Skip to main content

Main Features

SHIELD Drive is an enterprise file management service that securely stores organizational files, manages them based on policies, and supports collaboration and integration with external systems.

Integrate different storage systems such as NAS, SharePoint, Google Drive, and Amazon S3 into a single screen, and encrypt files for storage in each storage.Secure Storageand directly linking to the original of the existing repositoryGeneral SaveYou can choose from among them. All file events are subject to role permissions, conditional policies, document ratings, and approval processes, and the results are logged.

Overview of File Processing Structure​


Files in SHIELD Drive are processed in the following flow.

[User / Integration System (Teams · SHIELD Gate · Network Link)]
↓
[User Authentication (Security365 Account · SSO)]
↓
[File Processing (Upload / View / Edit / Share / Move·Copy / Download)]
↓
[Policy Application (Role Permissions · Conditional Policies · Document Ratings · Approval)]
↓
[Storage Method Application]
├ Secure Storage: Encrypt · Obfuscate and Store
└ Regular Storage: Store as Original
↓
[Storage Storage or External System Delivery]
↓
[Log Recording (Admin Console · Integrated Log)]

Overview of Key Features​


areaCore Features
1. File and Folder ManagementUpload · Download, Move · Copy, Trash, Multi-select Batch Operations, Favorites · Pin to Top · Recent Documents, Automatic Deletion of Personal Folder Files
2. SearchIntegrated search, conditional search, tag-based search, trash search
3. Sharing and CollaborationShare box, Link sharing, Invite external users, Comments, Version control, Notifications
4. Document Viewing and EditingSHIELD Viewer, Web · App Collaborative Editing (Microsoft · Google · Hancom · OOS), App Editing
5. Storage ManagementMulti-storage integration, purpose-based configuration, role permissions, capacity allocation, storage method selection
6. General StorageExisting NAS original connection, introduction without data transfer, lock-based app editing
7. Conditional PoliciesTarget · Conditions · Action-based event control, priority · Copy, execution workflow integration
8. Document Grade (N2SF)Storage · Document Classification, Classification-Based Upload · Move · Copy Control
9. Upload · Download ApprovalApproval process integration, approval request box, approval status notification
10. Security FeaturesEncryption storage, access control, sensitive information protection, automatic logout
11. Logs and AuditsUser · Admin Log, Log Download, Integrated Log Integration
12. Dashboard and StatisticsUser · Storage · Policy Status, Activity Chart
13. Admin FeaturesUser Management, Settings, Admin Trash, Edge Server Management
14. External Service IntegrationManagement Center, Teams, Microsoft 365 · Google, EDO, Edge Server, Network Link, SHIELD Gate

1. File and Folder Management​


Function ClassificationProvided FeaturesExplanation
File Input and OutputFile UploadUpload files · folders from local PC. Drag and drop support, maintain substructure when uploading folders.
File DownloadSingle file, multiple selection files, folder (compressed) download
Download Progress StatusDisplay download progress (%) in real time
Creation / Structure ManagementFile · Folder CreationCreating folders and document files in Drive
Move / CopyFile · Move · Copy files or folders to another path or different storage. Allow all according to policy · Allow within the same tree · Block
Name ChangeRenaming Files and Folders
Multi-Select Batch OperationWhen selecting multiple items, you can process move, copy, delete, and download at once from the top action bar.
Delete / RestoredeleteMove to Recycle Bin when deleting files and folders
RecoveryRestore files · folders from the recycle bin to their original location
Automatic Deletion of Personal FilesAutomatically clean up files in the personal storage designated by the administrator according to the set period. Users can specify automatic deletion exceptions on a 1st depth folder basis.
Search / SortFile AccessViewing file contents with a viewer or editor (Chapter 4)
SortingSort by name, modified date, size
Detailed InformationCheck name, type, size, creator, modifier, modification date, security level, etc.
Modified date display methodDisplay according to administrator settings in elapsed time or date format (YYYY-MM-DD HH:mm)
Sharing / Convenience FeaturesCopy linkCreating links for file and folder sharing
Copy PathCopy the path of the file · folder in Drive
FavoritesFrequently Used Files · Registering Folders as Favorites
Fixed TopPin frequently used items to the top of the list
Recent DocumentsRecent Views · Check the Documents You Edited
Environment IntegrationInter-network transmissionFile Transfer to Registered Network (Chapter 14)

Provided FeaturesExplanation
Integrated SearchSearch by file · folder name across all accessible storage
Condition SearchSpecify search criteria to narrow the result range.
Tag-based searchSearch by specified tags in files · folders
Recent Search TermsSave recent searches to search again
Trash SearchSearch for items in the trash bin

Search is provided for secure storage. Regular storage is excluded from the search target.

