Driving device for security device system providing folder protection function and operating method thereof

JP7734385B2Active Publication Date: 2025-09-05KIWONTECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023554928
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-07-30
Publication Date
2025-09-05
Estimated Expiration
2041-07-30

AI Technical Summary

Technical Problem

Existing security systems face vulnerabilities due to uniform folder system architectures, making them susceptible to hacking and data leakage, with manual changes requiring significant time and resources.

Method used

A drive device and method that encrypts and dynamically converts folder structures within a security system, using an encryption processing unit to generate a converted tree structure, managed by a folder structure management unit, and converts file read commands, enhancing security without manual intervention.

Benefits of technology

This approach strengthens folder system security by preventing unauthorized access and minimizing costs and time for structural changes, ensuring continuous system integrity and protection against malicious intrusions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007734385000001
    Figure 0007734385000001
  • Figure 0007734385000002
    Figure 0007734385000002
  • Figure 0007734385000003
    Figure 0007734385000003
Patent Text Reader

Abstract

An operating method of a driving device for driving a security equipment system according to an embodiment of the present invention includes an encryption processing step of converting an original folder tree structure to generate converted tree structure information according to an encryption process of the security equipment system, a folder structure management step of managing folder structure conversion information of the security equipment system based on the converted tree structure information, and a conversion processing step of converting a path of a file read command requested from inside the security equipment system based on the folder structure conversion information.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a drive device and a method thereof, and more particularly to a drive device and an operating method thereof for a security device system that provides a folder protection function. [Background technology]

[0002] Generally, an operating system efficiently manages system hardware and software resources and coordinates data processing and work planning. A file system, which is a subsystem of such an operating system, can provide a data management system that allows users to search for and access data, such as files, stored in the system. Such file systems have different characteristics and can be provided in various types depending on the operating system. For example, file systems in Windows-based operating systems are typically provided as FAT32 (File Allocation Table 32) and NTFS (New Technology File System). File systems in Unix and Linux operating systems are provided as UFS (Unix File System) and EXT (Extended File System), respectively, and file systems for MacOS are provided as APFS (Apple file system).

[0003] A file system can logically manage data stored in a storage device so that the operating system can efficiently manage hardware and software resources. A file system can store data in a specific storage device space and provide a data management system that accesses the stored data so that it can be retrieved. Such a file system's data management system can be organized in a folder (directory) structure. The folder structure can be configured hierarchically, such as a tree structure.

[0004] As a result, the folder structure can be used as a location path for the system management process of the operating system and the execution of a specific application program. The folder structure also provides a storage location path for data files that need to be read (called) during the execution of the operating system process or application program, making them accessible.

[0005] On the other hand, if a hacker with malicious intent infiltrates an intranet through hacking, or a user who connects to a security equipment system through targeted email attacks or spear phishing, knows the data management system, which is the folder structure of the security equipment system, in advance, there is a risk that confidential information could easily be leaked or the security equipment system could malfunction.

[0006] In particular, when security systems are made by the same manufacturer, the folder system architecture is usually the same or similar, so by analyzing the same or similar equipment from that manufacturer, it is possible to disable the target equipment and easily seize files.

[0007] Although it is possible to sell folder system structures that are different for each piece of equipment, this takes time and money each time, and there are limitations to how much can be managed because it requires additional infrastructure construction and management costs for central management.

[0008] Furthermore, if the folder system structure is leaked, a security system engineer must be dispatched to change the system structure, which requires excessive time and expense since this must be done for each individual piece of equipment.If the folder system structure is leaked, it would be desirable to periodically change the folder system, but similarly, a security system engineer must be dispatched to change the system structure, which requires excessive time and expense since this must be done for each individual piece of equipment, and this response method has practical limitations. Summary of the Invention [Problem to be solved by the invention]

[0009] The present invention has been made to solve the above-mentioned conventional problems, and its object is to provide a driving device for a security equipment system and an operating method thereof, which provides a folder protection function that can control access to and process execution within the security equipment system, so as to prevent malicious external intruders or internal users from misusing information in a data management system within the security equipment system to disable the system and thereby causing harmful effects on the internal information system and illegal data leakage, modification, and destruction. [Means for solving the problem]

[0010] A method according to an embodiment of the present invention to solve the above problem includes, in an operating method of a driving device that drives the security equipment system, an encryption processing step of converting an original folder tree structure to generate converted tree structure information according to an encryption process of the security equipment system, a folder structure management step of managing folder structure conversion information of the security equipment system based on the converted tree structure information, and a conversion processing step of converting a path of a file read command requested from inside the security equipment system based on the folder structure conversion information.

