WO2020060542A1 - System and method for securely accessing, manipulating and controlling documents and devices using natural language processing - Google Patents
System and method for securely accessing, manipulating and controlling documents and devices using natural language processing Download PDFInfo
- Publication number
- WO2020060542A1 WO2020060542A1 PCT/US2018/051648 US2018051648W WO2020060542A1 WO 2020060542 A1 WO2020060542 A1 WO 2020060542A1 US 2018051648 W US2018051648 W US 2018051648W WO 2020060542 A1 WO2020060542 A1 WO 2020060542A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- user
- transaction
- electronic device
- data
- smart box
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0894—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
- H04L9/3231—Biological data, e.g. fingerprint, voice or retina
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3234—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3236—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
- H04L9/3239—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving non-keyed hash functions, e.g. modification detection codes [MDCs], MD5, SHA or RIPEMD
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q30/00—Commerce
Definitions
- the present invention is direction to 3 ⁇ 4 system and method tor securely accessing, manipulating and controlling documents and devices using natural language processing.
- Electronic devices tend to be designed and configured for a particular purpose or function. While electronic devices may be multi-function devices e.g., a multi-function printer, or a smart phone that can make phone calls, take pictures and play music, the tunetipnfs) are typically pre-programmed, and a user of the device is limited to these pre-programmed functions. However, because an electronic device is pre-programmed for a particular function or functions does not mean those are the onl functions the device Is capable of performing. To the contrary;, many electronic devices are capable of performing functions for which they are not programmed.
- multi-function devices e.g., a multi-function printer, or a smart phone that can make phone calls, take pictures and play music, the tunetipnfs
- an electronic device is pre-programmed for a particular function or functions does not mean those are the onl functions the device Is capable of performing. To the contrary;, many electronic devices are capable of performing functions for which they are not programmed.
- a user is limited to the pre-programmed and available functions of an electronic device unless the user pays to upgrade the device to enhance and/or expan its functionality it is currently not possible fora user, in real-time, to use a personal electronic device like a smartphone to access and control a target electronic device in a way that changes the function or functionality of the target device
- a multi-function printer GMRR a multi-function printer GMRR
- this device is configured to perform certain functions, e.g., print, scan, copy, email, it is also able to perform functions beyond these.
- a typical MFP is capable of scanning a document and sendin it via email by accessing an address book stored in the MFP provided that the user is in front of the MFP and directly controlling it.
- an MFP email documents using its own address book an only using documents it scans.
- an MFP has on-board intelligence beyon what is necessary to control the core junctions of the printer.
- MFPs have networking functionality, enhab!ing direct or wireless connection to a network, and authorization functionality to prevent unauthorized use of or access to the MFP, as two examples.
- the present invention is directed to solving tile technical problem of providing seeuritx for an electronic device, system, document, etc that is accessible and controllable by a user with a user electronic device.
- the phrase“electronic device” is used to describe any of a singular electronic device, or one or more electronic devices connected or connectable via any means that can communicate with each other. This phrase is further used in an expansive way, intende to encompass any type of known or hereafter-developed electronic device usable in connection with, or suitable for carrying out all or part off the present invention.
- An embodiment of the present invention is directed to a. system configured to secure a transaction between a user and an electronic device or an electronic document.
- the transaction is initiated using a user electronic device, and the electronic device is connectable to a network and the electronic document is accessible over the network.
- the system comprises a smart box connectable to the network and having a processor and memory havin stored therein general purpose software, and having storable therein smart box special purpose software, :
- the system further comprises a user device control installable on the user electronic device, wherein the user device control enables a user of the user electronic device to initiate the transaction.
- the system still further comprises a hot storable in memory of the smart box, configured to collect data for the transaction, and pertaining to at least one of the user, a process or the transaction.
- a system further comprises a user account file associated with the user and stored In memory of a server, the user account file containing at least one user permission, wherein the hot is configured to collect data corresponding to the at least one user permission, and to provide the data to the server, wherein a processor of the server is configured to determine whether to allow or deny the transaction by comparing the data with the at least one user permission.
- the smart box processor is further configured to cause the hot to transmit the data to a server having a processor and server special purpose software, and wherein the server special purpose software is configured to cause the server processor to determine, from the data, whether the transaction is an anomaly, an tocause the smart box processor to deny the transaction when the transaction is an anomaly.
- the smart box processor is further configured to cause the bot to transmit the data to a server having a processor an server special purpose software, and wherein the server special purpose software is configured to cause the server processor to determine, from the data, whether the transaction is an anomaly, and to cause the smart box processor to allow the transaction when the transaction is an anomaly
- the server special purpose software is further configured to cause the server processor to cause the smart box processor to allow only the transaction when the transaction is an anomaly.
- the smart box processor is further configured to cause the bot to transmit the data to a server having a processor and server special purpose software and wherein the server special purpose software is configured t cause the server processor to determine, from the data, whether the transaction is an anomaly, to notify an administrator when the transaction is an anomaly, to receive an instruction from the administrator, and to cause the smart box processor to carry-out the instruction.
- the transaction comprises at least of one of accessing, controlling or manipulating the electronic device or electronic document.
- the transaction comprises causing the electronic device to execute a command.
- the transaction comprises executing command on the electronic device. 10020 ⁇
- the electronic device is a multi-function printer ( MFP), and. wherein the smart box is connectable to the MFP as a super-user
- the hot comprises machine-executable instructions that, when executed, cause the smart box processor to collect data about the transaction that may he used by the smart box processor to access, manipulate or control an electronic de vice or electronic document
- a system further comprises an application programming interface (“AR ) on a cloud-based server configured to receive dat from the hot and determine whether the transaction is an anomaly
- AR application programming interface
- the API provides bloekehain functionality to create a cryptographic structure and to verify a data unit.
- the verified data unit is for the transaction.
- Another embodiment of the present inventio is directed to a method for securing a transaction between a user and an electronic device or an electronic document.
- the transaction is initiated using a user electronic device, the electronic device is connectable to a network, and the electronic document is accessible over the network.
- the method is performed by at least one processor operable by machine-readable instructions,
- the metho comprises the step of providing a smart box connectable to the network, the smart box having a central processing unit comprising a processor and memory having stored therein general purpose software, and having storable therein a hot and smart box special purpose software.
- the smart box special purpose software i configured for receiving a request to authenticate the user using biometric data of the user, receiving a command to control an electronic device or access an electronic document, receiving a determination of whether the transaction is an anomaly, and allowing or denying the transaction based upon the determination of whether the transaction is an anomaly.
- the hot is at least one of user-centric, process-centric or transaction-centric, and is configured for collecting data for the transaction and transmittin the data to a cloud-based server.
- the bot is a user- centric hot, and further configured to activate in response to a req uest to authenticate from a specific user.
- the bot is a process-centric hot, arid further configured to activate in response to a request to carry-out a specific process
- the bot is a transaction-centric bot, and further configured to activate in response to initiation of a transaction request by a user,
- the step of receiving a request to authenticate the user using biometric data of the user further comprises recei ving an audio signal from an audio input device of the user electronic device or proxima te the electronic device.
