Main Features
SHIELD Drive is an enterprise file management service that securely stores organizational files, manages them based on policies, and supports collaboration and integration with external systems.
Integrate different storage systems such as NAS, SharePoint, Google Drive, and Amazon S3 into a single screen, and encrypt files for storage in each storage.Secure Storageand directly linking to the original of the existing repositoryGeneral SaveYou can choose from among them. All file events are subject to role permissions, conditional policies, document ratings, and approval processes, and the results are logged.
Overview of File Processing Structure
Files in SHIELD Drive are processed in the following flow.
[User / Integration System (Teams · SHIELD Gate · Network Link)]
↓
[User Authentication (Security365 Account · SSO)]
↓
[File Processing (Upload / View / Edit / Share / Move·Copy / Download)]
↓
[Policy Application (Role Permissions · Conditional Policies · Document Ratings · Approval)]
↓
[Storage Method Application]
├ Secure Storage: Encrypt · Obfuscate and Store
└ Regular Storage: Store as Original
↓
[Storage Storage or External System Delivery]
↓
[Log Recording (Admin Console · Integrated Log)]
Overview of Key Features
| area | Core Features |
|---|---|
| 1. File and Folder Management | Upload · Download, Move · Copy, Trash, Multi-select Batch Operations, Favorites · Pin to Top · Recent Documents, Automatic Deletion of Personal Folder Files |
| 2. Search | Integrated search, conditional search, tag-based search, trash search |
| 3. Sharing and Collaboration | Share box, Link sharing, Invite external users, Comments, Version control, Notifications |
| 4. Document Viewing and Editing | SHIELD Viewer, Web · App Collaborative Editing (Microsoft · Google · Hancom · OOS), App Editing |
| 5. Storage Management | Multi-storage integration, purpose-based configuration, role permissions, capacity allocation, storage method selection |
| 6. General Storage | Existing NAS original connection, introduction without data transfer, lock-based app editing |
| 7. Conditional Policies | Target · Conditions · Action-based event control, priority · Copy, execution workflow integration |
| 8. Document Grade (N2SF) | Storage · Document Classification, Classification-Based Upload · Move · Copy Control |
| 9. Upload · Download Approval | Approval process integration, approval request box, approval status notification |
| 10. Security Features | Encryption storage, access control, sensitive information protection, automatic logout |
| 11. Logs and Audits | User · Admin Log, Log Download, Integrated Log Integration |
| 12. Dashboard and Statistics | User · Storage · Policy Status, Activity Chart |
| 13. Admin Features | User Management, Settings, Admin Trash, Edge Server Management |
| 14. External Service Integration | Management Center, Teams, Microsoft 365 · Google, EDO, Edge Server, Network Link, SHIELD Gate |
1. File and Folder Management
| Function Classification | Provided Features | Explanation |
|---|---|---|
| File Input and Output | File Upload | Upload files · folders from local PC. Drag and drop support, maintain substructure when uploading folders. |
| File Download | Single file, multiple selection files, folder (compressed) download | |
| Download Progress Status | Display download progress (%) in real time | |
| Creation / Structure Management | File · Folder Creation | Creating folders and document files in Drive |
| Move / Copy | File · Move · Copy files or folders to another path or different storage. Allow all according to policy · Allow within the same tree · Block | |
| Name Change | Renaming Files and Folders | |
| Multi-Select Batch Operation | When selecting multiple items, you can process move, copy, delete, and download at once from the top action bar. | |
| Delete / Restore | delete | Move to Recycle Bin when deleting files and folders |
| Recovery | Restore files · folders from the recycle bin to their original location | |
| Automatic Deletion of Personal Files | Automatically clean up files in the personal storage designated by the administrator according to the set period. Users can specify automatic deletion exceptions on a 1st depth folder basis. | |
| Search / Sort | File Access | Viewing file contents with a viewer or editor (Chapter 4) |
| Sorting | Sort by name, modified date, size | |
| Detailed Information | Check name, type, size, creator, modifier, modification date, security level, etc. | |
| Modified date display method | Display according to administrator settings in elapsed time or date format (YYYY-MM-DD HH:mm) | |
| Sharing / Convenience Features | Copy link | Creating links for file and folder sharing |
| Copy Path | Copy the path of the file · folder in Drive | |
| Favorites | Frequently Used Files · Registering Folders as Favorites | |
| Fixed Top | Pin frequently used items to the top of the list | |
| Recent Documents | Recent Views · Check the Documents You Edited | |
| Environment Integration | Inter-network transmission | File Transfer to Registered Network (Chapter 14) |
2. Search
| Provided Features | Explanation |
|---|---|
| Integrated Search | Search by file · folder name across all accessible storage |
| Condition Search | Specify search criteria to narrow the result range. |
| Tag-based search | Search by specified tags in files · folders |
| Recent Search Terms | Save recent searches to search again |
| Trash Search | Search for items in the trash bin |
Search is provided for secure storage. Regular storage is excluded from the search target.
