Configurable Internet Isolation for Laptops
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malware infections in host computer systems compromise security and efficiency, leading to potential data loss, unauthorized access, and loss of command and control, as users unintentionally download harmful software while accessing the internet.
Innovation Solution
Implementing a configurable and customizable internet isolation system that segregates memory spaces using sandboxed computing environments and firewalls, allowing only trusted applications to access secure networks, and enforcing strict communication protocols to prevent unauthorized data exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If users access the internet to retrieve data, then information accessibility is improved, but the risk of malware infection increases
Solution Approach 1:
The system segments the internet connection into two distinct pathways: a sandboxed environment for accessing untrusted internet resources and a protected environment for accessing trusted local network resources. This segmentation allows users to retrieve information from the internet while preventing malware from reaching the main system, as the sandbox acts as an isolated barrier.
Solution Approach 2:
The patent introduces a firewall and sandboxed computing environment as intermediary components between the internet and the host system. These intermediaries filter and control data flow, allowing legitimate information retrieval while blocking malicious content before it can infect the system.
2Adaptability or versatility
If malware is downloaded to the host system, then the system can execute any functionality, but security and system integrity are compromised
Solution Approach 1:
The system divides the computing environment into a sandboxed segment and a protected host segment. Malware can be downloaded and executed within the sandboxed segment, providing full functionality and adaptability, while the protected host segment maintains system security and integrity through isolation barriers.
Solution Approach 2:
Different security qualities are applied to different parts of the system: the sandboxed environment allows unrestricted execution for testing and functionality, while the host environment maintains strict security controls. This local differentiation enables both high adaptability in the sandbox and high reliability in the host.
3Object-generated harmful factors
If an infected host system is used to attack other network resources, then the malware can spread, but detection by users and administrators is difficult
Solution Approach 1:
The patent extracts the potentially harmful internet-accessing applications into a sandboxed environment, separating them from the host system. This extraction prevents malware from spreading to the host or other network resources, as the sandbox acts as an isolated containment zone that cannot infect external systems.
4Reliability
If firewall rules are configured to block all incoming traffic, then system security is improved, but legitimate network communication is prevented
Solution Approach 1:
The system segments network communication into sandboxed internet traffic and protected local network traffic. The firewall can aggressively block all incoming traffic to the sandboxed environment without affecting legitimate local network communications, as the two environments are isolated from each other.
Data Source
AI summary
Methods and systems are disclosed for internet isolation and security schemes for a host computer system having an internet isolation system. The internet isolation system may be installed on a laptop computer and/or similar devices at or during the time of manufacture, sale, and/or prior to delivery of the laptop computer. The internet isolation system may be pre-installed with a generic configuration. Upon delivery to a user or enterprise, the internet isolation system may be configured with specific rules tailored to the needs of the user. The configuration may identify which applications or processes should be isolated in the laptop computer using a container and/or virtual machine. The configuration may identify which addresses or sites may or may not be accessed from outside an isolated computing system (e.g., from outside a container or virtual machine). The configuration may configure proxy settings and devices for the isolated computing systems.