- the smart box special purpose software is further configured for providing an application programming interface (“APT”) to a cloud-based server, wherein the API is configured to receive data froth the bot and determine whether the transaction is an anomaly
- API application programming interface
- the API provides: blockehaih functionality to create a cryptographic unit from the received data, and to verify the data.
- the data is tor the transaction.
- the smart box special purpose software is further configured for receiving an instruction to allow the transaction when the transaction is an anomaly
- the instruction is only for the transaction
- the present invention introduces a paradigm shift in the way electronic devices are accessed and controlled by creating a user-centric environment that transfers control over the function and functionality of a target electronic device from the device itself (he., a device-centric environment) to a user electronic device (he., a user-centric environment).
- a target electronic device he.g., a device-centric environment
- a user electronic device he.g., a user-centric environment
- the prior art teaches rudimentary access to and control of an electronic device from user electronic device (e.gcken controlling your thermostat from your mobile phone)
- embodiments of the present invention enable a user to not only control the electronic device, but to add functionality, change functionality, or otherwise modify the operation of foe electronic device.
- Such an innovative and unconventional technologi cal solution to the techno logical problem o ⁇ controlling electronic devi ces and systems is not foun in the prior art.
- foe user-centrieity created by foe present invention places, in each uni ue user’s hands, the ability to effect such control over a target electronic device in accordance with that unique users needs or desires.
- the present invention eliminates user learning curves for new devices, integration issue associated with adding/replacing devices, and restrictions o available functionality from pre- eonfigured devices
- embodiments of the present invention are tied to a specific structure, connection and arrangement of components, purposefully structured, connected and arrange to achieve an inventive technological solution to a technological problem specific to electronic devices and systems - the inability of a user to control the function: and functionality of such devices and, systems.
- the prior art representing a device-centric environment restricts control of electronic devices and systems to either authorized entities (e.g , manufacturers, service personnel, etc ), users in proximity, or users with only access and control limited to the pre -configuration of the device
- the present invention creates it user-centric environment: that enables user to each independently an separately control not only the function but. also the functionality of electronic devices and systems.
- an intelligence aspect of electronic devices and systems is relocated from the device itself to an edge of a network within which the devices and systems operate - one such edge being defined from the perspective of each unique user’s electronic device looking inward into the network - thus creating a user-centric network architecture and environment That intelligence aspect is control over the function and functionality of the devices and systems which, in accordance with embodiments of the present invention, is now in the hands of each user.
- Embodiments of the present invention also provide a method and system for securing a user-initiated transaction carried-out by an electronic device, and/or carried out by and/or on an electronic document to address shortcomings associated with ensuring security when accessing, manipulating, and/or controlling an electronic device and/or electronic document using natural language processing.
- the present invention provides universality in its solution to the problems with the prior art discussed above. More specifically, the present invention advantageously recognizes that a user of a smartphone, for example, does not encounter a learning curve when additional features are added to the smartphone, or when the smartphone is used in a new way, as with the present invention. Rather, the introduction of new features and functionality to the user via the ⁇ user’s smartphone is relatively seamless. Thus, the present invention enables a user to change the function and/or functionality of a target electronic device without having to learn how to use that device to perform the new/ehanged function.
- the present invention also advantageously provides un versality across controllable electronic devices. Regardless of the type of device, or of the manufacturer of a device type (e,g., HP, Dell, Canon, etc, for MFPs) to he accessed and controlled, the present invention enables a user electronic device to access and control an electronic device by separating the user interface from the target electronic device and placing it with the user on a platform with which the user is familiar.
- the present invention thus makes its technology ftictionless, as the user need not care or kno about the type of electronic device being accessed or controlled to realize the advantages of the present invention.
- the present invention also advantageously extends a periphery about an electronic device from in-iaet proximity to the device, to a smart box connectable to the electronic device overa network, and to a user electronic device.
- the present invention not only places access to and control over electronic devices to which the user desires to connect or interact in the user's hand, the present invention further makes such access and control user-centric.
- the present invention introduces a paradigm shift from a device-centric world to a riser-centric world with respect to accessing and controlling electronic devices m a way that enables the user to change the function or functionality of the device.
- a user could access and control an electronic device, but the control was limited to the functions and functionality pre-programmed into the electronic device.
- a user under the new user-centric paradigm, a user ⁇ an change and/or ad foneticmality to a target electronic device. What an electronic device is able to do is no longer limited to bow it was programmed. Rather, the present invention places control of the functionality of an electronic device in the bands of a user, creating a user-centric, edge-based intelligence in a network.
- voice recognition technology ⁇ may be used to cause a target electronic device to respond to voice commands when the target device is not configured for voice activation.
- a target electronic device can utilize 2-factor authentication such as, by way of illustration and not limitation, biometric authentication ; by ittilizing functionality native to user electronic device and by causing, by virtue of the present invention, the target electronic device to employ 2-factor authentication.
- the present invention leverages the nativity of a function (e.g., 2-factor biometric authentication) on the user electronic device to enable the MFP (i.e., the target electronic device) to respon as if the function is native to the MFP
- a function e.g., 2-factor biometric authentication
- intelligent usage and management of a target electronic de vice is possible through access to, an collection and analysi of usage data already collected b the target device. Prior to the present invention, such data was not readily available, certainly not to users of the target electronic devke(s) . and certainly not by these users to intelligently use and manage the target device.
- a system and metho are disclosed that provide securit for an electronic device, system, document, etc. that is accessible and controllable by a user with a user electronic device. That security may be provided by one or more of btodkehain, multi-factor biometric authentication (e.g , voice authentication), and one or more monitoring bets BRIEF DESCRIPTION OF THE DRAWINGS
- FIG. 1 is a schematic diagram of system and network architecture in accordance with embodiments of the present invention.
- FIG 2 depicts a single board computer of a smart box in accordance with embodiments of the present in ventio ;
- FIG. 3 depicts the structure and function of a user device control in accordance with embodiments of the : present i vention ⁇
- FIG 4 is a flow diagram of a smart box start-up and configurati n process in accordance with embodiments of the present invention.
- FIG. 5 Is a low diagram of user electronic device start-up, configuration and use process in accordance with embodiments of the present invention
- FIG, 6 depicts the structure and function of special purpose software of a server in accordance with embodiments of the present invention
- 71 depict screen shots of interfaces provided by a use device control on a user devi ce in accordance with embodi ments of the present inven tion;
- FIG. 8 Is a flow diagram depicting a method for providing security for an electronic device in accordance with embodiments of the present inven tion;
- FIG 9 is a flow diagram depicting a method for creating a cryptograph for a data unit in accordance with embodiments of the present invention.
- FIG. 10 is a flow diagram depleting a method for verifying a data unit in accordance with embodiments of the present invention.
- FIG i i depicts an illustrative, non-limiting cryptograph structure for use with embodiments of the present invention.
- FIG. 12 depicts an illustrative, non-limiting embodiment of special purpose software for carrying-out certain security aspects of the present invention.
- the : phrase personal electronic device or user electronic device means, by way of illustration and not limitation, smartphones, tablets, mobile computers, desk-top computers, mobile Internet devices, laptops, wearable computers, calculator watches, sraartwatches, head-mounted displays, personal digital assistants, enterprise digital assistants, handheld game consoles, portable media players, calculators, digital still cameras, digital video cameras, personal navigation devices, and smart cards, or any other .known or hereafter developed personal electronic device.
