Computer System Network Isolation via Management Processor

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer systems are unable to reliably prevent the spread of unauthorized access even after disconnecting from the network, leaving them vulnerable to further diffusion of malicious events.

Innovation Solution

A computer system comprising multiple service computers managed by a central management computer, where each service computer includes a monitoring program that detects unauthorized events, such as virus infections, and sends alerts directly to the management computer via a dedicated processor, allowing for immediate isolation and blocking of affected systems to prevent propagation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a computer system disconnects from the network to prevent unauthorized access, then the immediate threat is reduced, but the system cannot reliably prevent the diffusion of malicious events to other computers

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddiffusion of unauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the computer system into isolated segments by creating separate network connections for each computer. When unauthorized access is detected, the management computer can disconnect specific computers from the network while maintaining connections for other computers, thereby segmenting the system to prevent malicious event diffusion while preserving legitimate operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The management computer acts as an intermediary between service computers and the network. It controls network connections and manages communication, allowing it to isolate infected computers without affecting the entire system. The management computer mediates the disconnection process, ensuring that only compromised systems are isolated while maintaining network security for other computers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the network connection is disconnected to prevent virus propagation, then the spread of computer viruses is reduced, but the system cannot ensure continued operation of unaffected computers

Engineering Contradiction:
Improvevirus propagationVSAvoidsystem operation continuity
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent implements segmentation at the network connection level, allowing individual computers to be isolated from the network while other computers continue to operate. The management computer maintains separate connection management for each computer, enabling selective disconnection of infected systems without interrupting service operations for healthy computers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by treating each computer's network connection independently. The management computer can apply different connection states to different computers based on their security status. Infected computers are disconnected while unaffected computers maintain normal network access, ensuring that security measures are applied locally rather than system-wide.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If conventional disconnection methods are used, then network access is blocked for infected computers, but the unauthorized access events can still diffuse to other computers in the system

Engineering Contradiction:
Improveunauthorized access blockingVSAvoidsystem protection reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where service computers report their status to the management computer, and the management computer responds with appropriate connection control. When unauthorized access is detected, the management computer receives feedback about the infected computer and automatically executes disconnection commands, creating a closed-loop security response system that improves protection reliability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The management computer serves as an intermediary that receives security status information from service computers and executes appropriate network control actions. This intermediary role allows the system to respond reliably to unauthorized access events by coordinating between detection and execution functions, ensuring that disconnection actions are properly implemented to prevent further diffusion.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10623439B2Computer system and control method thereof
Publication Date: 2020.04.14 HITACHI VANTARA LTD
  • US10623439B2 patent drawing
  • US10623439B2 patent drawing
  • US10623439B2 patent drawing

AI summary

A computer system is reliably protected from unauthorized access. The present invention provides a computer system comprising a plurality of service computers each capable of performing predetermined services, and a management computer which manages each of the plurality of service computers. Each of the plurality of service computers comprises a controller which executes an operating system, and a management processor for managing computer hardware. The controller executes a monitoring program which manages predetermined events. The management processor sends information of a detected event to the management computer via a port for connecting to the management computer.