Network Interface Data Leakage Prevention via Storage Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information processing apparatuses with multiple network interfaces face challenges in preventing data leakage from a storage area to unauthorized networks, especially when sharing devices with different security requirements, as users may inadvertently select incorrect network interfaces for data transmission.
Innovation Solution
The apparatus includes a memory that stores regulation information defining permitted network interfaces for data output, with an input/output control section managing access and transmission based on this information to ensure secure data handling across different networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an information processing apparatus is connected to multiple networks through multiple network interfaces to enable sharing and cost efficiency, then the device can be accessed by different networks (first network with high confidentiality and second network with lower confidentiality), but data stored in the storage area may be leaked from the confidential network to the non-confidential network through unauthorized access paths
Solution Approach 1:
The patent segments the storage area into multiple independent storage areas, each associated with a specific network interface. This segmentation prevents data from one network from being accessed by another network, as each storage area is isolated and can only be accessed through its designated network interface. The segmentation principle directly addresses the data leakage issue by creating network-specific storage partitions.
Solution Approach 2:
The patent applies local quality by assigning different access permissions and security attributes to different storage areas based on their associated network interfaces. Each storage area has specific access control rules tailored to its network context, allowing the system to maintain high security for confidential network data while permitting broader access for non-confidential network data. This localized security approach prevents unauthorized cross-network access.
2Reliability
If regulation information is stored in the storage area itself, then access control can be enforced at the storage level, but the storage capacity is reduced due to the overhead of storing regulation information
Solution Approach 1:
The patent extracts the regulation information from the storage area and stores it separately in a management table in the memory. This separation allows the storage area to be used exclusively for data storage without the overhead of storing access control information. The management table contains all necessary regulation information and is used by the control unit to enforce access control, thereby preserving storage capacity while maintaining reliable access control enforcement.
3Ease of operation
If all data in the storage area is made accessible to all network interfaces, then any network can access any data, but security and confidentiality requirements cannot be satisfied
Solution Approach 1:
The patent implements dynamic access control where the accessible storage area is determined based on the network interface through which the access request arrives. The control unit dynamically adjusts the accessible storage area according to the requesting network interface and the associated regulation information. This dynamic approach allows the system to provide different levels of access to different networks, satisfying both ease of operation for authorized access and security compliance for confidential data.
Data Source
AI summary
An information processing apparatus includes; a plurality of network interfaces; a storage area for storing data; and a memory section that stores regulation information that defines a network interface permitted as an output path of data stored in the storage area in association with the storage area.