- reaction* $V' whe used in connection with user-centric control refers to any instruction, command, request, order, etc. provided by a user to access, manipulate, control, or otherwise interact; with an electronic device or document.
- FIGS. 1 and 2 respectively depict a schematic diagram of a system 100 and network architecture 200, and a single board computer 1 2 of a smart bo 1 10 in accordance with embodiments of the present invention.
- the system 100 comprises a smart box 1 10, a user device control 160 installable on a user electronic device 20, and a hot 180 installable in memory of the smart bo 1 10, tha are connected or connectable to a private network 12 or a public network 10 and are in communication with each other and wit electronic devices 30.
- the smart box 110 and electronic devices 30 are part of and/or connectable to a private network 12.
- a server 130 may be provided in the private network 12, or public network 10, and the user electronic devices 20 are part of and/or connectable to a public network 10.
- the smart box 1 10 may be part of and/or connectable to the : public network 10, yet he connectable to another smart box 110 or electronic device 30 that are both part of a private network 12.
- Embodiments of the present invention provide the user device control 160 at an edge 210 of the network, thus placing the ability to control the function or functionality of an electronic device in the hands of users at the network edge 210.
- the server 130 may be implemented, by way of non-limiting example, at least i part based on the machine learning platform provided by Amazon Web Services (AWS) cloud computing and storage services.
- the server 130 carries out certai administrative functions of the present invention For example the server 130 communicates initially with a smart box 1 10 when the smart box 110 first connects to the network and comes on line. In this capacity, licensing: and configuration data 134c previously saved as a data file 134 in server data storage 136 is communicated to the smart box 110 and usable by the smart box ! !0 for its initial configuration. Further configuration of the smart box 110 may be required and performed by an administrator, as describe in more detail herein.
- the server 130 also communicates software updates to a smart box 110 as necessary, which are stored as an update data file 134b, This communication occurs automatically and Is managed by a scheduler on one or both of the server 130 and smart box 110.
- the server 130 is also a repository for usage data and statistics for " the electronic devices in the network iO, 12. The data and statistics are acquired from each electronic device 30 by the smart box 1 10, and communicated thereby to the server 130, where the data and statistics are stored as device stats 134a in a data file 134.
- the server 130 also communicate initially with
- a user electronic device 20 through the user device control 160 to create an account for andauthenticate the riser, and to bring the user electronic device .20 online.
- the server 130 has a processor and memory having stored therein general purpose software comprising commands or instructions executable by the processor for carrying out basic junctions of the server 130, and special purpose software 132 comprising commands or instructions executable by the processor for carrying out. aspects of the present invention. See also FIG, 6.
- the server 130 has data storage 136 that may be part of or separate from the server 130.
- One or more data files 134 created by use of the present invention are stored in the data storage 136 as one or more files or databases. Exemplary types or categories of files or databases ar depicted in FIGS.
- device stats 134a created by an electronic device 30 is eaptura le by the smart box 110, an may be transmited thereby to the server 1 0 at predetermined times.
- Such device stats 134a are currently created by an MFP, for example, but are not currently eapturable nor captured by any device other than the MFP, Embodiments of the present invention capture that data and transmit it. to the server 130 for storage and later use.
- Data files 134 may also comprise update data 1 34b for updates for one or more electronic devices 30 that are transmittable, downloadable, etc.
- Updates may include, by way of non-limiting example, updates for general operation and function of the smart box 1 10, and updates for operation an function of inventive aspects of the smart box 1 10.
- Data files 134 may further comprise licensing and configuration data 134c that: is unique for, and specific to a particular smart box 110
- Licensing and configuration data 134c generally comprises inlbnimfion provided by an administrator of a smart box HO, for example, that is used to define certain operational parameters for the smart: box 1 10, as well as data provided b the server 130
- licensing and configuration date 134c for a company may include the format of a user’s email, foe number of users, the number of electronic devices 30 identifiers for each electronic device 30 (e.g., IP address), codes specific to the company and/or a grou or department within foe company, an API key unique to each smart box 1 10 that comprises a license ID and machine key, essentially a. user name and password for the smart box 110, and other data and
- Data files 134 may also comprise service ticket data 1344 collected by the smart box
- Service ticket data 134d may be generated by a user or by an electronic device 30, indicative of a state of foe electronic device 30 that may require intervention, e.g., paper jam, toner cartridge replacement etc
- the server special purpose software 132 may comprise an application programming interlace, or API, that functions: as a KEST- based API endpoint for communication with the smart box 110 and/or user electronic device 20. Communication between and among the various electronic devices may use java script object notation.
- the API special purpose software 132 Is structured based upon subcomponents that provide microservices within the API that may include, by way of non -limiting example, storing data rece ved from a smart box 1 .10 about one or more electronic devices 30, providing updates to a smart box 1 10, routing service ticket requests, and/other selectively programmable microservices that may facilitate communication between and among smart boxes 110, user electronic devices 20, target electronic devices 30, electronic documents 1 50 in a ocument repository 154, and other dev ices and systems, either in the private network 12, the public network 10, or a combination of both.
- the special purpose software 132 may additionally comprise user device control 160 uploadable to a user device 20 that provides a user interface 700 (see, e.g., FIG 7A) While in a preferred embodiment the user device control 160 is an application downloadable by/to a user electronic device from an app store, an alternative embodiment provides the user device control. 160 on the server 30.
- the smart box 1 10 generall functions as a «traversal controller that manages and controls communication by, between and among the various electronic devices that comprise the present invention, as well as the various electronic devices and documents with which the present invention accesses, manipulates, and/or controls.
- the majority of communication by the user device 20 via the user device control 160 is received by or at least passes throug the smart box 1 10.
- the smart box 1 10 is thus able to, and does in fact, capture much of the data and informatio created by use of the present invention, including data created by target electronic devices 30.
- the smart box 110 is thus also able to function as a sentry to ensure secure transactions with electronic devices and electronic documents.
- the special purpose software 1 12 of the smart box 1.10 functions as an API endpoint for the user device control 160.
- the smart box 1 10 also controls all user access to and control of target electronic devices 30 and electronic documents 156 from a plurality of user device controls 160.
- the smart box 1 10 comprises a single board computer 122 having a central processing unit 114 comprising a processor 124 and memory 126 having stored therein general purpose software comprising commands or instructions executable by the processor to carry out basic functions of the smart box i 10.
- basic functions of the smart box 1 10 enable : the smart box 1.1.0 to power up and communicate and control communication over a variety of interfaces 116, such as USB, Ethernet, video, audio, and MDMh
- Each smart box 1 10 may preibrably be configured with dual Ethernet ports In order to communicate with each of an Ethernet -based private local area network 12 and an electronic device 30.
- Each smart box 1 10 serves as an intermediary that employs its Ethernet interface to monitor communications of its associated electronic devices 30 via the private network 12, provide instructions to be executed by the electronic device 30, and retrieve data from the electronic de vice 30.
- An exemplary single board computer 122 is available from the Raspberr Pi
- This model is a credit card-sized computer powered by a Broadcom BC 2835 central processing unit (syste -oma-cliip) 114 that includes a 32 ⁇ bit ARMT ⁇ 76jZFS processor 124, clocked at 700MHz * a Videocore IV Graphics Processing Unit, and 256MB of random access memory 126.
