Document sharing protection with watermark
Provided is a computing system for protection against document sharing. The computing system includes a processor having associated memory, the processor being configured to execute instructions using portions of the memory to cause the processor to implement a compliance portal where a policy is established covering a plurality of documents, transmit the policy to a client device having a display screen, and in response to receiving an indication that the client device has triggered the policy, instruct the client device to modify a graphics pipeline to add an opaque watermark to a screen image displayed on the display screen.
1 . A computing system for protection against unauthorized document sharing, comprising:
a server computing device including a processor having associated memory, the processor being configured to execute instructions using portions of the memory to cause the server computing device to:
implement a data leak prevention compliance portal where a policy is established covering a plurality of documents;
transmit the policy to a client device having an associated display screen, wherein the policy, in response to being triggered at the client device, causes the client device to modify a graphics pipeline by a windows manager of the client device at an operating system (OS) level to add an opaque watermark to a screen image displayed on the display screen;
receive a camera-captured image of the display screen including at least a portion of the watermark; and
decode secure information from the watermark.
2 . The computing system of claim 1 , wherein the secure information is encoded in the watermark as a hash value.
3 . The computing system of claim 2 , wherein the server computing device is further configured to:
receive the secure information and the hash value corresponding to the secure information once the client device has triggered the policy;
store the secure information and hash value; and
in response to a query including the hash value that is decoded from the watermark, retrieve the secure information.
4 . The computing system of claim 1 , wherein the secure information is encoded in a graphical pattern of the watermark.
5 . The computing system of claim 4 , wherein the graphical pattern illustrates a binary code using at least one of dots and dashes.
6 . The computing system of claim 1 , wherein the secure information includes at least one of a document file name, a document file type, a document file path, a timestamp, and a device and/or user identifier of the client device.
7 . The computing system of claim 1 , wherein the policy is further configured to cause the client device to divide the screen image into a plurality of regions and display the watermark in each of the plurality of regions.
8 . The computing system of claim 7 , wherein each of the plurality of regions is divided into a plurality of blocks including an anchor block indicating a start or a stop of a graphical pattern of the watermark.
9 . The computing system of claim 7 , wherein each block encodes 1 bit of data in a graphical pattern such that the graphical pattern of one region formed of the plurality of blocks encodes a plurality of bits of data.
10 . The computing system of claim 1 , wherein the screen image is a final rendered screen image displayed by the entire display screen.
11 . A method for protection against unauthorized document sharing, comprising:
at a server computing device:
implementing a data leak prevention compliance portal where a policy is established covering a plurality of documents; and
transmitting the policy to a client device having an associated display screen, wherein the policy, in response to being triggered at the client device, causes the client device to modify a graphics pipeline by a windows manager of the client device at an operating system (OS) level to add an opaque watermark to a screen image displayed on the display screen;
receiving a camera-captured image of the display screen including at least a portion of the watermark; and
decoding secure information from the watermark.
12 . The method of claim 11 , wherein the secure information is encoded in the watermark as a hash value.
13 . The method of claim 12 , further comprising, at the server computing device:
receiving the secure information and the hash value corresponding to the secure information once the client device has triggered the policy;
storing the secure information and hash value; and
in response to a query including the hash value that is decoded from the watermark, retrieving the secure information.
14 . The method of claim 11 , wherein the secure information is encoded in a graphical pattern of the watermark.
15 . The method of claim 14 , wherein the graphical pattern illustrates a binary code using at least one of dots and dashes.
16 . The method of claim 11 , wherein the secure information includes at least one of a document file name, a document file type, a document file path, a timestamp, and a device and/or user identifier of the client device.
17 . The method of claim 11 , wherein the policy is further configured to cause the client device to divide the screen image into a plurality of regions and display the watermark in each of the plurality of regions.
18 . The method of claim 17 , wherein each of the plurality of regions is divided into a plurality of blocks including an anchor block indicating a start or a stop of a graphical pattern of the watermark.
19 . The method of claim 11 , wherein the screen image is a final rendered screen image displayed by the entire display screen.
20 . A computing system for protection against unauthorized document sharing, comprising:
a server computing device including a processor having associated memory, the processor being configured to execute instructions using portions of the memory to cause the server computing device to:
implement a data leak prevention compliance portal where a policy is established covering a plurality of documents; and
transmit the policy to a client device having an associated display screen, wherein the policy, in response to being triggered at the client device, causes the client device to:
divide a screen image displayed on the display screen into a plurality of regions;
modify a graphics pipeline by a windows manager of the client device at an operating system (OS) level to add a watermark to be displayed in each of the plurality of regions; and
divide each of the plurality of regions into a plurality of blocks each including an anchor block indicating a start or a stop of a graphical pattern of the watermark;
receive a camera-captured image of the display screen including at least a portion of the watermark; and
decode secure information from the watermark.