A single PC-based physical network segretation method and apparatus that operates in an environment that uses the operating system installed on the built-in disk device of the laptop PC
The network separation dongle for laptops addresses space constraints and security vulnerabilities by enabling direct data transfer and automatic WiFi suppression, ensuring secure single-PC network separation.
Patent Information
- Authority / Receiving Office
- KR · KR
- Patent Type
- Applications
- Current Assignee / Owner
- STORAGEAN INC
- Filing Date
- 2025-01-11
- Publication Date
- 2026-07-21
AI Technical Summary
Existing single-PC physical network separation technologies face challenges with laptop PCs due to limited space for installing separate M.2 SSDs, requiring cloning and formatting, and lack of direct data transfer between internal and external networks, which increases security vulnerabilities.
A network separation dongle for laptops that uses USB Type-C connectors, low-speed and high-speed USB interfaces, and network signal converters to enable separate network connections or blocking without network connectivity, allowing direct data transfer between internal and external networks through designated folders, and suppresses WiFi function automatically.
Provides a secure, single-PC network separation environment with reduced hacking risks, eliminating manual network management and enhancing security by preventing unauthorized data transfer.
Smart Images

Figure PAT00003_ABST
Abstract
Description
Technology Field
[0001] The present invention relates to providing a physical network separation environment for laptop PC users by simply connecting the network separation dongle of the present invention to the laptop PC, without replicating the operating system embedded in the laptop PC into an internal network operating system and an external network operating system to an M.2 SSD storage device separately provided outside the laptop PC.
[0002] The network isolation software for this purpose consists of a graphical user interface in addition to device drivers, and in terms of hardware, it is characterized by the absence of an M.2 SSD for installing internal / external network operating systems.
[0003] In addition, in addition to the form in which internal / external network cables are connected, when the user's smartphone and the network separation dongle of the present invention are connected, the tethering function of the smartphone is activated and signals such as 5G, LTE, and WiFi are transmitted to the network separation dongle of the present invention as USB signals, thereby enabling the external network to be configured by converting the USB signals transmitted from the smartphone into Ethernet signals inside the network separation dongle of the present invention.
[0004] In addition, when the network separation dongle of the present invention is connected to a laptop PC, the device driver constituting the network separation software of the present invention simultaneously suppresses the WiFi function of the laptop PC, thereby preventing the inconvenience of the user having to artificially suppress the WiFi function every time it is used.
[0005] In addition, when a web browser is launched within the virtual machine software immediately after the virtual machine software used as an external network is started, a website is connected to the starting URL for the external network specified by the user on the graphical user interface of the present invention.
[0006] Finally, in a single PC-based physical network separation environment where the network separation dongle of the present invention is used, when it is necessary to bring data downloaded from an external network into an internal network or to transfer data from an internal network to an external network environment, network security can be further enhanced by enabling direct data transmission within a single PC through a method of designating or de-designating an arbitrary folder specified by the user as a shared folder in the explorer window on the virtual machine software side and the main screen side of the operating system, without using network connectivity through a conventional network. Background Technology
[0007] Upon booting, the PC connects to the network regardless of the user's will, and since all disk devices, including the internal disk drive containing user data without an operating system installed, remain connected until the PC is shut down, by the time the PC completes booting and becomes usable, all disk devices, including the internal disk drive, are left exposed on the network. Consequently, the user can only finally use their PC once it has become vulnerable to hacking.
[0008] In an effort to fundamentally resolve these problems, physical network separation was introduced approximately 10 years ago and continues to this day, but a physical network separation environment has been configured with two desktop PCs for one user while entailing the problems described above.
[0009] However, from a user's perspective, if we examine the usage environment of a physically separated PC consisting of two computers, the necessity of using two PCs arises from the inevitable reason for their necessity. For instance, if a user searches for certain data on the external network (the Internet) and references it on the internal business network to write a report, an environment with two PCs is inevitably required.
[0010] Accordingly, in the conventional single-PC-based physical network separation, virtual machine software is utilized for external network access in order to maintain physical network separation while providing a usage environment similar to using two PCs as described above, even though only one PC is used.
[0011] Meanwhile, regarding physical network separation based on a single PC, the patents filed under the following items, which have been filed by the applicant under the following patent application number as a priority claim, constitute the background technology for the present invention.
[0012] - May 23, 2023, Patent Application No. 10-2023-0066393
[0013] - June 14, 2023, Patent Application No. 10-2023-0075982
[0014] - July 25, 2023, Patent Application No. 10-2023-0096573
[0015] - January 26, 2024, Patent Application No. 10-2024-0012738
[0016] - May 22, 2024, Patent Application No. 10-2024-0066664 The problem to be solved
[0017] The block diagram showing the physical network separation of a single PC in the prior art of FIG. 1 was intended to implement the physical network separation using two PCs in the past with a single PC. To this end, an operating system for the internal network and an operating system for the external network were provided separately so that even the operating systems were physically separated. The basic operation was to control the internal network operating system to remain in a blocked state when booting into the internal network operating system in the network separation control unit (B7), and conversely, to maintain the internal network operating system in a blocked state when booting into the external network operating system.
[0018] However, recent laptop PCs, like smartphones, generally have a structure that prevents users from artificially opening the bottom cover to access the built-in storage device. Furthermore, even if the bottom cover is opened, due to the limited space of the laptop PC, the length becomes longer when the M.2 SSD is inserted into the M.2 Adapter card as shown in Fig. 1, making installation difficult. Additionally, even if a short M.2 SSD is used, there is a problem involving the inconvenience of having to copy the operating system from the existing M.2 SSD to a separate M.2 SSD that is short.
[0019] In addition, to clone an M.2 SSD, which is an internal disk device on which an operating system was installed in a laptop PC, to an M.2 SSD for an internal network operating system and an M.2 SSD for an external network operating system, one had to use a separate cloning program or a separate docking station equipped with an M.2 SSD slot.
[0020] In addition, although laptop PCs are generally equipped with an M.2 SSD slot for user data in addition to the M.2 SSD for the operating system, a problem arises where the M.2 SSD for user data is effectively eliminated if an internal network operating system and an external network operating system are installed on the two M.2 SSDs, in addition to the issues of installing the aforementioned M.2 Adapter card or cloning the operating system.
[0021] Accordingly, due to the problems described above, the physical network separation based on a single PC of the conventional technology based on FIG. 1 is a block diagram suitable for enabling physical network separation with only one desktop PC, whereas previously two desktop PCs were used for one user. In addition to the M.2 Adapter card for combining an M.2 SSD with an internal / external network operating system installed, the network selector (B5) and the network connection means (B6) are configured as physically separated independent configurations and are each connected to a USB Type-C port provided on a PCIe Bracket on a network separation PCIe card that forms a network separation control unit.
[0022] Nevertheless, in order to provide a physical network separation environment to notebook PC users in the conventional technology, a physical network separation dongle was presented in the form of a network selector (B2), a network connection means (B6), and an M.2 SSD connector on which an M.2 SSD with an internal / external network operating system installed can be installed, as shown in FIG. 2. However, this was merely a physical network separation environment based on a single PC in a desktop PC usage environment transferred in a physically integrated form. Therefore, in addition to the inconvenience of having to clone the operating system embedded in the notebook PC as described above to the M.2 SSD (D19, D21) provided in FIG. 2, there was also the problem of having to format the M.2 SSD embedded in the notebook PC with the operating system installed after the cloning was completed.
