Data Encryption and Overwrite Guide
Data Encryption and Overwrite Guide
com
Data Encryption/Overwrite
OPERATION GUIDE
Introduction
This Setup Guide explains the procedures for installing and operating the Data Encryption/Overwrite Functions
(hereinafter called Security Functions) and the procedure for system initialization.
• Nominate a reliable person for the machine administrator when installing the security functions.
• Sufficiently supervise the nominated administrator so that it can observe the security policy and
operation rules at the organization to which it belongs and properly operate the machine in accordance
with the operation guide of the product.
• Sufficiently supervise the general users so that they can operate the machine while observing the
security policy and operation rules at the organization to which they belong.
Instructions for General Users (for Both General Users and Administrators)
Instructions for Administrators (for Those in Charge of Installation and Operation of the
Security Functions)
1
Instructions for General Users (for Both General Users and Administrators)
Security Functions
The security functions enable overwriting and encryption.
NOTE: If you install the security functions, Running security function... appears when the machine starts up
and it may take a while.
Overwriting
Multi-functional products (MFPs) temporarily store the data of scanned originals and print jobs, as well as other
data stored by users, on the hard disk or in FAX memory, and the job is output from that data. As the data
storage areas used for such data remain unchanged on the hard disk or in FAX memory until they are
overwritten by other data, the data stored in these areas is potentially restorable using special tools.
The security functions delete and overwrite (hereinafter collectively referred to as overwrite(s)) the unnecessary
data storage area used for the output data or deleted data to ensure that data cannot be restored.
Overwriting is performed automatically, without user intervention.
CAUTION: When you cancel a job, the machine immediately starts overwriting the data that was stored on the
hard disk/SSD or in FAX memory.
Overwrite Methods
There are two overwrite methods, which can be switched at any time.
NOTE: For SSD and FAX memory, the method used is Once Overwrite.
2
Encryption
MFPs store the data of scanned originals and other data stored by users in the hard disk/SSD. It means the data
could be possibly leaked or tampered with if the hard disk/SSD is stolen.
The security functions encrypt data before storing it in the hard disk/SSD. It guarantees higher security because
no data cannot be decoded by ordinary output or operations.
Encryption is automatically performed and no special procedure is required.
CAUTION: Encryption helps enhance security. However, the data stored in the Document Box can be decoded
by ordinary operations. Do not store any strictly confidential data in the Document Box.
Security Functions
Hard disk/SSD
Copying
Send
Print
Printing
Security Functions
Save original
data Send
Faxing
Fax memory
• If the security functions are introduced, the destination where data received by FAX is to be saved is
changed from SSD to hard disk. If you want to change the destination to SSD, contact your dealer or
service technician.
3
Touch Panel Display after the Security Functions are Installed
Hard Disk Icon Display
Admin In Security Mode, the security functions have been
Select the function. properly installed and is running. The hard disk icon
appears on the lower right side of the touch panel in
Security Mode.
Copy Send FAX Custom Box
The table below shows the icons displayed and their descriptions.
CAUTION: Do not turn the power switch off while is displayed. Risk of damage to the hard disk/SSD or FAX
memory.
NOTE: If you turn the machine off at the power switch during overwriting, data may not be overwritten
completely from the hard disk. Turn the machine back on at the power switch. Overwriting automatically
resumes. If you accidentally turn the main power switch off during overwriting or initialization, the hard disk icon
might not switch to the second icon shown above. This would be caused by a possible crash or failed
overwriting of the data to be overwritten. This will not affect subsequent overwriting processes. However, hard
disk initialization is recommended so as to return to normal stable operations. (Initialization should be
performed by the administrator following the steps in System Initialization on page 15.)
4
Instructions for Administrators (for Those in Charge of Installation and
Operations of the Security Functions)
If any kind of problem occurs in the installation or use of the security functions, contact your dealer or service
technician.
• License Certificate
• Installation Guide (for service personnel)
• Notice
Before Installation
• Make sure that the service representative must be a person who belongs to the supplying company.