[0011] In addition, an apparatus according to an embodiment of the present invention for solving the above-mentioned problems is a driving device for a security equipment system, including a folder structure management unit that manages folder structure conversion information of the security equipment system, and a conversion processing unit that converts the path of a file read command requested from inside the security equipment system based on the folder structure conversion information.

[0012] The method according to the embodiment of the present invention for solving the above problems can be embodied as a program for executing the method or a computer-readable recording medium having the program recorded thereon. [Effects of the Invention]

[0013] According to an embodiment of the present invention, the structure of a folder system, which is a data management system, can be dynamically changed to prevent hackers or internal users who maliciously access an intranet security equipment system. This strengthens the security of the folder system structure applied and operated as a default to the security equipment system, ensuring normal security functions of the security equipment system and thereby protecting the internal information system from intruders. Furthermore, security enhancement can be maximized by allowing an administrator to directly change the folder system structure of the security equipment system periodically or as needed through a user interface. In this way, the folder system structure can be dynamically changed without an on-site visit by a manufacturer's engineer or security equipment expert, minimizing the time required for setting changes and reducing costs. [Brief explanation of the drawings]

[0014] [Figure 1] 1 is a conceptual diagram illustrating an overall system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing in more detail a driving device according to an embodiment of the present invention. [Figure 3] 4 is a flowchart illustrating an operation method of a driving device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0015] The following merely exemplifies the principles of the present invention. Therefore, those skilled in the art will be able to devise various devices and methods that embody the principles of the present invention and fall within the concept and scope of the present invention, even if not explicitly described or illustrated herein. Furthermore, all conditional terms and embodiments listed in this specification are expressly intended solely for the purpose of helping to understand the concept of the present invention, and should not be understood as being limited to the embodiments and conditions specifically listed in this specification.

[0016] Furthermore, all detailed descriptions reciting specific embodiments as well as principles, aspects, and embodiments of the present invention should be understood to be intended to encompass structural and functional equivalents of such items, and these equivalents should be understood to include not only currently known equivalents but also equivalents developed in the future, i.e., all elements invented to perform the same function, regardless of structure.

[0017] Thus, for example, the block diagrams herein should be understood to represent conceptual views of illustrative circuitry embodying the principles of the invention. Likewise, all flowcharts, state change diagrams, pseudocode, and the like, may be substantially represented on a computer-readable medium and should be understood to represent various processes performed by a computer or processor, whether or not a computer or processor is explicitly illustrated.

[0018] The functions of the various elements illustrated in the figures, including functional blocks represented as processors or similar concepts, may be provided through the use of dedicated hardware as well as hardware capable of executing software in association with suitable software. When provided by a processor, the functions may be provided by a single dedicated processor, a single shared processor, or a plurality of individual processors, some of which may be shared.

[0019] Additionally, the explicit use of terms such as processor, control, or similar concepts should not be construed as exclusively referring to hardware capable of executing software, but should be understood to implicitly include, without limitation, digital signal processor (DSP) hardware, ROM, RAM, and non-volatile memory for storing software. Other hardware known and commonly used may also be included.

[0020] In the claims of this specification, elements expressed as means for performing a function described in the detailed description are intended to include any method of performing that function, including, for example, a combination of circuit elements that perform that function, or any form of software, including firmware / microcode, combined with appropriate circuitry for executing the software to perform that function. The invention defined by these claims is such that the functions provided by the various recited means are combined and combined in the manner required by the claims, and therefore any means that can provide those functions should be understood to be equivalent to those grasped from this specification.