[0023] Furthermore, in the conventional single-based physical network separation, the operation of the device driver was described as proceeding by monitoring the startup status of web browsers corresponding to the internal and external networks respectively within the device driver without a separate graphical user interface; however, there was a problem in that it was difficult to detect the operation of web browsers running within virtual machine software from the main screen.
[0024] Finally, in existing physical network separation environments, even though physical network separation is in place to prevent hacking from the outside, when it is necessary to bring data downloaded from the external network into the internal network or move data prepared in the internal network to the external network, data transmission is inevitably required through a network interconnection system. Consequently, the network connection between the internal and external networks for network interconnection inevitably acts as a security vulnerability.
[0025] In this invention, even without network connectivity through a network connection, data transfer between internal and external networks is enabled by designating a specific folder in the explorer window of the main screen and the explorer window of the virtual machine software used from within a single PC to an external network as a shared folder, thereby further enhancing security from a network perspective. means of solving the problem
[0026] A single PC-based physical network separation method and device for achieving the above objective, which operates in an environment using an operating system installed on an internal disk device of a notebook PC according to the present invention, comprises: a first USB Type-C connector for connecting to a notebook PC; A low-speed USB hub connected to low-speed USB pins provided in the USB Type-C connector to generate a first low-speed USB interface signal and a second low-speed USB interface signal; a low-speed interface conversion means connected to the low-speed USB hub and the first low-speed USB interface signal; a network connection means that connects an internal network, connects an external network, or blocks both an internal network and an external network according to an internal network selection signal or an external network selection signal output from the low-speed interface conversion means; a first low-speed network signal conversion unit connected to the network connection means to convert a network signal into a low-speed USB signal and connect it to the low-speed USB hub as the second low-speed USB interface signal; a first network signal connection means for connecting an internal network cable connected to the network connection means; a second network signal connection means for connecting an external network cable connected to the network connection means; a power supply unit connected to power pins provided in the USB Type-C connector to generate power for internal use; and a printed circuit board for mounting the components of each of the above components. In a physical network separation control means comprising: a low-speed interface conversion means, wherein the network connection means is connected to the internal network in the case of an internal network by means of a pin output according to the status information received by the first low-speed USB interface signal, the network connection means is connected to the external network in the case of an external network, and the network connection means is blocked in the case of network blocking.
[0027] In addition, a first USB Type-C connector for connection to a laptop PC; A low-speed interface conversion means connected to low-speed USB pins provided in the USB Type-C connector; a network connection means that connects an internal network, connects an external network, or blocks both an internal network and an external network according to an internal network selection signal or an external network selection signal output from the low-speed interface conversion means; a first high-speed network signal conversion unit connected to the network connection means to convert a network signal into a high-speed USB signal and connect it to a high-speed USB signal provided in the first USB Type-C connector; a first network signal connection means for connecting an internal network cable connected to the network connection means; a second network signal connection means for connecting an external network cable connected to the network connection means; a power supply unit connected to power pins provided in the USB Type-C connector to generate power for internal use; and a printed circuit board for mounting the components of each of the above components. In a physical network separation control means comprising, the low-speed interface conversion means is configured such that, in the case of an internal network, the network connection means is connected to an internal network by means of a pin output according to the status information received as a low-speed USB interface signal of the first USB Type-C connector, in the case of an external network, the network connection means is connected to an external network, and in the case of network blocking, the network connection means is blocked.
[0028] In addition, a first network adapter provided for the main screen when an operating system installed on a PC internal disk device boots; a second network adapter provided for virtual machine software installed on the operating system; physical network separation software installed on the operating system and composed of a graphical user interface unit and a device driver; a monitor displaying components on the desktop and taskbar provided by the operating system, such as the graphical user interface unit of the physical network separation software, a web browser launched on the main screen and the virtual machine software, respectively; a network separation control unit receiving status information related to the connection or blocking of an internal network and an external network generated by the graphical user interface unit through the device driver; a first network signal connection means for connecting an internal network cable; and a second network signal connection means for connecting an external network cable. A network connection means connected to each of the first network signal connection means and the second network signal connection means, and performing an operation to connect an internal network signal of the first network signal connection means, connect an external network signal of the second network signal connection means, or block both the internal network signal and the external network signal according to a control signal output from the network separation control unit; and an ETHERNET-USB converter connected to the network connection means and converting an ETHERNET network signal into a USB signal.It is configured such that when the network separation software is not started, the network separation control unit maintains the network connection means in a network-blocked state, and when the network separation software is started, the graphical user interface unit transmits state information to the device driver side that allows the network to be connected to an internal network, connected to an external network, or maintained in a network-blocked state according to a preset setting, or when the user selects an internal network, selects an external network, or transmits state information storing network blocking selection information to the device driver side, the device driver causes the first network adapter corresponding to the internal network to be connected, the second network adapter corresponding to the external network to be connected, or the first network adapter and the second network adapter to be simultaneously blocked according to the state information, and the network separation control unit causes the network connection means to be connected to an internal network, connected to an external network, or in a network-blocked state according to the state information. Effects of the invention
[0029] Through a single PC-based physical network separation method and device that operates in an environment where the operating system installed on the internal disk device of a notebook PC according to the present invention is used as is, users can use a physical network separation environment simply by connecting a physical network separation dongle to the USB port of a notebook PC or desktop PC, and thereby can use the PC with peace of mind without worrying about hacking, data leakage, ransomware, and infection from various malware from the outside.
[0030] In addition, the network remains blocked from the moment the PC boots up until the user launches the network isolation software and opens a web browser. Furthermore, even while the network isolation software is running, if it is determined that there is no change in the URL field for a series of web browsers open on the monitor for a preset period, the network is switched to a blocked state while the state of the screen displayed in the web browser is maintained, thereby significantly reducing the possibility of hacking from the outside.
[0031] In addition, when the user's smartphone is connected to the network separation dongle of the present invention, the tethering function of the smartphone is activated to convert signals such as 5G, LTE, and WiFi received by the smartphone into Ethernet network signals and connect them to the external network port of the network separation dongle to form an external network. At the same time, the device driver of the network separation software, which recognizes that the network separation dongle of the present invention is connected to a PC, suppresses the PC's built-in WiFi function, thereby eliminating the inconvenience of the user having to manually suppress the WiFi function every time it is used. Brief explanation of the drawing
[0032] FIG. 1 is a diagram showing a physical network separation block configuration based on a single PC in which an M.2 SSD with an internal network operating system installed, an M.2 SSD with an external network operating system installed, a network connection means, and a network selector are each physically independent components connected to a network separation control board. FIG. 2 is a block diagram of a physical network separation dongle for realizing physical network separation for a notebook PC according to the prior art, and an example of a physical network separation dongle for a notebook PC that is hardware-embodied therein on a single printed circuit board. FIG. 3 is a block diagram of a network separation dongle for physical network separation for a notebook PC according to the present invention, and is a diagram schematically showing a single PC-based physical network separation configuration using an operating system installed on an internal disk device provided inside the notebook PC. FIG. 4 is a block diagram of a physical network separation dongle that operates in accordance with low-speed USB interface signals and low-speed network signals in an environment where an operating system installed on a disk device inside a notebook PC is used as is, according to the block diagram of FIG. 3 according to the present invention. FIG. 5 is a block diagram of a physical network separation dongle in which, in an environment where an operating system installed on a disk device provided inside a notebook PC is used as is according to the block diagram of FIG. 3 according to the present invention, a low-speed USB interface signal is used for control of a network connection part, and a high-speed USB interface signal is used for a high-speed network signal interface. Figure 6 is a flowchart of the operation of network separation software consisting of a device driver and a graphical user interface that displays physical network separation operations step by step for a notebook PC equipped with an internal disk device having an operating system installed. FIG. 7 is an execution screen of an embodiment illustrating the configuration of an internal network web browser on the main screen, an external network web browser on the virtual machine software screen, a shared folder, a graphical user interface, and a taskbar on the monitor, according to the operation flowchart of FIG. 6 according to the present invention. FIG. 8 is an example showing a graphical user interface portion excluding the device driver in physical network separation software according to the present invention. Specific details for implementing the invention
[0033] The terms used in this specification are for describing embodiments and are not intended to limit the invention.