- the single board computer 122 is powered by a 5V AC charger connectable to a micro USB port 1 18. It will be obvious to persons skilled in the art and from the disclosure provided herein that other single hoard computers ma be used in connection with the present invention.
- the smart box 110 further comprises special purpose software 1 12 storable in memory 12 comprising commands or instruction executable by the processor that enables the smart: box P0 carry out certain inventive aspects of the present invention
- the special purpos software 112 is an API with programmable functionality.
- the API special purpose software 1 12 is structured based upon sub-components that provide mieroservices within the API that may include, by way of non-limiting example, copy, email, collect, and service, as well as other selectively programmable functionality. Any of the foregoing ma be enhanced by voice- enable or two-factor biometric authentication aspects of embodiments of the present invention.
- Each mierpserviee calls a unique API path tor the desired functionality - the path being to at least one of the smart box II 0 and server 130.
- the special purpose software 1 12 is selectively programmable and adaptable to ohange/add/delete one or more functions it provides.
- the monitor bots 180 depicted in FIG. 1 may be embodied as special purpose software that causes the smart box processor to monitor certain activities of the smart box 110 and/or electronic device 30 or electronic document 156.
- Each monitor hot 180 may be configured to monitor s ecific activities such as, by way of non-limiting example, hard drive/memoiy access, I/D port access (e.g., US B, niicro-USB. etc.) Wi-Fi access, email usage, include permited and prohibited domains, time/day usage, transaction size, data flooding, and other activitie identified as actual or potential risks to the systems, documents, information, etc.
- a bot 180 may be configured for 24/7 monitoring, functioning as an always alert sentry for electronic devices 30 and electronic documents 156.
- bot 180 may be configured to regularly wipe clean a hard drive of an electronic device 30 to ensure that no data remains on that hard drive
- a bot 180 may also or alternatively be configured to ensure that the IP address for an electronic device is not the factory default IP address, as that address is more susceptible to hacking.
- a bot 180 may alternatively he configured for industry specific monitoring, such as, by way of non-limiting example, financial services, medical records (e.g, HIPPA), and any other industry in which access to, manipulation of. and control of electronic devices and electronic documents using natural language p ocessing present security issues,
- FIG. 4 An exemplary process 400 for initial configuration of the smart box 1 10 is depicted in FIG, 4, As an initial step, a smart box 1 10 is pre-programmed with an API key comprised of a license ID and machine key, each unique to the smart box 1 10 and that together function as a user name (license ID) and password (machine key). Prior to a smart box 110 first use, it is programmed with certain data and information to enable it to connect to a server 130 upon power-up and to effect a handshake between the server 130 and smart box 110. The smart box 110 initially cycles through a start-u sequence or process when power is first applied at step 402.
- the general purpose software of the smart box 1 10 establishes a connection over the network 10 or pri vate network 12 to the server 130 at step 404 and transmits the A : P1 key to the server : 130 - communicating with the server API 132.
- the server API 132 is configured to detect and identify the smart box 1 10, and to transmit configuration data to the smart box 1 10, at step 406.
- the configuration data was previously constructed as licensing and configuration data 134c stored in data storage 134 of tire server 130 based upon information provided by a systems administrator, for example.
- Configuration of the smart box 110 is controlled by the API special purpose: software 112, and is set by the licensing and configuration data file 134c Once the licensing and data configuration file I34e is installed on the smart box 110, the smart box 110 is operational and ready to connect with user electronic devices 30 and carry out aspects of the present invention.
- the server 130 and/or smart box 1 10 may be configured to transrmt- ' roceivc regular software updates. At least one of the server API 132 and smart box API 112 ensures that the updates are intelligently communicated, ensuring that updates to the smart box 110 do not bypass sequential updates, i.e > , preventing an update from version 1.1 to version 1 9, where intermediate versions contain important updates that may or may not be included in the most recent update.
- the user device 20 may he any electronic device capable of carrying out aspects of the present invention as disclosed herein.
- Preferred embodiments include, by way of non-limiting example, a smartphone or tablet.
- Other electronic devices 20 are also disclosed herein, and are thus contemplated by, and within the scope and spirit of the present invention, as are any hereafter developed electronic devices capable of carrying out aspects of the present inventio as disclosed herein.
- a user desiring to utilize the present invention installs the user device control 160 on a user electronic device 20
- the user device control 160 is preferably an app downloadable to the user electronic device 20 from an app store or from the server 130 Once the app is installed the user can launch the user device control 160 to utilize aspects of the present invention initially, a user must configure his/her user device 20 to carry out aspects of the present invention.
- FIG 5 a startup and configuration process 500 for a user electronic device 20 is depicted. The user first downloads the user device control 160 from an app store or from the server 130 to the user device 20, at step 502, and launches the user device control 160 at step 504.
- the user device control 160 provides a plurality of user interfaces that enable the user to utilize aspects : of the present invention.
- the user device control 160 determines if the user is a new user at step 512, in which ease the user can create an account on the server 130, step 506, and thereafter use the user device control 160, smart bos 110 and server 130 to access and control a target electronic device 30 in accordance with embodiments of the present invention. Reluming users, as detected at step 512, can login at step 510 and thereafter use the user device control 160, smart box 110 and server 130 to access and control a target electronic device 30 in accordance with embodiments of the present invention. As depicted in FIGS. ⁇ A - 7J, the user device control 160 provides interfaces and carries out certain inventive aspects of the present invention.
- the user device control 160 When launched, the user device control 160 provides a user interface 700 on a display trf foe user electronic device via which the user can utilize aspects of the present invention.
- the user interface 700 comprises a plurality of screens, as depicted in FIGS. 7 A - 7.1, each of which provide a user with access to aspects of the present invention.
- the user device control 160 When launched, the user device control 160 provides the user interface 700A depicted in FIG. 7 A as a home scree via which a user can either select login (returning user) 7 03 or register (first-time user) 704.
- a first-time user must select register 704, and will then be prompted to enter a unique Company Code 706 via the user interface 700B depicted in FIG, 7B, That information is transmitted to the server 130, which create an account for the user if the information entered by the user matches information in the licensing and configuration data 134c.
- die server 130 transmits an email with a temporary PIN to the user email address, which queries: the user to verily the mail by return response that includes the temporary PIN and the permanent PIN. if the email address, temporary PIN and permanent PIN match data on the server 130, the new user account i validated.
- a company my penult self-validation by empowering the administrator to indicate which of the users attempting to register are authorized users.
- an administrator will have access to a list of users attempting to register, and can indicate (by check -bos, for example) which users are authorized - this exchange occurring between the server 130 and administrator, with the information regarding validated users being captured and stored by the server 130.
- biometric authentication may be selectively require by. for example, fingerprint authentication 714, in which case the user interface 700E depicted in FIG. 7E will be provided by the user device control 160.
- fingerprint authentication 714 in which case the user interface 700E depicted in FIG. 7E will be provided by the user device control 160.
- This aspect of the present invention leverages certain functionality native to the user electronic tie vice 20 that may not be native to the target electronic device 30 to cause that device 30 to carry-out: or utilize the native functionality.
