Automatic protection of partial document content
Protecting a fragment of a document includes automatically detecting the fragment without user intervention based on the content of the fragment and/or the context of the fragment within a set of documents, selectively encrypting the fragment to prevent unauthorized access, and providing an alternative view of the fragment that prevents viewing and access of content corresponding to the fragment unless a decryption password is provided. Automatically detecting the fragment may include detecting numbers and alphanumeric sequences of sufficient length that do not represent commonly known abbreviations, detecting generic terms, detecting proper names, detecting terms signifying a type of content, detecting mutual location of terms and sensitive content, and/or detecting user defined terms. The generic terms may correspond to password, passcode, credentials, user name, account, ID, login, confidential, and/or sensitive. The proper names may be names of financial organizations and security organizations.
1. A method of protecting a document, comprising:
identifying a plurality of hints in the document based on a dictionary of content sensitivity hints, wherein the dictionary is compiled from a plurality of sources and includes a plurality of hint types that corresponds to a plurality of predefined routines, wherein the plurality of hint types includes at least generic terms associated with one or more of information security, terms signifying special types of content, proper names associated with sensitive content, custom terms added by a user, and specific terms that are subject to encryption every time they appear; and
for each of the plurality of hints, automatically and without user intervention:
determining a respective hint type and a respective predefined routine corresponding to the respective hint type;
in accordance with the respective predefined routine, detecting a respective fragment of the document for possible encryption based on at least one of: content of the respective fragment and context of the respective fragment within the document;
encrypting the respective fragment using at least one decryption password required for decrypting and visualizing original content of the respective fragment; and
enabling display of the respective fragment according to a respective one of a plurality of view options.
2. The method of claim 1 , further comprising:
in accordance with a determination that the at least one decryption password is provided, displaying fragments associated with at least a subset of the plurality of hints without encryption.
3. The method of claim 2 , wherein the fragments associated with at least a subset of the plurality of hints are displayed without encryption temporarily until another document is selected for display.
4. The method of claim 1 , wherein a first hint is a first generic term associated with information security and corresponds to a first routine, and detecting the respective fragment for the first hint in accordance with the first routine further comprises:
identifying, as the respective fragment, a short separate line of text that follows the first hint and does not form a grammatically correct sentence.
5. The method of claim 4 , wherein the first hint is one of “user name,” “password,” “account ID,” and “login”.
6. The method of claim 1 , wherein a second hint is a term signifying a special type of content and corresponds to a second routine, and detecting the respective fragment for the second hint in accordance with the second routine further comprises:
identifying the second hint combined with a location defining word; and
identifying, as the respective fragment, content following the location defining word, the content having a format associated with the special type of content.
7. The method of claim 6 , wherein the content includes one of an image, a formula and a chart.
8. The method of claim 1 , wherein a third hint is a proper name associated with sensitive content, and includes one or more names of banks, financial organizations, and security organizations.
9. The method of claim 1 , wherein a fourth hint is one of a plurality of specific terms that are subject to encryption every time they appear, and corresponds to one of sensitive projects, technical names or denotations, milestones dates, schedules, and events.
10. The method of claim 1 , further comprising:
modifying at least one of the plurality of predefined routines based on content of the document.
11. The method of claim 1 , further comprising:
receiving a user input of the at least one decryption password.
12. A computer system, comprising:
one or more processors; and
memory having instructions stored thereon, which when executed by the one or more processors cause the processors to perform operations comprising:
identifying a plurality of hints in a document based on a dictionary of content sensitivity hints, wherein the dictionary is compiled from a plurality of sources and includes a plurality of hint types that corresponds to a plurality of predefined routines, wherein the plurality of hint types includes at least generic terms associated with one or more of information security, terms signifying special types of content, proper names associated with sensitive content, custom terms added by a user, and specific terms that are subject to encryption every time they appear; and
for each of the plurality of hints, automatically and without user intervention:
determining a respective hint type and a respective predefined routine corresponding to the respective hint type;
in accordance with the respective predefined routine, detecting a respective fragment of the document for possible encryption based on at least one of: content of the respective fragment and context of the respective fragment within the document;
encrypting the respective fragment using at least one decryption password required for decrypting and visualizing original content of the respective fragment; and
enabling display of the respective fragment according to a respective one of a plurality of view options.
13. The computer system of claim 12 , wherein a subset of the fragments associated with the plurality of hints is located at two distinct portions of the document, each portion having a distinct decryption password, and each fragment in the subset is encrypted using the distinct decryption password of a corresponding one of the two distinct portions at which the respective fragment is located.
14. The computer system of claim 12 , wherein:
the plurality of view options includes at least an obfuscated view, a collapsed view, and a completely hidden view;
the obfuscated view is at least one of: blurred, pixelated, filled with a solid color, filled with a regular geometric pattern, and filled with an irregular geometric pattern;
the collapsed view is configured to replace the respective fragment with one or more characters; and
the completely hidden view is configured to cause the respective fragment to be removed from a display of the document.
15. The computer system of claim 12 , wherein the plurality of hints includes a first hint, and the memory further stores instructions for:
for the first hint, enabling display of a partial protection user interface for approving and editing of the respective fragment, wherein the partial protection user interface is configured to select the respective fragment for encryption, display the plurality of view options, receive a user selection of the respective one of the plurality of view options, and receive a user input of the at least one decryption password.
16. A non-transitory computer-readable medium, having instructions stored thereon, which when executed by one or more processors cause the processors to perform operations comprising:
identifying a plurality of hints in a document based on a dictionary of content sensitivity hints, wherein the dictionary is compiled from a plurality of sources and includes a plurality of hint types that corresponds to a plurality of predefined routines, wherein the plurality of hint types includes at least generic terms associated with one or more of information security, terms signifying special types of content, proper names associated with sensitive content, custom terms added by a user, and specific terms that are subject to encryption every time they appear; and
for each of the plurality of hints, automatically and without user intervention:
determining a respective hint type and a respective predefined routine corresponding to the respective hint type;
in accordance with the respective predefined routine, detecting a respective fragment of the document for possible encryption based on at least one of: content of the respective fragment and context of the respective fragment within the document;
encrypting the respective fragment using at least one decryption password required for decrypting and visualizing original content of the respective fragment; and
enabling display of the respective fragment according to a respective one of a plurality of view options.
17. The non-transitory computer-readable medium of claim 16 , wherein the operations are implemented by a content management system, and the document includes a note in the content management system.
18. The non-transitory computer-readable medium of claim 17 , wherein the content management system is cloud based, and shares content across a plurality of client devices of a user.
19. The non-transitory computer-readable medium of claim 16 , wherein the plurality of view options is provided on a mobile device, and the mobile device is one of a mobile phone, a tablet and a laptop computer.