[0034] In this specification, the singular form includes the plural form unless specifically stated otherwise in the text.
[0035] In addition, the network separation dongle, physical network separation dongle, and physical network separation control means mentioned in this invention are basically used with the same meaning.
[0036] Hereinafter, a single PC-based physical network separation method and apparatus operating in an environment using an operating system installed on an internal disk device (E11) of a notebook PC (B1) according to a preferred embodiment of the present invention will be described with reference to the drawings as follows.
[0038] FIG. 3 is a block diagram for providing a physical network separation usage environment for a notebook PC according to the present invention. In accordance with the organic operation between the physical network separation control means (E1), abbreviated as network separation dongle, network separation software (E9), and web browsers displayed on the main screen (3) used as an internal network and the virtual machine screen (5) used as an external network on the monitor (100), the internal network web browser (103) on the main screen (101) and the external network web browser (107) on the virtual machine software screen (105) are performed together with the execution screen of the embodiment displayed on the monitor (100) as shown in FIG. 7. The physical network separation operation is performed by examining the corresponding blocks or components according to the indicated symbols as follows.
[0039] For reference, among the symbols used in the single PC-based physical network separation block configuration diagram of the prior art in FIG. 1 and FIG. 2 and the symbols used in the present invention from FIG. 3 onwards, identical symbols correspond to blocks that perform the same function, and newly added function blocks are indicated by a new alphabet + number combination symbol.
[0041] First, the network connection means (B6) connects the internal network (B3) signal or the external network (B4) signal to the ETHERNET ~ USB converter (E3) side according to the network switching control signal output from the network separation control unit (B7).
[0042] The ETHERNET ~ USB converter (E3) takes into account that as the thickness of recent notebook PCs becomes thinner, the use of RJ45 connectors (not shown, but in the form of D25, D27) used for directly connecting network cables is excluded and replaced by USB Type-C connectors (not shown, but in the form of D1). Accordingly, the ETHERNET network signal transmitted from the network connection means (B6) is converted into a low-speed USB signal such as USB 2.0 if it is a low-speed network signal of 100 Mbps or less, and into a high-speed USB signal such as USB 3.0 or higher if it is a high-speed network signal of 1 Gbps or more.
[0043] The network signal converted into a low-speed USB signal or a high-speed USB signal through the ETHERNET ~ USB converter (E3) is connected to a USB port (E5) equipped with a USB Type-C connector.
[0044] When used with a notebook PC (B1), the physical network separation control means (E1) of the present invention is connected to any USB port (E7) provided in the notebook PC (B1) using a separate USB Type-C cable (not shown).
[0045] The network separation control unit (B7) is connected to the USB port (E5) and receives a control signal from a device driver that is one of the components of the network separation software (E9) installed on the internal disk device (E11) on which the operating system of the notebook PC (B1) is installed via a low-speed USB interface, and outputs a network switching control signal such as an internal network connection signal, an external network connection signal, or a blocking signal between the internal network and the external network for the network connection means (B6).
[0046] The physical network separation control means (E1) of the present invention does not necessarily have to be connected before the notebook PC (B1) is booted, and can be connected to the notebook PC (B1) and used at a time when security is deemed necessary during use of the notebook PC (B1) even after booting is completed.
[0048] The network isolation software (E9) consists of a device driver and a graphical user interface and is installed on an embedded disk device (E11) on which an operating system is installed.
[0049] While the booting operation of the laptop PC (B1) is in progress, the network separation control unit (B7) maintains a network blocking state, and when the user launches the network separation software by double-clicking the network separation software execution icon (111) on the desktop of the main screen (101) of the monitor (100) with a mouse (not shown), the network separation software (E9) creates a network separation software icon (113) on the taskbar (116) at the bottom of the monitor (100) and simultaneously transmits a control signal to the device driver to connect the internal network to the network separation control unit (B7).
[0050] When the network separation software (E9) is launched immediately after the network separation software (E9) is installed, the internal network selection button is pressed, which is the initial setting state, and the internal network is connected. However, when the network separation software (E9) is launched via the extended graphical user interface (140), the user may be allowed to select one of network blocking, internal network connection, or external network connection. Alternatively, the previous connection state may be maintained by saving the connection state information that the user last used and reading the connection state information from the newly started network separation software (E9).
[0051] Accordingly, in execution immediately after installation of network separation software (E9), the device driver maintains the network adapter-I (B11) for the internal network in an active state through the network switching unit (B10), and switches the network adapter-E (B13), which corresponds to the virtual network adapter used for the external network in the virtual machine software, to an unused state.
[0052] Then, the network separation control unit (B7) causes the network connection means (B6) to be connected to the internal network (B3) according to the network switching control signal transmitted from the device driver, and a network signal connection path is formed through the network signal to the ETHERNET ~ USB converter (E3), USB port (E5), USB port (E7), network switching unit (B10), and network adapter-I (B11), and when the user activates the web browser icon (not shown) provided on the desktop or taskbar of the main screen (101), the web browser (B15, 103) opens on the main screen (101) and connects to a website with a URL that the user has previously specified.
[0054] As described above, while physical network separation is maintained in the internal network usage environment, when the user wants to access the external network and clicks the network separation software icon (113) provided on the taskbar with a mouse, a minimized graphic user interface (121) of the network separation software (E9) opens in the center of the monitor (100).
[0055] Figure 7 shows a state in which a miniaturized graphic user interface (121) that has popped up in the center of the monitor is moved to the bottom of the screen by the user dragging it with a mouse.
[0056] When a user presses the external network selection button (129) provided in the reduced graphical user interface (121) of the network separation software user interface (120) shown in FIG. 8 to access the external network, the existing green background internal network selection button (127) is deactivated and changed to a gray background button, and at the same time, the external network selection button changes from the existing gray background to a red background external network button (129).
[0057] At this time, the device driver transmits a control signal to the network separation control unit (B7) and the network switching unit (B10) indicating that it is connected to an external network, thereby making the network connection path an external network (B4), a network connection means (B6), an ETHERNET to USB converter (E3), a USB port (E5), a USB port (E7), a network switching unit (B10), and a network adapter-E (B13). When it is determined that the virtual machine software is not open, the device driver starts the virtual machine software and displays a virtual machine screen (105) used for the external network in an arbitrary area on the monitor (100). Subsequently, the device driver refers to the virtual machine start URL (151) provided in the extended graphical user interface (140) of the network separation software (E9) and causes the web browser launched on the virtual machine screen (105) to be connected to the external network website of the corresponding URL.