[0021] The above-mentioned objects, features, and advantages will become more apparent through the following detailed description taken in conjunction with the accompanying drawings, so that those skilled in the art can easily implement the technical concept of the present invention. Furthermore, when it is determined that a detailed description of well-known technologies related to the present invention may unnecessarily obscure the gist of the present invention, the detailed description will be omitted.

[0022] Hereinafter, preferred embodiments of the present invention will be described in more detail with reference to the accompanying drawings. In order to facilitate overall understanding, the same components in the drawings will be designated by the same reference numerals, and redundant description of the same components will be omitted.

[0023] FIG. 1 is a conceptual diagram showing an outline of an entire system according to an embodiment of the present invention.

[0024] An overall system including a security device system providing a folder protection function according to an embodiment of the present invention may include an internal IT system 1 and an external IT system 200. The internal IT system 1 may include a security device system 10, a network device 20, and a server / client 30.

[0025] The internal IT system 1 can be configured independently from the external network (Internet network) through a communication path that branches off from the external network. In this case, the internal IT system 1 can secure a communication path independent from the extranet through communication equipment (not shown) such as an Internet gateway router, thereby enabling the construction of an additional IT infrastructure below the Internet gateway router. The internal IT system 1 can be configured to utilize IT resources, including a security equipment system 10, network devices 20, and server / client 30 that transfers, shares, and processes data.

[0026] In this case, the security device system 10 may include information protection equipment or systems that can block unauthorized connections from the extranet and prevent the inflow of abnormal data. Specifically, the security device system 10 may include a network firewall, a web firewall, an anti-DDoS, a network access control (NAC), an intrusion prevention system (IPS), and a spam mail blocking system.

[0027] Here, the driving device 100 according to an embodiment of the present invention may be an operation control device that is installed in the security equipment system 10 and controls the operation of the security equipment system 10, and may include one or more hardware modules and a software module for operating the hardware modules. For example, the driving device 100 may include one or more microprocessor-based circuits in which a software operating system is implemented in hardware to operate a network firewall, a web firewall, anti-DDoS, a network access control (NAC), an intrusion prevention system (IPS), a spam blocking system, etc. by driving the security equipment system 10.

[0028] The network device 20 may also be configured with equipment such as a router, a switch, a hub, etc., that performs communication path specification and expansion functions.

[0029] Servers can be classified into mail servers, web servers, web application servers, database servers, etc., and clients can be classified into user terminals such as PCs and terminals.

[0030] The external IT system 200 is an unspecified IT system connected to an external network, through which required data transfer, exchange and processing services can be provided.

[0031] The internal IT system 1 can be connected to the security equipment system 10, the network device 20, and the server / client 30 through an intranet, and can communicate with each other. The internal IT system 1 can also be connected to the external IT system 200 through an external network (Internet network), and can communicate with each other.

[0032] Here, each of the networks can be implemented as any type of wired or wireless network, such as a local area network (LAN), a wide area network (WAN), a value-added area network (VAN), a personal area network (PAN), a mobile radio communication network, or a satellite communication network.

[0033] The user terminal may be an individual device selected from the group consisting of a computer, a mobile phone, a smart phone, a smart pad, a laptop computer, a personal digital assistant (PDA), and a portable media player (PMP), or may be a multi-device including at least one of a shared device such as a kiosk or a fixed display device installed in a specific location. This allows the user terminal to use data transmission / reception services for IT resources provided by the internal IT system 1 and the external IT system 200.

[0034] FIG. 2 is a block diagram showing in more detail the driving device according to one embodiment of the present invention.

[0035] 2, the driving device 100 of the security equipment system 10 according to the embodiment of the present invention includes a control unit 110, a folder structure management unit 120, an encryption processing unit 130, a conversion processing unit 140, an interface providing unit 150, and a communication unit 160. Furthermore, the encryption processing unit 130 may include a normal conversion confirmation unit 131.

