IP Library Granted Patent US 9,438,629
Granted Patent B2
US 9,438,629 · App. 14/362,169 · Granted Sep 6, 2016

Sensitive information leakage prevention system, sensitive information leakage prevention method, and computer-readable recording medium

Inventor: Hiroaki Takeyasu (Tokyo, JP)
Assignee: NEC SOLUTION INNOVATORS, LTD.
H04L63/20H04L9/3271H04L63/0209H04L63/0245H04L63/08H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,438,629
App. No.
14/362,169
Granted
Sep 6, 2016
Kind
B2
Abstract

A client device ( 100 ) determines whether or not access is allowed, based on security levels that are set for an application program and data held in a server device ( 200 ), and performs authentication with the server device ( 200 ) based on a challenge code generated using packet data from the application program. The server device ( 200 ), when the challenge code is transmitted thereto, transmits a preset response code to the client device ( 100 ), and permits access by the client device ( 100 ) if the server device ( 200 ) receives a set response to the response code from the client device ( 100 ).

Claims (42)

1. A sensitive information leakage prevention system for preventing leakage of sensitive information between a client device and a server device, comprising:

a client device realized by a computer and configured to execute an application program; and

a server device realized by a computer and configured to hold data to be used by the application program,

wherein a processor of the client device the client device determines whether or not access by the application program is allowed, based on a security level that is set for the application program and a security level that is provided to data held in the server device, and transmits, if it is determined that access is allowed, a challenge code that is generated using packet data from the application program to the server device and requests authentication, and

a processor of the server device transmits, when the challenge code is transmitted thereto, a preset response code to the client device, determines that authentication is successful if the server device receives a set response to the response code from the client device, and thereafter permits access by the client device,

wherein the client device assigns a label that indicates a preset security level to each of a plurality of application programs including the application program,

wherein the client device monitors network access by the application programs, and upon network access by an application program having begun, determines s allowed in accordance the label assigned to the application program and a label of an access destination folder,

wherein the server devices performs authentication processing with the client device in which access control is performed in accordance with the labels,

and wherein the server device performs no authentication processing with the client device in which access control cannot be performed in accordance with the client device, such that all network communication is prohibited.

2. The sensitive information leakage prevention system according to claim 1 ,

wherein the server device transmits the response code if the transmitted challenge code satisfies a set condition, and thereafter determines that authentication is successful when the same code as the challenge code is received from the client device.

3. The sensitive information leakage prevention system according to claim 2 ,

wherein the server device causes the client device to transmit a challenge code with a different content multiple times, and permits access by the client device if it is determined that authentication is successful for each challenge code.

4. The sensitive information leakage prevention system according to claim 1 ,

wherein the server device registers a client device whose access is permitted in a list, and rejects access by a client device that is not registered in the list.

5. The sensitive information leakage prevention system according to claim 4 ,

wherein the server device sets a time period during which access is permitted when access by the client device is permitted, registers the set time period in the list, and thereafter does not permit access by the client device after the time period has elapsed.

6. The sensitive information leakage prevention system according to claim 1 ,

wherein both the client device and the server device have a common key,

the client device transmits the challenge code that has been encrypted with the common key, and

the server device transmits the response code that has been encrypted with the common key.

7. A method for preventing leakage of sensitive information between a client device that executes an application program and a server device that holds data to be used by the application program, the method comprising:

a step (a) of the client device determining whether or not access by the application program is allowed, based on a security level that is set for the application program and a security level that is provided to the data held in the server device;

a step (b) of the client device transmitting, if it is determined that access is allowed, a challenge code that is generated using packet data from the application program to the server device and requesting authentication;

a step (c) of the server device transmitting, when the challenge code is transmitted thereto, a preset response code to the client device, and determining that authentication is successful if a set response to the response code is received from the client device; and

a step (d) of the server device permitting access by the client device if it is determined that authentication is successful,

wherein a processor of the client device performs steps (a) and (b), and a processor of the server device perform steps (c) and (d),

wherein the client device assigns a label that indicates a preset security level to each of a plurality of application programs including the application program,

wherein the client device monitors network access by the application programs, and upon network access by an application program having begun, determines s allowed in accordance the label assigned to the application program and a label of an access destination folder,

wherein the server devices performs authentication processing with the client device in which access control is performed in accordance with the labels,

and wherein the server device performs no authentication processing with the client device in which access control cannot be performed in accordance with the client device, such that all network communication is prohibited.

8. A non-transitory computer-readable recording medium storing a program for accessing, by a computer, data held in a server device, the program containing a command for causing the computer to execute:

a step (a) of determining whether or not access by the application program is allowed, based on a security level that is set for the application program used in the computer and a security level that is provided to the data held in the server device; and

a step (b) of transmitting, if it is determined in the step (a) that access is allowed, a challenge code that is generated using packet data from the application program to the server device and requesting authentication.

9. A non-transitory computer-readable recording medium storing a program for determining, by a computer, whether or not a client device is allowed to access data to be used by an application program that is executed by the client device, the program containing a command for causing the computer to execute:

a step (a) of transmitting a preset response code to the client device if a challenge code that is generated using packet data from the application program is transmitted for requesting authentication from the client device;

a step (b) of determining that authentication is successful if a set response to the response code is received from the client device after the step (a) is executed; and

a step (c) of permitting access by the client device if it is determined in the step (b) that authentication is successful,

wherein the client device assigns a label that indicates a preset security level to each of a plurality of application programs including the application pro rg am,

wherein the client device monitors network access by the application programs, and upon network access by an application program having begun, determines s allowed in accordance the label assigned to the application program and a label of an access destination folder,

wherein the server devices performs authentication processing with the client device in which access control is performed in accordance with the labels,

and wherein the server device performs no authentication processing with the client device in which access control cannot be performed in accordance with the client device, such that all network communication is prohibited.

Assignments (2)
MERGER AND CHANGE OF NAME Recorded Jul 10, 2014
From: NEC SYSTEM TECHNOLOGIES, LTD.; NEC SOFT, LTD.
To: NEC SOLUTION INNOVATORS, LTD.
Reel/Frame 033285/0512 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2014
From: TAKEYASU, HIROAKI
To: NEC SOLUTION INNOVATORS, LTD.
Reel/Frame 033007/0781 →
Priority Claims (1)
JP 2011-263621 · Dec 1, 2011 · national
Continuity (1)
Related Publication 20140325684A1 · Oct 30, 2014