IP Library › Granted Patent US 11,928,250
Granted Patent B2
US 11,928,250 · App. 17/358,332 · Granted Mar 12, 2024

Securing visible data

Inventors: Venkata Vara Prasad Karri (Visakhapatnam, IN); Abhishek Jain (Baraut, IN); Pardeep Singh (Pune, IN); Rakesh Chinhara (Pune, IN)
Assignee: International Business Machines Corporation
G06F21/84G06F21/31G06F21/577G06F21/602G06F2221/2103
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,928,250
App. No.
17/358,332
Granted
Mar 12, 2024
Kind
B2
Abstract

A method, computer system, and a computer program product for securing visible data is provided. The present invention may include encrypting an on-screen data rendered on a display of an endpoint device. The present invention may also include authenticating an external decryption device within a periphery defined by the endpoint device. The present invention may further include decrypting the encrypted on-screen data on the authenticated external decryption device.

Claims (65)

1. A computer-implemented method, comprising:

encrypting an on-screen data for viewing by a primary user, wherein the encrypted on-screen data is rendered on a display of an endpoint device of the primary user based on a security policy set by the primary user;

identifying a second external decryption device within a periphery defined by the endpoint device based on the security policy set by the primary user, wherein the identified second external decryption device is associated with a secondary user;

transmitting a challenge to the identified second external decryption device including a request for a passphrase generated by the primary user of the endpoint device; and

authenticating the identified second external decryption device based on receiving a response from the identified second external decryption device including the passphrase generated by the primary user of the endpoint device; and

decrypting the encrypted on-screen data for viewing by the secondary user using the authenticated identified second external decryption device.

2. The method of claim 1 , wherein encrypting the on-screen data rendered on the display of the endpoint device further comprises:

detecting, using a camera component of the endpoint device, at least one untrusted third-party within a field of view of the display of the endpoint device; and

in response to the detected at least one untrusted third-party, automatically generating the encrypted on-screen data rendered on the display of the endpoint device.

3. The method of claim 1 , further comprising:

detecting, using a camera component of the endpoint device, at least one untrusted third-party within a field of view of the display of the endpoint device; and

dynamically adjusting, using the endpoint device, a size of the periphery to exclude the detected at least one untrusted third-party from within the periphery.

4. The method of claim 1 , further comprising:

identifying a location of the endpoint device to determine whether the endpoint device is in a public space or a private space;

calculating a probability of data theft in the identified location of the endpoint device; and

dynamically adjusting, using the endpoint device, a size of the periphery relative to the endpoint device based on the calculated probability of data theft.

5. The method of claim 1 , wherein encrypting the on-screen data rendered on the display of the endpoint device further comprises:

analyzing a sensitivity level of an application data rendering on the display of the endpoint device; and

in response to determining that the application data rendering on the display of the endpoint device includes at least one sensitive data, automatically encrypting the at least one sensitive data to generate the encrypted on-screen data.

6. The method of claim 1 , further comprising:

identifying, in the passphrase generated by the primary user, an access level limitation associated with the authenticated second external decryption device, wherein the identified access level limitation is set by the primary user; and

limiting access to a decrypted on-screen data for the authenticated second external decryption device based on the identified access level limitation.

7. A computer system for securing visible data, comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage media, and program instructions stored on at least one of the one or more computer-readable tangible storage media for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is capable of performing a method comprising:

encrypting an on-screen data for viewing by a primary user, wherein the encrypted on-screen data is rendered on a display of an endpoint device of the primary user based on a security policy set by the primary user;

identifying a second external decryption device within a periphery defined by the endpoint device based on the security policy set by the primary user, wherein the identified second external decryption device is associated with a secondary user;

transmitting a challenge to the identified second external decryption device including a request for a passphrase generated by the primary user of the endpoint device; and

authenticating the identified second external decryption device based on receiving a response from the identified second external decryption device including the passphrase generated by the primary user of the endpoint device; and

decrypting the encrypted on-screen data for viewing by the secondary user using the authenticated identified second external decryption device.

