Specifications

Print Controller Design Guide for Information Security:
Page 48 of 92
When sending an email from the MFP via the SMTP server, the operator can either send the
scanned image as a file attachment, or send a text-only email that contains the URL for accessing
the image in the MFP HDD. Using this URL, the operator then accesses the image via
DeskTopBinder or Desk Top Editor for Production.
When authenticating with User Codes, the User Code data is sent from the TWAIN driver in binary
format (unencrypted). However when using User Authentication with the TWAIN driver, the
password is encrypted before being sent. In addition, the password set from the MFP operation
panel for accessing Document Server documents is not sent to DeskTopBinder or Desk Top Editor
for Production. This password is only used for authentication when downloading the requested
Document Server documents to these PC applications, or for access control with remote
forwarding.
Data Flow Security Considerations
Forwarding operations are unidirectional, sending image data to pre-programmed email addresses,
folders and forwarding servers only. Since there is no receiving aspect, it is not possible for the
Scanner function to receive any illegal data from an external interface.
When sending image data to an SMTP server, it is possible to introduce an authentication process
at the POP server before making the connection to the SMTP server (POP before SMTP), and at
the SMTP server itself (SMTP authentication).
When sending image data to an SMTP server or Windows PC (SMB), it is possible to encrypt the
password using a DIGEST algorithm. When sending the file in PDF format, it is possible to pre-set
the password necessary to open the encrypted PDF data at the PC side, the password necessary
for changing the document’s access level, and other security settings associated with the
document (Printing, Changes, Content Copying and Extraction).
The TWAIN driver will not process any binary data that does not conform to the predetermined
protocol of the command interface. The supported protocols are SNMPv1, v2 and v3. When using
SNMP v3, it is necessary to use the TWAIN V4 driver. In order to utilize the authentication features
with the TWAIN V4 driver, the operator must first set the necessary authentication information in
the authentication tool that comes with the driver.