IoT Remote Access via MUD Files and Management Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security mechanisms, such as DMZs, often prevent IoT devices from allowing remote access for troubleshooting, data analytics, and software updates, making it challenging for vendors and manufacturers to communicate with their deployed devices.

Innovation Solution

A management service establishes a trust relationship with entities associated with IoT endpoints, using Manufacturer Usage Description (MUD) files to configure remote access connections by providing credentials and configuring the network to allow remote access, leveraging the MUD protocol to signal the desire for access and manage security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security mechanisms such as DMZ are implemented to protect IoT networks, then network security is improved, but remote access capability for vendors and manufacturers deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidremote access capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a management service as an intermediary between the DMZ-protected network and external entities. This service receives MUD files from endpoints, extracts remote access requirements, and configures appropriate access policies without breaking the DMZ security boundary. The management service acts as a mediator that enables controlled remote access while maintaining the protective barrier of the demilitarized zone.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by collecting remote access requirements in advance through MUD files during endpoint onboarding. Instead of configuring access policies reactively when access is needed, the management service proactively processes MUD files to pre-establish access rules and credentials, enabling seamless remote access when required while maintaining security posture.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If manual configuration of remote access policies is performed, then remote access capability is improved, but device complexity and configuration time increase

Engineering Contradiction:
Improveremote access capabilityVSAvoidconfiguration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling endpoints to automatically generate and communicate their own remote access requirements through MUD files. The management service automatically processes these files, extracts access requirements, and configures policies without human intervention. This eliminates the need for manual configuration by network administrators, reducing both complexity and configuration time while maintaining secure access capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary configuration actions automatically by processing MUD files during endpoint onboarding. Remote access policies, credentials, and network rules are pre-configured based on the endpoint's declared requirements in the MUD file, eliminating the need for complex manual configuration later and reducing deployment time significantly.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If DMZ is implemented to prevent unauthorized access, then network security is improved, but troubleshooting and maintenance operations become more difficult

Engineering Contradiction:
Improvenetwork securityVSAvoidtroubleshooting capability
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The management service serves as an intermediary that facilitates troubleshooting and maintenance operations without compromising the DMZ security boundary. It processes MUD files to identify and configure appropriate access channels for diagnostic and maintenance activities, enabling authorized personnel to troubleshoot endpoints while the DMZ remains intact and protecting against unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11863555B2Remote access policies for IoT devices using manufacturer usage description (MUD) files
Publication Date: 2024.01.02 CISCO TECHNOLOGY INC
  • US11863555B2 patent drawing
  • US11863555B2 patent drawing
  • US11863555B2 patent drawing

AI summary

In one embodiment, a management service for a network that is executed by one or more devices establishes a trust relationship with an entity associated with an endpoint in the network. The management service receives, via a Manufacturer Usage Description (MUD) file for the endpoint, an indication that the entity desires remote access to the endpoint in the network. The management service configures, based on the indication, the network to provide a remote access connection between the entity and the endpoint in the network. The management service provides, to the entity, credentials to the entity for the remote access connection.