Sandboxed Collaboration Software Isolation via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Host computer systems are vulnerable to malware infections through collaboration software, which can lead to security losses, efficiency reductions, and loss of command and control, compromising user privacy and allowing unauthorized access to network resources.

Innovation Solution

Implementing a sandboxed computing environment with internal and host-based firewalls to isolate collaboration software from the workspace, segregating memory spaces and requiring user authentication for communication, thereby preventing unauthorized data transfers and malware spread.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If collaboration software is allowed to communicate freely with the workspace, then ease of operation is improved, but security reliability deteriorates due to malware infection risks

Engineering Contradiction:
Improvecollaboration software accessibilityVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the computer environment into distinct segments: a workspace memory space for legitimate applications and an isolated memory space for collaboration software. This segmentation allows collaboration software to operate with necessary accessibility while preventing malware from affecting the main workspace, thus resolving the contradiction between ease of operation and security reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A memory space isolation mechanism acts as an intermediary between the workspace and collaboration software. This intermediary enables controlled communication through specific interfaces while blocking malicious data transfers, allowing collaboration functionality to remain accessible while maintaining system security against malware infections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If collaboration software is isolated from the workspace, then security reliability is improved, but ease of operation deteriorates due to communication restrictions

Engineering Contradiction:
Improvesystem securityVSAvoidcollaboration software accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system creates segmented memory spaces that physically isolate collaboration software from the workspace while maintaining defined communication channels. This segmentation ensures security through isolation while preserving operational ease through controlled interfaces that allow necessary data exchange between the isolated environment and the workspace.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The memory space isolation mechanism serves as an intermediary that enables selective communication between the isolated collaboration software and the workspace. It allows legitimate collaboration operations to proceed smoothly while blocking malicious communications, thus maintaining both security reliability and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If memory spaces are segregated with firewalls, then reliability against malware is improved, but device complexity increases due to isolation mechanisms

Engineering Contradiction:
Improvemalware protectionVSAvoidisolation architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements memory space segmentation that creates isolated environments for collaboration software. This segmentation provides robust malware protection through architectural isolation while managing complexity by using operating system-level memory management features to enforce the separation, rather than requiring complex external isolation infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The memory space isolation mechanism acts as an intermediary layer that provides malware protection through controlled access between isolated and non-isolated memory spaces. This approach manages device complexity by integrating the isolation functionality at the memory management level, avoiding the need for separate complex isolation hardware or software layers.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of information

If isolated computing environment is implemented, then loss of information is reduced, but device complexity increases due to sandboxing requirements

Engineering Contradiction:
Improvedata exfiltration preventionVSAvoidsandboxed environment
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments memory spaces to create an isolated computing environment for collaboration software. This segmentation prevents malware from exfiltrating information from the workspace by confining malicious activities to the isolated memory space, while managing complexity through integration with existing operating system memory management capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The memory space isolation mechanism serves as an intermediary that prevents information loss by blocking unauthorized data transfers from the isolated collaboration software environment to the workspace. It manages device complexity by implementing protection at the memory access level, avoiding the need for complex monitoring and control systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11223601B2Network isolation for collaboration software
Publication Date: 2022.01.11 CROGA INNOVATIONS LTD
  • US11223601B2 patent drawing
  • US11223601B2 patent drawing
  • US11223601B2 patent drawing

AI summary

Methods and systems are disclosed for isolation of collaboration software on a host computer system. A networked computer system may include a network, a first host computer system, a border firewall and/or a web proxy. The host computer system may be configured to run a collaboration software application or process that enables interaction with one or more other host computer systems. The collaboration software application or process may be run within an untrusted memory space. The collaboration software application or process may enable interaction between a second host computer system and the untrusted memory space such that the second host computer system may access meeting data within a sandboxed computing environment operating within the untrusted memory space.