[0059] This time, when the user presses the internal network selection button (127) on the miniaturized graphical user interface (121), the device driver changes the network path back to the internal network (B3), the network signal to the ETHERNET ~ USB converter (E3), USB port (E5), USB port (E7), network switching unit (B10), and network adapter-I (B11), and the previously opened web browser is connected to the internal network again, and the web browser (107) on the virtual machine screen (105) maintains a blocked network state, while the screen that was previously displayed when connecting to the external network remains the same.
[0060] If, in this state, the user presses the network block button (125), the network separation control unit (B7), which receives status information from the device driver, outputs a network switching control signal to switch the network connection means (B6) to a state where both the internal network (B3) and the external network (B4) are blocked, and the device driver switches the network adapter-I (B11) for the internal network and the network adapter-E (B13) for the external network to a state where they are not used through the network switching unit (B10).
[0062] Next, as the next action, when the user presses the internal network selection button (127) or the external network selection button (129), the network connection or blocking path for each of the cases described above is made so that the network for the corresponding button can be used again.
[0063] That is, to summarize the operation of the block diagram of FIG. 3, when the network separation software (E9) is not started, the network separation control unit (B7) maintains the network connection means (B6) in a network-blocked state, and when the network separation software (E9) is started, it transmits state information to the device driver side so that the network is connected to an internal network, connected to an external network, or maintained in a network-blocked state according to the user's preset settings in the graphic user interface (120), or transmits state information to the device driver side so that the user selects an internal network, selects an external network, or stores network-blocked selection information through the graphic user interface.
[0064] At this time, the device driver connects the network adapter-I (B11) corresponding to the internal network to the state information, connects the network adapter-E (B13) corresponding to the external network, or simultaneously blocks both the network adapter-I (B11) and the network adapter-E (B13).
[0065] At this time, the network separation control unit (B7) makes the network connection means (B6) connect to an internal network, connect to an external network, or make the network blocked according to the status information received as a control signal.
[0067] FIG. 4 is a block diagram of a physical network separation dongle (E1) that operates in accordance with low-speed USB interface signals and low-speed network signals in an environment using an operating system installed on a disk device (E11) provided inside a notebook PC (B1) according to the block diagram of FIG. 3 according to the present invention, and the functional blocks according to the indicated symbols are as follows.
[0068] The low-speed USB HUB (D3) is connected to the low-speed USB pin and low-speed USB signal wiring provided in the USB Type-C connector (D1) corresponding to the USB port (E5) of FIG. 3, and the first low-speed USB interface signal and the second low-speed USB interface signal branched from the low-speed USB HUB (D3) are respectively connected to the low-speed USB interface unit (D17) and the ETHERNET-to-low-speed USB converter unit (D9).
[0069] The low-speed USB interface unit (D17) is connected to the network isolation control unit (D29) via a UART (Universal Asynchronous Receiver Transmitter) serial interface signal or a TTL (Transistor to Transistor Logic) level pin signal, which is transmitted by the device driver of the network isolation software (E9) via the low-speed USB HUB (D3) as a first low-speed USB interface signal, or when the network isolation control unit (D29) is not used, it is connected to the network connection unit (D15) via a TTL level pin signal instead.
[0070] Additionally, when the low-speed USB interface unit (D17) is not in use, it outputs an ON / OFF control signal to the LED provided in the direct LED display unit (D23).
[0071] The network separation control unit (D29) receives status information related to network control transmitted from the device driver of the network separation software (D9) received through the low-speed USB HUB (D3) and the low-speed USB interface unit (D17) as the same status information as the control of the network switching unit (B10) for the internal network adapter-I (B11) and the external network adapter-E (B13) on the network separation software (E9) side, and outputs this as a network switching control signal to perform control on the network connection unit (D15) corresponding to the network connection means (B6) of FIG. 3 regarding whether to select the internal network (B3) or the external network (B4).
[0072] The network separation control unit (D29) has a built-in MCU (Micro Processor Unit) and can perform various operations through a built-in program. For example, when configuring an external network using a user's smartphone by replacing the RJ45 connector-E (D27) to which an external network cable is connected, it can respond to various operations beyond the limited functions of the low-speed USB interface unit (D17), such as charging control operations to prevent the smartphone's battery from discharging due to the external network configuration.
[0073] Meanwhile, the network separation control unit (D29) drives the LED provided in the LED display unit (D23) according to the status information received from the device driver.
[0075] The LED display unit (D23) drives the green LED to turn ON when the network separation software (E9) is selected as an internal network according to the LED control signal output from the low-speed USB interface unit (D17) or the network separation control unit (D29), drives the red LED to turn ON when the external network is selected, and drives the green LED corresponding to the internal network and the red LED corresponding to the external network to turn OFF respectively when the network is blocked.
[0077] The network connection part (D15) is connected to the network pin signals provided in the RJ45 connector-I (D25), to which the internal network (B3) of FIG. 3 is connected, and the RJ45 connector-E (D27), to which the external network (B4) is connected.
[0078] When the network connection unit (D15) does not have a network separation control unit (D29), it outputs an internal network signal (B3) or an external network signal (B4) to the ETERNET pin side provided in the ETHERNET~low-speed USB converter (D9) according to the network switching control signal output from the low-speed USB interface unit (D27).
[0079] In the case where the network switching control signal output from the low-speed USB interface unit (D17) or the network separation control unit (D29) is network blocking, the network signal input to the ETHERNET~low-speed USB converter (D9) can be blocked by maintaining the RESET pin provided in the network connection means (B6) in a reset state or by completely blocking the power input to the network connection unit (D15).
[0081] The ETHERNET~low-speed USB conversion unit (D9) performs the operation of converting the ETHERNET network signal transmitted from the network connection unit (D15) into a low-speed USB signal and transmits it to the low-speed USB HUB (D3) as a second low-speed USB interface signal. Then, the low-speed USB HUB (D3) is connected to any USB port (E7) provided in the notebook PC through a separate USB cable (not shown) connected to the USB Type-C connector (D1) corresponding to the USB port (E5) of FIG. 3, which converts the network signal into a low-speed USB signal.
[0082] In the case where a separate MCU is built into the ETHERNET~low-speed USB converter (D9) and it does not have a non-volatile program memory area of its own, a separate EEPROM (not shown) or Flash PROM (D11) is provided externally.
[0083] The power supply unit (D7) receives power supplied from the notebook PC (B1) through the power pin of the USB Type-C connector (D1) and generates and supplies power suitable for various function blocks provided inside the network isolation dongle (E1).
[0085] Meanwhile, a WiFi function block (not shown) is built into a laptop PC (B1) to provide a wireless internet access environment, but this only provides an environment to connect to a network and can act as a vulnerability from a security perspective.
[0086] In order to solve this problem, the present invention removes the RJ45 connector-E (D27) to which the external network (B4) of FIG. 3 is connected, and in its place, a USB Type-C connector (D37) that can be directly connected to the user's smartphone is provided, and a low-speed USB to Ethernet converter (D33) is provided between the USB Type-C connector (D37) and the network connection part (D15).
[0087] The low-speed USB to ETHERNET converter (D33) is functionally identical to the ETHERNET to low-speed USB converter (D9) described above, except that the order of the terms has been reversed for intuitive understanding.
[0088] When the USB Type-C connector (D37) is connected to the user's smartphone (D39) via a separate cable (not shown), and the user activates the tethering function of the smartphone, the smartphone (D39) converts signals such as 5G, LET, and WiFi into USB signals and outputs them to the USB Type-C connector (D37).
[0089] The low-speed USB to ETHERNET converter (D33) converts the network signal transmitted as a low-speed USB signal into an ETHERNET signal and transmits it to the external network (B4) side of the network connection unit (D15) described above.
