Relay-Switch Sandboxed Connections for Internal Network Malware Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to adequately protect internal networks from malware and cyber threats when connecting to external networks, as firewalls allow unrestricted communication through various ports, necessitating a solution to ensure safe and secure data exchange.

Innovation Solution

A relay-switch device with sandbox communication connections that enables one-sided network connections at a time, utilizing left and right side sandboxes to isolate and inspect data for malware, with a control layer managing network connectivity to prevent simultaneous access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If firewalls are used to allow free communication through various ports, then network connectivity and ease of operation are improved, but network security and protection from malware deteriorate

Engineering Contradiction:
Improvenetwork connectivityVSAvoidmalware and cyber threats
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a relay-switch device as an intermediary component between the internal network and external networks. This relay-switch includes sandbox environments that mediate all communications, allowing data to be inspected and threats to be detected before reaching the internal network, thus maintaining connectivity while blocking malware

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments network communication into distinct paths: one path allows internal network access while another path handles external network access through sandboxed relay-switches. This segmentation ensures that even if external networks are compromised, the internal network remains isolated and protected

Inventive Principle:
Principle #1Segmentation

2Productivity

If direct communication between internal and external networks is allowed, then data exchange efficiency is improved, but network security and threat isolation deteriorate

Engineering Contradiction:
Improvedata exchange efficiencyVSAvoidcyber threats
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The relay-switch device acts as a mediator that enables data exchange between internal and external networks without allowing direct communication. All data passes through the relay-switch which inspects it in sandbox environments, maintaining productivity while ensuring threat isolation

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If sandboxes are used to isolate and inspect data, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvemalware protectionVSAvoidsystem architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The relay-switch device is designed as a universal component that can handle multiple functions: network switching, sandboxed inspection, threat detection, and data filtering. By consolidating these functions into a single multi-functional device, the patent manages complexity while maintaining strong security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12373577B2Relay-switch with sandbox communication connections
Publication Date: 2025.07.29 BANK OF AMERICA CORP
  • US12373577B2 patent drawing
  • US12373577B2 patent drawing
  • US12373577B2 patent drawing

AI summary

A network connection device may include at least one sandbox to detect, isolate, and remove any discovered malware or cyber threat. The device may be configured to receive, save, and inspect data. A control layer may manage network connectivity so that only home organization network connections or external party network connections are connected at given moment in time.