Dynamic Software Defined Network Segmentation for IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network operators face challenges in effectively identifying and mitigating infected devices on their networks, as existing systems struggle to provide comprehensive security protections for diverse devices, including IoT devices, and to dynamically isolate or remediate infected devices without disrupting network operations.
Innovation Solution
The implementation of Dynamic Software Defined Networking (DSDN) provides network-level security protections by dynamically isolating infected devices, quarantining them, or limiting their network traffic to approved destinations. DSDN also creates VPN tunnels for devices with strong security to enhance defense layers, such as for medical devices with embedded PKI certificates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing botnet notification and remediation systems are used to identify infected devices, then network operators can detect infected devices, but they struggle to provide comprehensive security protections for diverse devices including IoT devices and to dynamically isolate infected devices without disrupting network operations
Solution Approach 1:
The patent implements a universal network segmentation system that creates virtual network segments capable of accommodating diverse device types including traditional devices and IoT devices. The system uses a network controller that can dynamically provision and manage segmentation for any device type, providing comprehensive security protection across the entire device ecosystem through a single unified platform
2Reliability
If infected devices are quarantined or isolated from the network, then network security is improved, but network operations and device functionality are disrupted
Solution Approach 1:
The patent divides the network into multiple virtual segments or zones using VLANs and routing protocols. Infected devices are moved to isolated segments while healthy devices remain in separate segments, allowing security containment without complete network disconnection. This segmentation enables selective isolation that maintains overall network productivity while protecting against infection spread
Solution Approach 2:
The patent introduces a network controller as an intermediary that manages device movement between network segments. The controller dynamically provisions routing rules and segmentation configurations to isolate infected devices while maintaining controlled access to necessary network resources, thereby preserving essential functionality during remediation
3Reliability
If network traffic is limited to approved destinations for infected devices, then infection spread is prevented, but device functionality is restricted
Solution Approach 1:
The patent applies different traffic restriction policies to different network segments and device types. Approved destinations for infected devices are specifically configured based on device criticality and security requirements, allowing essential functionality to be maintained while blocking harmful traffic patterns. This localized quality control enables differentiated access permissions that balance security and functionality
Data Source
AI summary
A wireless communication system includes an external provider subsystem and an electronic network subsystem in operable communication with the external provider subsystem. The electronic network subsystem is configured to provide a first microservice and a second microservice different from the first microservice. The wireless communication system further includes an in-home subsystem (i) separate from the external provider subsystem, (ii) in operable communication with the electronic network subsystem, and (iii) including a first micronet and a second micronet different from the first micronet. The first micronet is configured to operably interact with the first microservice, and the second micronet is configured to operably interact with the second microservice. The wireless communication system further includes at least one electronic device configured to operably connect with one of the first micronet and the second micronet.