• Install the machine in a safe location with controlled access, and unauthorized access to the machine can
be prevented.
• The hard disk/SSD will be initialized during installation of the security functions. This means that the data
stored in the hard disk will be all overwritten. Special attention should be given if you install the security
functions on the MFP currently used.
• The network to which the machine is hooked up must be protected by a firewall to prevent extraneous
attacks.
• The Repeat Copy function will be unavailable after the installation.
• [Adjustment/Maintenance] -> [System Initialization] will not be displayed in the System Menu after the
installation.
• When installing the security functions, change the machine settings as follows.
Item Value
User Login/Job Accounting User Login Setting Local User Change the administrator password.
List
System Menu Date/Timer/Energy Saver Date/Time Set the date and time.
• If the security functions are introduced, the destination where data received by FAX is to be saved is
changed from SSD to hard disk. If you want to change the destination to SSD, contact your dealer or
service technician.
Installation
Installation of the security function is performed by the service person or the administrator. The service person
or the administrator should log in the system menu to enter the encryption code.
5
Encryption Code
As an encryption key is then created from this code, it is safe enough to continue using the default code.
CAUTION: Be sure to remember and securely manage the encryption code you entered. If you need to enter
the encryption code again for some reason and you do not enter the same encryption code, all the data stored
on the hard disk/SDD will be overwritten as a security precaution.
Installation Procedure
Use the procedure below to select the interface.
2 Press [System/Network].
Once
Overwrite
10 Press [OK]. Hard disk/SSD formatting begins.
11 When formatting finishes, follow the on screen
Encryption
Code
6
12 After the opening screen is displayed, confirm that
a hard disk icon (Overwritten completion icon of
unnecessary data in the hard disk) is shown in the
lower right corner of the screen.
7
After Installation
Change the machine setting as follows to securely operate it. If the system in the machine is initialized, it returns
to the settings before installation, so make changes in the same way. If you allow service personnel to conduct
maintenance operations, confirm the set values.
8
Item Value
Network Protocol Protocol Settings Print NetBEUI Off
Settings Protocols LPD Off
FTP Server Off
(Reception)
IPP Off
IPP over On
SSL
IPP Off
Authentication
Raw Off
WSD Print Off
POP3 Off
(E-mail RX)
Send SMTP On
Protocols (E-mail TX)
FTP Client On
(Transmission)
SMB Off
WSD Scan Off
DSM Scan Off
eSCL Off
eSCL over SSL Off
Other SNMPv1/v2c Off
Protocols SNMPv3 Off
HTTP Off
HTTPS On
Enhanced Off
WSD
Enhanced On
WSD(SSL)
LDAP Off
IEEE802.1X Off
LLTD Off
REST Off
REST over Off
SSL
VNC(RFB) Off
VNC(RFB) Off
over SSL
Enhanced Off
VNC(RFB)
over SSL
9
Item Value
Security Device Device Edit Restriction Address Administrator
Settings Security Security Book Only
Settings One Touch Administrator
Key Only
Authentication Password Password On
Security Policy Policy
Settings Settings Maximum Setting any
password value
age
Minimum On
password 8 or more
length characters
Password Setting any
complexity value
Security Device Device Authentication User Account Lockout On
Settings Security Security Security Lockout Policy
Settings Settings Settings Number of Setting any
Retries until value
Locked
Lockout Setting any
Duration value
Lockout All
Target
Network Network Secure SSL On
Security Security Protocol Serverside TLS Version SSL3.0/TLS1.0:
Settings Settings Settings Disable
TLS1.1: Disable
TLS1.2: Enable
Effective ARCFOUR:
Encryption Disable,
DES: Disable,
3DES: Enable,
AES: Enable,
AES-GCM:
Setting any
value
HTTP Security Secure Only
(HTTPS)
IPP Security Secure Only
(IPPS)
Enhanced Secure Only
WSD Security (Enhanced WSD
over SSL)
Clientside TLS Version SSL3.0/TLS1.0:
Settings Disable
TLS1.1: Disable
TLS1.2: Enable
Effective ARCFOUR:
Encryption Disable,
DES: Disable,
3DES: Enable,
AES: Enable,
AES-GCM:
Setting any
value
Certificate On
Verification
10
Item Value
Management Authentication Settings Authentication General Authentication Local
Settings Settings Authentication
