Network-Isolated Storage Selection for Data Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In information processing apparatuses that connect to multiple networks, there is a risk of data leakage from a network handling confidential data to a network handling non-confidential data, especially when a shared device like a digital MFP is used, as users may inadvertently select a storage area with improper output permissions.

Innovation Solution

The apparatus includes multiple network interfaces and storage areas, with an obtaining unit that determines the user's accessible networks and a presenting unit that restricts the selection of storage areas to only those with permitted output paths, ensuring data is not transmitted to unauthorized networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an information processing apparatus connects to multiple networks simultaneously to share the device, then device utilization and cost-effectiveness improve, but the risk of data leakage from confidential networks to non-confidential networks increases

Engineering Contradiction:
Improvedevice sharing capabilityVSAvoiddata leakage risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The storage area is divided into multiple regions with different access permissions. Each region is associated with specific network interfaces, creating segmented access control. This allows the same storage device to serve multiple networks while preventing unauthorized data access across network boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The control unit acts as an intermediary between the storage areas and network interfaces. It manages data access requests by checking permission associations, allowing legitimate access while blocking unauthorized data leakage paths between networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If dedicated storage areas are created for different networks to prevent data leakage, then data security improves, but device complexity and management difficulty increase

Engineering Contradiction:
Improvedata leakage preventionVSAvoidstorage area management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The storage area management system provides universal functionality across multiple networks. A single control unit manages all storage areas and handles access control for different networks, eliminating the need for separate management systems for each network while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the permission parameters of storage areas dynamically based on network interface associations. Instead of creating physically separate storage areas, the same storage infrastructure is reconfigured with different access permissions for different networks, simplifying hardware while maintaining security.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If users can freely select any storage area for data output, then ease of operation improves, but the risk of selecting inappropriate storage areas with wrong output permissions increases

Engineering Contradiction:
Improveuser freedom in storage selectionVSAvoidimproper data output risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The control unit provides feedback to users about the permission status of storage areas. When a user attempts to access a storage area, the system checks the association between the user's network interface and the storage area's permitted interfaces, and either allows or denies access accordingly, preventing improper data output.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11553104B2Information processing apparatus capable of controlling a document stored in a memory not to leak to a network not permitted to access and non-transitory computer readable medium
Publication Date: 2023.01.10 FUJIFILM BUSINESS INNOVATION CORP
  • US11553104B2 patent drawing
  • US11553104B2 patent drawing
  • US11553104B2 patent drawing

AI summary

An information processing apparatus includes multiple network interfaces, multiple storage areas for saving data, an obtaining unit, and a presenting unit. The multiple network interfaces are connected to corresponding networks. For each of the multiple storage areas, a network interface permitted as an output path of the saved data is defined. The obtaining unit obtains network information indicating a network available to a group to which each user belongs. The presenting unit presents to a user a list of storage areas selectable as a data storage destination. The presenting unit presents a list of storage areas for which a network interface connected to a network available to the group to which the user belongs, which is indicated by the network information, is defined as the output path.