Skip to main content

Function Specification (Internal → External Access)

※ Last updated: 2026-04-02

This document is a functional specification for cases of securely accessing external internet and SaaS services from an internal work environment.
Common management features such as user, group, license, conditional policy, and authentication settings areSecurity365 Management Center Functional SpecificationPlease refer to.


RFP Notation Standards

NotationMeaningDescription
RequiredCommon Evaluation CriteriaCommonly Required Features in Web Isolation (RBI) Business RFP
SpecializationDifferentiation ItemsUnique features of SHIELD Gate provide an advantage over competitors —Recommendation to Add Evaluation Criteria to the RFP
SelectionAdditional ItemsFeatures proposed optionally based on customer requirements

User Features

Major CategorySubcategorysubcategoryDetailed descriptionRFP notationspecifications
Isolated BrowsingWeb AccessIsolated Browser AccessIsolation browser access feature that executes web browsing on the server and streams only the screen to neutralize online threats.Requiredlink
URL input fieldProvide an input field where users can directly enter a URL to access.Requiredlink
URL Input Field Search Engine IntegrationA feature that automatically links to the search results page of the configured search engine (Google, Naver, Daum, Nate, Bing) when a search term that is not in URL format is entered in the URL input field.Specializationlink
App AccessThe feature to access external SaaS through SHIELDGate and set user-specific access permissions.Requiredlink
Browser CompatibilityMulti-Browser SupportSupport features for major browsers such as Chrome, Edge, Firefox, and SafariRequiredlink
Support for Advanced Web FeaturesJavaScript interaction, WebGL 3D rendering, basic browser features such as translation, zooming, and right-clicking.Requiredlink
Fully Isolated ArchitectureDevice Isolation and Code/Data Blocking① There is no direct communication between the device browser and the corresponding web server, ② the script and HTML code of the web server do not execute on the device, and ③ cookies, temporary files, etc. are not stored on the device at all, resulting in a completely isolated structure.Specializationlink
HTTPS Single Port Secure CommunicationConnect to the RBI server using standard HTTPS (TCP 443) with a single port and single session without using UDP, and transmit 1:1 without relay servers such as TURN — no need for separate firewall port openings or relay infrastructure, ensuring a security level equivalent to or higher than VPN when accessing externally (such as IAP).Specializationlink
High-Quality Screen StreamingAn intelligent screen transmission feature that prioritizes sending keyframes immediately upon connection to ensure high quality from the initial screen, and automatically adjusts the resolution in the event of network jitter to maintain responsiveness instead of interruptions.Specializationlink
Security Plugin SupportEndpoint Broker TechnologyFunctionality that supports web applications requiring internal communication on PCs, such as banking security programs.Specializationlink
Access PermissionsAccess Environment-Based PermissionsA feature that sets app usage permissions based on user location, device, and time conditions.Requiredlink
User Behavior ControlAccess ControlAccess Allow/DenyA feature that allows or blocks access to target URLs and categories based on conditional policies.Requiredlink
Additional AuthenticationAdditional identity verification feature through email verification code or OTP authentication when access is grantedRequiredlink
Behavior ControlKeyboard Input BlockingA feature that blocks keyboard input in the isolated browserRequiredlink
Site Navigation BlockageA feature that blocks page navigation to external domains.Selectionlink
URL Exposure ControlA feature that controls the visibility of the current access URL in the URL input field based on conditions.Selectionlink
Idle Screen LockA feature that switches to the lock screen after a set idle time to protect data on the screen.Selectionlink
File Transfer ControlAllow/Block UploadsFeature to Allow or Block File Uploads in Isolated BrowserRequiredlink
Allow/Block DownloadsFeature to Allow or Block File Downloads in Isolated BrowserRequiredlink
