Skip to main content

SDF Function Specification


This is a feature specification document that organizes the user functions provided by SDF into large, medium, and small categories.


Major CategoryMid-categorySubcategoryDetailed DescriptionNote
EncryptionDRM EncryptionDAC EncryptionThe document owner directly specifies access permissions for encryption
- Control individual permissions such as reading, editing, decrypting, external transmission, and printing.
- Granting permissions on a user or group basis
MAC EncryptionAutomatic encryption applied according to the organization's security classification policy (Confidential, Restricted, General, etc.)
GRADE EncryptionEncryption based on security levels (Classified, Sensitive, Open), multi-DAC authorization assignment by level
AIP EncryptionApplying AIP ProtectionSelect the Microsoft AIP label defined by the organization to perform encryption
DecryptionDRM DecryptionSimplificationRemove both AIP + DRM protection from the encrypted document to restore it to the original document.
DecryptionOptionally remove only the external encryption layer, while maintaining the internal encryption.
AIP DecryptionAIP Protection ReleaseAIP label and decryption, if DRM is applied separately, DRM is maintained
Encryption VerificationType InquiryCheck Encryption TypeCheck the encryption types applied to the document (MAC, DAC, GRADE, Unencrypted)
Document Type IdentificationCheck Document Protection TypeDistinguishing between DRM documents, AIP documents, and general documents
Document Information RetrievalHeader RetrievalSecurity Header Information RetrievalAccess level of the encryption document, encryption method, policy information, etc. Security header query
Hidden Information InquiryDocument Tracking Information InquiryRetrieve tracking information such as document ID, author, creation path, security level, etc.
Label ListView All Label ListView the complete list of AIP labels available in the organization
Label DetailsIndividual Label Detail ViewView detailed settings, protection policies, and permission information by label ID
Hidden Information ManagementInquiryRetrieving Hidden AttributesRetrieving Custom Metadata Inserted in Office Documents (Department, Project Name, etc.)
additionalAdd Hidden AttributeInserting Name-Value Type Custom Metadata in Office Documents
deleteDelete Hidden AttributeDelete specific hidden attribute by specifying attribute name
Security Level ManagementGrade List InquiryView All Grade ListView the complete security classification list set in the organization and the associated label information.
Document Grade InquiryDocument Security Level InquiryCheck the current security level and confidentiality level applied to the document
Document Grade SettingDocument Security Level SettingsAssigning, Modifying, and Deleting Security Levels in the Document
Creating SOM FileFile CreationCreating files for external transmissionCreating a Secure Executable File (SOM) That Can Be Accessed Without Document Security Software
Access ControlPassword ProtectionSetting a password (combination of letters and numbers) for the SOM file
Save AsAllow/Block Save As Control
Print LimitationsPrint permission and number of times (1-10 times) limit, complete blocking possible
Access RestrictionView count limit (1 to 99 times or unlimited)
Automatic DestructionAutomatic destruction of documents after expiration date
Specific PC LimitationsDocument can only be viewed on the designated PC.
Viewer SettingsViewer SupportSelect Office/Image/Text Viewer when opening the SOM file.
Conditional PolicyPolicy Basic InformationPolicy Creation/ManagementPolicy name, description, version, activation status, and validity period management
App SelectionConnect App DesignationSelect the target app for policy application
User AssignmentUser/Group AssignmentSpecify Target Users/Groups for Policy Application and Set Exceptions
General DocumentExtension FilterAll/Not Applied/Select Specific Extensions (.docx, .xlsx, .pdf, etc.)
DRM DocumentDRM Type FilterAll/Not Applied/Select Specific DRM Type (DAC, MAC, GRADE)
AIP DocumentAIP label filterSelect All/Not Applied/Specific AIP Label
Security LevelGrade/Label FilterApply policies only to documents of a specific security level, combination of level + label possible
Hidden InformationHidden Attribute MatchingApply policy only to documents where the specific hidden attribute name and value match
Location/IP ConditionsIP-based conditionsApplication of Policy Based on Request Source IP Range (Internal/External Distinction)
Time ConditionTime-based conditionsPolicy Application/Exclusion by Requested Time Zone (Differentiation Between Business/Non-Business Hours)
DRM Encryption ExecutionDAC/MAC/GRADE applicationAutomatic encryption with the selected DRM type when conditions are met
AIP encryption executionApplying AIP LabelAutomatic encryption with the selected AIP label when conditions are met
Standardization ExecutionRemove all protectionsAutomatically remove both AIP + DRM protection when conditions are met
Decryption ExecutionRemove external protectionAutomatically remove only the external encryption layer when conditions are met, keep the internal encryption.
Capsule ExportCreating SOM FileAutomatic generation of SOM files with specified permissions when conditions are met
Insert Hidden InformationInserting MetadataAutomatic insertion of hidden information for classification/tracking in the document when conditions are met
Application of Security LevelsApply Security LabelAutomatically apply security level labels to documents when conditions are met
Maintain StateException PassMaintain current status without applying additional policies when conditions are met
Document EventsTrigger EventAutomatic execution of follow-up policies upon events such as encryption, decryption, and capsule extraction.