IoT Network Service Control Through MUD-Based Policy Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing campus networks struggle with managing the complex security and quality requirements of diverse IoT terminals, lacking a method to map manufacturer-defined requirements to network policies, leading to increased operational costs and management complexity.

Innovation Solution

A method and apparatus that utilize MUD files to generate network policies based on IoT terminals' security isolation, quality assurance, and access permission requirements, automatically deploying these policies through a network management device to align with manufacturer-defined specifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of network policies for IoT terminals is performed, then network security and quality requirements can be met, but enterprise operating costs and management complexity increase

Engineering Contradiction:
Improvenetwork security and quality assuranceVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing IoT terminals to automatically provide their own network policy requirements through MUD files. The terminal includes manufacturer information and access permission requirements in the MUD file, which the network management device automatically processes to generate appropriate network policies without manual intervention

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The solution implements preliminary action by pre-defining network policy requirements in MUD files during terminal manufacturing. The manufacturer usage descriptions are prepared in advance and stored in the terminal, enabling automatic policy generation when the terminal connects to the network, eliminating the need for manual post-deployment configuration

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If automated policy generation from MUD files is implemented, then management complexity is reduced, but mapping accuracy from manufacturer requirements to network policies becomes challenging

Engineering Contradiction:
Improvemanagement easeVSAvoidpolicy mapping accuracy
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The system applies parameter changes by transforming the abstract manufacturer usage descriptions in MUD files into concrete network policy parameters. The network management device parses MUD file content and converts manufacturer-defined requirements into specific network access permissions, security rules, and quality of service parameters that the network can enforce

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The network management device serves as an intermediary that bridges the gap between manufacturer-defined MUD files and network-enforceable policies. It receives MUD files from terminals, interprets the manufacturer requirements, and generates corresponding network policies by translating between different representation formats and network policy languages

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4089965B1Network service control method and apparatus for internet of things terminal, and storage medium
Publication Date: 2025.11.05 HUAWEI TECH CO LTD
  • EP4089965B1 patent drawingFigure 1~2
  • EP4089965B1 patent drawingFigure 3
  • EP4089965B1 patent drawingFigure 4

AI summary

A method and an apparatus for controlling a network service of an Internet of things terminal, and a storage medium are disclosed, and pertain to the field of communications technologies. In the method, after receiving a URL sent by an Internet of things terminal in an authentication process, a network management device obtains a MUD file based on the URL, and parses the MUD file to obtain content of at least one field included in the MUD file, where the MUD file includes at least one type of the following fields: a first-type field and a second-type field, the first-type field is used to describe a security isolation requirement, and the second-type field is used to describe a quality assurance requirement. In this way, the network management device can synchronize information with the Internet of things terminal in a network security isolation dimension and a network quality assurance dimension. Then, the network management device generates, based on the content of the at least one field, a policy that is used to control a network service of the Internet of things terminal. In this way, deployment of the Internet of things terminal in terms of security isolation and quality assurance can be automatically completed, so that enterprise operating costs are reduced.