3. Sharing and Collaboration​


Provided FeaturesExplanation
Share boxA collaborative folder where members are invited to work together. The folder owner invites members, and member permissions are set within the limits of the owner's permissions.
Member Invitation EmailShare Invitation · Send Email on Change (When Using Management Center Mail Server)
Inviting External UsersInvite external users to share (when using admin settings and mail server)
Link SharingLink to transfer files · folders. Guidance by reason if there are no permissions or preview is not supported.
Collaborative EditingSimultaneous Editing of a Document by Multiple Users (Chapter 4)
commentComment by file
Version ControlVersion storage by save point, check previous versions · download · restore
NotificationNotification of sharing, invitation, approval status changes, read processing, and displaying the number of unread messages.

4. Document Viewing and Editing​


Editing · Viewing ToolsSupport StorageSupported Extensions
Microsoft Web · App Co-EditingOneDrive, SharePointdocx, xlsx, pptx
Google Web Collaborative EditingGoogle Drivedocx, xlsx, pptx
Hancom Web Collaborative EditingNAS, Security NAS, Amazon S3hwp, hwpx, odt, ods, odp, etc.
OOS Web Collaborative EditingNAS, Security NAS, Amazon S3docx, xlsx, pptx
Editing Microsoft AppsNAS, Security NAS, Amazon S3docx, xlsx, pptx
SHIELD ViewerAll TypesSHIELD Viewer supported file extensions (dynamically query the supported list)
  • Edit permissions areEdit in WebandEdit with the appSet by dividing into.
  • General storage NAS documentation provides file locking-based app editing (Chapter 6).

5. Storage Management​


role

  • Integrating different storages into a single UI
  • Storage Purpose · Permissions · Policy Separation
  • Storage Usage Status Visualization

Supported Storage Types

typeRegistration ConditionsSupport PurposeStorage Method
NASalwaysPersonal folder, Shared folder, Common folder, Teams folderSecure Storage / Regular Storage
Secure NASWhen using Edge serverPersonal folder, Shared folder, Common folder, Teams folderSecure Storage / Regular Storage
SharePointWhen using Microsoft integrationshared box, common boxSecure Storage
Google DriveWhen using Google integrationshared box, common boxSecure Storage
Amazon S3alwaysshared box, common boxSecure Storage
OneDriveAutomatic creation when integrating with MicrosoftpersonalizationSecure Storage
SharePoint (Teams)Automatically created during Teams tab synchronizationTeams folderSecure Storage

Storage Purpose

PurposeExplanation
personalizationUser-specific personal file space
Common functionShared folder used by organization members
Share boxMember Invitation Based Collaboration Space
Teams folderMicrosoft Teams Team · Folders Linked to Channels

Provided Features

Provided FeaturesExplanation
Storage Registration · ModificationType · Purpose · Storage Method · Access Information Settings, Enable / Disable. Sensitive information such as access information is masked on the screen.
Select Storage MethodSelect secure storage or regular storage upon registration (Chapter 6)
Role Permission ManagementRole-based member assignment and permission settings (viewing, web · app editing, uploading, downloading, moving · copying, deleting, sharing, file transfer, etc.)
Capacity ManagementSetting the total capacity of NAS personal storage, default allocation capacity, and individual allocation capacity per user (individual allocation priority)
Capacity Notification EmailSend usage status email to the administrator when storage usage is nearing the limit or at the end of the month.
Security Level DesignationDocument Rating in Storage (Chapter 8)
Enable ApprovalStorage Unit Upload · Download Approval Usage Setting (Chapter 9)
Activity LogCheck Storage Configuration Change History

6. General Storage​


General storage is a method of connecting the customer's operating NAS to SHIELD Drive storage in its original form without encryption or obfuscation. It can be used under the permissions and policies of SHIELD Drive without moving the existing file and folder structure, allowing for easy implementation without the burden of data migration.

Introduction Effect

  • Since the file and folder structure of the existing NAS is used as is, there is no need for data migration.
  • You can use NAS alongside other systems and access paths while maintaining the original format.
  • Access to NAS can be controlled by the role permissions of the SHIELD Drive and conditional policies.
  • You can use lock-based app editing as a working repository that is not read-only.