3. Sharing and Collaboration
| Provided Features | Explanation |
|---|---|
| Share box | A collaborative folder where members are invited to work together. The folder owner invites members, and member permissions are set within the limits of the owner's permissions. |
| Member Invitation Email | Share Invitation · Send Email on Change (When Using Management Center Mail Server) |
| Inviting External Users | Invite external users to share (when using admin settings and mail server) |
| Link Sharing | Link to transfer files · folders. Guidance by reason if there are no permissions or preview is not supported. |
| Collaborative Editing | Simultaneous Editing of a Document by Multiple Users (Chapter 4) |
| comment | Comment by file |
| Version Control | Version storage by save point, check previous versions · download · restore |
| Notification | Notification of sharing, invitation, approval status changes, read processing, and displaying the number of unread messages. |
4. Document Viewing and Editing
| Editing · Viewing Tools | Support Storage | Supported Extensions |
|---|---|---|
| Microsoft Web · App Co-Editing | OneDrive, SharePoint | docx, xlsx, pptx |
| Google Web Collaborative Editing | Google Drive | docx, xlsx, pptx |
| Hancom Web Collaborative Editing | NAS, Security NAS, Amazon S3 | hwp, hwpx, odt, ods, odp, etc. |
| OOS Web Collaborative Editing | NAS, Security NAS, Amazon S3 | docx, xlsx, pptx |
| Editing Microsoft Apps | NAS, Security NAS, Amazon S3 | docx, xlsx, pptx |
| SHIELD Viewer | All Types | SHIELD Viewer supported file extensions (dynamically query the supported list) |
- Edit permissions areEdit in WebandEdit with the appSet by dividing into.
- General storage NAS documentation provides file locking-based app editing (Chapter 6).
