Network Interface Data Leakage Prevention via Storage Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information processing apparatuses with multiple network interfaces face challenges in preventing data leakage from a storage area to unauthorized networks, especially when sharing devices with different security requirements, as users may inadvertently select incorrect network interfaces for data transmission.

Innovation Solution

The apparatus includes a memory that stores regulation information defining permitted network interfaces for data output, with an input/output control section managing access and transmission based on this information to ensure secure data handling across different networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an information processing apparatus is connected to multiple networks through multiple network interfaces to enable sharing and cost efficiency, then the device can be accessed by different networks (first network with high confidentiality and second network with lower confidentiality), but data stored in the storage area may be leaked from the confidential network to the non-confidential network through unauthorized access paths

Engineering Contradiction:
Improvenetwork connectivityVSAvoiddata leakage
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the storage area into multiple independent storage areas, each associated with a specific network interface. This segmentation prevents data from one network from being accessed by another network, as each storage area is isolated and can only be accessed through its designated network interface. The segmentation principle directly addresses the data leakage issue by creating network-specific storage partitions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different access permissions and security attributes to different storage areas based on their associated network interfaces. Each storage area has specific access control rules tailored to its network context, allowing the system to maintain high security for confidential network data while permitting broader access for non-confidential network data. This localized security approach prevents unauthorized cross-network access.

Inventive Principle:
Principle #3Local quality

2Reliability

If regulation information is stored in the storage area itself, then access control can be enforced at the storage level, but the storage capacity is reduced due to the overhead of storing regulation information

Engineering Contradiction:
Improveaccess control enforcementVSAvoidstorage capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the regulation information from the storage area and stores it separately in a management table in the memory. This separation allows the storage area to be used exclusively for data storage without the overhead of storing access control information. The management table contains all necessary regulation information and is used by the control unit to enforce access control, thereby preserving storage capacity while maintaining reliable access control enforcement.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If all data in the storage area is made accessible to all network interfaces, then any network can access any data, but security and confidentiality requirements cannot be satisfied

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic access control where the accessible storage area is determined based on the network interface through which the access request arrives. The control unit dynamically adjusts the accessible storage area according to the requesting network interface and the associated regulation information. This dynamic approach allows the system to provide different levels of access to different networks, satisfying both ease of operation for authorized access and security compliance for confidential data.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11368601B2Information processing apparatus and non-transitory computer readable medium storing program
Publication Date: 2022.06.21 FUJIFILM BUSINESS INNOVATION CORP
  • US11368601B2 patent drawing
  • US11368601B2 patent drawing
  • US11368601B2 patent drawing

AI summary

An information processing apparatus includes; a plurality of network interfaces; a storage area for storing data; and a memory section that stores regulation information that defines a network interface permitted as an output path of data stored in the storage area in association with the storage area.