Network-Isolated Storage Selection for Data Leakage Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In information processing apparatuses that connect to multiple networks, there is a risk of data leakage from a network handling confidential data to a network handling non-confidential data, especially when a shared device like a digital MFP is used, as users may inadvertently select a storage area with improper output permissions.
Innovation Solution
The apparatus includes multiple network interfaces and storage areas, with an obtaining unit that determines the user's accessible networks and a presenting unit that restricts the selection of storage areas to only those with permitted output paths, ensuring data is not transmitted to unauthorized networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an information processing apparatus connects to multiple networks simultaneously to share the device, then device utilization and cost-effectiveness improve, but the risk of data leakage from confidential networks to non-confidential networks increases
Solution Approach 1:
The storage area is divided into multiple regions with different access permissions. Each region is associated with specific network interfaces, creating segmented access control. This allows the same storage device to serve multiple networks while preventing unauthorized data access across network boundaries.
Solution Approach 2:
The control unit acts as an intermediary between the storage areas and network interfaces. It manages data access requests by checking permission associations, allowing legitimate access while blocking unauthorized data leakage paths between networks.
2Object-affected harmful factors
If dedicated storage areas are created for different networks to prevent data leakage, then data security improves, but device complexity and management difficulty increase
Solution Approach 1:
The storage area management system provides universal functionality across multiple networks. A single control unit manages all storage areas and handles access control for different networks, eliminating the need for separate management systems for each network while maintaining security.
Solution Approach 2:
The system changes the permission parameters of storage areas dynamically based on network interface associations. Instead of creating physically separate storage areas, the same storage infrastructure is reconfigured with different access permissions for different networks, simplifying hardware while maintaining security.
3Ease of operation
If users can freely select any storage area for data output, then ease of operation improves, but the risk of selecting inappropriate storage areas with wrong output permissions increases
Solution Approach 1:
The control unit provides feedback to users about the permission status of storage areas. When a user attempts to access a storage area, the system checks the association between the user's network interface and the storage area's permitted interfaces, and either allows or denies access accordingly, preventing improper data output.
Data Source
AI summary
An information processing apparatus includes multiple network interfaces, multiple storage areas for saving data, an obtaining unit, and a presenting unit. The multiple network interfaces are connected to corresponding networks. For each of the multiple storage areas, a network interface permitted as an output path of the saved data is defined. The obtaining unit obtains network information indicating a network available to a group to which each user belongs. The presenting unit presents to a user a list of storage areas selectable as a data storage destination. The presenting unit presents a list of storage areas for which a network interface connected to a network available to the group to which the user belongs, which is indicated by the network information, is defined as the output path.