- the user electronic device 20 ts capable of carrying out two-factor authentication using biometric data as one factor, and embodiments of the present invention enable that function to be used in connection with the target electronic device 30.
- user interface 700E prompt the user to a biometric authentication - a finger print in this example via a touch sensor fingerprint; authentication 714.
- Voice recognition functionality may be provided by embodiments of the present invention through interaction between one or more of an audio interface 170 of the user electronic device 20, a separate audio interface 170 proximate an electronic device 30 and a voice recognition server 150 such as, by way of non-limiting example, IBM Watson.
- a voice signature for the user may be stored in the user 'account file 1 34c ot otherwise in memory of the server 130 or a web server 150 capable of voice recognition.
- the verbal command entered " by the user though the user device control 160 (via the audio interface 170) is captured (at least temporarily) thereby enabling comparison of the user ' s voice with the voice signature for that user previously stored
- a user invokes this functionality with voice command captured or recei ed by an audio interface 170 such as a speakerimierophone on the user electronic device 20 (see, e,g , FIG. 1 ), or a stand-alone speaker/mlerophone, and voice activation interface 76Q of the user device control 160 in FIG, 7F.
- receipt or detection of a specific wake-up word or phrase causes the voice recognition aspect of the present invention to change from an inactive or passive state, where audio is received by the audio interface 170, but no action is Invoked in response thereto, to an active state, where audio is received by the audio interface 170 and causes the smart box 110 to react according to the content of the received audio.
- the audio interface 170 and voice recognition aspects of the present invention do not capture ail audio within range of the audio interface 170, b only audio that is preceded by the specific word or phrase.
- the user can access and utilize the present invention through user interface 7O0F depicted in FIG. 7F, which provides the user wife a plurality of functions the user may select to access and control a electronic device 30
- these functions include, by way of non-limiting example, copy functio 720, email functionou730, collect function 740 and sendee function 750.
- the user can also use voice activation 760 to carry-out aspects of the present invention, or log out 716,
- Each of these functions maps to API commands within the user device control 160, and to the smart box 1 ID which, in turn, accesses and controls a target electronic device 30 to enable that device to perform or respond to the selected function.
- This aspect of the present invention leverages certain functionality native to the user electronic device 20 that may not be native to the target electronic device 30 to cause that device 30 to carry-out or utilize the native functionality in this ease, the user electronic device 20 is capable of responding to audible commands, and embodiments of the present invention enable that function to be used in connection with die target electronic device 30. when that functionality is not native to the target device 30.
- Operation and operation#! aspects of the present invention will now be described, with continued reference to the drawings The present invention i addable to existing private networks 12 and public networks 10 without significant change to either.
- the smart box 1 10 is pre-programmed for use in a specific network and network configuration, and to know the credentials of electronic devices 30 in its network.
- Parameters fo pre-programming the smart box 1 10 may be rovided, at least in part. h> a person or entity involved with the configuration, setup and operation of aspects of the present invention.
- pre-programming parameters may include, by way of non- limiting example, IP addresses of each electronic device 30 in the network to be accessed and controlled by the present invention. This information may be saved as a licensing and configuration data 134c in a data file 134 in data storage 136 of the server 130, and foay also be associate with a unique company code that maps a smart box 1 10 to the licensing and configuration data 134c.
- the smart box 1 10 may initially be programmed with an APT key that includes a license ID and machine key unique to the smart box 110.
- the smart box 110 When the smart box 110 is initially connected to the private or public network, 12, 10, the smart box 110 communicates: the API key to the server 130 as a user name or login ID and password.
- the server 130 identifies the data file 134 for this smart box I 10, and returns the licensing and configuration data 134c to the smart box 1 10,
- the server 130 sends an email, text, or other communication to a destination previously identified when programming parameters were provided about the smart box 1 10.
- this woul be an email address of a system administrator, in that email address a hyper-link is provided that, when selected by the administrator, connects the administrator to the smart box i 10 as a console, providing the administrator with access to pertain control function for the smart bo 110 and its configuration.
- the administrator will have access to a pull-down menu on which each electronic device 30 that is accessible and controllable using the present invention "is identified.
- an user device control 160 the administrator pro ides super-user credentials for each electronic device 30. This enables the smart box 1 10 and user device control 160 to access a target electronic device 30 as a super-user (i.e,, as an administrator, service, tech, manufacturer, etc.) and gain access to data captured and stored by/on the electronic device 30.
- the smart box 1 10 sits in an idle state until a user, using the; user device control 160, chooses to initiate a transaction to utilize aspects of the present invention. This begins a process through which the electronic device 30 changes from a closed state to an open state for this specific user.
- a smart box 1 10 Because access to and control of, a smart box 1 10 is user-centric, so too is control of electronic devices 30 and documents 156, Thus, one user's access to and control of a smart box 10 doe not impact an other user’s access and control If a user is denied access to an electronic device 30 or document 156, that does not impact any other user’s access to the same electronic device 30 or document 156. Notwithstanding the foregoing, the smart box 110 is able to communicate with the server 130 and receive configuration updates from the server 130, as depicted in the flow diagram of FIG 4
- the smart box 1 10 will access a voice recognition service to receive, analyze, and parse the voice commend and to return a response to the smart, box 1 10 that is then in a format that is transmittable to and understandable by an electronic device 30, anil that can cause or enable the electronic device 30 to perform the requested function.
- a voice command spoken by a user into the user’s electronic device 20 is transmitted by the user device control 160 to the smart box 110, which identifies the command as a voice command, and transmits it via & secure connection to a voice recognition server 150, such as IBM Watson or Amazon Web Services (“AWS”) platform.
- a voice recognition server 150 such as IBM Watson or Amazon Web Services (“AWS”) platform.
- Communication between smart box 1 10 and voice recognition server 150 is preferably carried out using a Transport Layer Security (TLS) 1.2 protocol ⁇
- Voice recognition may alternatively be implemented in a variety of other ways, including by means of the server 130 and data storage 136 in combination with an associated smart box 110, or by another specialized server and data storage,
- special purpose software i the form of an API 152 may be provided on the voice recognition server 150, and be configured with speech to text, NLP, and text to speech capabilities.
- the voice recognition server 150 returns text commands to the smart box 110, for transmission thereby to the target electronic device 30.
- a user can access the copy function of the present: invention via the user interface 700F depicted in FIG. ?F, and by selecting Copy 720, after which the user is presented v ⁇ ith the user interlace 700(3 depicted in FIG. 7G Via thi user interface 70QG the user can control the target electronic device 30 an cause it to carr out various transactions associated with using that device 30 for copying a document.
- a user can access the email function of the present invention via the user interlace 700F depicted in FIG. 7F, and by selecting. Email 730, The user device control.
- the 160 then presents the user interface 7Q0H depicted in FIG, 7H, enabling a user to use the present invention to Cause a target electronic device 30, an MFP in this ease, to send an email to a recipient selecte by the user without access to the email list of the MFP.
- the present invention thus accesses data and information native to the user electronic device 20 or particular to the user, in this case, the user’s email address book 736, This enables the user to cause the target electronic device 30 to send an email to a recipient that is not known to that device 30.
- the present invention enables a user to access and control an MFP to cause that MFP to carry out a function different than the functions it is configured to cany out.