Extension ControlFunction to control the allowance of file extensions during upload and downloadRequiredlink
Transmission via Interconnected SolutionsA feature that supports file upload and download through an existing network connection solution operating in a network separation environment.Specializationlink
Clipboard ControlBidirectional Clipboard ControlA feature that controls copy/paste direction between the isolated browser and the user PC.Requiredlink
Sensitive Information ControlBlocking Sensitive Information InputFunction to detect personal information patterns in user input and block transmission (including generative AI services)Specializationlink
Complete Logging of Generative AI Prompts and ResponsesA feature that allows for complete logging of input prompts and response content when using commercial generative AI.Specializationlink
Print ControlPrint Allow/Block and WatermarkFeature to Allow or Block Printing in Isolated Browser — Watermark with User Identifiable Information May Be Applied When AllowedRequiredlink
Screen SecuritySecurity ScreenBlocking and Guidance ScreenA feature that displays a blocking notification screen when a policy is blocked and provides a notification screen in case of technical issues such as connection errors or session termination.Requiredlink
Screen MarkingScreen MarkingFunction to display user identification information as a watermark on the screen (automatically inserted during screen capture as well)Requiredlink
File SecurityFile EncryptionEncryption Storage and Key ManagementFunction to encrypt and store files during upload and dispose of the encryption key when deleting files.Requiredlink
Extension ControlHandling by ExtensionFunction to control uploads and downloads according to file extension blocking policyRequiredlink
Malware Scanning and DisinfectionMalware Scanning and CDRA feature that automatically applies malware scanning and CDR (Content Disarm and Reconstruction) processing during file upload and download.Requiredlink
Sensitive Information DetectionAutomatic Sensitive Information DetectionA feature that automatically detects personal information within files and blocks transmission.Requiredlink
Document Viewer IntegrationSHIELD Viewer IntegrationFunction to provide read-only previews through SHIELD Viewer when downloading filesRequiredlink
File ManagementStorage IntegrationExternal Storage and Edge ServerIntegration features for external storage such as NAS, OneDrive, Google Drive, and Edge server-based local storage.Selectionlink
Document EditingCollaborative EditingMS365·Google Docs·Hancom Web·S3/NAS-based document collaboration featureSelectionlink
Read-Only ViewRead-Only Document Viewing Functionality through SHIELD ViewerSelectionlink
Teams IntegrationTeams File IntegrationFeatures that support file viewing, uploading, editing, and team-based tab access within the Teams appSelectionlink
File SharingSharing and Permission ManagementURL link sharing, specifying the sharer, and setting permissions, managing shared foldersSelectionlink
Exploration · Classification · CollaborationExploration and ClassificationFile and folder search, tagging, bookmarking, pinning important items to the top featureSelectionlink
Collaboration and HistoryDocument comment writing, file change notification subscription, viewing, editing, and downloading history check featuresSelectionlink
Deletion PolicyDeleted File ManagementA feature that automatically deletes files after retaining them for a certain period and allows setting the retention period for the file folder.Selectionlink
SaaS SupportSaaS CompatibilityMicrosoft 365Features that support M365 services such as Teams, Office365, Word, PowerPoint, and SSORequiredlink
Video ConferenceSupport for voice, video, and screen sharing features of video conferencing platforms such as Teams and Zoom.Requiredlink
Video StreamingSupport for video streaming and playback of DRM-protected contentSpecializationlink
InterfaceUI and MenuHide/Show Top BarA feature that allows you to hide or expand the top bar to support full-screen viewing and immersive browsing.Selectionlink
Home Menu and GNB ShortcutsSetting the Home Menu Usage and Displaying/Fixing Recently Accessed Apps and URLs in the GNBSelectionlink
Custom URL ButtonAdding a button to the top bar for calling external URLs and passing user information as parametersSelectionlink