5. Storage Management
role
- Integrating different storages into a single UI
- Storage Purpose · Permissions · Policy Separation
- Storage Usage Status Visualization
Supported Storage Types
| type | Registration Conditions | Support Purpose | Storage Method |
|---|---|---|---|
| NAS | always | Personal folder, Shared folder, Common folder, Teams folder | Secure Storage / Regular Storage |
| Secure NAS | When using Edge server | Personal folder, Shared folder, Common folder, Teams folder | Secure Storage / Regular Storage |
| SharePoint | When using Microsoft integration | shared box, common box | Secure Storage |
| Google Drive | When using Google integration | shared box, common box | Secure Storage |
| Amazon S3 | always | shared box, common box | Secure Storage |
| OneDrive | Automatic creation when integrating with Microsoft | personalization | Secure Storage |
| SharePoint (Teams) | Automatically created during Teams tab synchronization | Teams folder | Secure Storage |
Storage Purpose
| Purpose | Explanation |
|---|---|
| personalization | User-specific personal file space |
| Common function | Shared folder used by organization members |
| Share box | Member Invitation Based Collaboration Space |
| Teams folder | Microsoft Teams Team · Folders Linked to Channels |
Provided Features
| Provided Features | Explanation |
|---|---|
| Storage Registration · Modification | Type · Purpose · Storage Method · Access Information Settings, Enable / Disable. Sensitive information such as access information is masked on the screen. |
| Select Storage Method | Select secure storage or regular storage upon registration (Chapter 6) |
| Role Permission Management | Role-based member assignment and permission settings (viewing, web · app editing, uploading, downloading, moving · copying, deleting, sharing, file transfer, etc.) |
| Capacity Management | Setting the total capacity of NAS personal storage, default allocation capacity, and individual allocation capacity per user (individual allocation priority) |
| Capacity Notification Email | Send usage status email to the administrator when storage usage is nearing the limit or at the end of the month. |
| Security Level Designation | Document Rating in Storage (Chapter 8) |
| Enable Approval | Storage Unit Upload · Download Approval Usage Setting (Chapter 9) |
| Activity Log | Check Storage Configuration Change History |
6. General Storage
General storage is a method of connecting the customer's operating NAS to SHIELD Drive storage in its original form without encryption or obfuscation. It can be used under the permissions and policies of SHIELD Drive without moving the existing file and folder structure, allowing for easy implementation without the burden of data migration.
Introduction Effect
- Since the file and folder structure of the existing NAS is used as is, there is no need for data migration.
- You can use NAS alongside other systems and access paths while maintaining the original format.
- Access to NAS can be controlled by the role permissions of the SHIELD Drive and conditional policies.
- You can use lock-based app editing as a working repository that is not read-only.
Comparison of Secure Storage and Regular Storage
| item | Secure Storage | General Save |
|---|---|---|
| Storage Format | Encryption · Obfuscation Storage, Managing Folder Structure with Metadata | Save the original as is, maintain the folder structure of the original repository. |
| Support Storage | All Types | NAS, Security NAS |
| Support Purpose | All Purposes | personal box, common box |
| Search · Version Control · Recent Documents | support | Not supported |
| Trash Can | support | Not Supported (Immediate Permanent Deletion) |
| Link Sharing · Share · Export | According to the policy | Unsupported (Fixed Block) |
| Move · Copy | According to the policy | only within the same storage |
| Edit | According to the policy | Lock-based app editing (SFTP connection) |
| Activity Log | support | Not supported |
| Inter-network transmission | support | Not supported |
| Document Grade · Upload · Download Approval | support | Not supported |
| Capacity Management · Automatic Deletion of Personal Files | Support (NAS Personal Folder) | Not supported |
Scope of Support
| item | Content |
|---|---|
| Storage Type | NAS, Security NAS |
| Purpose | personal box, common box |
| Connection Method | WebDAV, SFTP (SFTP requires host key fingerprint) |
| Specify Storage Method | Specified only during storage registration, cannot be changed after registration. |
| Common Function Configuration | Register only 1 depth folder. |
| NAS own permissions | Permissions and policies set on NAS do not integrate with SHIELD Drive. |
Lock-based app editing
A user locks the original NAS file while editing the document in the local Office app to prevent editing conflicts caused by overwriting from other users.
| item | condition |
|---|---|
| Connection Method | SFTP |
| Lock Support Judgment | Storage determined to be locked after registration (can be rechecked in storage details) |
| Permission | Edit permissions for role permissions |
| extension | docx, xlsx, pptx |
| Editing App | Local Office app (Linux not supported) |
| Editing Method | One editor per file (exclusive lock) |
- Select Open with App from the file.
- The original NAS file is locked and opened with the local Office app.
- When saved in the app, it will be reflected in the original NAS path. The lock will remain even if saved multiple times.
