Dynamic Network Segmentation via Real-Time Device Tagging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network segmentation methods are inadequate for dynamic and diverse environments, such as those with IoT devices, where static IP address schemes and manual tagging limit the effectiveness of segmentation and increase security risks.

Innovation Solution

Implement a dynamic segmentation management system that assigns tags to entities in real-time based on their characteristics, rather than solely on IP addresses, allowing for adaptive and granular segmentation policies that can be applied across various network environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static IP address schemes and manual tagging are used for network segmentation, then device identification and segmentation policy application are simplified, but the system cannot adapt to dynamic network environments and diverse device types, reducing segmentation effectiveness and increasing security risks

Engineering Contradiction:
Improveadaptability to dynamic network environmentsVSAvoidcomplexity of segmentation management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic segmentation by transitioning from static IP-based segmentation to a system that continuously discovers devices, determines their characteristics, and dynamically assigns segmentation tags. The network segmentation system adapts in real-time to device joins, leaves, and state changes, making the segmentation dynamically responsive to network conditions while maintaining manageable complexity through automated processes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system enables self-service segmentation by automatically discovering devices on the network, determining their characteristics without manual intervention, and assigning appropriate segmentation tags. The automated device discovery and characteristic determination processes eliminate the need for manual tagging, allowing the system to self-configure segmentation policies based on observed device behavior and attributes.

Inventive Principle:
Principle #25Self-service

2Reliability

If scanning of each device is performed to monitor and secure the network, then security monitoring capability is improved, but the time and resources required for device discovery and vulnerability assessment increase significantly

Engineering Contradiction:
Improvenetwork security monitoring capabilityVSAvoidtime for device discovery and scanning
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing device discovery and characteristic determination as devices join the network, before security threats can develop. The system proactively identifies devices, determines their characteristics, and establishes segmentation policies in advance, rather than waiting for security incidents to occur. This preliminary segmentation reduces the need for extensive later scanning and monitoring.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses segmentation to divide the network into isolated zones based on device characteristics and risk profiles. By segmenting the network dynamically, the system limits the scope of required scanning and monitoring to specific segments rather than the entire network. This reduces the overall time and resources needed for security monitoring while maintaining comprehensive coverage through targeted segment-specific assessments.

Inventive Principle:
Principle #1Segmentation

3Productivity

If dynamic segmentation based on device characteristics is implemented, then segmentation effectiveness and security response capability are improved, but the complexity of real-time device monitoring and tag assignment increases

Engineering Contradiction:
Improvesegmentation policy application efficiencyVSAvoidcomplexity of real-time monitoring system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal device discovery and characteristic determination system that handles multiple device types and network protocols through a single automated process. The segmentation tag assignment mechanism serves multiple functions: identifying devices, categorizing them by characteristics, determining segmentation policies, and enforcing security rules. This multi-functionality improves productivity by consolidating what would otherwise require separate systems into one unified platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages complexity by dynamically changing segmentation parameters (tags, zones, policies) based on device characteristics rather than maintaining fixed configurations. When devices join or leave the network, or when their characteristics change, the system automatically adjusts segmentation parameters in real-time. This parameter-based approach allows flexible adaptation to changing network conditions without requiring complex reconfiguration of the underlying system architecture.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12289294B2Dynamic segmentation management
Publication Date: 2025.04.29 FORESCOUT TECHNOLOGIES INC
  • US12289294B2 patent drawing
  • US12289294B2 patent drawing
  • US12289294B2 patent drawing

AI summary

Systems, methods, and related technologies for segmentation management are described. In certain aspects, an entity communicatively coupled to a network is selected and one or more characteristics of the entity may be determined. A segmentation policy may be selected based on the one or more characteristics of the entity and one or more tags to be assigned to the entity based on the segmentation policy may be determined. A zone for the entity based on the one or more tags may be determined and one or more enforcement points associated with the zone for the entity may be determined. One or more enforcement actions may then be assigned to the one or more enforcement points based on the zone associated with the entity.