[0090] In this way, the user can configure an external network usage environment through a simple configuration connecting a laptop PC (B1), a network separation dongle corresponding to a physical network separation control means (E1), and a smartphone.
[0091] Meanwhile, the device driver of the network separation software (E9) recognizes that the connected target is the network separation dongle (E1) through the model name (146) displayed on the extended network separation software user interface (140) of FIG. 8, thereby suppressing the WiFi function built into the laptop PC (B1), thereby reducing the inconvenience of the user having to manually suppress the WiFi function every time it is used, and if the network separation dongle (E1) is not connected or is connected and then disconnected, it switches the WiFi function back to a usable state.
[0093] FIG. 5 is a block diagram of a physical network separation dongle (E1) in which, in an environment using an operating system installed on a disk device provided inside a notebook PC (B1) according to the block diagram of FIG. 3 according to the present invention, a low-speed USB interface signal is used for control of a network connection unit (D15) and a high-speed USB interface signal is used for a high-speed network signal interface. The functional blocks according to the indicated symbols are as follows.
[0094] The low-speed USB pin provided in the USB Type-C connector (D1) corresponding to the USB port (E5) of Fig. 3 is connected to the low-speed USB interface section (D17) with a low-speed USB interface signal, and the high-speed USB pin is connected to the ETHERNET-to-high-speed USB converter section (D6) with a high-speed USB interface signal.
[0095] The detailed description of the low-speed USB interface section (D17) and the network separation control section (D29) is the same as that described above in FIG. 4, and the RJ45 connector-I (D25) for the internal network corresponding to the internal network (B3) of FIG. 3 and the RJ45 connector-E (D27) for the external network corresponding to the external network (B4) connected to the network connection section (D15) are also identical to those of the corresponding block shown in FIG. 4, so a redundant description of them is omitted.
[0096] However, the low-speed USB interface unit (D17) and the network separation control unit (D29) of FIGS. 4 and 5 correspond to the network separation control unit (B7) in FIG. 3.
[0098] The ETHERNET ~ high-speed USB converter (D6) receives an Ethernet network signal output from the network connection unit (D15), converts it into a high-speed USB interface signal, and connects it to a pin for a high-speed USB signal provided in the USB Type-C connector (D1).
[0099] In the block diagram for the high-speed network signal interface of FIG. 5, the low-speed USB interface section (D17) is directly connected to the low-speed USB pin of the USB Type-C connector (D1), unlike in FIG. 4. The low-speed USB interface section (D17) is used to transmit a network switching control signal for selecting or blocking one of the internal network (B3) or external network (B4) signals for the network connection section (D15) by means of the low-speed USB interface signal containing status information transmitted by the device driver. Since the high-speed USB interface signal is used to transmit the ETHERNET network signal through the ETHERNET ~ high-speed USB converter (D6) to the notebook PC (B1) as a high-speed USB signal, a separate low-speed USB HUB (D3) as in FIG. 4 is not required.
[0101] Meanwhile, as in FIG. 4, the external network (B4) can be connected to the user's smartphone (D39) by replacing the RJ45 connector-E (D27) in FIG. 5. In this case, a high-speed USB to ETHERNET converter (D34) is provided between the USB Type-C connector (D37) for connecting to the smartphone (D39) and the network connection part (D15).
[0102] When the user activates the tethering function in the settings of the smartphone while the network separation dongle (E1) for the high-speed network interface shown in Fig. 5 is connected to the smartphone (D39), the smartphone transmits signals such as 5G, LTE, or WiFi as high-speed USB interface signals to the high-speed USB-ETHERNET converter (D34) through the communication protocol between the high-speed USB-ETHERNET converter (D34) and the smartphone (D39), and the high-speed USB-ETHERNET converter (D34) converts the high-speed USB interface signals into high-speed ETHERNET network signals and transmits them to the external network (B2) of the network connection unit (D15).
[0104] FIG. 6 is a flowchart of the operation of network separation software (E9) composed of a device driver and a graphical user interface that displays physical network separation operations in stages for a notebook PC (B1) equipped with an internal disk device having an operating system installed, and the operation in stages according to the symbols is as follows.
[0106] When the user turns on the power of the notebook PC (B1) (S1), the PC performs the operation of recognizing various peripheral devices by means of the program of the ROM BIOS (not shown). (S3)
[0107] If a network separation dongle, indicated as a physical network separation control means (E1), is connected to any USB port (E7) of the laptop PC (B1), the network separation dongle (E1) is recognized as a peripheral device in this step (S3).
[0109] The notebook PC (B1) performs a boot operation by the operating system of the internal disk device (11) on which the operating system is installed. (S5)
[0110] At this time, if a network isolation dongle is connected to the laptop PC (B1), the low-speed USB interface part (D17) or the network isolation control part (D29) of the network isolation dongle outputs a network switching control signal in a network blocking state to maintain the network in a blocked state and switches the WiFi function of the laptop PC (B1) to a suppressed state. (S7)
[0112] Next, it is determined whether the network isolation software (E9) has been executed. (S9)
[0113] The network separation software (E9) can be executed by double-clicking the network separation software execution icon (111) provided on the desktop of the main screen (101) of the monitor (100) with a mouse, and the network separation software (E9) can be executed automatically when the network separation software auto-execution checkbox (not shown) is checked when a network separation dongle is detected in the graphic user interface (120) of the network separation software (E9).
[0114] If the network isolation software (E9) is executed, the operation of the device driver is initiated, and at the same time, the network isolation software icon (113) is provided on the taskbar.
[0115] When the user clicks the network separation software icon (113) provided on the taskbar with the mouse, a minimized graphical user interface (121) is displayed on the monitor (100).
[0117] The device driver reads the network connection information from the previous state. (S11)
[0118] If the network connection information in the previous state was an internal network, the device driver switches through the network switching unit (B10) so that the network adapter-E (B13), which corresponds to the virtual network adapter used for the virtual machine software, i.e., the virtual machine screen, becomes unused, thereby blocking the external network, and switches to a state where the network adapter-I (B11), which is used for the main screen, becomes used, thereby connecting to the internal network. (S15)
[0120] Along with this, the device driver also transmits a control signal containing the status information of step S15 to the network isolation dongle (E1) so that the external network is blocked and the internal network is connected. (S19)
[0122] Meanwhile, if it is determined in step S13 that the network connection information in the previous state was an external network, the device driver ensures that the network for the virtual machine screen is connected so that the external network is connected, and ensures that the network for the main screen is blocked. (S17)
[0124] Along with this, the device driver also transmits a control signal containing the status information of step S17 to the network isolation dongle (E1) so that the external network is connected and the internal network remains blocked. (S21)
[0126] In the above, in order to provide convenience for the user in step S11, the network connection information of the previous state is read, but depending on the implementation method, the internal network selection, external network selection, or network blocking may be selected by placing a checkbox in the extended graphical user interface to enable or disable reading the network connection information of the previous state, or the user may directly select the internal network, external network selection, or network blocking in the reduced graphical user interface (121) of the network separation software (E9) by clicking a button with a mouse or entering a shortcut key directly on the reduced graphical user interface (121).
