Skip to main content

Usage Scenarios

Introducing how to utilize SHIELD Gate in various work environments.


1. VPN Alternative​

situation​

Remote Access Environment of Large Organizations

The problem many organizations face:

  • Burden of installing and managing VPN clients on all employee PCs
  • Version updates, certificate renewals, and other ongoing management are necessary.
  • Access to the entire internal network after VPN connection (security risk)
  • Connection delay during peak times due to simultaneous user limit
  • Slow speed due to encryption overhead

Utilizing SHIELD Gate​

Composition Plan

1. Internal Work System Registration
- ERP, Groupware, HR System, etc.
- Register access URLs for each system

2. Conditional Policy Settings
- Internal IP: Allow all functions
- Remote IP: Restricted functions + OTP
- Overseas IP: Block or require approval

3. Authentication Integration
- Active Directory SSO
- Microsoft 365 account integration
- Google Workspace integration

4. Gradual Transition
- Step 1: Operate in parallel with VPN
- Step 2: Transition some departments to SHIELD Gate
- Step 3: Expand company-wide

Expected Effects

  • Simplification of Management: No client installation or management required
  • Strengthening Security: Application-level access control instead of network-level
  • Performance Improvement: Faster connection speed compared to VPN
  • scalability: Unlimited simultaneous connections supported
  • Cost Reduction: Reducing VPN Equipment and License Costs

2. Vendor Access Management​

situation​

Collaboration with multiple external partners

Challenges in Managing Partner Companies:

  • Separate account issuance and management for each partner company
  • Account Recovery Omission After Project Completion
  • Accessing from unmanaged PC (risk of malware infection)
  • Difficulty in tracking work details
  • Risk of Information Leakage Due to Excessive Authorization

Utilizing SHIELD Gate​

Composition Plan

1. Project-specific access rights  
Project A member → Access only to Project A folder
Project B member → Access only to Project B folder

2. Complete isolation mode applied
- All access through isolated browser
- Complete blocking of downloads
- Blocking of copy and paste
- Blocking of screenshots

3. Work history tracking
- Access time history
- File view and edit history

4. Automatic permission management
- Project start date → Automatic permission granting
- Project end date → Automatic permission revocation

3. Strengthening SaaS Security​

situation​

Utilizing cloud SaaS such as Microsoft 365, Google Workspace

Security Challenges of Using SaaS:

  • Difficulty distinguishing between personal accounts and company accounts
  • Send to personal email after downloading the file
  • Irresponsible creation of external sharing links
  • Save company files to personal OneDrive

Utilizing SHIELD Gate​

Composition Plan

1. URL Level Detailed Policy
company.sharepoint.com
→ Company SharePoint: All features allowed

personal-account.onedrive.com
→ Personal OneDrive: Access blocked

web.whatsapp.com
→ WhatsApp Web: Upload blocked

2. Tenant Control
- Only company tenant (@company.com) access allowed
- Access from other tenants blocked

3. File Download Control
- SharePoint file download → CDR applied
- Teams attachments → Automatic sanitization
- External sharing link creation → Blocked

4. Safe Use of Generative AI​

situation​

Need to utilize AI tools such as ChatGPT, Copilot, etc.

The Dilemma of Using Generative AI:

  • Need for AI tools for work efficiency
  • Concerns about entering sensitive information (source code, customer data, etc.)
  • Unconditional blocking leads to employee dissatisfaction and decreased productivity
  • Bypass using a personal account

Utilizing SHIELD Gate​

Composition Plan

1. Allow access to AI services + isolation  
chatgpt.com → Open in isolation browser
copilot.microsoft.com → Isolation mode

2. Keyboard input pattern inspection
- When entering resident registration number pattern → Block
- When entering account number pattern → Block
- IP address pattern → Block

3. Copy and paste control
- Internal → AI: Block
- AI → Internal: Allow
(Code copying is possible, but source upload is blocked)

5. Remote Work Environment​

situation​

Corporate Remote Work or Hybrid Work

Security Challenges of Remote Work:

  • Employee home PC security status uncertain (no antivirus installed, patches not applied)
  • Cafes, using public WiFi in public places

Utilizing SHIELD Gate​

Composition Plan

1. All Access Isolation
- Access through an isolated browser on any device
- Even infected devices are safe

2. Screen Watermark
- Display username and ID
- Display access time
- Traceable when taking screenshots

3. Policy by Network
- When accessing from external IP
→ Additional OTP authentication
→ Block downloads

4. Storage Location Control
- Block local downloads
- Allow saving only to SHIELD Drive
- Save files encrypted

6. Personal Desktop Remote Access​

situation​

High-spec PC required tasks (design, development, video editing)

Challenges of Utilizing High-Spec PCs:

  • Unable to perform high-spec tasks while working from home
  • VDI Construction Cost Burden (Server, License)
  • Need access to office PC for external workers (freelancers)

Utilizing SHIELD Gate​

Composition Plan

1. Personal PC Registration
- Register on the office desktop SHIELD Gate
- Set access permissions (only for yourself or team members)

2. Wake on LAN
- You can turn off the PC when leaving work
- Power on remotely

3. Conditional Access Control
- Weekday working hours: Free access
- Night/weekend: Access not allowed
- Overseas business trip: Access not allowed

4. Session Monitoring
- Access history logging
- Automatic logout after task completion

7. Server Management Console​

situation​

Operating multiple Linux/Unix servers

Security Challenges of Server Management:

  • Security Risks of Direct SSH Access
  • Difficulty in tracking administrator work history

Utilizing SHIELD Gate​

Composition Plan

1. Web-based SSH Terminal
- Direct SSH access from the browser
- No separate terminal program needed

2. Work History Record
- Who, when, where, on which server

8. Response to Phishing Attacks​

situation​

Increase in Email Phishing Attacks

The Reality of Phishing Attacks:

  • Accessing malicious sites by clicking email links
  • Limitations of Security Training (People Make Mistakes)
  • Sophisticated phishing sites are difficult to distinguish.
  • Risk of transmission infection even with just one click

Utilizing SHIELD Gate​

Composition Plan

1. Isolation of all external links
- All links in emails → Isolated browser
- Messenger links → Isolated browser
- Links within documents → Isolated browser

2. Automatic isolation of unclassified sites
- Sites not in the category DB → Complete isolation
- New sites → Block keyboard input
- Suspicious domains → Block downloads

3. Input control
- Phishing suspected sites → Block keyboard input
- Login forms detected → Warning popup
- Requests for personal information → Block

4. File download sanitization
- All attachments → Automatic CDR application
- Executable files → Block
- Compressed files → Internal re-inspection

9. Compliance Response​

situation​

Compliance with regulations required (Personal Information Protection Act, Medical Act, Financial Act, etc.)

Compliance Requirements:

  • Obligation to Record Personal Information Access History
  • Principle of Least Privilege
  • Prevention of Sensitive Information Leakage
  • Submission of Evidence of Gratitude
  • Insider Threat Management

Utilizing SHIELD Gate​

Composition Plan

1. Perfect Access History Record  
Who: User ID, Name
When: Access Start/End Time
Where: IP Address, Location
What: Accessed System, File
How: View, Edit, Download

2. Sensitive Information Access Control
- When accessing patient information → Watermark automatically displayed
- Customer data download → Reason input required
- Confidential document printing → Administrator approval needed

3. Principle of Least Privilege
- Access only the information necessary for work
- Differential privileges based on position and department
- Automatic privilege revocation upon expiration

4. Log Integrity Assurance
- Log tampering prevention technology
- Blockchain-based hash verification
- Automatic backup to external storage