Distributed Policy Enforcement for Connected Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected devices, such as IoT and M2M devices, are vulnerable to attacks from their own networks, leading to significant costs due to data usage issues, security vulnerabilities, and inefficient handling of network issues, which existing security solutions like authentication and firewalls fail to adequately address.

Innovation Solution

Implementing a distributed policy-based security system that includes a policy enforcement agent on each device, which receives and applies policy rules for traffic filtering, network access, power management, and application management, learned from data usage patterns and AI/ML techniques, to manage security and optimize data costs and latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication and firewall security solutions are used for connected devices, then basic network security is provided, but devices remain vulnerable to attacks from their own networks and suffer from data usage issues and security vulnerabilities

Engineering Contradiction:
Improvesecurity vulnerabilityVSAvoidattacks from own networks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security system is segmented into distributed policy enforcement agents deployed on individual devices rather than centralized security infrastructure. Each agent independently enforces security policies locally, enabling devices to defend themselves against attacks from their own network without relying on external authentication servers or firewalls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Devices perform self-security enforcement through local policy evaluation and execution. The policy enforcement agents on each device autonomously monitor and control network traffic, application behavior, and device operations without requiring continuous external verification, enabling devices to protect themselves from attacks originating within their network.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If centralized security management is used, then security policies can be uniformly applied, but response time increases and devices cannot quickly adapt to local threats

Engineering Contradiction:
Improvepolicy adaptationVSAvoidsecurity response time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

Security policy enforcement is segmented from centralized management to distributed local execution. Policy enforcement agents are deployed on each device to evaluate and enforce security policies locally, eliminating the time delay associated with centralized policy dissemination and enabling immediate response to local security threats while maintaining policy consistency through centralized policy definition.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security policies are pre-configured and cached on devices through policy enforcement agents before threats occur. This preliminary action enables devices to immediately enforce security measures without waiting for real-time instructions from centralized systems, significantly reducing security response time while maintaining policy uniformity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security monitoring is implemented across all devices, then network security is improved, but power consumption increases and resource-constrained devices are overwhelmed

Engineering Contradiction:
Improvenetwork securityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Security monitoring is implemented with local quality by deploying lightweight policy enforcement agents on each device that execute security policies locally without requiring continuous communication with centralized systems. This approach maintains network security through distributed monitoring while minimizing power consumption by processing security events locally and only communicating when necessary.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial security monitoring by focusing policy enforcement on specific critical functions and events rather than comprehensive continuous monitoring of all device operations. Policy enforcement agents monitor and enforce security policies for high-priority activities while using less intensive monitoring for lower-priority functions, reducing overall power consumption while maintaining effective security coverage.

Inventive Principle:
Principle #16Partial or excessive action

4Loss of energy

If data usage is heavily monitored and restricted, then data costs are reduced, but legitimate application functionality may be impacted

Engineering Contradiction:
Improvedata costVSAvoidapplication functionality
Core Design Contradiction:
Loss of energyVSEase of operation

Solution Approach 1:

Policy enforcement agents implement feedback-based data usage management by continuously monitoring application behavior and network traffic patterns, comparing them against defined policies, and dynamically adjusting data transmission accordingly. This feedback mechanism reduces data costs by blocking anomalous and unnecessary traffic while preserving legitimate application functionality through policy-based exceptions and adaptive control.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes data usage parameters dynamically based on policy evaluation results. Policy enforcement agents adjust data transmission parameters such as bandwidth allocation, traffic filtering rules, and communication frequency according to application behavior and policy requirements, optimizing data cost reduction while maintaining necessary application functionality through adaptive parameter adjustment.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20220353297A1Method and system for distributed policy-based security for connected devices
Publication Date: 2022.11.03 AERIS COMM INC
  • US20220353297A1 patent drawing
  • US20220353297A1 patent drawing
  • US20220353297A1 patent drawing

AI summary

A computer-implemented method, system, and computer program product for providing distributed policy-based security for one or more devices enabled for connectivity over a communications network are disclosed. The computer-implemented method for providing distributed policy-based security for one or more devices enabled for connectivity over a communications network includes providing a policy enforcement agent for each of one or more devices enabled for connectivity; providing policy rules to the policy enforcement agent, wherein the policy rules comprise one or more of: traffic filter policy rules, network access policy rules, power management policy rules and application management policy rules; and managing policy-based security for the one or more devices by the policy enforcement agent by applying the provided policy rules immediately or based on the provided criteria evaluated on the device.