[0128] The device driver determines whether the network isolation software (E9) has terminated. (S23)
[0129] The network isolation software (E9) is terminated by the user clicking the X area displayed at the top right of the graphical user interface (120) with a mouse. When it is determined that the network isolation software (E9) has been terminated at step S23, the device driver causes the internal / external network to be blocked for the network isolation dongle (E1). (S25)
[0131] Along with this, the external network adapter-E (B13) used for the virtual machine screen and the internal network adapter-I (B11) used for the main screen are each switched to an unused state so that both the internal and external networks are blocked. (S27)
[0133] After the various resources used by the network separation software (E9) are returned and the network separation software (E9) is terminated, the process proceeds to a step (S9) for determining whether the network separation software (E9) was executed. (S29)
[0135] Meanwhile, if it is determined that the network separation software (E9) has not been terminated in step S23, the system monitors whether a network switch has occurred by inputting a button or a shortcut key provided in the graphical user interface (120). (S31)
[0136] If it is determined that a network switch has occurred in step S31, the device driver saves the switched network connection information (S35) and then moves to step S11; if it is determined that no network switch has occurred, it checks whether the network block button or the corresponding shortcut key has been pressed. (S33)
[0137] If it is determined that the network is blocked in step S33, after performing steps S25 and S27 as described above, the process proceeds to step (S9) for determining whether the network separation software (E9) has been executed.
[0139] If it is determined that the network is not blocked and the PC is not shut down (S37), the device driver captures the entire monitor screen, creates an arbitrary folder under the installation folder of the network isolation software (E9) program, saves the image file of the captured entire screen there, and then determines whether a change in the URL Field has been detected. (S35)
[0140] While repeatedly performing steps S23, S31, S33, and S37, the device driver captures full screen data at regular intervals and compares it with the image file saved immediately before, detects the location of a closed-loop star-shaped favorite icon (167) among the main components (160) of the web browser shown in FIG. 7, and considers the horizontal area of that location as a URL field (165).
[0141] In the URL field (165) area searched in the manner described above, a Test-type URL is extracted from the image and compared with the previous one, or the image is compared with the corresponding area of the previous picture file in the URL field (165) area and determined to be a match, and if it is determined that no change has occurred in the URL fields of web browsers open on the monitor even after the time set by the user entered in the Network block time (141) field in the extended graphic user interface (140) has elapsed, network blocking operations corresponding to S25 and S27 are performed.
[0142] If it is determined that a change in the URL field has occurred in any web browser before the time set by the user has elapsed, the network blocking action is not performed.
[0144] When the laptop PC is shut down, the shutdown process is performed and the PC power is cut off. (S39)
[0146] As described above, we have examined the operation of a device driver and a graphical user interface (120) linked thereto that constitute a network separation software (E9) for physical network separation based on a single PC, which uses an operating system installed on an internal disk device provided inside the notebook PC (B1) according to the present invention of FIG. 3.
[0148] FIG. 7 is an execution screen of an embodiment illustrating the configuration of an internal network web browser (103) of a main screen (101), an external network web browser (107) of a virtual machine software screen (105), a shared folder (104), a graphic user interface (121), and a taskbar (116) on a monitor (100) according to the operation flowchart of FIG. 6 according to the present invention. Excluding the duplicate content mentioned in the block diagram of FIG. 3 to the operation flowchart of FIG. 6 described above, the following is an examination of the network separation setting user interface (170) displayed as PNS (Physical Network Segregation) Settings, which pops up when the administrator's password is entered upon pressing the network separation setting button (123) of FIG. 8.
[0149] The shared folder is used to exchange data between the internal network of the main screen (101) and the external network of the virtual machine software screen (105), and when the Mapping folder (177) button is pressed with the mouse, an Explorer window appears in which the internal disk device (E11) on which the operating system of the main screen is installed is displayed as C: along with the operating system display logo.
[0150] When the user selects any folder at the bottom of C:, which is an internal disk device (E11) on which the operating system to be used as a shared folder is installed, in the Explorer window (not shown) for specifying the mapping folder, the path of the folder is displayed in the mapping folder field (173), and at the same time, the Explorer window (not shown) for specifying the mapping folder is closed.
[0151] When the Mapping folder: Enable checkbox (171) is checked and you try to close the window by clicking the X mark displayed at the top right of the PNS setting interface (170) window, you are asked whether to restart the network separation software (E9). If you click OK with the mouse, the device driver saves the changes and restarts the network separation software (E9); otherwise, it does not save the changes, closes the network separation setting user interface (170) window, and returns to the previous state.
[0152] When the network separation software (E9) is restarted with the path of the mapping folder for setting up the shared folder specified and saved in this manner, a network separation software icon (113) is created on the taskbar (116) as described above, and when the user clicks the network separation software icon (113) with a mouse, a minimized graphic user interface (121) pops up.
[0153] When the user clicks the external network selection button (129) with a mouse or inputs a shortcut key (Ctrl+Alt+e) corresponding to this button, the device driver starts the virtual machine software and displays the virtual machine software screen (105) in any area of the monitor (100).
[0154] At this time, the user can confirm that a shared folder (104) has been created on the desktop of the virtual machine software screen (105) with the path of the mapping folder specified in the network separation settings user interface (170) window.
[0156] FIG. 8 is an embodiment showing a graphical user interface (120) portion excluding the device driver in physical network separation software (E9) according to the present invention. Although the major components have been described in the above description from FIG. 3 to FIG. 7, the overall configuration and operation, excluding duplicate parts, are as follows according to the indicated symbols.
[0157] Depending on the user's settings, the network separation software (E9) can be executed simultaneously with device recognition when the network separation dongle (E1) is connected to the laptop PC (B1), or it can be executed by double-clicking the network separation software execution icon (111) provided on the desktop with a mouse.
[0158] When the network separation software (E9) is executed, a network separation software icon (113) is created on the taskbar, and when this is clicked with a mouse, a minimized graphical user interface (121) as shown at the top of FIG. 8 appears.
[0159] The network separation setting button (123) is used for an administrator to set various control options for virtual machine software used for physical network separation, and for this purpose, a login window (not shown) for the administrator to enter, register, and change a password to log in pops up before the network separation setting user interface (170) window opens.
[0160] When an administrator logs into the network separation settings user interface (170) window by entering a password, the system consists of items (177) for specifying a mapping folder path for setting the shared folder described above from the top, a command input item (179) to be executed immediately after the virtual machine software is started by the device driver, and items (181) for enabling or disabling various control-related options provided by the virtual machine software.
[0162] Regarding the item (177) for specifying the mapping folder path for setting up a shared folder, if the Mapping folder: Enable check box (171) is checked, the folder at the path entered in the mapping folder field (173) is created as a shared folder on the virtual machine software screen (105), and if it is not checked, the shared folder is not created.
[0163] If the Read Only checkbox (175) is checked, the files within the created shared folder are enabled as read-only for the virtual machine software, so that the user cannot save any file downloaded through the web browser of the virtual machine software (105) to the shared folder and move it to the main screen (101) of the internal network.
[0165] The command input field of the command input item (179) is a place where a command to be executed immediately after the virtual machine software (105) starts up is entered. In the present invention, a web browser is automatically executed along with the start of the virtual machine software (E9), and the starting URL of the web browser is included at the end of the command.
[0167] Item (181) for enabling or disabling various control options provided by virtual machine software includes control options such as network, clipboard, printer, audio, video and virtual GPU (vGPU).
[0168] In the present invention, the network option is not a control option that can be used by an administrator because the device driver uses it for connection control regarding internal / external networks, and in the case of the clipboard option, the user is not allowed to arbitrarily copy and paste operations between the virtual machine software (105) side and the main screen (101) side, and data transmission is made possible only through the shared folder designation as described above.
