发明名称 Sensitive information leakage prevention system, sensitive information leakage prevention method, and computer-readable recording medium
摘要 A client device (100) determines whether or not access is allowed, based on security levels that are set for an application program and data held in a server device (200), and performs authentication with the server device (200) based on a challenge code generated using packet data from the application program. The server device (200), when the challenge code is transmitted thereto, transmits a preset response code to the client device (100), and permits access by the client device (100) if the server device (200) receives a set response to the response code from the client device (100).
申请公布号 US9438629(B2) 申请公布日期 2016.09.06
申请号 US201214362169 申请日期 2012.10.04
申请人 NEC SOLUTION INNOVATORS, LTD. 发明人 Takeyasu Hiroaki
分类号 G06F11/00;H04L29/06;H04L9/32 主分类号 G06F11/00
代理机构 代理人
主权项 1. A sensitive information leakage prevention system for preventing leakage of sensitive information between a client device and a server device, comprising: a client device realized by a computer and configured to execute an application program; and a server device realized by a computer and configured to hold data to be used by the application program, wherein a processor of the client device the client device determines whether or not access by the application program is allowed, based on a security level that is set for the application program and a security level that is provided to data held in the server device, and transmits, if it is determined that access is allowed, a challenge code that is generated using packet data from the application program to the server device and requests authentication, and a processor of the server device transmits, when the challenge code is transmitted thereto, a preset response code to the client device, determines that authentication is successful if the server device receives a set response to the response code from the client device, and thereafter permits access by the client device, wherein the client device assigns a label that indicates a preset security level to each of a plurality of application programs including the application program, wherein the client device monitors network access by the application programs, and upon network access by an application program having begun, determines s allowed in accordance the label assigned to the application program and a label of an access destination folder, wherein the server devices performs authentication processing with the client device in which access control is performed in accordance with the labels, and wherein the server device performs no authentication processing with the client device in which access control cannot be performed in accordance with the client device, such that all network communication is prohibited.
地址 Tokyo JP