IoT Gateway Secure Compartmentalization via Zone-Based Conduit Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional firewall policies in IoT gateways are inadequate for managing complex and numerous applications, particularly in scenarios involving data collection, edge computing, and automation control across different security levels, leading to insufficient network security defense capabilities.

Innovation Solution

Implementing a method of secure compartmentalization by creating multiple zones corresponding to subnets within the IoT gateway, deploying applications into these zones, and configuring conduit policies to manage packet transmission, thereby isolating and securing data, applications, and services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewall policies are used in IoT gateways, then network security is provided, but the security management becomes inflexible and inefficient for complex applications

Engineering Contradiction:
Improvenetwork security defense capabilityVSAvoidsecurity management flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the network into multiple zones (e.g., sensor zone, actuator zone, data zone) separated by firewalls. Each zone contains specific applications or devices, allowing granular security control. This segmentation enables flexible security management by treating different parts of the network differently, resolving the contradiction between providing comprehensive security and maintaining management flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements zone-specific conduit policies that define unique security rules for each zone. Instead of applying uniform firewall rules, the system creates localized security measures tailored to the specific needs of each zone (e.g., allowing data transmission from sensor zone while blocking access to actuator zone). This local quality approach enhances both security effectiveness and management flexibility.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If the IoT gateway manages more complex applications, then functionality is enhanced, but the conventional firewall policies become inadequate

Engineering Contradiction:
Improveapplication management capabilityVSAvoidsecurity defense capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

By segmenting applications into different zones based on their security requirements and functional categories, the system can manage complex applications effectively. Each zone can be independently configured with appropriate conduit policies, allowing the gateway to handle diverse application types (data collection, edge computing, control) while maintaining adequate security for each.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables dynamic security policy configuration where conduit policies can be adjusted based on the specific applications deployed in each zone. This dynamic approach allows the security system to adapt to changing application requirements and network conditions, maintaining reliability while supporting enhanced functionality.

Inventive Principle:
Principle #15Dynamics

3Ease of manufacture

If applications are deployed without zone-based compartmentalization, then deployment is simple, but packet transmission control is insufficient

Engineering Contradiction:
Improveapplication deployment simplicityVSAvoidpacket transmission control efficiency
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent segments packet transmission control into zone-based conduit policies, where each zone has defined rules for allowing or blocking traffic. This segmentation enables efficient packet transmission control by processing security decisions at the zone level rather than requiring complex centralized analysis, thus improving productivity while maintaining deployment simplicity through automated zone assignment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system automatically assigns applications to appropriate zones and configures conduit policies based on predefined templates and security requirements. This self-service mechanism reduces manual configuration complexity while enabling sophisticated packet transmission control, resolving the contradiction between deployment simplicity and control efficiency.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250007881A1Method of secure compartmentalization for IoT application and IoT gateway using the same
Publication Date: 2025.01.02 MOXA INC
  • US20250007881A1 patent drawing
  • US20250007881A1 patent drawing
  • US20250007881A1 patent drawing

AI summary

A method of secure compartmentalization for IoT application and a IoT gateway using the same are provided. The method is adapted to the IoT gateway and includes the following steps. A plurality of zones corresponding to a plurality of subnets are created by partitioning the subnets. An application installed in the IoT gateway is deployed to one of the zones. A conduit policy associated with at least one of the zones is configured. Packet transmission of the zones is managed based on the conduit policy.