Asset Tagging for Legacy IoT Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial IoT networks face significant challenges in enforcing security policies due to the presence of legacy devices that lack authentication methods and system patching, leading to difficulties in defining adequate security measures.
Innovation Solution
The implementation of asset tagging based on deep packet inspection of traffic associated with endpoint devices, allowing networking devices to identify and enforce policies by assigning component and activity tags to traffic flows, and initiating corrective measures for policy violations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (e.g., 802.1x) are used for security policy enforcement, then security control is strengthened, but legacy devices that do not support these methods cannot be secured
Solution Approach 1:
The patent introduces an intermediary system consisting of network telemetry collectors and asset tagging mechanisms that sit between the legacy devices and security policy enforcement points. This intermediary captures traffic telemetry, assigns semantic tags to traffic flows, and enables policy enforcement without requiring direct authentication support from legacy devices themselves.
2Measurement precision
If deep packet inspection is implemented for telemetry collection, then traffic analysis precision is improved, but network device processing complexity increases
Solution Approach 1:
The patent segments the deep packet inspection function into discrete, manageable components. Network telemetry collectors are deployed at specific network points to perform DPI on particular traffic flows, rather than requiring every network device to perform comprehensive inspection. This segmentation distributes processing complexity while maintaining high analysis precision where needed.
3Reliability
If comprehensive security policies are enforced on all devices, then security coverage is improved, but devices lacking authentication capabilities cannot comply
Solution Approach 1:
The patent enables security policy enforcement to work in a self-service manner for legacy devices. Instead of requiring devices to actively participate in authentication, the system passively observes their traffic patterns, assigns appropriate tags based on their behavior, and automatically applies security policies. This allows legacy devices to be secured without their active cooperation or authentication capability.
Data Source
AI summary
According to one or more embodiments of the disclosure, a networking device receives a policy for an endpoint in a network. The policy specifies one or more component tags and one or more activity tags that were assigned to the endpoint based on deep packet inspection of traffic associated with the endpoint. The networking device identifies a set of tags for a particular traffic flow in the network associated with the endpoint. The set of tags comprises one or more component tags or activity tags associated with the particular traffic flow. The networking device makes a determination that the particular traffic flow violates the policy based on the set of tags comprising a tag that is not in the policy. The networking device initiates, based on the determination that the particular traffic flow violates the policy, a corrective measure with respect to the particular traffic flow.


