Individualized IoT Network Security Controls via DHCP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices often introduce security risks to enterprise IT infrastructures due to lack of network security controls, malware infections, and unmanaged behavior, making it difficult for network operators to track and protect against malicious activities.

Innovation Solution

Implementing individualized network flow controls and access controls specific to each IoT device by querying authoritative rule sources and translating these rules into configuration parameters for network flow control devices, which monitor and manage communications to prevent malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If generic network flow control rules are applied to IoT devices, then network management is simplified, but security protection effectiveness deteriorates because IoT devices exhibit many different types of behavior

Engineering Contradiction:
Improvenetwork management simplicityVSAvoidsecurity protection effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments network security management by creating device-specific configuration files for each IoT device type. Instead of applying a single generic rule set to all devices, the system divides security policies into individualized configurations that address the unique behavior patterns and security requirements of each device type, thereby maintaining both management simplicity and security effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by tailoring network flow control rules to match the specific characteristics of each IoT device type. Each device receives customized security policies based on its behavior patterns, ensuring that security protection is optimized for local device requirements rather than applying uniform generic rules across all devices.

Inventive Principle:
Principle #3Local quality

2Reliability

If individualized network flow control rules are implemented for each IoT device, then security protection effectiveness is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling IoT devices to automatically obtain their own network flow control rules through DHCP option 121. Devices self-configure with appropriate security policies without requiring manual administrator intervention, which reduces management overhead while maintaining individualized security protection for each device type.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies universality by using a standardized DHCP infrastructure to deliver device-specific security configurations. The same DHCP mechanism serves multiple functions: device identification, IP address assignment, and security policy distribution. This universal approach simplifies management by using existing infrastructure rather than requiring separate complex management systems for each device type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If IoT devices are connected without registration, then ease of device deployment is improved, but network operator ability to track and remove problematic devices deteriorates

Engineering Contradiction:
Improvedevice deployment simplicityVSAvoiddevice tracking capability
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback by requiring IoT devices to register with the network operator upon connection. This registration process provides the network operator with visibility into deployed devices, enabling tracking and monitoring capabilities. The feedback loop allows operators to identify problematic devices and remove them from the network while maintaining relatively simple deployment procedures.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10735422B2Automated individualized network security controls for internet of things (IoT) devices
Publication Date: 2020.08.04 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10735422B2 patent drawing
  • US10735422B2 patent drawing
  • US10735422B2 patent drawing

AI summary

A method, apparatus and computer program product for protecting enterprise Information Technology (IT) infrastructures by automatically instantiating individualized network flow controls and/or network access controls specific to an IoT device. In this approach, an IoT device is identified, e.g., via network scanning or other observational sensors, or by receipt of information from a network administrator. In response to receiving information about the new IoT device, a control component obtains applicable network flow control and/or access control rules for the IoT device. These rules are obtained from one or more authoritative (trusted) sources, e.g., querying a website of the IoT vendor, an industry site, or an enterprise site. In this manner, applicable network flow control and/or access control rules are obtained. The control component then translates those rules into configuration parameters that are consumable by the particular network flow control device that is (or will be) associated with the IoT device.