[0036] As described above, the driving device 100 according to an embodiment of the present invention may be an operation control device that is installed in the security equipment system 10 and controls the operation of the security equipment system 10, and may include one or more hardware modules for this purpose and a software module for operating the same.

[0037] First, the control unit 110 may be implemented with one or more processors for controlling the operation of folders and file systems of the security equipment system 10 and for overall control of the operation of each component of the driving device 100. For example, the control unit 110 of the driving device 100 may include one or more microprocessor-based driving circuits that implement in hardware all or part of the software operating system functions that operate a network firewall, a web firewall, anti-DDoS, a network access control (NAC), an intrusion prevention system (IPS), a spam blocking system, etc., by driving the security equipment system 10.

[0038] The folder structure management unit 120 can then manage folder structure conversion information of the security equipment system 10. The folder structure conversion information can be generated according to an encryption process previously performed by the encryption processing unit 130. The folder structure conversion information can also include converted tree structure information obtained by converting the tree structure of the original folders of the security equipment system 10. The folder structure conversion information can also include tree structure information of the original folders that is mapped to the converted tree structure information.

[0039] The folder structure management unit 120 can provide a hierarchical storage system using a folder tree structure to uniquely represent the location path of files present in a storage device included in the security equipment system 10. As a result, the folder structure management unit 120 can use the hierarchical storage system to ensure a unique path when changes such as expansion and contraction of the folder tree structure are made. The hierarchical storage system can designate or assign text such as letters, numbers, and symbols to be assigned to folder names generated as each folder tree structure, and can restrict use by generating an unauthorized event for duplicate or unauthorized text.

[0040] For reference, files can be classified into data files, program files, system files, etc. Among these, system files can be managed by an operating system installed to control the hardware and software provided for the operation of the security device system.

[0041] The folder structure management unit 120 can separately manage tree structure information of the original folder using a hierarchical storage system. The folder structure management unit 120 can manage the tree structure information of the original folder as a default tree structure and store it in a non-volatile memory. The folder structure management unit 120 can block access to data deletion and change processes for the tree structure information of the original folder, which is the default tree structure.

[0042] The folder structure management unit 120 can manage a default tree structure in which related data files are located as tree structure information of original folders so that processes required for driving and providing functions of the security device system 10 can be performed.

[0043] In this way, the folder structure management unit 120 can map folder structure conversion information acquired by expanding, contracting, or converting the folder tree structure when an event related to a change in the folder tree structure occurs based on the tree structure information of the original folder. As a result, the folder structure conversion information can correctly track the path of a file read command issued from within the security device system 10.

[0044] The folder structure management unit 120 can store and manage folder structure conversion information in a random access memory configured in the security device system 10. In response to a file read command, the folder structure management unit 120 searches for folder structure conversion information resident in the random access memory, thereby obtaining the location path of the file from which the file is to be read.

[0045] The folder structure management unit 120 can store and activate folder structure conversion information in a random access memory when the security device system 10 is started up. On the other hand, information about the original tree structure can be stored in a non-volatile memory and managed as master information.

[0046] The encryption processing unit 130 performs an encryption process to convert the tree structure of the original folder into a converted tree structure. The tree structure of the original folder and the converted tree structure may be stored as folder structure conversion information and managed by the folder structure management unit 120. The encryption process may include a process of mapping the tree structure information of the original folder to the converted tree structure that has been randomly encrypted.

[0047] The encryption process can convert each folder name included in the tree structure information of the original folder by inputting arbitrary text through a random encryption process. Also, the encryption process can convert the folder name of the primarily processed converted tree structure by random encryption process to each folder name when a conversion event occurs, to generate a secondary converted tree structure.

[0048] In this case, the encryption process can select target folders whose names should be changed in the folder tree structure and set the minimum or maximum number of target folders whose names should be changed. The encryption process can also set the type of text to be applied to the folder name and the minimum or maximum length of the selected text. The encryption process can also set whether to change a specific part of an existing folder name or to change the entire existing folder name. In this way, the encryption process can set different scopes and types of targets to be changed in the original folder tree structure.

