Air Gap Network Isolation Circuit Board Design

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage solutions for sensitive data, such as passwords, documents, and cryptocurrencies, are vulnerable to loss, theft, or hacking, especially when stored on devices that are continuously connected to the internet.

Innovation Solution

A storage system that utilizes discrete on-demand memory resources, which can persistently store sensitive data in an off-state and only become accessible through an external trigger signal, allowing for remote activation over a non-IP network channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive data is stored on devices continuously connected to the internet, then data accessibility is improved, but security against hacking and unauthorized access deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity against hacking
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing an air gap isolation before any data access occurs. The physical disconnection is maintained as a default state, and network connectivity is only established temporarily when authentication occurs. This preliminary isolation prevents unauthorized access while allowing legitimate access when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically transitions between isolated and connected states based on authentication events. The air gap is not a static barrier but a dynamic control mechanism that opens or closes network connectivity based on real-time security requirements. This dynamic behavior allows the system to maintain security while enabling access on-demand.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If sensitive data is stored in cloud network accounts, then data accessibility is improved, but vulnerability to man-in-the-middle attacks deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system establishes network connectivity only after authentication is complete, performing the security verification action before enabling data access. This preliminary authentication step prevents man-in-the-middle attacks by ensuring that no network path exists for attackers to intercept data before the legitimate user is verified.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication mechanism acts as an intermediary between the user and the network connection. Rather than allowing direct network access to cloud accounts, the system introduces an authentication layer that mediates all access requests, verifying user identity before permitting any network communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hardware storage devices are used for sensitive data, then security against online hacking is improved, but vulnerability to physical loss and theft deteriorates

Engineering Contradiction:
Improvesecurity against online hackingVSAvoidvulnerability to physical loss
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the security function into two separate components: physical device security (protecting against online hacking through air gap isolation) and data protection (protecting against physical loss through encryption and authentication). This segmentation allows each component to address its specific vulnerability without compromising the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the state parameters of the storage device from always-connected to dynamically isolated. By controlling the network connectivity parameter (connected vs. isolated) based on authentication state, the system transforms a physically vulnerable device into a securely accessed resource that combines the benefits of both hardware storage and cloud accessibility.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250119414A1Air gap-based network isolation device circuit board
Publication Date: 2025.04.10 GOLDILOCK SECURE LTD
  • US20250119414A1 patent drawing
  • US20250119414A1 patent drawing
  • US20250119414A1 patent drawing

AI summary

A circuit board for an air-gap-based, network isolation device includes a set of connection port elements, each connection port element in the set of connection port elements being connected to relay array and comprising a plurality of connection ports. Each of the connection port elements comprises a network connection port configured to connect the circuit board to a network link. The circuit board further includes a controller connected to each relay array, and a communications module comprising a set of communication receivers connected to the controller. The communications module receives commands from a master computer, external to the circuit board, to close each relay array connected to each of the set of connection port elements.