Comparison of Secure Storage and Regular Storage

itemSecure StorageGeneral Save
Storage FormatEncryption · Obfuscation Storage, Managing Folder Structure with MetadataSave the original as is, maintain the folder structure of the original repository.
Support StorageAll TypesNAS, Security NAS
Support PurposeAll Purposespersonal box, common box
Search · Version Control · Recent DocumentssupportNot supported
Trash CansupportNot Supported (Immediate Permanent Deletion)
Link Sharing · Share · ExportAccording to the policyUnsupported (Fixed Block)
Move · CopyAccording to the policyonly within the same storage
EditAccording to the policyLock-based app editing (SFTP connection)
Activity LogsupportNot supported
Inter-network transmissionsupportNot supported
Document Grade · Upload · Download ApprovalsupportNot supported
Capacity Management · Automatic Deletion of Personal FilesSupport (NAS Personal Folder)Not supported

Scope of Support

itemContent
Storage TypeNAS, Security NAS
Purposepersonal box, common box
Connection MethodWebDAV, SFTP (SFTP requires host key fingerprint)
Specify Storage MethodSpecified only during storage registration, cannot be changed after registration.
Common Function ConfigurationRegister only 1 depth folder.
NAS own permissionsPermissions and policies set on NAS do not integrate with SHIELD Drive.

Lock-based app editing

A user locks the original NAS file while editing the document in the local Office app to prevent editing conflicts caused by overwriting from other users.

itemcondition
Connection MethodSFTP
Lock Support JudgmentStorage determined to be locked after registration (can be rechecked in storage details)
PermissionEdit permissions for role permissions
extensiondocx, xlsx, pptx
Editing AppLocal Office app (Linux not supported)
Editing MethodOne editor per file (exclusive lock)
  1. Select Open with App from the file.
  2. The original NAS file is locked and opened with the local Office app.
  3. When saved in the app, it will be reflected in the original NAS path. The lock will remain even if saved multiple times.
  4. Closing the editing window will unlock it.
Another approach during editingresult
Open SHIELD Drive for other usersOpened in read-only mode, display of editing users
SHIELD Drive Overwrite by Other Users · Move · Rename · DeleteBlock
Accessing NAS Directlyallow
Editing and Saving Direct Access to NASBlock
Overwriting · Moving · Renaming · Deleting Direct Access to NASNot blocked

Constraints

  • Deletion is permanent deletion that does not go through the recycle bin, and it cannot be recovered.
  • Secure storage cannot be moved or copied.
  • The path to directly access the NAS and the manipulation of the NAS administrator account is outside the control of SHIELD Drive.
  • There is a waiting time until the unlock after the app editing ends.
  • SharePoint general storage is scheduled for integration.

7. Conditional Policies​


When a file event occurs, it checks the policy target and conditions, and if the conditions are met, it executes the specified action.

Policy Components

ComponentsContent
TargetStorage and members (users · groups) to which the policy will be applied. Exclusions take precedence if allocations and exclusions overlap.
conditionAccess location (IP), access time (day of the week · time zone), device type (PC · mobile · Teams), document properties (file type · inclusion of personal information · security grade). All conditions must be met for application.
ActionEvent-specific Allow/Deny and Post-processing

Control Events and Actions

eventAction
Upload · DownloadAllow, Block, CDR (Decontamination) and other post-processing, Approval Request
viewingAllow, Block, Specify Viewing Methods (App · Web)
deleteDeletion Limit, Move to Trash
ShareInternal sharing · External sharing allow / block respectively
Move · CopyStorage Internal · External Transfer · Copy Allow / Block
Version RestoreAllow / Block

Policy Management

  • Supports changing priority, copying policies, and toggling active/inactive in the policy list.
  • Policy registration · modification · deletion · priority change · copying · activation switching will be recorded in the management log.
  • The detailed handling of actions is configured in conjunction with the EDO execution workflow.

Policy Processing Flow

File event occurrence  
↓
Target verification
↓
Condition check
↓
Policy action execution (enforcement workflow)
↓
Reflecting allow / block / pending approval results

8. Document Grade (N2SF)​


Apply the security grading system defined in the Security365 management center to storage and documents, controlling the import and export of files according to the grade.

Provided FeaturesExplanation
Storage Class DesignationSpecify security level when registering storage. Storage without a specified level is excluded from level control.
Document Grade DisplayFile List · Display Security Level Badge in Details
Automatic Grade AssignmentWhen you upload an unclassified file to the graded storage, a storage grade is automatically assigned.
Import ControlIf the file grade is higher than the storage grade, upload · move · copy will be blocked.
Export ControlFiles of a higher grade than the current storage cannot be moved or copied to another storage.
Cross ControlBlocking Movement · Copying Between Designated Storage and Undesignated Storage
Unspecified File OptionAllow / Block Uploading and Downloading of Unrated Files at the Organization Level
Log RecordsStorage · Record document grade information in the integrated log
  • It is applied to secure storage and must have the security level feature activated in the management center to be used.