[0169] However, regarding the remaining control options for printer, audio, video, and virtual GPU, excluding these two control options, the administrator can arbitrarily set them to enabled or disabled on a per-user basis.
[0171] When the network block button (125) is pressed, steps S25 and S27 on the operation flowchart shown in FIG. 6 are performed so that both the internal network and the external network are switched to a blocked state, and the open virtual machine software (105) and the web browser (107) inside it are not closed and remain as they are.
[0172] The shortcut for the network block button is Ctrl+Alt+b, which performs the same function as pressing the network block button (125).
[0174] The internal network selection button (127) switches the network connection state, which is either blocked or selected as an external network, to the internal network by performing steps S13, S15, and S19 on the operation flowchart.
[0175] The shortcut for the internal network selection button is Ctrl+Alt+i, which performs the same function as pressing the internal network selection button (127).
[0177] The external network selection button (129) switches the network connection state, which is either in a blocked state or selected as an internal network, to an external network by performing steps S13, S17, and S21 on the operation flowchart, and at the same time causes the device driver to start the virtual machine software (105) and open a web browser (107) for external network access inside the virtual machine software (105).
[0178] The shortcut for the external network selection button is Ctrl+Alt+e, which performs the same function as pressing the external network selection button (129).
[0180] When the expand button (133) is pressed, the expandable graphic user interface (140) is displayed, and when the close button (131) is pressed, it switches to the minimized graphic user interface (121).
[0182] The detailed components of the extended graphical user interface (140) are as follows.
[0183] When the checkbox is activated, the entire screen of the monitor is saved to a folder designated as an image file at regular intervals for the network blocking time (141). When the time entered in the network blocking time field has elapsed, if it is determined that no change will occur when comparing the image file of a certain area in the same row as the favorite icon (167) of the internal network web browser (103) of the main screen (101) displayed on the monitor (100) and the text extracted from the image file with the previously saved text at the corresponding location, steps S25 and S27 of the operation flowchart of FIG. 6 are performed to block the network, thereby switching both the internal and external networks to a blocked state.
[0185] When the checkbox for the speech bubble (143) is checked, and the user places the mouse cursor (not shown) over the network separation setting button (123), network blocking button (125), internal network selection button (127), or external network selection button (129) provided in the miniaturized graphic user interface (121), the function of the corresponding button is briefly displayed in the pop-up speech bubble and then disappears.
[0187] When you click the information icon (145) with your mouse, the version of the network isolation software (E9) and the manufacturer's homepage address are displayed in the pop-up window.
[0189] The connection status display unit (147) displays the connection status with the network separation dongle (E1) by referring to the status information.
[0191] When the language selection icon (149) is pressed, the types of languages that the user can select are displayed through a pop-up window, and the reduced graphical user interface (121) and the expanded graphical user interface (140) of the network separation software (120) are displayed in the language selected by the user.
[0193] The virtual machine start URL (151) is linked to the start URL that follows the command when a path for a command to be executed by a web browser is entered in the command input item (179) of the network separation setting user interface (170), so that when the user presses the external network selection button (129) and the virtual machine software (E9) is started, the web browser (107) for external network access connects to the virtual machine start URL (151) and is executed.
[0195] The log display area (153) displays the content of the event as a text-based message along with date information of the year / month / day / hour / minute / second when the event occurred, as well as when changes occurred to various items provided in the graphic user interface (120), in addition to input of buttons or shortcut keys operated by the user on the graphic user interface (120), and log files are created in the installation folder on a different date.
[0197] Although the present invention is described on the premise that the network separation dongle (E1) is connected to and used with a laptop PC, it also includes the possibility of being connected to and used with any USB port provided on a desktop PC (not shown).
[0199] Although preferred embodiments according to the present invention have been described in detail above, those skilled in the art may implement various variations and modifications within the scope of the claims without departing from the scope of the claims. Explanation of the symbols
[0200] B1: Laptop PC main body, B2: Physical network separation control means, B3: Internal network, B4: External network, B5: Network selector, B7: Network separation control unit, B8: Network separation control board, B9: Network port, B10: Network switching unit, B11: Network adapter for internal network, B13: Network adapter for external network, B15: Network separation software, B15: Web browser for internal network, B17: Web browser for external network, B20: Operating system for internal network, B22: Operating system for external network, B23: M.2 Adapter card for internal network operating system, B25: M.2 Adapter card for external network operating system, D1: USB Type-C connector, D3: Low-speed USB HUB, D4, D11, D35: Flash PROM, D5: High-speed interface signal converter, D6: ETHERNET ~ High-speed USB converter, D7: Power supply unit, D9: Ethernet to low-speed USB converter unit, D13: High-speed signal converter unit, D15: Network connection unit, D17: Low-speed USB interface unit, D19: M.2 SSD #1 (Operating system installation for internal network), D21: M.2 SSD #2 (Operating system installed for external network), D23: LED display, D25: Network port for internal network, D27: Network connector for external network, D29: Network isolation control unit, D33: Low-speed USB to Ethernet converter, D34: High-speed USB to Ethernet converter, D37: USB Type-C connector, D39: Smart phone, E1: Physical network isolation control means (or network isolation dongle), E3: Ethernet to USB converter, E5: USB port (network isolation dongle side), E7: USB port (laptop PC side), E9: Network isolation software, E11: Built-in disk device with operating system installed, 1: Monitor, 3: Main screen, 5: Virtual machine screen, 7: Physical network isolation dongle, 10: Front view of physical network isolation dongle, 100: Monitor, 101: Main screen, 103: Web browser (main screen, for internal network), 104: Shared folder, 105: Virtual machine (software) screen, 107: Web browser (virtual machine screen, for external network), 109: Main screen start button, 111: Network isolation software launch icon (desktop), 112: Explorer window icon, 113: Network isolation software icon, 114: Virtual machine software launch icon, 115: Virtual machine start button, 116: Taskbar, 117: Network connection status icon (virtual machine screen), 119: Network connection status icon (main screen), 120: Network isolation software user interface (PNS GUI), 121: Minimal graphical user interface, 123: Network isolation settings button, 125: Network blocking button, 127: Internal network selection button, 129: External network selection button, 140:Extensible graphical user interface, 141:Network blocking time, 146:Model name, 151:Virtual machine start URL, 160:Web browser key components, 165:URL field, 167:Favorites icon, 170:Network segmentation settings user interface.