- the present invention further uses native technology of the user electronic device 20 to leverage already existing connections and permissions f e.g., login details) to facilitate access to documents, services, applications, etc., for various types of user accounts. For example, a user need not enter login credentials for access: to files stored in a DROPBO account in order to access these files for use by the present invention, in effect enabling the target electronic device 30 to access these files without requiring the user’s login credentials.
- the smart box HO also has the ability to determine whether a user is violating a predefined rule o attempting to initiate a transaction that would be considered an anomaly.
- email rules may be defined regarding permitted and/or restricted email addresses. That information may he stored in a data file 134 on the server 130, in memory on the smart box 1 tO, or both.
- the smart box 1 10 and/or server 130 cab compare the: email recipient against a white-list of permitted recipients, or a black-list of restricted recipients, to determine i f the email should be sent.
- a user can access the collect function of the present invention via the user interlace 70OF depleted in FIG. 7P. and by selecting Collect 740, which provides user interface 7001 depicted in FIG, 71,
- This function -enables a user to collect secure documents at the target electronic device 30, in this case the MFP, that can only be printed by the : user.
- Any of the afore-discussed functions may also be accessed using voice recognition via the user interface 700F depicted in FIG. ?F, and selecting the microphone 760.
- the functions available to the user via the user interface 700 provide acces to further functions.
- copy 720 and email 730 functions may provide aft option to charge a client or customer for use of the electronic device 30 It is typical for law firms and accounting forms, for example, to charge clients for copies. In such cases, a code must be entered designating the correct eharge-to entity before the electronic device 30 can be used.
- the present invention enables a user to access one or more databases of such codes located on foe; server 130. a remote server or other data storage device that is not connected to and may not be in the same network as the electronic device 30 being accessed and controlled.
- the user interface 700G for the copy 720 function is depicted in FIG.
- an includes a“Bill To” pull-down menu 722 which provides the user with access to a database of client codes selectable by the user to designate a client to charge for use of the electronic device 30.
- the client codes accessible to the user via the pull down menu have been previously mapp d to the: user's account, thus providing limited and user- specific information,
- the use interface 7Q0H for the email 730 function is depicted in FIG: 7H, an includes a“Sill To” puLl-down menu 732 which provides the user with access to a database of client codes selectable Lw the user to designate a client to charge for use of the electronic device 30.
- This user interface 70DIT also includes a“Recipient” field 734 that can be populated with one or more email addresses selected irons the user’s contacts.
- an MFP can he configured and used to send email, it is limited to the contacts programmed into the MFP, With the present invention, the email function of an MFP is accessed and controlled in a way that enables the user to send emails from the MFP to recipients in the user’s contact list, or from a contact list that is not known by the MFP or other electronic device 30
- Another embodiment of the present: invention provides the ability to intelligently manage one or more target electronic devices 30.
- the smart box 1 10 has super -user access to data collected and stored by an electronic device 30.
- data provides a variety of useful informatio about usage of the electronic device 30 such as, for example, which paper trays are used most often, time-based use of the device 30, and other use and operational characteristics ami data of the device 30,
- the smart box 110 having access to this data, may use this data to intelligently control use of the electronic "device 30.
- the present invention can direct print, copy, etc,, commands to effect a mom unifor use of the target electronic device 30. This will result in greater longevity lot the parts of the electronic device 30, and a reduction in service calls and repairs. 10079 ⁇
- the present invention can also be used to automate certain service conditions for a target: electronic device 30, For a type of device, like an MFP, there may be a finite set of problems that occur with the greatest frequency. Once this set of problems is identified, the smart hoxj 10 can be configured to automaticaliy detect the occurrence of such a problem at a target electronic device 30 and automatically create a service call without the need for user in volvement
- a licensing and data configuration file 134c may contain information specific to thi user, including rules that define authorized and unauthorized features thi user is permitted to access and other rules defining permissible use by this use of the electronic device 30 It is thus possible for the smart box 110 to initially flag a transaction from a user, and to communicate with the server 130 to determine whether the transaction violates a rule for that user. Information about user permissions may also be contained in a user account file 134e, Server 130 may, for example, be configured as an artificial intelligence-based analysis engine capable of analyzing a risk level associated with the transaction based on data gathered by a smart box 1 10 for similar transactions made On the electronic device 30 as well as other similar electronic devices 30 (e.g , electronic devices 30 in the same private network 1 ).
- the server 130 can thus determine whether the transactio is an anomaly or an exception, and i f so, whether the exception has been or can be resolved.
- the smart box 1 10 functions as a universal controller, controlling user access to and use of electronic devices 30 and electronic documents 156.
- the smart box 110 can determine if the transaction is an exception or anomaly that is Out of compliance with rules: for the user.
- the server 130 may transmit information back to the smart box 1 10 providing a disposition command with respect to the requested transaction, e.g., indicating that the transaction has been executed or not (9981 j
- a disposition command with respect to the requested transaction, e.g., indicating that the transaction has been executed or not (9981 j
- server 130 will consider past experience with the requesting user, the electronic device 30, and other similar electronic devices 30, as well as other pertinent information that may be available to the server 130 (for example, suspectproduction request patterns reported by other document production centers), the server 130 may prepare a request disposition and transfer this information to the smart box 1 10 to guide the response of the : smart box 1 10 to the document production request.
- the response disposition may authorize the smart box 110 to instruct the electronic device 30 to proceed to fulfill the document request in its entirety (“green light'’).
- the request disposition may instruct the smar box 1 10 to provide altered instructions to the documen processing device (“yellow light’ ).
- the request disposition may instruct the smart box 1 10 to diminish the requested number of copies or rate of printing of copies as would be expected in response to the production request.
- the smart box 110 may be instructed to forward the document request to another smart box 110 associated with art electronic device 30 that, for example, has been reserved and isolated for production requests identified as presenting some risk.
- the request disposition may call for the rejection of the production request (“fed light”).
- the smart box 1 10 may preferably collect execution information from the electronic device 30 providing details about the execution and/or information about the current state and resources available to the electronic device 30 In any case, the electronic device 30 or electronic document 15ft are still available to other users regardles of whether a transaction request by particular user is denied
- a system and method for securely accessing, manipulating an controlling electronic devices or electronic documents uses multi -factor biometric authentication and bloekchain technology in some respects embodiment of the present invention increase access to electronic devices and documents.
- a MFP may have stored in local memory documents contai ing sensitive information, e.g., confidential client information for attorneys, personal health information for medical professionals, and other types of information intended for restricted access.
- Cloud-based computing enables the remote storage of and access to documents, data, information, etc.
- cloud storage repositories such as DROPBOX, GOOGLE DRIVE, MICROSOFT AZURE, AMAZON DRIVE, and others provide data storage over the internet that is delivered on demand with just-in-timecapacity and costs, thus eliminating the need for an individual or enterprise to buy and manage its own data storage infrastructure.
- This provides agility, global scale and durability, and anytime, anywhere data access it thus is important that embodiments of the present invention provide adequate and suitable controls for protecting such types of information from unauthori zed access and use. To this end, the present invention provides embodiments that accomplish this differently.
- bloekchain technology is used to ensure that a user is an authenticated user, and should he accessing the eiccnonie device(s), documents, information, data, etc. made possible with aspects of the present invention.
