External Segmentation Orchestrator for Untrusted Device Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current traffic segmentation solutions struggle to effectively manage untrusted devices outside a trusted network, such as mobile phones and IoT gateways, due to their characteristics like public Internet exposure and frequent connection changes, leading to challenges in applying and verifying segmentation tags across the network infrastructure.

Innovation Solution

The introduction of an external segmentation orchestrator that generates and distributes cipher-based segmentation tags to untrusted devices, allowing them to onboard onto a trusted network while preventing tampering, and utilizing an internal orchestrator to manage trusted devices, with trusted network edges verifying the tags using a provisioned key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If segmentation tags are applied at untrusted devices, then traffic segmentation capability is improved, but device complexity and management difficulty increase

Engineering Contradiction:
Improvetraffic segmentation capabilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the orchestration function into two parts: an internal orchestrator for trusted devices and an external orchestrator for untrusted devices. This segmentation allows each orchestrator to handle specific device types with appropriate security models, improving traffic segmentation capability while managing complexity through functional division.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An external orchestrator is introduced as an intermediary component that specifically manages untrusted devices. This intermediary handles the complexity of securing untrusted devices, preventing tampering, and verifying segmentation tags, thereby improving overall system adaptability without burdening the internal orchestrator with untrusted device management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If untrusted devices are onboarded to the trusted network, then network accessibility is improved, but security risk increases

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity trust level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system applies different security qualities to different parts of the network: trusted devices receive full trust and internal orchestrator management, while untrusted devices receive restricted trust with external orchestrator management and tamper prevention. This local differentiation allows untrusted devices to access the network while maintaining appropriate security boundaries.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The external orchestrator implements beforehand cushioning by preventing tampering with segmentation tags before untrusted devices can exploit them. Security measures are in place in advance to protect against potential security risks, allowing network accessibility while mitigating security risks proactively.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Device complexity

If internal orchestrator manages all devices, then centralized control is maintained, but operational efficiency decreases

Engineering Contradiction:
Improvecentralized controlVSAvoidoperational efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The orchestration function is segmented into internal and external orchestrators based on device trust levels. This segmentation improves operational efficiency by allowing parallel processing of trusted and untrusted devices through specialized orchestrators, while maintaining centralized control through coordinated operation of both orchestrators under the overall system architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11647019B2Systems and methods for providing security orchestration for trusted traffic segmentation on untrusted devices
Publication Date: 2023.05.09 CISCO TECHNOLOGY INC
  • US11647019B2 patent drawing
  • US11647019B2 patent drawing
  • US11647019B2 patent drawing

AI summary

A method includes generating, by an internal segmentation orchestrator, a key to cipher/decipher a cryptographic segmentation tag used by an untrusted device, transmitting the key to an external segmentation orchestrator, transmitting the cryptographic segmentation tag to the external segmentation orchestrator and provisioning a trusted network edge with the key and optionally the cryptographic segmentation tag. The method can also include onboarding, based on the key and the cryptographic segmentation tag, the untrusted device, wherein the untrusted device receives the cryptographic segmentation tag from the external segmentation orchestrator.