[0049] In this way, the encryption process may be performed in a random encryption manner, with settings for the scope and type of change in folder structure or folder name. Furthermore, the encryption process may be applied in a manner that swaps and mixes folder names between folders using currently assigned folder names.

[0050] The random encryption process may include an encryption process that randomly changes at least one of the depth or path name of the tree structure information of the original folder to generate the converted tree structure. For example, the random encryption process may generate a converted tree structure by changing the tree structure of the original folder containing the "123.sys" file in the "2" folder, which is a subfolder of the top-level "1" folder in the tree structure information of the original folder, and the "3" folder, which is a subfolder of the "2" folder, to the "A" folder and the "2" folder to the "A2" folder. In addition, the converted tree structure may generate an "A4" folder under the converted "A3" folder and convert it to the path where the "123.sys" file is located in the "A4" folder.

[0051] In addition, the encryption processing unit 130 may perform a chain conversion on the converted tree structure obtained by converting the tree structure of the initial original folder. For example, the encryption processing unit 130 may convert the tree structure of the original folder to obtain a first converted tree structure. Subsequently, the encryption processing unit 130 may perform an encryption process on the first converted tree structure to obtain a second converted tree structure. In this way, the [n]th converted tree structure may be converted into the [n+1]th, [n+2]th, [n+3]th, ..., [n+m]th converted tree structures by performing the encryption process.

[0052] The encryption process can be repeatedly performed at each elapsed first period by the operation of the security device system 10. The encryption process can be performed based on settings input according to an administrator's periodic inspection schedule, or can be performed immediately as needed. The encryption process generates and applies a conversion tree structure periodically or as needed, thereby strengthening security and preventing the risk of external intrusion or malicious insider access to the system that may be caused by the leakage of folder structure information, while also ensuring the integrity of the internal system.

[0053] The encryption processing unit 130 may include a normal conversion confirmation unit 131. The normal conversion confirmation unit 131 may cancel the ongoing operation if an error occurs in the converted tree structure mapped to the tree structure information of the original folder or if it is determined that the path is not unique. The normal conversion confirmation unit 131 may check for abnormalities by determining consistency with the existing tree structure before the converted tree structure is finally saved as folder structure conversion information.

[0054] According to an embodiment of the present invention, the encryption processing unit 130 may generate the following conversion tree structure. A particular storage device, i.e., a disk, may have an original folder tree structure in which top-level folders are "A1," "A2," and "A3," subfolders of the "A1" folder are "B11" and "B12," subfolders of the "A2" folder are "B21," and subfolders of the "A3" folder are "B31," "B32," and "B1." The encryption processing unit 130 performs an encryption process to convert the original folder tree structure as follows: The encryption processing unit 130 converts only the "A1" folder to "B1" through a random encryption process in the encryption process. Through the encryption process, the encryption processing unit 130 may obtain a conversion tree structure in which the "B1" folder has subfolders "B11" and "B12," the "A2" folder has subfolders "B21," and the "A3" folder has subfolders "B31," "B32," and "B1." In this case, the normal conversion confirmation unit 131 acquires "B1," "A2," and "A3" as folders in the top hierarchy, but the "B1" folder, which is the top hierarchy folder, may have the same folder name as "B1," which is a subfolder of the "A3" folder. In this case, consistency can be determined according to the conditions of the normal conversion confirmation unit 131 for ensuring a unique path. If the normal conversion confirmation unit 131 restricts the use of duplicate folder names as a consistency determination condition, the conversion tree structure converted to "B1" is canceled and the folder name structure can be restored to its original state. If the normal conversion confirmation unit 131 sets the consistency determination condition based on the file path to the absolute path and allows duplicate folder names in other hierarchy levels, the converted tree structure is approved and can be managed as folder structure conversion information.

[0055] In this way, when conversion to the original tree structure is required, such as when an error occurs during folder structure conversion or when the user's folder structure encryption input corresponds to a rollback command, the encryption processing unit 130 can perform a rollback function using master information that is the original tree structure and return the folder structure to the original tree structure.