Admin Features

Major CategorySubcategorysubcategoryDetailed descriptionRFP notationspecifications
Isolated Browser ControlAccess Control PolicyPolicy ManagementFunction to create, modify, delete, and manage the priority of access control policies for each member's work system.Requiredlink
Member and Condition SettingsFunction to designate the members subject to policy application and set conditions for location, time, and device.Requiredlink
Access to Business SystemA feature to individually set the accessibility of the app menu and URL input field menu.Requiredlink
Maximum Tab Count LimitA feature that controls the maximum number of tabs that can be opened simultaneously in an isolated browser.Selectionlink
Session ManagementReal-time Session MonitoringReal-time query function for resource status and tab information of all user sessions currently connected.Requiredlink
Session Force LogoutFunction to forcibly terminate the selected session immediately or with a grace period — input for termination reason (required), countdown warning displayed on user screen, simultaneous termination of all tabs, automatic saving of termination records supportedSpecializationlink
Access ControlApp and URL ManagementApp Access SettingsFunction to register apps accessible through SHIELDGate and set user-specific access permissionsRequiredlink
URL List · Group ManagementA feature that allows you to register and manage access control target URLs and group them for use as a policy application unit.Requiredlink
Manage Movable URLsFunction to register and control movable URLs in a specific SaaSSelectionlink
Web Category ManagementCategory View·Edit·RollbackFunction to check the category classification of the website and customize it or restore to default.Requiredlink
Connection Environment ControlConnection Condition RegistrationA feature to register user access environment conditions (IP, device, time, etc.) and set app access permissions.Requiredlink
Conditional PolicyPolicy ManagementPolicy Creation, Modification, DeletionA feature that supports adding, editing, and deleting conditional policies, adjusting priorities, importing and exporting, and setting expiration dates.Requiredlink
Importing and Exporting PoliciesExport conditional policies as a JSON (single) or ZIP (multiple) file, and the ability to import and register backup files.Selectionlink
Policy Application Status InquiryFunction to query policies that were actually applied (heating) and those that were not applied by period, sorted by the number of applications and the most recent application date — Excel download supportSpecializationlink
Download Policy Status ExcelFunction to download all registered policies or search results as an Excel (.xlsx) file (provided separately from JSON backup)Selectionlink
Target ApplicationMember SettingsFunction to designate policy application members and separately configure exclusion membersRequiredlink
Target Site SettingsFunction to select the target of policy application among the entire site, registered sites/groups, and web categories.Requiredlink
Connection ConditionsLocation, Time, Device ConditionsA feature that sets the policy application environment by combining location, time, and device conditions.Requiredlink
Access PolicyAccess Allow/Block and Additional AuthenticationFunction to set URL access blocking or allowing and configure email·OTP additional authenticationRequiredlink
Behavior ControlKeyboard · Site Navigation · URL ExposureFunction to control keyboard input, block external domain navigation, and set URL exposure based on conditionsRequiredlink
File Upload and Download ControlFunction to set whether file upload and download is allowed, along with conditions for file extensions and storage.Requiredlink
Clipboard · Screen LockFunction to Control Clipboard Direction Between Isolated Browser and PC and Set Idle Lock ScreenRequiredlink
Screen Marking · Printing WatermarkFunction to set whether to apply screen marking and print watermark by conditional policyRequiredlink
Context Menu ControlFunction to control the right-click menu of the RBI browser on an item-by-item basis (page background, text, links, images, videos, audio, input fields) for the target area — when an item is OFF, the associated shortcut keys are also blocked.Specializationlink
Sensitive Information ControlBlocking Sensitive Information InputFunction to detect personal information patterns in user input and block transmission (including generative AI services)Specializationlink
Screen Security SettingsLock Screen SettingsImage and Message CustomizationFunction to customize the image and guidance message displayed on the lock screenSelectionlink
Guide Screen SettingsImage and Text CustomizationFunction to set images and guidance text for error screens such as system errors and session termination.Selectionlink
Screen Marking SettingsWatermark Design SettingsFunction to set display information, font, angle, spacing, and transparency of screen marking and provide real-time preview.Requiredlink
File Security PolicyFile Transfer PolicyExtension · Conditional ControlFunction to set differential file upload and download transfer policies by extension, user, and site.Requiredlink
Clipboard and Print Watermark ControlFunction to set clipboard directionality between PC and browser and apply print watermarks.Specializationlink
File ManagementStorage ManagementStorage and Edge Server ConfigurationFunction to integrate external storage and register/manage Edge serversSelectionlink
Viewer and Permission PolicyDownload and Access Permission SettingsFunction to set viewing, editing, uploading, and downloading permissions by download repository policy and access path.Selectionlink
Authentication and IntegrationUser AuthenticationAuthentication IntegrationFunction to set up AD integrated authentication, SSO integration, OTP, and additional email authentication.Requiredlink
ProvisioningUser Automatic SynchronizationFunction to automatically synchronize users and groups by integrating with external systems.Selectionlink
User and Group ManagementAccount ManagementUser Registration and ManagementFunction to individually or batch register users and manage their activation status and passwords.Requiredlink
Group ManagementGroup Creation and Policy ApplicationFunction to create and manage units for organization and policy application and manage membersRequiredlink
Administrator SettingsRole-based permissionsSeparation of Administrator Roles and NotificationsFunction to refine administrator roles and provide notifications when key activities occurRequiredlink
License ManagementLicense AssignmentA feature that assigns licenses automatically or manually based on user activation status.Selectionlink
Account SecuritySecurity Policy ConfigurationFunction to set account security policies such as password rules, change cycles, and automatic logout.Requiredlink
System Operation SettingsMenu · PAC · Button SettingsFunction to configure the operating environment, such as menu display options, PAC file distribution, and custom URL buttons.Selectionlink
Logs and MonitoringLog InquirySystem LogFunction to view user and administrator activity logs, support for backup, archiving, and integrity verification.Requiredlink
Generative AI Usage LogLogging the entire content of queries (Input) and responses (Output) from major generative AI services such as ChatGPT, Claude, Gemini, Grok, and Perplexity, with the ability to filter and view based on AI service, user, duration, and conversation content — this can be used to understand AI usage status by user and for auditing information leaks within the company, with support for downloading in CSV format.Specializationlink
Log Storage and IntegrationLong-term Storage and SIEM TransmissionStore user logs for more than one year according to administrator settings, with features for proof of tamper prevention through backups and transmission to SIEM (Security Information and Event Management).Specializationlink
Access MonitoringConnection Status DashboardA feature that provides website access status and real-time isolated browser operation status on a dashboard.Requiredlink
Connection Quality and Error ManagementA feature that measures user-side connection speed and provides an interface for reporting errors.Selectionlink
System MonitoringNode MonitoringMonitoring system resource usage per node in an On-Premise environmentSelectionlink