Dynamic Software Defined Network Segmentation for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network operators face challenges in effectively identifying and mitigating infected devices on their networks, as existing systems struggle to provide comprehensive security protections for diverse devices, including IoT devices, and to dynamically isolate or remediate infected devices without disrupting network operations.

Innovation Solution

The implementation of Dynamic Software Defined Networking (DSDN) provides network-level security protections by dynamically isolating infected devices, quarantining them, or limiting their network traffic to approved destinations. DSDN also creates VPN tunnels for devices with strong security to enhance defense layers, such as for medical devices with embedded PKI certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing botnet notification and remediation systems are used to identify infected devices, then network operators can detect infected devices, but they struggle to provide comprehensive security protections for diverse devices including IoT devices and to dynamically isolate infected devices without disrupting network operations

Engineering Contradiction:
Improvenetwork security protectionVSAvoidcompatibility with diverse devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal network segmentation system that creates virtual network segments capable of accommodating diverse device types including traditional devices and IoT devices. The system uses a network controller that can dynamically provision and manage segmentation for any device type, providing comprehensive security protection across the entire device ecosystem through a single unified platform

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If infected devices are quarantined or isolated from the network, then network security is improved, but network operations and device functionality are disrupted

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork operation continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the network into multiple virtual segments or zones using VLANs and routing protocols. Infected devices are moved to isolated segments while healthy devices remain in separate segments, allowing security containment without complete network disconnection. This segmentation enables selective isolation that maintains overall network productivity while protecting against infection spread

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network controller as an intermediary that manages device movement between network segments. The controller dynamically provisions routing rules and segmentation configurations to isolate infected devices while maintaining controlled access to necessary network resources, thereby preserving essential functionality during remediation

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If network traffic is limited to approved destinations for infected devices, then infection spread is prevented, but device functionality is restricted

Engineering Contradiction:
Improveinfection containmentVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different traffic restriction policies to different network segments and device types. Approved destinations for infected devices are specifically configured based on device criticality and security requirements, allowing essential functionality to be maintained while blocking harmful traffic patterns. This localized quality control enables differentiated access permissions that balance security and functionality

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12279119B2Systems and method for micro network segmentation
Publication Date: 2025.04.15 CABLE TELEVISION LAB INC
  • US12279119B2 patent drawing
  • US12279119B2 patent drawing
  • US12279119B2 patent drawing

AI summary

A wireless communication system includes an external provider subsystem and an electronic network subsystem in operable communication with the external provider subsystem. The electronic network subsystem is configured to provide a first microservice and a second microservice different from the first microservice. The wireless communication system further includes an in-home subsystem (i) separate from the external provider subsystem, (ii) in operable communication with the electronic network subsystem, and (iii) including a first micronet and a second micronet different from the first micronet. The first micronet is configured to operably interact with the first microservice, and the second micronet is configured to operably interact with the second microservice. The wireless communication system further includes at least one electronic device configured to operably connect with one of the first micronet and the second micronet.