Asset Tagging for Legacy IoT Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial IoT networks face significant challenges in enforcing security policies due to the presence of legacy devices that lack authentication methods and system patching, leading to difficulties in defining adequate security measures.

Innovation Solution

The implementation of asset tagging based on deep packet inspection of traffic associated with endpoint devices, allowing networking devices to identify and enforce policies by assigning component and activity tags to traffic flows, and initiating corrective measures for policy violations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (e.g., 802.1x) are used for security policy enforcement, then security control is strengthened, but legacy devices that do not support these methods cannot be secured

Engineering Contradiction:
Improvesecurity controlVSAvoidcompatibility with legacy devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary system consisting of network telemetry collectors and asset tagging mechanisms that sit between the legacy devices and security policy enforcement points. This intermediary captures traffic telemetry, assigns semantic tags to traffic flows, and enables policy enforcement without requiring direct authentication support from legacy devices themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If deep packet inspection is implemented for telemetry collection, then traffic analysis precision is improved, but network device processing complexity increases

Engineering Contradiction:
Improvetraffic analysis precisionVSAvoidnetwork device processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the deep packet inspection function into discrete, manageable components. Network telemetry collectors are deployed at specific network points to perform DPI on particular traffic flows, rather than requiring every network device to perform comprehensive inspection. This segmentation distributes processing complexity while maintaining high analysis precision where needed.

Inventive Principle:
Principle #1Segmentation

3Reliability

If comprehensive security policies are enforced on all devices, then security coverage is improved, but devices lacking authentication capabilities cannot comply

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy compliance ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables security policy enforcement to work in a self-service manner for legacy devices. Instead of requiring devices to actively participate in authentication, the system passively observes their traffic patterns, assigns appropriate tags based on their behavior, and automatically applies security policies. This allows legacy devices to be secured without their active cooperation or authentication capability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12218912B2Telemetry collection and policy enforcement using asset tagging
Publication Date: 2025.02.04 CISCO TECHNOLOGY INC
  • US12218912B2 patent drawing
  • US12218912B2 patent drawing
  • US12218912B2 patent drawing

AI summary

According to one or more embodiments of the disclosure, a networking device receives a policy for an endpoint in a network. The policy specifies one or more component tags and one or more activity tags that were assigned to the endpoint based on deep packet inspection of traffic associated with the endpoint. The networking device identifies a set of tags for a particular traffic flow in the network associated with the endpoint. The set of tags comprises one or more component tags or activity tags associated with the particular traffic flow. The networking device makes a determination that the particular traffic flow violates the policy based on the set of tags comprising a tag that is not in the policy. The networking device initiates, based on the determination that the particular traffic flow violates the policy, a corrective measure with respect to the particular traffic flow.