partial action by selectively processing and transmitting only the images to authorized attendees. The system generates images continuously to maintain the live display illusion but only transmits them when access control rules permit, reducing unnecessary processing time and computational resources for unauthorized users while preserving the viewing experience for authorized users.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If access control rules are applied to screen shared content, then data privacy is protected, but the screen sharing functionality is restricted and not all attendees can view all content

Engineering Contradiction:
Improveconfidential information exposureVSAvoidscreen sharing accessibility
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by differentiating the treatment of different attendees based on their access control status. The system maintains uniform screen sharing functionality for authorized attendees while applying selective restrictions for unauthorized attendees. The access control rules are applied locally to each attendee's received image, allowing authorized users to view complete content while restricting unauthorized users from viewing sensitive information, thus preserving overall screen sharing versatility while protecting data privacy.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11616814B2Data privacy in screen sharing during a web conference
Publication Date: 2023.03.28 THINKRITE INC
  • US11616814B2 patent drawing
  • US11616814B2 patent drawing

AI summary

Data privacy in screen sharing during Web conferencing includes selecting a third-party application executing in contemporaneously with a conferencing application. Screen sharing is activated during a Web conference in the conferencing application so as to share a display screen of the third-party application with different attendee computers over a computer communications network. An interface to the application is then queried with the attendees in order to receive access control data for the attendees. Then, a protected data field is identified in the display screen and determined whether one of the attendee computers is associated with one of several access control rules based upon the access control data that prohibits display of content in the protected data field. The data field is masked in the shared display screen for the one of the attendee computers while displaying remaining portions of the shared display screen in the one of the attendee computers.