[0056] The conversion processing unit 140 can convert the path of a file read command issued from within the security equipment system 10 based on the folder structure conversion information.

[0057] According to one embodiment of the present invention, the tree structure of the original folder may be composed of top-level folders "dir1," "dir2," and "dir3," folders under "dir1" may be "dir11," "dir12," and "dir13," folders under "dir2" may be "dir21," "dir22," and "dir23," and folders under "dir3" may be "dir31" or "dir32." Furthermore, folders under "dir31" may be "dir41" and "dir42," and an executable file "setup.exe" may exist in "dir41." When " / " is used as a separator to distinguish between upper and lower folders, the entire path of the executable file "setup.exe" may be expressed as "dir3 / dir31 / dir41." In this case, the encryption processor 130 performs an encryption process based on the folder structure encryption input, converting the folder names of the "dir3" folder to "change3," the "dir31" folder to "change31," and the "dir41" folder to "change41," respectively, and acquiring conversion tree structure information to include in the folder structure conversion information. As a result, when the "setup.exe" file is called by a process related to the operation of the security device system, the executable file can be called and executed through the file path "change3 / change31 / change41" rather than the existing path "dir3 / dir31 / dir41." Furthermore, the folder structure conversion information resides in random access memory, and can be acquired by mapping the file paths for files that must be read by the "setup.exe" file to the folder structure conversion information in random access memory.In this way, the file paths used by 'setup.exe' and specific processes are also converted, so the folder structure conversion information can block access to executable files from malicious external intruders or internal users who know the initial folder tree structure information configured in the security device system, and at the same time, it can protect system files or configuration files that can control the functions of the security device.

[0058] The interface providing unit 150 may output an administrator interface driven by the security device system 10 to process a pre-executed encryption process. The pre-executed encryption process may be processed by a user's folder structure encryption input corresponding to the administrator interface. The folder structure encryption input may include an instruction to immediately execute the encryption process or an instruction to set a repetition period.

[0059] FIG. 3 is a flowchart illustrating a method of operating a driving device according to an embodiment of the present invention.

[0060] Referring to FIG. 3, in the operating method of the driving device of the security device system providing the folder protection function, the encryption processing step (S101) may convert the tree structure of the original folder through the encryption process of the security device system 10 to generate converted tree structure information.

[0061] The folder structure management step (S103) may manage folder structure conversion information of the security equipment system 10 based on the conversion tree structure information. The folder structure management step (S103) may store and manage the folder structure conversion information in a random access memory of the security equipment system. The folder structure conversion information is generated when the security equipment system 10 is started up and is stored in the random access memory as a volatile storage.

[0062] The folder structure conversion information may be generated by a pre-encryption process performed in the encryption process step (S101) and may include the converted tree structure information and tree structure information of an original folder mapped to the converted tree structure information. The pre-encryption process may include a process of mapping the tree structure information of the original folder to the converted tree structure that has been randomly encrypted. The random encryption process may include an encryption process of randomly changing at least one of the depth or path name of the tree structure information of the original folder to generate the converted tree structure.

[0063] The pre-executed encryption process can be repeated for each first cycle elapsed by the operation of the security device system 10 .

[0064] The conversion process step (S105) can convert the path of a file read command requested from within the security device system based on the folder structure conversion information.

[0065] The interface providing step (S107) may output an administrator interface driven by the security device system 10 to process the pre-executed encryption process. The pre-executed encryption process may be processed by inputting a user's folder structure encryption corresponding to the administrator interface. The folder structure encryption input may include an instruction to immediately execute the encryption process or an instruction to set a repetition period.

[0066] The method according to the present invention described above can be produced as a program to be executed by a computer and stored in a computer-readable recording medium, examples of which include ROM, RAM, CD-ROM, magnetic tape, floppy disk, optical data storage device, etc.

[0067] The computer-readable recording medium can be distributed among computer systems connected via a network, and the computer-readable code can be stored and executed in a distributed manner.Functional programs, codes, and code segments for implementing the method can be easily construed by programmers skilled in the art to which the present invention pertains.

