Dynamic MUD File Updates for IoT Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manufacturer-embedded certificates, such as X.509 certificates, are not designed to change, which limits the ability of multi-purpose devices and IoT devices to adapt their access control policies when new applications are installed, restricting the functionality of newly installed applications.

Innovation Solution

A trusted application provider or service generates a new MUD file and certificate that includes updated access control permissions based on the installed applications, allowing the device to request an updated device identifier with a new MUD URI, enabling the appropriate access control for the device's new functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manufacturer-embedded certificates are used to control network access, then device security and access control are improved, but device adaptability and functionality are restricted when new applications are installed

Engineering Contradiction:
Improveaccess control securityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic MUD files that can be automatically updated when new applications are installed on the device. The system monitors application installations and retrieves updated MUD files from the manufacturer's server, allowing access control policies to adapt dynamically to new device functionality while maintaining security through automated policy updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where the device reports installed applications to the network infrastructure, which then triggers automatic retrieval of updated MUD files from the manufacturer. This feedback mechanism ensures that access control policies remain synchronized with the device's current application state, resolving the contradiction between static security policies and dynamic device functionality.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If predetermined manufacturer usage descriptions are used, then network access control is simplified, but device functionality expansion is limited

Engineering Contradiction:
Improveaccess control managementVSAvoidapplication functionality
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The manufacturer pre-configures MUD files with anticipated future applications and their required access permissions. When a device installs a pre-planned application, the corresponding MUD file portion is already available for automatic retrieval and integration, eliminating the need for manual policy updates and enabling seamless functionality expansion while maintaining simplified access control management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system transforms static predetermined MUD files into dynamic, automatically updating policy documents. The device and network infrastructure work together to detect application installations and retrieve updated MUD files, maintaining ease of operation through automated processes while enabling continuous device adaptability to new applications.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If static certificates are embedded in devices, then security management is simplified, but policy updates require network infrastructure intervention

Engineering Contradiction:
Improvecertificate managementVSAvoidpolicy update time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The device is equipped with self-service capabilities to automatically retrieve and apply updated MUD files from the manufacturer's server without requiring manual intervention from network administrators. The device monitors its own application state, detects changes, and autonomously updates its access control policies, reducing both complexity and update time while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Updated MUD files are prepared and made available in advance on the manufacturer's server before they are needed. When the device requests updates, the files are already ready for immediate retrieval and application, eliminating delays associated with manual policy creation and deployment while keeping the device's self-service mechanism simple.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11902277B2Secure modification of manufacturer usage description files based on device applications
Publication Date: 2024.02.13 CISCO TECHNOLOGY INC
  • US11902277B2 patent drawing
  • US11902277B2 patent drawing
  • US11902277B2 patent drawing

AI summary

Techniques for providing secure modification of manufacturer usage description (MUD) files based on device applications are provided. In one embodiment, a method for secure modification of MUD files may include obtaining a request for one or more applications from a device. The method also includes providing to the device the one or more applications and a certification that includes an updated MUD identifier determined based on the one or more applications requested. The updated MUD identifier is associated with a concatenated MUD file that comprises individual MUD file portions for each of the one or more applications requested. The device is configured to request an updated device identifier using the certification. The updated device identifier includes the updated MUD identifier that is associated with the concatenated MUD file.