Computer System Network Isolation via Management Processor
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computer systems are unable to reliably prevent the spread of unauthorized access even after disconnecting from the network, leaving them vulnerable to further diffusion of malicious events.
Innovation Solution
A computer system comprising multiple service computers managed by a central management computer, where each service computer includes a monitoring program that detects unauthorized events, such as virus infections, and sends alerts directly to the management computer via a dedicated processor, allowing for immediate isolation and blocking of affected systems to prevent propagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a computer system disconnects from the network to prevent unauthorized access, then the immediate threat is reduced, but the system cannot reliably prevent the diffusion of malicious events to other computers
Solution Approach 1:
The patent divides the computer system into isolated segments by creating separate network connections for each computer. When unauthorized access is detected, the management computer can disconnect specific computers from the network while maintaining connections for other computers, thereby segmenting the system to prevent malicious event diffusion while preserving legitimate operations.
Solution Approach 2:
The management computer acts as an intermediary between service computers and the network. It controls network connections and manages communication, allowing it to isolate infected computers without affecting the entire system. The management computer mediates the disconnection process, ensuring that only compromised systems are isolated while maintaining network security for other computers.
2Object-affected harmful factors
If the network connection is disconnected to prevent virus propagation, then the spread of computer viruses is reduced, but the system cannot ensure continued operation of unaffected computers
Solution Approach 1:
The patent implements segmentation at the network connection level, allowing individual computers to be isolated from the network while other computers continue to operate. The management computer maintains separate connection management for each computer, enabling selective disconnection of infected systems without interrupting service operations for healthy computers.
Solution Approach 2:
The patent applies local quality by treating each computer's network connection independently. The management computer can apply different connection states to different computers based on their security status. Infected computers are disconnected while unaffected computers maintain normal network access, ensuring that security measures are applied locally rather than system-wide.
3Object-affected harmful factors
If conventional disconnection methods are used, then network access is blocked for infected computers, but the unauthorized access events can still diffuse to other computers in the system
Solution Approach 1:
The patent implements a feedback mechanism where service computers report their status to the management computer, and the management computer responds with appropriate connection control. When unauthorized access is detected, the management computer receives feedback about the infected computer and automatically executes disconnection commands, creating a closed-loop security response system that improves protection reliability.
Solution Approach 2:
The management computer serves as an intermediary that receives security status information from service computers and executes appropriate network control actions. This intermediary role allows the system to respond reliably to unauthorized access events by coordinating between detection and execution functions, ensuring that disconnection actions are properly implemented to prevent further diffusion.
Data Source
AI summary
A computer system is reliably protected from unauthorized access. The present invention provides a computer system comprising a plurality of service computers each capable of performing predetermined services, and a management computer which manages each of the plurality of service computers. Each of the plurality of service computers comprises a controller which executes an operating system, and a management processor for managing computer hardware. The controller executes a monitoring program which manages predetermined events. The management processor sends information of a detected event to the management computer via a port for connecting to the management computer.