- Closing the editing window will unlock it.
| Another approach during editing | result |
|---|---|
| Open SHIELD Drive for other users | Opened in read-only mode, display of editing users |
| SHIELD Drive Overwrite by Other Users · Move · Rename · Delete | Block |
| Accessing NAS Directly | allow |
| Editing and Saving Direct Access to NAS | Block |
| Overwriting · Moving · Renaming · Deleting Direct Access to NAS | Not blocked |
Constraints
- Deletion is permanent deletion that does not go through the recycle bin, and it cannot be recovered.
- Secure storage cannot be moved or copied.
- The path to directly access the NAS and the manipulation of the NAS administrator account is outside the control of SHIELD Drive.
- There is a waiting time until the unlock after the app editing ends.
- SharePoint general storage is scheduled for integration.
7. Conditional Policies
When a file event occurs, it checks the policy target and conditions, and if the conditions are met, it executes the specified action.
Policy Components
| Components | Content |
|---|---|
| Target | Storage and members (users · groups) to which the policy will be applied. Exclusions take precedence if allocations and exclusions overlap. |
| condition | Access location (IP), access time (day of the week · time zone), device type (PC · mobile · Teams), document properties (file type · inclusion of personal information · security grade). All conditions must be met for application. |
| Action | Event-specific Allow/Deny and Post-processing |
Control Events and Actions
| event | Action |
|---|---|
| Upload · Download | Allow, Block, CDR (Decontamination) and other post-processing, Approval Request |
| viewing | Allow, Block, Specify Viewing Methods (App · Web) |
| delete | Deletion Limit, Move to Trash |
| Share | Internal sharing · External sharing allow / block respectively |
| Move · Copy | Storage Internal · External Transfer · Copy Allow / Block |
| Version Restore | Allow / Block |
Policy Management
- Supports changing priority, copying policies, and toggling active/inactive in the policy list.
- Policy registration · modification · deletion · priority change · copying · activation switching will be recorded in the management log.
- The detailed handling of actions is configured in conjunction with the EDO execution workflow.
Policy Processing Flow
File event occurrence
↓
Target verification
↓
Condition check
↓
Policy action execution (enforcement workflow)
↓
Reflecting allow / block / pending approval results
8. Document Grade (N2SF)
Apply the security grading system defined in the Security365 management center to storage and documents, controlling the import and export of files according to the grade.
| Provided Features | Explanation |
|---|---|
| Storage Class Designation | Specify security level when registering storage. Storage without a specified level is excluded from level control. |
| Document Grade Display | File List · Display Security Level Badge in Details |
| Automatic Grade Assignment | When you upload an unclassified file to the graded storage, a storage grade is automatically assigned. |
| Import Control | If the file grade is higher than the storage grade, upload · move · copy will be blocked. |
| Export Control | Files of a higher grade than the current storage cannot be moved or copied to another storage. |
| Cross Control | Blocking Movement · Copying Between Designated Storage and Undesignated Storage |
| Unspecified File Option | Allow / Block Uploading and Downloading of Unrated Files at the Organization Level |
| Log Records | Storage · Record document grade information in the integrated log |
- It is applied to secure storage and must have the security level feature activated in the management center to be used.
9. Upload · Download Approval
When uploading and downloading files from the specified storage, an approval process is required.
| Provided Features | Explanation |
|---|---|
| Enable Approval | Enabling storage approval and configuring the approval behavior of conditional policies will apply. |
| Approval Request | Upload · Change to approval pending status when requesting download and request approval through the common approval service. |
| Approval Request Form | Check pending and completed items in the top bar, receive the downloaded files that have been approved. |
| Approval Status Notification | Notification of changes in request status such as approval and rejection |
| Bypass Blocking | Moving · Copying Between Approved Storage and Other Storage - Bidirectional Blocking |
- Security NAS and general storage in the Edge environment are excluded from the approval targets.
10. Security Features
Security Design Characteristics
- Files are automatically encrypted and stored upon upload (secure storage).
- The encryption keys are protected by a separate Key Management System (KMS).