- voice authentication is used either alone or in connection with bloekchain technology » to ensure that a user is an authenticated user.
- one or more monitor bets are deployed to monitor usage of electronic de vices accessed by and/or with the present invention to ensure that such access is within a normal or expected type of usage (e.g,, not too many copies, not at off-hours, not activating Wi-Fi, etc,). Any detected usage that is no is flagged as an anomaly and subject to intervention and Anther authentication before a requested transaction may be allowed
- the present invention uses biometric authentication together with blockchain technology and one or more monitor hots to provide the inventive system and method.
- An inventive aspect of the present invention is applicants’ combination of biometric authentication as a building block of a sentinel aspect of the present invention - providing for secure access - and the use of btoekehain technology and one or more monitor hots to enable the secure access and secure manipulation and control of documents and devices.
- the present invention requires biometric authentication before a user will be provided with access to a device or document Biometric authentication ma be by one or more of fingerprint via a user electronic device 20, voice recognition via a user electronic device 20 using; an integral or separate audio interface 170
- a user may login to access a device or document using the user electronic device 20 and a biometric entry device through an interface provided by the user device control 160, at. step 830 If a user is not authenticated, as determined at step 820, the transaction is denied at step 814. Once a user is authenticated, the user can now transmit to the smart box 110 a command for a transaction to control the device 30 or access a document 156 in a document repository 154.
- the status of die device 30 changes from closed to open, indicating that the user has been authenticated and may now present or transmit: commands for a transaction to control the device, at. step 802.
- whether the transactions are carried-out by the electronic device 30 will depend, at least in part, upon whether the requested transaction is an anomaly, as described further herein.
- a monitor hot 180 may be separately configured to monitor users, processes, and/or transactions, and that may automatically launc when a user has been authenticated and when the electronic device status changes to open.
- a monitor hot 180 may be configured to monitor users according to predefined criteria or parameters that define acceptable uses of the device, or access to the document by a particular tsen
- the hots I SO may also be configured to identify when a user presents a command for a transactio that is not. within the predefined criteria or parameters.
- the smart box" 1.10 receives a command from the user device control 160 to access and control the electronic device 30 or documen 156.
- Monitor hots 180 may be launched at step 834 based upon a user identification (he., user-centric), upon initiation of, or a request to initiation a process (he., process -cent uc ), e.g., open Wi-Fi, or upon initiation of, or a request to initiate a transaction (he., transaction-centric), e.g., access to a device or document
- One or more monitor hots 180 may gather information about the requested transaction, and push that information to a cloud-based API, at step 804, where logic is provided to determine whether the transaction request is an anomaly, at step 810, based upon certain predefined criteria.
- the present invention may evaluate whether a transactio is an anomaly by comparing the transaction and its characteristics (e.g., type of transaction (e.g., print, copy, entail, etc.), time, size/quantity, user, etc.) with permissions defined in a user account file I 34e for that user. If the transaction request is consistent with these permissions and, therefore, is not an anomaly, the transaction is allowed, as ste 818.
- characteristics e.g., type of transaction (e.g., print, copy, entail, etc.), time, size/quantity, user, etc.
- anomalies may include Wi-Fi access and control, email to non-approved recipients or domains, and document downloads to removable storage devices,
- permissions may include, by way of non-limiting example, and times of day the user is permitted to initiate a transaction, type of transactions allowed (e.g., print, email, document download, etc;, size/frequeney of a transaction type, e.g., print jobs limi ted to not more than 500 pages per week).
- type of transactions allowed e.g., print, email, document download, etc;, size/frequeney of a transaction type, e.g., print jobs limi ted to not more than 500 pages per week.
- the present invention provides an override capability determine at step 812 by creating and transmitting a notification to a predetermined destination and recipient typicall a system administrator. Transmission of the notification may be by email, text, or other suitable communication means.
- the recipient has the authority and ability to override the anomaly, be,, to allow the transaction to proceed, in which case the process proceeds to step 81 where th user account file I 34e for the particular user may be updated so that the permission(s) contained therein now reflect that what was previously considered ail anomaly should not thereafter e considered as such.
- a b!oekchain data set may also be employed and updated to reflect the outcome of the anomaly analysis
- the rec ipien t of the noti fication can reject the transaction because of the anomaly, in which case the transaction is denied, at step 814.
- an automatic override in at least some cases may permit a transaction to proceed when an anomaly is identified.
- the user account file 134e may contain permissions that are defined by ranges of allowable values, e.g., user A typically prints on weekdays between the hours of 9:00 AM and 5:00 PM, but print sobs on weekdays at 6:00 PM are permissible.
- the transaction is allowed, at step 818.
- the present invention may utilize blockehain technology: as at least a part of the inventive solution to ensure that access to, manipulation of, and control of a device or document is secure.
- step 816 when an anomaly has been identified, evaluated, and the transaction allowed, this outcome is captured in an update to a blockehain data set that ma be defined for thi user, this process, this transaction, or combinations and/or variations of the foregoing.
- a blockehain data set that ma be defined for thi user, this process, this transaction, or combinations and/or variations of the foregoing.
- winch may be suitable for carrying-out this aspect of foe present invention.
- the disclosure provided herein regarding blockehain technology and its implementation in the present invention are illustrative, nan-limiting examples.
- the present invention is directed to avoid using user personal data or information in a hlockchain data set in certain applications of the present invention, personal information of a user may be accessed, obtained, or otherwise made available, e.g., personally identifiable information ⁇ Pii f or sensitive personal information. (SPI).
- SPI personally identifiable information
- implementations of the present invention preferably create a link table that provides cross-reference between the user PIT, SPI, etc data, and data submitted to the biockehain data set
- a smart box 110 receives a command for the transaction fro a user device control 160, step 802, biockehain technology may be used to verify the transaction.
- FIG. 9 a process for creating a cryptographic structure (Le , a cryptograph) is depicted, A server 130 as depicted for example in FIG.
- Cryptographic structure 1 preferably a cloud-based server - receives a data unit, at ste 902 of FIG, 9, and hashes the dat unit, at step 904, generating a first cryptograph based upon the hash, at step 906, publishing the first cryptograph on biockehain, at step 908, an creating a proof associated wife the data unit using a hash algorithm* at step 910
- a non-limiting cryptographic structure i 100 as produced by the process of FIG. 9 is depicted in FIG, 11.
- Cryptographic structure 1 100 may be generated by server special purpose software 132 configured as a. cryptographic structure odule to create such a structure, as described below with reference to FIG. 12,
- data units .1 1 16, 1118, 1 120 an 1 122 may be hashe (i 1 AO,
- First hash 1 108 may correspond to data unit 1 1 16, first hash 1 1 10 to data unit 1118, first hash 1 112 to data unit 1 120, an first hash II 14 to data unit 1 122
- first hashes 1 108, .1 1 .10, 1 112 and 1 1 14 may again be hashed (1140, 1142, 1 144, 1146) to form second hashes H04 and 1 106
- Second hash 1104 may correspond to first hashes 1108 and P 10
- second hash 1106 may correspond to first hashes 11 12 and 1 1 14
- second hashes 1104 an 1 106 may be hashed ⁇ 1 150 and i i 3 ⁇ 4 1 1 o form a top hash 1 102 - a single hash that represents data units 1116 018, 1120 and 1 122, and the intermediary hashes 1108, 1 110,
- a process for verifying a data unit is depicted in FIG. 10.