8. The computer system of claim 7 , wherein encrypting the on-screen data rendered on the display of the endpoint device further comprises:

detecting, using a camera component of the endpoint device, at least one untrusted third-party within a field of view of the display of the endpoint device; and

in response to the detected at least one untrusted third-party, automatically generating the encrypted on-screen data rendered on the display of the endpoint device.

9. The computer system of claim 7 , further comprising:

detecting, using a camera component of the endpoint device, at least one untrusted third-party within a field of view of the display of the endpoint device; and

dynamically adjusting, using the endpoint device, a size of the periphery to exclude the detected at least one untrusted third-party from within the periphery.

10. The computer system of claim 7 , further comprising:

identifying a location of the endpoint device to determine whether the endpoint device is in a public space or a private space;

calculating a probability of data theft in the identified location of the endpoint device; and

dynamically adjusting, using the endpoint device, a size of the periphery relative to the endpoint device based on the calculated probability of data theft.

11. The computer system of claim 7 , wherein encrypting the on-screen data rendered on the display of the endpoint device further comprises:

analyzing a sensitivity level of an application data rendering on the display of the endpoint device; and

in response to determining that the application data rendering on the display of the endpoint device includes at least one sensitive data, automatically encrypting the at least one sensitive data to generate the encrypted on-screen data.

12. The computer system of claim 7 , further comprising:

identifying, in the passphrase generated by the primary user, an access level limitation associated with the authenticated second external decryption device, wherein the identified access level limitation is set by the primary user; and

limiting access to a decrypted on-screen data for the authenticated second external decryption device based on the identified access level limitation.

13. A computer program product for securing visible data, comprising:

one or more computer-readable storage media and program instructions collectively stored on the one or more computer-readable storage media, the program instructions executable by a processor to cause the processor to perform a method comprising:

encrypting an on-screen data for viewing by a primary user, wherein the encrypted on-screen data is rendered on a display of an endpoint device of the primary user based on a security policy set by the primary user;

identifying a second external decryption device within a periphery defined by the endpoint device based on the security policy set by the primary user, wherein the identified second external decryption device is associated with a secondary user;

transmitting a challenge to the identified second external decryption device including a request for a passphrase generated by the primary user of the endpoint device; and

authenticating the identified second external decryption device based on receiving a response from the identified second external decryption device including the passphrase generated by the primary user of the endpoint device; and

decrypting the encrypted on-screen data for viewing by the secondary user using the authenticated identified second external decryption device.

14. The computer program product of claim 13 , wherein encrypting the on-screen data rendered on the display of the endpoint device further comprises:

detecting, using a camera component of the endpoint device, at least one untrusted third-party within a field of view of the display of the endpoint device; and

in response to the detected at least one untrusted third-party, automatically generating the encrypted on-screen data rendered on the display of the endpoint device.

15. The computer program product of claim 13 , further comprising:

detecting, using a camera component of the endpoint device, at least one untrusted third-party within a field of view of the display of the endpoint device; and

dynamically adjusting, using the endpoint device, a size of the periphery to exclude the detected at least one untrusted third-party from within the periphery.

16. The computer program product of claim 13 , further comprising:

identifying a location of the endpoint device to determine whether the endpoint device is in a public space or a private space;

calculating a probability of data theft in the identified location of the endpoint device; and

dynamically adjusting, using the endpoint device, a size of the periphery relative to the endpoint device based on the calculated probability of data theft.

17. The computer program product of claim 13 , wherein encrypting the on-screen data rendered on the display of the endpoint device further comprises:

analyzing a sensitivity level of an application data rendering on the display of the endpoint device; and

in response to determining that the application data rendering on the display of the endpoint device includes at least one sensitive data, automatically encrypting the at least one sensitive data to generate the encrypted on-screen data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2021
From: JAIN, ABHISHEK; SINGH, PARDEEP; CHINHARA, RAKESH
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 056667/0479 →
Continuity (1)
Related Publication 20220414272A1 · Dec 29, 2022