Claims
Claim 1 A first USB Type-C connector for connection to a laptop PC; A low-speed USB hub (HUB) connected to low-speed USB pins provided in the above USB Type-C connector to generate a first low-speed USB interface signal and a second low-speed USB interface signal; Low-speed interface conversion means connected to the above low-speed USB hub and the first low-speed USB interface signal; Network connection means for connecting an internal network, connecting an external network, or blocking both the internal network and the external network according to an internal network selection signal or an external network selection signal output from the low-speed interface conversion means; A first low-speed network signal converter connected to the above network connection means, converting a network signal into a low-speed USB signal so as to be connected to the low-speed USB hub via the second low-speed USB interface signal; A first network signal connection means for connecting an internal network cable connected to the above network connection means; A second network signal connection means for connecting an external network cable connected to the above network connection means; A power supply unit connected to power pins provided in the above USB Type-C connector to generate power used internally; and A physical network separation control means comprising: a printed circuit board for mounting the components of each of the above-mentioned constituent parts; A single PC-based physical network separation device characterized by the above low-speed interface conversion means, wherein the network connection means is connected to an internal network in the case of an internal network, the network connection means is connected to an external network in the case of an external network, and the network connection means is blocked in the case of network blocking, by means of a pin output according to status information received by the first low-speed USB interface signal. Claim 2 In Article 1, Additionally, a network separation control unit that receives status information transmitted via the above-mentioned low-speed interface conversion means is further provided, A single PC-based physical network separation device characterized in that the network connection means is configured such that when the network separation control unit determines that the internal network is selected based on status information received through the low-speed interface conversion unit, the network connection means is configured to be connected to the internal network, when the external network is determined to be selected, the network connection means is configured to be connected to the external network, and when network blocking is determined to be selected, the network connection means is configured to block both the internal network and the external network. Claim 3 In Article 1, A second USB Type-C connector for connecting to the user's smartphone; Additionally, a second low-speed network signal converter provided between the second USB Type-C connector and the network connection means, replacing the second network signal connection means; A single PC-based physical network separation device characterized by connecting a low-speed USB signal transmitted from a user smartphone received through the second USB Type-C connector to the second low-speed network signal converter, so that the second low-speed network signal converter outputs an ETHERNET network signal to configure an external network. Claim 4 A first USB Type-C connector for connection to a laptop PC; Low-speed interface conversion means connected to low-speed USB pins provided in the above USB Type-C connector; Network connection means for connecting an internal network, connecting an external network, or blocking both the internal network and the external network according to an internal network selection signal or an external network selection signal output from the low-speed interface conversion means; A first high-speed network signal converter connected to the above network connection means to convert a network signal into a high-speed USB signal and connect it to the high-speed USB signal provided in the first USB Type-C connector; A first network signal connection means for connecting an internal network cable connected to the above network connection means; A second network signal connection means for connecting an external network cable connected to the above network connection means; A power supply unit connected to power pins provided in the above USB Type-C connector to generate power used internally; and A physical network separation control means comprising: a printed circuit board for mounting the components of each of the above-mentioned constituent parts; A single PC-based physical network separation device characterized by the above low-speed interface conversion means, wherein the network connection means is connected to an internal network in the case of an internal network, the network connection means is connected to an external network in the case of an external network, and the network connection means is blocked in the case of network blocking, by means of a pin output according to status information received as a low-speed USB interface signal of the first USB Type-C connector. Claim 5 In Paragraph 4, Additionally, a network separation control unit that receives status information transmitted via the above-mentioned low-speed interface conversion means is further provided, A single PC-based physical network separation device characterized in that the network connection means is configured such that when the network separation control unit determines that the internal network is selected based on status information received through the low-speed interface conversion unit, the network connection means is configured to be connected to the internal network, when the external network is determined to be selected, the network connection means is configured to be connected to the external network, and when network blocking is determined to be selected, the network connection means is configured to block both the internal network and the external network. Claim 6 In Paragraph 5, A second USB Type-C connector for connecting to the user's smartphone; Additionally, a second high-speed network signal converter provided between the second USB Type-C connector and the network connection means, replacing the second network signal connection means; A single PC-based physical network separation device characterized by connecting a high-speed USB signal transmitted from a user smartphone received through the second USB Type-C connector to the second high-speed network signal converter, so that the second high-speed network signal converter outputs an ETHERNET network signal, thereby configuring an external network. Claim 7 A first network adapter provided for the main screen when an operating system installed on a PC internal disk device boots up; A second network adapter provided for virtual machine software installed on the above operating system; Network isolation software installed on the above operating system and composed of a graphical user interface unit and a device driver; A monitor displaying components on the desktop and taskbar provided by the operating system, such as the graphical user interface of the network isolation software, the main screen, and a web browser launched in the virtual machine software, respectively; A network separation control unit that receives status information related to the connection or blocking of an internal network and an external network generated in the above graphical user interface unit through the above device driver; First network signal connection means for connecting an internal network cable; A second network signal connection means for connecting an external network cable; A network connection means connected to each of the first network signal connection means and the second network signal connection means, and performing an operation to connect an internal network signal of the first network signal connection means, connect an external network signal of the second network signal connection means, or block both the internal network signal and the external network signal according to a control signal output from the network separation control unit; It is composed of an ETHERNET-USB converter connected to the above-mentioned network connection means and converting an ETHERNET network signal into a USB signal; If the above network isolation software is not started, the above network isolation control unit ensures that the above network connection means maintains a network-blocked state, and When the above network isolation software is started, the graphical user interface unit transmits status information to the device driver side according to a preset setting, such that it is connected to an internal network, connected to an external network, or maintains a network blocking state, or transmits status information to the device driver side in which the user selects an internal network, selects an external network, or transmits network blocking selection information, The device driver, according to the state information, causes the first network adapter corresponding to the internal network to be connected, causes the second network adapter corresponding to the external network to be connected, or causes the first network adapter and the second network adapter to be simultaneously blocked, and A single PC-based physical network separation method characterized in that the network separation control unit causes the network connection means to be connected to an internal network, connected to an external network, or in a network blocking state according to the status information. Claim 8 In Article 7, The above graphic user interface unit is equipped with an internal network selection button, an external network selection button, and a network blocking button, or additionally equipped with an internal network selection shortcut key (HOT KEY) corresponding to the internal network selection button, an external network selection shortcut key corresponding to the external network selection button, or a network blocking shortcut key corresponding to the network blocking button, and When the internal network selection button is pressed or the internal network selection shortcut key is entered, the internal network remains connected and the external network remains blocked. When the external network selection button is pressed or the external network selection shortcut key is entered, the external network remains connected and the internal network remains blocked. A single PC-based physical network separation method characterized by the fact that when a network blocking button is pressed or a network blocking shortcut key is entered, the internal network and the external network are simultaneously switched to a blocked state. Claim 9 In Paragraph 8, A single PC-based physical network separation method characterized by the fact that when an external network selection button provided in the graphical user interface is pressed or an external network selection shortcut key is input, the graphical user interface determines whether the virtual machine software is open, and if the virtual machine software is not open, the device driver starts the virtual machine software. Claim 10 In Article 9, A single PC-based physical network separation method characterized by the fact that, when a start URL for the virtual machine software is entered in the graphical user interface section and stored in the state information, after the virtual machine software is started, the virtual machine software refers to the start URL of the virtual machine software stored in the state information and starts a web browser with the virtual machine software start URL within the display area. Claim 11 In Article 7, The above device driver refers to the state information in which the network blocking transition time entered on the graphical user interface unit is stored, and at regular intervals detects the TEXT entered in the URL field for each web browser along with location information for each web browser, or detects the image of the area corresponding to the URL field, and if it is determined that no change has occurred in the URL field of the previous state, stores the state in which the network is blocked in the state information. The above device driver causes the first network adapter corresponding to the internal network and the second network adapter corresponding to the external network to be switched to a network blocking state according to the above state information, and A single PC-based physical network separation method characterized by the above network separation control unit causing the network connection means to be in a network blocking state according to the above status information. Claim 12 In Article 7, For a shared folder path specified through the graphical user interface, if the mapping folder is active, the path is saved in the status information, and if the mapping folder is inactive, the path is deleted from the status information. A single PC-based physical network separation method characterized in that when the above network separation software is restarted after being closed, the device driver refers to the shared folder path information of the state information and makes the folder of the corresponding path stored in the state information a shared folder for the virtual machine software when the virtual machine software is started.