- Access to files will be immediately blocked in case of policy violations.
Provided Features
| Provided Features | Explanation |
|---|---|
| File Encryption · Obfuscated Storage | Encrypt and obfuscate files in secure storage |
| Policy-Based Access Control | Access control for files based on role permissions, conditional policies, and document classification. |
| Sensitive Information Protection | Mask sensitive information such as storage access information, and return after verifying the requester's permissions. |
| Automatic Logout | Automatic logout of idle users according to the period set in the management center |
| Duplicate Login Detection | Duplicate login detection for the same account |
| Admin Re-authentication | User Management · Re-authentication of password when accessing major management menus such as Edge Server |
| Page Separation Operation | Separate user page and admin page by different ports |
| Activity Log | User and administrator activity log recording, log retention for audit purposes |
11. Logs and Audits
| Provided Features | Explanation |
|---|---|
| User Log | Upload · Download · View · Edit · Share · Delete and other file event logs |
| Admin Log | Storage · Policy · Management actions such as configuration changes and administrator menu view records |
| Search Period · Search | 1 week · 1 month · 6 months · 1 year period selection, name · type · target search |
| Log Download | Download the queried logs as a CSV file |
| Log Item Settings | Select log items to display in the list |
| Query Log Manager | Admin role that only accesses the log menu. Login · Email notification on logout |
| File Activity Log | Check Event History by File (Secure Storage) |
| Integrated Log Integration | File · Folder events are sent to the integrated log (InfoLineage) along with grade information. |
12. Dashboard and Statistics
| Provided Information | Explanation |
|---|---|
| Status Card | User, Storage, Policy, New Item Status. Display detailed information when selecting a card. |
| Storage Usage Status | Storage Usage by Type |
| Activity Status by Storage Type | File Activity Trends by Storage Type |
| User Activity | User-specific File Access · Activity History |
| Policy Usage Rate | Conditional Policy Application Status |
| Query Period | 1 week, 1 month, 6 months (up to 6 months) |
13. Admin Features
| Menu | Provided Features |
|---|---|
| User Management | User List · Search · Detailed View |
| Storage | Storage Registration · Modification, Role Permissions, Capacity, Grade, Approval Settings (Chapter 5) |
| Conditional Policy | Policy Registration · Modification · Priority · Copy (Chapter 7) |
| log | User · Admin Log View (Chapter 11) |
| Settings - Enable | Owner policy for shared folders, inviting external users, using SHIELD Viewer, displaying modified date format, etc. |
| Settings - File Management | Automatic Deletion Cycle of Personal Files and Applied Storage |
| Settings - Rating Settings | Upload and Download Allow / Block for Unclassified Files |
| Settings - SHIELD Drive Works | PC Agent Installation · Patch File Management |
| Admin Trash Bin | Search Deleted Items, Restore, Permanently Delete |
| Edge server | Edge server and cluster service registration · modification · activation |
| User Page Navigation | Directly move from the admin page to the user page |
14. External Service Integration
| Integration Target | Integration Details |
|---|---|
| Security365 Management Center | Automatic logout period, mail server, logo · title · favicon, security grade system, etc. common settings integration |
| Microsoft Teams | Exploring SHIELD Drive files in the Teams tab, attaching files to chat · posts with Message Extension, synchronizing team · channel member permissions |
| Microsoft 365 · Google | OneDrive · SharePoint · Connect Google Drive as storage, web co-editing |
| EDO | Conditional Policy Enforcement Workflow, CDR · Personal Information Detection, Approval Request Integration |
| Edge server | External Network · Internal Network Separation Environment Security NAS Integration |
| Disaster Recovery | Registered network file transfer, selection of receiving users by network, transfer quantity · capacity limit |
| SHIELD Gate | Role of the storage broker when uploading and downloading files in the business system, providing upload screen and file box. |
| Other | Support for External Service API Integration |