Local Local On
Authorization Authorization
Settings
Guest Guest Off
Authorization Authorization
Settings
Simple Login Simple Login Off
Settings
History History Settings Job Log History Recipient E-mail Address for
Settings E-mail Address the administrator
of the machine
Auto Sending On
Login History Login History On
Settings Recipient E-mail Address for
E-mail Address the administrator
of the machine
Auto Sending On
Device Log Device Log On
History Settings History
Recipient E-mail Address for
E-mail Address the administrator
of the machine
Auto Sending On
Secure Secure On
Communication Communication
Error Log Error Log
History
History Settings
Recipient E-mail Address for
E-mail Address the administrator
of the machine
Auto Sending On
11
Items changed on the machine
Item Value
System Menu System/Network Security Level Very High
Internet Internet Browser Off
For the procedures for changing the settings, refer to the machine OPERATION GUIDE and Command Center
RX User Guide.
After changing the settings, run [Software verification] in the system menu to verify that the machine operates
correctly. Periodically perform [Software verification] after installation as well.
After installing the security functions, you can change the security password as well as the method for
overwriting the entire hard disk.
Refer to page 13 for the procedures.
The administrator of the machine should periodically store the histories, and check each history to make sure
there was no unauthorized access or abnormal operation.
Grant regular users permission based on your company rules, and promptly delete any user accounts that stop
being used due to retirement or other reasons.
IPsec setting
It is possible to protect data by enabling the IPsec function that encrypts the communication path.
Please note the following points when enabling the IPsec function.
• The value set by the IPsec rule has to be matched with the destination PC. Communication error occurs in
case the setting does not match.
• IP address set by the IPsec rule has to be matched with the IP address of the SMTP server or FTP server
which is set on the main unit.
• In case the setting does not match, data sent by mail or FTP can’t be encrypted.
• Pre-shared key set by the IPsec rule has to be created by using the alphanumeric symbols of 8 digits or
more which will not be easily guessed.
12
Changing Security Functions
Changing Security Password
Enter the security password to change security functions. You can customize the security password so that only
the administrator can use the security functions.
2 Press [System/Network].
Password
CAUTION: Avoid any easy-to-guess numbers for the
# Keys security password (e.g. 11111111 or 12345678).
Confirm
Password
# Keys
9 Press [Confirm Password] to enter the same
password again.
13
Changing the Data Overwrite Method
The method used to overwrite data can be changed. Refer to Overwriting on page 2 for details.
NOTE: The overwrite methods are used both for overwriting and hard disk initialization, and cannot therefore
be set individually.
2 Press [System/Network].
9 Press [OK].
Cancel OK
10/10/2015m030241
10:10
14
System Initialization
Overwrite all the data stored in the system when disposing of the machine.
CAUTION: If you accidentally turn the power switch off during initialization, the system might possibly crash or
initialization might fail.
NOTE: If you accidentally turn the power switch off during initialization, turn the power switch on again.
Initialization automatically restarts.
2 Press [System/Network].
Close
m0201112
10/10/2015 10:10
15
Warning Message
If the encryption code information of the machine has been lost for some reason, the screen shown here appears
when the power is turned on.
Encryption
this will overwrite all the data stored in the hard disk/
Code
SSD. Exercise extreme caution when entering an
encryption code.
OK The encryption code is not the same as the security
10/10/2015 av0201
10:10
password.
Disposal
If the machine is unused and demolished, initialize the system of this product to erase the hard disk/SSD data
and FAX memory.
If the machine is unused and demolished, obtain directions for disposal from the dealer (from which you
purchased the machine) or your service representative.
16
Appendix
List of factory default settings
The default settings for security mode are shown below.