9. Upload · Download Approval​


When uploading and downloading files from the specified storage, an approval process is required.

Provided FeaturesExplanation
Enable ApprovalEnabling storage approval and configuring the approval behavior of conditional policies will apply.
Approval RequestUpload · Change to approval pending status when requesting download and request approval through the common approval service.
Approval Request FormCheck pending and completed items in the top bar, receive the downloaded files that have been approved.
Approval Status NotificationNotification of changes in request status such as approval and rejection
Bypass BlockingMoving · Copying Between Approved Storage and Other Storage - Bidirectional Blocking
  • Security NAS and general storage in the Edge environment are excluded from the approval targets.

10. Security Features​


Security Design Characteristics

  • Files are automatically encrypted and stored upon upload (secure storage).
  • The encryption keys are protected by a separate Key Management System (KMS).
  • Access to files will be immediately blocked in case of policy violations.

Provided Features

Provided FeaturesExplanation
File Encryption · Obfuscated StorageEncrypt and obfuscate files in secure storage
Policy-Based Access ControlAccess control for files based on role permissions, conditional policies, and document classification.
Sensitive Information ProtectionMask sensitive information such as storage access information, and return after verifying the requester's permissions.
Automatic LogoutAutomatic logout of idle users according to the period set in the management center
Duplicate Login DetectionDuplicate login detection for the same account
Admin Re-authenticationUser Management · Re-authentication of password when accessing major management menus such as Edge Server
Page Separation OperationSeparate user page and admin page by different ports
Activity LogUser and administrator activity log recording, log retention for audit purposes

11. Logs and Audits​


Provided FeaturesExplanation
User LogUpload · Download · View · Edit · Share · Delete and other file event logs
Admin LogStorage · Policy · Management actions such as configuration changes and administrator menu view records
Search Period · Search1 week · 1 month · 6 months · 1 year period selection, name · type · target search
Log DownloadDownload the queried logs as a CSV file
Log Item SettingsSelect log items to display in the list
Query Log ManagerAdmin role that only accesses the log menu. Login · Email notification on logout
File Activity LogCheck Event History by File (Secure Storage)
Integrated Log IntegrationFile · Folder events are sent to the integrated log (InfoLineage) along with grade information.

12. Dashboard and Statistics​


Provided InformationExplanation
Status CardUser, Storage, Policy, New Item Status. Display detailed information when selecting a card.
Storage Usage StatusStorage Usage by Type
Activity Status by Storage TypeFile Activity Trends by Storage Type
User ActivityUser-specific File Access · Activity History
Policy Usage RateConditional Policy Application Status
Query Period1 week, 1 month, 6 months (up to 6 months)

13. Admin Features​


MenuProvided Features
User ManagementUser List · Search · Detailed View
StorageStorage Registration · Modification, Role Permissions, Capacity, Grade, Approval Settings (Chapter 5)
Conditional PolicyPolicy Registration · Modification · Priority · Copy (Chapter 7)
logUser · Admin Log View (Chapter 11)
Settings - EnableOwner policy for shared folders, inviting external users, using SHIELD Viewer, displaying modified date format, etc.
Settings - File ManagementAutomatic Deletion Cycle of Personal Files and Applied Storage
Settings - Rating SettingsUpload and Download Allow / Block for Unclassified Files
Settings - SHIELD Drive WorksPC Agent Installation · Patch File Management
Admin Trash BinSearch Deleted Items, Restore, Permanently Delete
Edge serverEdge server and cluster service registration · modification · activation
User Page NavigationDirectly move from the admin page to the user page

14. External Service Integration​


Integration TargetIntegration Details
Security365 Management CenterAutomatic logout period, mail server, logo · title · favicon, security grade system, etc. common settings integration
Microsoft TeamsExploring SHIELD Drive files in the Teams tab, attaching files to chat · posts with Message Extension, synchronizing team · channel member permissions
Microsoft 365 · GoogleOneDrive · SharePoint · Connect Google Drive as storage, web co-editing
EDOConditional Policy Enforcement Workflow, CDR · Personal Information Detection, Approval Request Integration
Edge serverExternal Network · Internal Network Separation Environment Security NAS Integration
Disaster RecoveryRegistered network file transfer, selection of receiving users by network, transfer quantity · capacity limit
SHIELD GateRole of the storage broker when uploading and downloading files in the business system, providing upload screen and file box.
OtherSupport for External Service API Integration