IoT Remote Access via MUD Files and Management Service
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security mechanisms, such as DMZs, often prevent IoT devices from allowing remote access for troubleshooting, data analytics, and software updates, making it challenging for vendors and manufacturers to communicate with their deployed devices.
Innovation Solution
A management service establishes a trust relationship with entities associated with IoT endpoints, using Manufacturer Usage Description (MUD) files to configure remote access connections by providing credentials and configuring the network to allow remote access, leveraging the MUD protocol to signal the desire for access and manage security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security mechanisms such as DMZ are implemented to protect IoT networks, then network security is improved, but remote access capability for vendors and manufacturers deteriorates
Solution Approach 1:
The patent introduces a management service as an intermediary between the DMZ-protected network and external entities. This service receives MUD files from endpoints, extracts remote access requirements, and configures appropriate access policies without breaking the DMZ security boundary. The management service acts as a mediator that enables controlled remote access while maintaining the protective barrier of the demilitarized zone.
Solution Approach 2:
The system performs preliminary actions by collecting remote access requirements in advance through MUD files during endpoint onboarding. Instead of configuring access policies reactively when access is needed, the management service proactively processes MUD files to pre-establish access rules and credentials, enabling seamless remote access when required while maintaining security posture.
2Ease of operation
If manual configuration of remote access policies is performed, then remote access capability is improved, but device complexity and configuration time increase
Solution Approach 1:
The patent implements self-service by enabling endpoints to automatically generate and communicate their own remote access requirements through MUD files. The management service automatically processes these files, extracts access requirements, and configures policies without human intervention. This eliminates the need for manual configuration by network administrators, reducing both complexity and configuration time while maintaining secure access capabilities.
Solution Approach 2:
The system performs preliminary configuration actions automatically by processing MUD files during endpoint onboarding. Remote access policies, credentials, and network rules are pre-configured based on the endpoint's declared requirements in the MUD file, eliminating the need for complex manual configuration later and reducing deployment time significantly.
3Reliability
If DMZ is implemented to prevent unauthorized access, then network security is improved, but troubleshooting and maintenance operations become more difficult
Solution Approach 1:
The management service serves as an intermediary that facilitates troubleshooting and maintenance operations without compromising the DMZ security boundary. It processes MUD files to identify and configure appropriate access channels for diagnostic and maintenance activities, enabling authorized personnel to troubleshoot endpoints while the DMZ remains intact and protecting against unauthorized access.
Data Source
AI summary
In one embodiment, a management service for a network that is executed by one or more devices establishes a trust relationship with an entity associated with an endpoint in the network. The management service receives, via a Manufacturer Usage Description (MUD) file for the endpoint, an indication that the entity desires remote access to the endpoint in the network. The management service configures, based on the indication, the network to provide a remote access connection between the entity and the endpoint in the network. The management service provides, to the entity, credentials to the entity for the remote access connection.