17
Item Value
Network TCP/IP IPSec Policy Rule Off
Settings Rules Key IKEv1
Management
("Settings" Type
selection of
any of Rule Encapsulatio Transport
No.) n Mode
IP Address IP Version IPv4
IP No setting
Address(IPv
4)
Subnet Mask No setting
Authentication Local Side Authentication Pre-shared Key
Type
Pre-shared No setting
Key
Key Exchange (IKE phase1) Mode Main Mode
Hash SHA1
Encryption 3DES, AES-
CBC-128, AES-
CBC-192, AES-
CBC-256
Diffie- modp1024(2)
Hellman
Group
Lifetime 28800 seconds
(Time)
Data Protection (IKE phase2) Protocol ESP
Hash SHA1
Encryption 3DES, AES-
CBC-128, AES-
CBC-192, AES-
CBC-256
PFS Off
Lifetime Time & Data
Measuremen Size
t
Lifetime 3600 seconds
(Time)
Lifetime 100000KB
(Data Size)
Extended Off
Sequence
Number
18
Item Value
Network Protocol Protocol Settings Print NetBEUI On
Settings Protocols LPD On
FTP Server On
(Reception)
IPP Off
IPP over On
SSL
IPP Off
Authentication
Raw On
WSD Print On
POP3 Off
(E-mail RX)
Send SMTP Off
Protocols (E-mail TX)
FTP Client On
(Transmission)
SMB On
WSD Scan On
DSM Scan Off
eSCL On
eSCL over SSL On
Other SNMPv1/v2c On
Protocols SNMPv3 Off
HTTP On
HTTPS On
Enhanced On
WSD
Enhanced On
WSD(SSL)
LDAP Off
IEEE802.1X Off
LLTD On
REST On
REST over On
SSL
VNC(RFB) Off
VNC(RFB) Off
over SSL
Enhanced On
VNC(RFB)
over SSL
19
Item Value
Security Device Device Edit Restriction Address Off
Settings Security Security Book
Settings One Touch Off
Key
Authentication Password Password Off
Security Policy Policy
Settings Settings Maximum Off
password
age
Minimum Off
password
length
Password No more than
complexity two consecutive
identical char
Security Device Device Authentication User Account Lockout Off
Settings Security Security Security Lockout Policy
Settings Settings Settings Number of 3 times
Retries until
Locked
Lockout 1 minute
Duration
Lockout Remote Login
Target Only
Network Network Secure SSL On
Security Security Protocol Serverside TLS Version SSL3.0/TLS1.0:
Settings Settings Settings Enable
TLS1.1: Enable
TLS1.2: Enable
Effective ARCFOUR:
Encryption Enable,
DES: Disable,
3DES: Enable,
AES: Enable,
AES-GCM:
Disable
HTTP Security Secure Only
(HTTPS)
IPP Security Secure Only
(IPPS)
Enhanced Secure Only
WSD Security (Enhanced WSD
over SSL)
Clientside TLS Version SSL3.0/TLS1.0:
Settings Enable
TLS1.1: Disable
TLS1.2: Disable
Effective ARCFOUR:
Encryption Enable,
DES: Enable,
3DES: Enable,
AES: Enable,
AES-GCM:
Disable
Certificate On
Verification
20
Item Value
Management Authentication Settings Authentication General Authentication Off
Settings Settings Local Local Off
Authorization Authorization
Settings
Guest Guest Off
Authorization Authorization
Settings
Simple Login Simple Login Off
Settings
History History Settings Job Log History Recipient No setting
Settings E-mail Address
Auto Sending Off
Login History Login History Off
Settings Recipient No setting
E-mail Address
Auto Sending Off
Device Log Device Log Off
History Settings History
Recipient No setting
E-mail Address
Auto Sending Off
Secure Secure Off
Communication Communication
Error Log Error Log
History Settings History
Recipient No setting
E-mail Address
Auto Sending Off
21
© 2019 KYOCERA Document Solutions Inc. 2019.4
3MS2XTKDEN0
is a trademark of KYOCERA Corporation