Storage Area Attribute Change Control for Data Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information processing apparatuses connected to multiple networks face challenges in preventing data leakage from secure to non-secure networks, particularly when attributes set for storage areas are changed, potentially allowing data to be output via unauthorized network interfaces.

Innovation Solution

An information processing apparatus with multiple network interfaces and a storage area, where a change controller manages attribute changes based on the presence of data, ensuring that data is only output via permitted network interfaces, and includes a mechanism to prevent unintended leakage by authenticating users and controlling input/output operations based on predefined access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated storage area for saving data from the first network is provided with an attribute restricting output paths, then data leakage from the first network to the second network is prevented, but the attribute cannot be changed when data is present in the storage area

Engineering Contradiction:
Improvedata securityVSAvoidattribute changeability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by detecting the presence of data in the storage area before allowing attribute changes. When data is detected, the system proactively prevents the attribute change operation, thereby maintaining data security without requiring continuous monitoring during the change process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback control by continuously monitoring the storage area state and using this information to control whether attribute changes are permitted. The detection unit provides feedback about data presence to the control unit, which then decides whether to allow or prevent attribute changes, creating a closed-loop security mechanism.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If unlimited changes to the storage area attribute are permitted, then adaptability is improved, but data that was present before the change may be output via unauthorized network interfaces

Engineering Contradiction:
Improveattribute changeabilityVSAvoiddata leakage risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by detecting data presence and preventing attribute changes that would create security vulnerabilities. The control unit anticipates potential data leakage risks by checking the storage state before permitting attribute changes, thereby counteracting harmful effects before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The detection unit acts as an intermediary between the storage area and the attribute change operation. It monitors the storage state and mediates whether the attribute change should be permitted, preventing direct unauthorized changes while allowing legitimate modifications when the storage area is empty.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If the information processing apparatus is shared between the first network and the second network, then cost efficiency is improved, but the risk of data leakage from the first network to the second network increases

Engineering Contradiction:
Improvecost efficiencyVSAvoiddata leakage risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system segments the storage area into logically separated regions with different access permissions. By dividing the storage functionality and applying different attribute restrictions to different segments, the system enables cost-effective sharing between networks while maintaining security boundaries that prevent data leakage from the first network to the second network.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11182116B2Information processing apparatus and non-transitory computer readable medium
Publication Date: 2021.11.23 FUJIFILM BUSINESS INNOVATION CORP
  • US11182116B2 patent drawing
  • US11182116B2 patent drawing
  • US11182116B2 patent drawing

AI summary

An information processing apparatus includes multiple network interfaces, a storage area that saves data, and a change controller. An attribute defining a network interface permitted as an output path of the saved data is associated with the storage area. The change controller controls a change of the attribute corresponding to a change instruction to change the attribute, in accordance with a state regarding presence/absence of data in the storage area at a time point of receiving the change instruction.