IoT Asset Inventory Service for Device Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial IoT (IIoT) networks face challenges in accurately identifying devices due to multiple network identities and the use of Network Address Translation (NAT), which hinders traditional device discovery methods, especially in environments with redundant network interfaces and 'cookie-cutter' deployments using duplicate IP addresses.
Innovation Solution
An asset inventory service collects telemetry data passively and requests active discovery from sensor applications to generate an identity profile for nodes, correlating traffic properties, engineering data, and configuration information to reconcile multiple network identities and create singular node profiles, even across NAT boundaries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional active scanning device discovery approaches are used in IIoT networks, then device discovery can be performed, but NAT boundaries block the discovery process and prevent accurate identification of devices
Solution Approach 1:
The patent introduces an intermediary asset inventory service that acts as a mediator between the discovery process and NAT-protected devices. This service collects telemetry data from network traffic and correlates it with active discovery data to identify devices behind NAT boundaries, effectively bypassing the blocking effect of NAT while maintaining accurate device identification
Solution Approach 2:
The patent shifts from a single-dimension active scanning approach to a multi-dimensional identification approach by combining passive telemetry data collection with active discovery. This dimensional expansion allows the system to identify devices through multiple data sources and correlation techniques, overcoming the limitations of traditional single-method discovery
2Reliability
If multiple network identities are assigned to IIoT devices for redundancy and ease of deployment, then network resilience and deployment simplicity improve, but device identification becomes ambiguous and inaccurate
Solution Approach 1:
The patent merges multiple data sources including passive telemetry data, active discovery data, traffic flow information, and device responses into a unified device identity profile. This consolidation process correlates information from multiple network identities to establish accurate single device profiles, resolving the ambiguity caused by multiple identities while preserving the redundancy benefits
3Ease of manufacture
If IP addresses are repeated across network units for ease of deployment, then deployment simplicity improves, but device discovery and identification become erroneous
Solution Approach 1:
The patent implements a feedback mechanism where the asset inventory service continuously collects telemetry data, performs correlation analysis, and refines device identity profiles based on observed network behavior and traffic patterns. This iterative feedback process enables accurate differentiation of devices with repeated IP addresses by analyzing contextual network behavior rather than relying solely on static address information
Data Source
AI summary
According to one or more embodiments of the disclosure, an asset inventory service executed by one or more devices receives telemetry data collected passively by a sensor application regarding a node in a network. The asset inventory service requests, after receiving the telemetry data, that the sensor application perform active discovery of nodes in the network. The asset inventory service receives active discovery data collected by the sensor application via active discovery of nodes in the network. The asset inventory service generates, based on the telemetry data and the active discovery data, an identity profile for the node.