- the first step is obtaining the data unit for verification, at ste 1002, then obtain proofs for the data units (created at step 910 in FIG. 9) for verification, at step 1004.
- the data unit is hashed .at ste 1006 to recreate the cryptograph based upon proofs at step 1008.
- a step 1010, foe present invention verifies that the hasb(es) belong to the roots of the cryptograph.
- the process (method) depicted in FIG. 10 thus represents an embodiment of the present invention for verifying a transaction.
- the special purpose software may comprise a plurality of create modules 40, including a data unit module 42, a hash module 44, a storage module 46, a cryptographic structure module 48, a publication module 50, and a proof module 52,
- the special purpose software may also comprise a plurality of verify modules 60, including a data unit module 62, a hash module 64, a storage module 66, and a cryptographic structure /nodule 68.
- the special purpose software may in addition comprise a root verification module 80.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Life Sciences & Earth Sciences (AREA)
- General Engineering & Computer Science (AREA)
- Health & Medical Sciences (AREA)
- Computer Hardware Design (AREA)
- Biodiversity & Conservation Biology (AREA)
- Biomedical Technology (AREA)
- General Health & Medical Sciences (AREA)
- Theoretical Computer Science (AREA)
- Computing Systems (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Priority Applications (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/US2018/051648 WO2020060542A1 (en) | 2018-09-19 | 2018-09-19 | System and method for securely accessing, manipulating and controlling documents and devices using natural language processing |
CA3112706A CA3112706A1 (en) | 2018-09-19 | 2018-09-19 | System and method for securely accessing, manipulating and controlling documents and devices using natural language processing |
GB2104536.4A GB2592499B (en) | 2018-09-19 | 2018-09-19 | System and method for securely accessing, manipulating and controlling documents and devices using natural language processing |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/US2018/051648 WO2020060542A1 (en) | 2018-09-19 | 2018-09-19 | System and method for securely accessing, manipulating and controlling documents and devices using natural language processing |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2020060542A1 true WO2020060542A1 (en) | 2020-03-26 |
Family
ID=69887809
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/US2018/051648 WO2020060542A1 (en) | 2018-09-19 | 2018-09-19 | System and method for securely accessing, manipulating and controlling documents and devices using natural language processing |
Country Status (3)
Country | Link |
---|---|
CA (1) | CA3112706A1 (en) |
GB (1) | GB2592499B (en) |
WO (1) | WO2020060542A1 (en) |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US6088717A (en) * | 1996-02-29 | 2000-07-11 | Onename Corporation | Computer-based communication system and method using metadata defining a control-structure |
US20160277439A1 (en) * | 2015-03-20 | 2016-09-22 | Ncluud Corporation | Locking Applications and Devices Using Secure Out-of-Band Channels |
US9477737B1 (en) * | 2013-11-20 | 2016-10-25 | Consumerinfo.Com, Inc. | Systems and user interfaces for dynamic access of multiple remote databases and synchronization of data based on user rules |
US20170046698A1 (en) * | 2015-08-13 | 2017-02-16 | The Toronto-Dominion Bank | Systems and methods for establishing and enforcing transaction-based restrictions using hybrid public-private blockchain ledgers |
-
2018
- 2018-09-19 CA CA3112706A patent/CA3112706A1/en active Pending
- 2018-09-19 GB GB2104536.4A patent/GB2592499B/en active Active
- 2018-09-19 WO PCT/US2018/051648 patent/WO2020060542A1/en active Application Filing
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US6088717A (en) * | 1996-02-29 | 2000-07-11 | Onename Corporation | Computer-based communication system and method using metadata defining a control-structure |
US9477737B1 (en) * | 2013-11-20 | 2016-10-25 | Consumerinfo.Com, Inc. | Systems and user interfaces for dynamic access of multiple remote databases and synchronization of data based on user rules |
US20160277439A1 (en) * | 2015-03-20 | 2016-09-22 | Ncluud Corporation | Locking Applications and Devices Using Secure Out-of-Band Channels |
US20170046698A1 (en) * | 2015-08-13 | 2017-02-16 | The Toronto-Dominion Bank | Systems and methods for establishing and enforcing transaction-based restrictions using hybrid public-private blockchain ledgers |
Also Published As
Publication number | Publication date |
---|---|
GB2592499B (en) | 2022-12-14 |
GB202104536D0 (en) | 2021-05-12 |
GB2592499A (en) | 2021-09-01 |
CA3112706A1 (en) | 2020-03-26 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US10812680B2 (en) | System and method for securely accessing, manipulating and controlling documents and devices using natural language processing | |
US10430125B1 (en) | System, network architecture and method for accessing and controlling an electronic device | |
US9294550B2 (en) | Efficient data transfer for cloud storage by centralized management of access tokens | |
EP2571242B1 (en) | Management apparatus, image forming apparatus management system | |
JP2007265242A (en) | File access control device, password setting device, processing instructing device, and file access control method | |
JP2005284985A (en) | Network compatible device, maintenance method for maintaining network compatible device, program, medium storing program thereon, and maintenance system thereof | |
JP5558230B2 (en) | Log information processing apparatus, image forming apparatus, log information processing method, and log information processing program | |
US20190370717A1 (en) | System and method for recommending a transaction to replace a device based upon total cost of ownership | |
US10762058B2 (en) | System and method for providing user-centric content to an electronic device | |
US20230351008A1 (en) | Information processing device and method for managing history information of information processing device | |
JP2013197731A (en) | Manager for remote management system, management device targeted for management, and device installation processing method | |
JP2009199117A (en) | Apparatus use control system | |
WO2020060542A1 (en) | System and method for securely accessing, manipulating and controlling documents and devices using natural language processing | |
JP2008176506A (en) | Information processing apparatus, information processing method and management server | |
JP2016207144A (en) | Information processing apparatus, program, and authentication system | |
JP4771238B2 (en) | Image processing apparatus and program | |
JP5749239B2 (en) | Image forming apparatus, upload program, and upload system | |
WO2019236051A1 (en) | System, network architecture and method for accessing and controlling an electronic device | |
JP2016139961A (en) | Image forming apparatus and maintenance management system | |
JP2016081269A (en) | Information processing device, management system, management method, program, and information processing system | |
JP2018014550A (en) | Image formation system and image formation method | |
JP6299101B2 (en) | Service providing system, service providing method and program | |
JP2018014551A (en) | Image forming system and image forming method | |
JP5757527B2 (en) | Information transfer apparatus and information transfer method | |
JP2018014552A (en) | Image forming system and image forming method |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
ENP | Entry into the national phase |
Ref document number: 3112706 Country of ref document: CA |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
ENP | Entry into the national phase |
Ref document number: 202104536 Country of ref document: GB Kind code of ref document: A Free format text: PCT FILING DATE = 20180919 |
|
32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205 DATED 24/02/2022) |
|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18934179 Country of ref document: EP Kind code of ref document: A1 |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 18934179 Country of ref document: EP Kind code of ref document: A1 |