Dynamic MUD File Updates for IoT Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Manufacturer-embedded certificates, such as X.509 certificates, are not designed to change, which limits the ability of multi-purpose devices and IoT devices to adapt their access control policies when new applications are installed, restricting the functionality of newly installed applications.
Innovation Solution
A trusted application provider or service generates a new MUD file and certificate that includes updated access control permissions based on the installed applications, allowing the device to request an updated device identifier with a new MUD URI, enabling the appropriate access control for the device's new functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manufacturer-embedded certificates are used to control network access, then device security and access control are improved, but device adaptability and functionality are restricted when new applications are installed
Solution Approach 1:
The patent implements dynamic MUD files that can be automatically updated when new applications are installed on the device. The system monitors application installations and retrieves updated MUD files from the manufacturer's server, allowing access control policies to adapt dynamically to new device functionality while maintaining security through automated policy updates.
Solution Approach 2:
The system establishes a feedback loop where the device reports installed applications to the network infrastructure, which then triggers automatic retrieval of updated MUD files from the manufacturer. This feedback mechanism ensures that access control policies remain synchronized with the device's current application state, resolving the contradiction between static security policies and dynamic device functionality.
2Ease of operation
If predetermined manufacturer usage descriptions are used, then network access control is simplified, but device functionality expansion is limited
Solution Approach 1:
The manufacturer pre-configures MUD files with anticipated future applications and their required access permissions. When a device installs a pre-planned application, the corresponding MUD file portion is already available for automatic retrieval and integration, eliminating the need for manual policy updates and enabling seamless functionality expansion while maintaining simplified access control management.
Solution Approach 2:
The system transforms static predetermined MUD files into dynamic, automatically updating policy documents. The device and network infrastructure work together to detect application installations and retrieve updated MUD files, maintaining ease of operation through automated processes while enabling continuous device adaptability to new applications.
3Device complexity
If static certificates are embedded in devices, then security management is simplified, but policy updates require network infrastructure intervention
Solution Approach 1:
The device is equipped with self-service capabilities to automatically retrieve and apply updated MUD files from the manufacturer's server without requiring manual intervention from network administrators. The device monitors its own application state, detects changes, and autonomously updates its access control policies, reducing both complexity and update time while maintaining security.
Solution Approach 2:
Updated MUD files are prepared and made available in advance on the manufacturer's server before they are needed. When the device requests updates, the files are already ready for immediate retrieval and application, eliminating delays associated with manual policy creation and deployment while keeping the device's self-service mechanism simple.
Data Source
AI summary
Techniques for providing secure modification of manufacturer usage description (MUD) files based on device applications are provided. In one embodiment, a method for secure modification of MUD files may include obtaining a request for one or more applications from a device. The method also includes providing to the device the one or more applications and a certification that includes an updated MUD identifier determined based on the one or more applications requested. The updated MUD identifier is associated with a concatenated MUD file that comprises individual MUD file portions for each of the one or more applications requested. The device is configured to request an updated device identifier using the certification. The updated device identifier includes the updated MUD identifier that is associated with the concatenated MUD file.


