Network Gateway Device Zoning for Client Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless router device isolation techniques are inefficient and lack flexibility, requiring manual enablement/disabling for each device and not providing varying degrees of isolation, which compromises network security as vulnerable devices can attack others.

Innovation Solution

A network gateway device with multiple device zones that assign client devices based on parameters like type, MAC address, and functionality, offering customizable network access privileges and isolation levels, including a 'timeout' zone for compromised devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device isolation is enabled for each device individually, then network security is improved, but device complexity and ease of operation deteriorate due to manual configuration requirements

Engineering Contradiction:
Improvenetwork securityVSAvoidisolation configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is segmented into multiple device zones (e.g., trusted zone, untrusted zone, guest zone) based on security requirements. Each zone has predefined isolation policies, eliminating the need for individual device configuration while maintaining security. Devices are automatically assigned to appropriate zones based on their type or security posture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs automatic device zoning without requiring manual user intervention. The gateway device autonomously evaluates incoming devices, determines their security requirements, and assigns them to appropriate zones automatically, reducing operational complexity while maintaining security effectiveness.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If uniform device isolation is applied to all devices, then security is simplified, but adaptability deteriorates as different isolation levels are not provided

Engineering Contradiction:
Improveisolation policy managementVSAvoidisolation level flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

Different isolation policies are applied to different device zones. The trusted zone allows full network access, the untrusted zone provides partial isolation, and the guest zone enforces strict isolation. This local differentiation of security policies provides both ease of management through standardization and adaptability through zone-specific customization.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Devices can dynamically transition between zones based on their security status or user actions. A device can be moved from the untrusted zone to the trusted zone when security requirements change, providing flexible adaptability while maintaining simplified policy management through automated zone assignment.

Inventive Principle:
Principle #15Dynamics

3Reliability

If manual device isolation configuration is required, then security control is improved, but productivity deteriorates due to time-consuming setup

Engineering Contradiction:
Improvesecurity controlVSAvoiddevice onboarding speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Device zones and their isolation policies are pre-configured in the gateway device before any client devices connect. When a device joins the network, it is automatically evaluated and assigned to the appropriate pre-defined zone, enabling rapid onboarding while maintaining security control without manual configuration during device setup.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20210385229A1Device zoning in a network gateway device
Publication Date: 2021.12.09 DISH NETWORK LLC
  • US20210385229A1 patent drawing
  • US20210385229A1 patent drawing
  • US20210385229A1 patent drawing

AI summary

The disclosure is directed to a network gateway device (“gateway”) that provides various network management features, including a device zoning feature in which client computing devices (“client devices”) connected to the gateway are assigned to different device zones. The client devices connected to the gateway form a local area network (LAN) of the gateway, and can access an external network, e.g., Internet, using the gateway. Each of the device zones has a specific set of network access privileges. Different device zones can have different network access privileges and can provide device isolation in the LAN at different degrees.