Configurable Internet Isolation for Laptops

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware infections in host computer systems compromise security and efficiency, leading to potential data loss, unauthorized access, and loss of command and control, as users unintentionally download harmful software while accessing the internet.

Innovation Solution

Implementing a configurable and customizable internet isolation system that segregates memory spaces using sandboxed computing environments and firewalls, allowing only trusted applications to access secure networks, and enforcing strict communication protocols to prevent unauthorized data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If users access the internet to retrieve data, then information accessibility is improved, but the risk of malware infection increases

Engineering Contradiction:
Improveinformation accessibilityVSAvoidmalware infection risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system segments the internet connection into two distinct pathways: a sandboxed environment for accessing untrusted internet resources and a protected environment for accessing trusted local network resources. This segmentation allows users to retrieve information from the internet while preventing malware from reaching the main system, as the sandbox acts as an isolated barrier.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a firewall and sandboxed computing environment as intermediary components between the internet and the host system. These intermediaries filter and control data flow, allowing legitimate information retrieval while blocking malicious content before it can infect the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If malware is downloaded to the host system, then the system can execute any functionality, but security and system integrity are compromised

Engineering Contradiction:
Improvesystem functionalityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system divides the computing environment into a sandboxed segment and a protected host segment. Malware can be downloaded and executed within the sandboxed segment, providing full functionality and adaptability, while the protected host segment maintains system security and integrity through isolation barriers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security qualities are applied to different parts of the system: the sandboxed environment allows unrestricted execution for testing and functionality, while the host environment maintains strict security controls. This local differentiation enables both high adaptability in the sandbox and high reliability in the host.

Inventive Principle:
Principle #3Local quality

3Object-generated harmful factors

If an infected host system is used to attack other network resources, then the malware can spread, but detection by users and administrators is difficult

Engineering Contradiction:
Improvemalware spread capabilityVSAvoidattack detection difficulty
Core Design Contradiction:
Object-generated harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extracts the potentially harmful internet-accessing applications into a sandboxed environment, separating them from the host system. This extraction prevents malware from spreading to the host or other network resources, as the sandbox acts as an isolated containment zone that cannot infect external systems.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If firewall rules are configured to block all incoming traffic, then system security is improved, but legitimate network communication is prevented

Engineering Contradiction:
Improvesystem securityVSAvoidnetwork communication capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments network communication into sandboxed internet traffic and protected local network traffic. The firewall can aggressively block all incoming traffic to the sandboxed environment without affecting legitimate local network communications, as the two environments are isolated from each other.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11120125B2Configurable internet isolation and security for laptops and similar devices
Publication Date: 2021.09.14 L3 TECHNOLOGIES INC
  • US11120125B2 patent drawing
  • US11120125B2 patent drawing

AI summary

Methods and systems are disclosed for internet isolation and security schemes for a host computer system having an internet isolation system. The internet isolation system may be installed on a laptop computer and/or similar devices at or during the time of manufacture, sale, and/or prior to delivery of the laptop computer. The internet isolation system may be pre-installed with a generic configuration. Upon delivery to a user or enterprise, the internet isolation system may be configured with specific rules tailored to the needs of the user. The configuration may identify which applications or processes should be isolated in the laptop computer using a container and/or virtual machine. The configuration may identify which addresses or sites may or may not be accessed from outside an isolated computing system (e.g., from outside a container or virtual machine). The configuration may configure proxy settings and devices for the isolated computing systems.