Micro-segmentation for Enterprise IoT Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing prevalence of IoT devices poses a significant risk to enterprise networks due to unsecured devices providing hackers with undetected access, potentially compromising sensitive data and facilitating malicious cyberattacks.

Innovation Solution

Implementing a secure integration method for IoT devices into enterprise systems through network virtualization, micro-segmentation, and secure communication protocols, including VLANs, SDN, firewalls, and authentication layers to restrict access and prevent malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are integrated into enterprise networks, then network functionality and connectivity are improved, but network security and vulnerability to attacks deteriorate

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies network segmentation by dividing the enterprise network into multiple virtual network segments (VLANs) and further into micro-segments. Each IoT device is placed in its own isolated virtual network segment, allowing connectivity while preventing lateral movement of attacks. The network is segmented into management networks, operational technology networks, and IoT device networks with controlled communication paths between them.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces multiple intermediary components including network virtualization layer, software-defined networking (SDN) controllers, firewalls, and authentication servers that mediate between IoT devices and the core enterprise network. These intermediaries enforce security policies, authenticate devices, and control traffic flow without requiring direct access to sensitive network resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network segmentation is implemented, then security and access control are improved, but network complexity and infrastructure requirements worsen

Engineering Contradiction:
Improveaccess controlVSAvoidnetwork infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal network virtualization layer that provides multiple functions including segmentation, security policy enforcement, traffic management, and device authentication through a single SDN-controlled infrastructure. This multi-functional approach consolidates what would otherwise require separate systems for each function, reducing overall complexity despite the fine-grained segmentation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent adds a virtualization dimension to the physical network infrastructure, creating virtual network layers that overlay the physical topology. This allows complex segmentation and access control policies to be implemented in the virtual domain without fundamentally altering the physical network hardware, managing complexity through abstraction.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11405391B2Apparatus and methods for micro-segmentation of an enterprise internet-of-things network
Publication Date: 2022.08.02 BANK OF AMERICA CORP
  • US11405391B2 patent drawing
  • US11405391B2 patent drawing
  • US11405391B2 patent drawing

AI summary

Apparatus, systems, architectures and methods for communication over an enterprise internet-of-things (EIoT) network are disclosed. Network(s) may be micro- segmented. Network segment(s) may be associated with distinct function(s). EIoT device(s) may be identified by type(s), class(es), functionality(ies), function(s) and/or security level(s). EIoT device protocol(s) may be translated/emulated. EIoT device(s) may be temporarily/ permanently quarantined. Network gateway(s) may factor EIoT device/network data based on function(s) and/or specification(s). Data may be routed to network segment(s) based on associated function(s).