External Segmentation Orchestrator for Untrusted Device Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current traffic segmentation solutions struggle to effectively manage untrusted devices outside a trusted network, such as mobile phones and IoT gateways, due to their characteristics like public Internet exposure and frequent connection changes, leading to challenges in applying and verifying segmentation tags across the network infrastructure.
Innovation Solution
The introduction of an external segmentation orchestrator that generates and distributes cipher-based segmentation tags to untrusted devices, allowing them to onboard onto a trusted network while preventing tampering, and utilizing an internal orchestrator to manage trusted devices, with trusted network edges verifying the tags using a provisioned key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If segmentation tags are applied at untrusted devices, then traffic segmentation capability is improved, but device complexity and management difficulty increase
Solution Approach 1:
The system segments the orchestration function into two parts: an internal orchestrator for trusted devices and an external orchestrator for untrusted devices. This segmentation allows each orchestrator to handle specific device types with appropriate security models, improving traffic segmentation capability while managing complexity through functional division.
Solution Approach 2:
An external orchestrator is introduced as an intermediary component that specifically manages untrusted devices. This intermediary handles the complexity of securing untrusted devices, preventing tampering, and verifying segmentation tags, thereby improving overall system adaptability without burdening the internal orchestrator with untrusted device management complexity.
2Adaptability or versatility
If untrusted devices are onboarded to the trusted network, then network accessibility is improved, but security risk increases
Solution Approach 1:
The system applies different security qualities to different parts of the network: trusted devices receive full trust and internal orchestrator management, while untrusted devices receive restricted trust with external orchestrator management and tamper prevention. This local differentiation allows untrusted devices to access the network while maintaining appropriate security boundaries.
Solution Approach 2:
The external orchestrator implements beforehand cushioning by preventing tampering with segmentation tags before untrusted devices can exploit them. Security measures are in place in advance to protect against potential security risks, allowing network accessibility while mitigating security risks proactively.
3Device complexity
If internal orchestrator manages all devices, then centralized control is maintained, but operational efficiency decreases
Solution Approach 1:
The orchestration function is segmented into internal and external orchestrators based on device trust levels. This segmentation improves operational efficiency by allowing parallel processing of trusted and untrusted devices through specialized orchestrators, while maintaining centralized control through coordinated operation of both orchestrators under the overall system architecture.
Data Source
AI summary
A method includes generating, by an internal segmentation orchestrator, a key to cipher/decipher a cryptographic segmentation tag used by an untrusted device, transmitting the key to an external segmentation orchestrator, transmitting the cryptographic segmentation tag to the external segmentation orchestrator and provisioning a trusted network edge with the key and optionally the cryptographic segmentation tag. The method can also include onboarding, based on the key and the cryptographic segmentation tag, the untrusted device, wherein the untrusted device receives the cryptographic segmentation tag from the external segmentation orchestrator.