[0068] Furthermore, although the preferred embodiments of the present invention have been illustrated and described above, the present invention is not limited to the specific embodiments described above, and various modifications can be made by a person having ordinary skill in the art to which the invention pertains without departing from the gist of the present invention as claimed in the claims, and these modifications should not be understood individually from the technical ideas and perspectives of the present invention.

Claims

1. A driving device for driving a security device system, a folder structure management unit that manages folder structure conversion information of the security device system; an encryption processing unit that converts the tree structure of an original folder to obtain a converted tree structure according to an encryption process of the security device system, determines consistency between the obtained converted tree structure and the tree structure of the original folder, and then stores folder structure conversion information including the tree structure of the original folder and the converted tree structure in a volatile manner in a random access memory, and performs a roll-back to return the folder structure to the tree structure of the original folder stored in the non-volatile memory if an error occurs in the conversion of the converted tree structure as a result of the consistency determination; a conversion processing unit that converts a path of a file read command issued from inside the security device system based on the folder structure conversion information stored in the random access memory as a volatile memory; A drive device for a security equipment system, comprising:

2. The encryption process comprises:

2. The driving device of claim 1, further comprising a process for mapping the tree structure of the original folder to the randomly encrypted transformed tree structure.

3. The random encryption process includes: The driving device for the security device system according to claim 2 , further comprising an encryption process for randomly changing at least one of the depth and path name of the tree structure of the original folder to generate a converted tree structure.

4. The encryption process comprises:

3. The driving device for a security device system according to claim 2, wherein the driving device is repeatedly executed for each first period that has elapsed due to driving of the security device system.

5. an interface providing unit that outputs an administrator interface driven by the security device system to process the encryption process; The driving device of the security device system according to claim 2 , wherein the encryption process is handled by encrypting a folder structure input of a user corresponding to the administrator interface.

6. The encrypted input of the folder structure is:

6. The driving device for a security equipment system according to claim 5, further comprising an instruction to immediately execute the encryption process or an instruction to set a repetition period.

7. A method for operating a driving device that drives a security equipment system, comprising: Transforming the tree structure of the original folder according to the encryption process of the security device system to obtain a transformed tree structure; determining whether the obtained converted tree structure is consistent with the tree structure of the original folder, and then volatilely storing folder structure conversion information including the tree structure of the original folder and the converted tree structure in a random access memory; If an error occurs in the conversion of the conversion tree structure as a result of the consistency determination, performing a roll-back to return the folder structure to the tree structure of the original folder stored in a non-volatile memory; converting a path of a file read command requested from inside the security device system based on the folder structure conversion information stored in the random access memory as a volatile memory; A method for operating a drive device that drives a security equipment system, comprising:

8. The encryption process comprises:

8. A method for operating a driver that drives a security equipment system according to claim 7, comprising the step of mapping the tree structure of the original folder to the converted tree structure that has been subjected to random encryption.

9. The random encryption process includes:

9. A method for operating a driver that drives a security equipment system according to claim 8, comprising an encryption process that randomly changes at least one of the depth and path name of the tree structure of the original folder to generate a converted tree structure.

10. The encryption process comprises:

9. The method for operating a drive device for driving a security equipment system according to claim 8, which is repeatedly performed for each first period that has elapsed due to driving of the security equipment system.

11. and further comprising an interface providing step of outputting an administrator interface driven by the security device system to process the encryption process; The method of claim 8, wherein the encryption process is performed by encrypting a folder structure of a user corresponding to the administrator interface.

12. The encrypted input of the folder structure is:

12. A method for operating a driving device that drives a security equipment system according to claim 11, comprising an instruction to immediately execute the encryption process or an instruction to set a repetition period for the encryption process.

Citation Information

Patent Citations

  • Information disclosure restriction system

    JP2001356983A

  • Information processor, information processing method, and information processing program

    JP2010146196A

  • Secure network storage system, method, client device, server device, and program

    JP2012068988A

  • Encoding and decoding apparatus, method, and program, and recording medium

    WO2008084738A1