Automated IoT VLAN Configuration Through Traffic Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing networked IoT devices requires complex manual VLAN configuration, which is error-prone and difficult to maintain, while coarse-grained security strategies fail to prevent threats and compromise the entire network.

Innovation Solution

Automatically discover and classify new IoT devices through traffic analysis, establishing a VLAN and implementing zero-trust access policies using a traffic classifier, VLAN configurator, and IoT proxy to manage network traffic and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual VLAN configuration is used for IoT devices, then network security can be established, but the process becomes costly, error-prone, and difficult to maintain

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service by having the network infrastructure itself (switches, routers) automatically discover, classify, and configure VLANs for IoT devices without human intervention. The automated discovery mechanism monitors network traffic, identifies device types, and triggers appropriate VLAN creation and routing rules, allowing the system to service itself rather than requiring manual administrator intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-defining device templates and classification rules before devices are actually connected. When a device connects, the system already has the necessary configuration templates ready (VLAN assignments, routing rules, security policies) and can immediately apply them without delay, ensuring seamless onboarding.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If coarse-grained security perimeter is used, then network monitoring is simplified, but threats are not averted and the entire network can be compromised

Engineering Contradiction:
Improvesecurity monitoringVSAvoidnetwork security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system applies segmentation by creating separate VLANs for different IoT device types and purposes, isolating them from each other and from the main corporate network. This fine-grained segmentation ensures that if one device is compromised, the damage is contained to its specific VLAN rather than propagating throughout the entire network, thus maintaining security while managing complexity through automated management of these segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements local quality by tailoring security policies and network access rights specifically for each device type and its associated VLAN. Different device types receive customized security treatments based on their functional requirements, allowing precise security control at the local level rather than applying a uniform coarse-grained policy across the entire network.

Inventive Principle:
Principle #3Local quality

3Productivity

If automated device discovery and classification is implemented, then configuration efficiency is improved, but system complexity increases

Engineering Contradiction:
Improveconfiguration efficiencyVSAvoidsystem architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system achieves universality by implementing a single automated discovery and classification framework that handles multiple device types and scenarios through a unified approach. The same core mechanisms (traffic monitoring, template matching, classification algorithms) serve all device types, from simple sensors to complex actuators, eliminating the need for separate specialized systems for each device category.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces intermediary components (traffic classifiers, VLAN configurators, policy enforcement points) that act as mediators between the network infrastructure and the IoT devices. These intermediaries absorb the complexity of device discovery and classification, shielding the rest of the network from the intricacies of individual device configurations while maintaining high automation efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250279934A1Automated network configuration
Publication Date: 2025.09.04 MICRO FOCUS LLC
  • US20250279934A1 patent drawing
  • US20250279934A1 patent drawing
  • US20250279934A1 patent drawing

AI summary

Devices with low or no security are often added to networks. These devices have the ability to utilize the network and, accordingly, may pose a security risk. Systems and methods herein enable a device to be added to a network and, if the resulting new traffic matches a template, the device is established on an automatically created virtual local area network (VLAN) used solely for the new device. A router is automatically configured to allow traffic that matches the type of device that was newly added, but if other traffic is detected, the device may be treated as a threat and managed accordingly.