IoT Network Segmentation via Secure Gateway

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet of Things (IoT) devices have lower security capabilities due to inconsistent software updates, making them vulnerable to hacking, which existing security recommendations, such as limiting device manufacturers and enforcing frequent password changes, are impractical to implement effectively.

Innovation Solution

An apparatus and method that establish communication between two wireless local area networks with different security levels, allowing certain types of messages to pass between them while blocking others, thereby isolating potentially hacked IoT devices from more secure networks to prevent them from exploring and compromising the entire home network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If loT devices are allowed to communicate freely on the network, then device functionality and usability are improved, but security risks increase due to potential hacking

Engineering Contradiction:
Improvedevice usabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides the network into multiple virtual networks (first virtual network for secure devices, second virtual network for loT devices) that are logically separated but can communicate through controlled gateways. This segmentation allows loT devices to function while isolating them from the main secure network, resolving the contradiction between usability and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces gateway devices that act as intermediaries between the first virtual network (secure devices) and the second virtual network (loT devices). These gateways control and filter communications, allowing necessary data exchange while blocking malicious traffic, thus enabling device functionality while mitigating security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If strict security measures are implemented (limiting manufacturers, frequent password changes), then security risks are reduced, but device complexity and user burden increase

Engineering Contradiction:
Improvesecurity risksVSAvoidsecurity management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

By segmenting devices into different virtual networks based on their security requirements, the system automatically applies appropriate security policies without requiring users to manually manage complex security settings for each device. This reduces both security risks and management complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system automatically classifies devices into appropriate virtual networks and configures security policies without requiring user intervention for password changes or security settings. The network infrastructure itself provides the security service, eliminating the need for complex user-side security management.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If loT devices are isolated from the main network, then security risks are mitigated, but device functionality and communication capability are reduced

Engineering Contradiction:
Improvesecurity risksVSAvoiddevice communication capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

Gateway devices serve as intermediaries that enable controlled communication between isolated virtual networks. They allow necessary data exchange for device functionality while maintaining network isolation for security, thus preserving communication capability without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway devices perform multiple functions including routing, filtering, and protocol translation, enabling them to facilitate diverse communication needs between different virtual networks while maintaining security boundaries. This multi-functionality preserves device adaptability across different network contexts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3208991B1Network security for internet of things
Publication Date: 2018.11.28 SONY GROUP CORP
  • EP3208991B1 patent drawingFigure 1
  • EP3208991B1 patent drawingFigure 2
  • EP3208991B1 patent drawingFigure 3

AI summary

Two wireless networks are established in a local network, one for less-secure loT devices and one for more-secure conventionally networked devices, with a bridge establishing connectivity between the two networks. Message exchange between the two networks is tailored to reduce the risk of a security breach in the network with the less-secure loT devices infecting the network with more-secure devices.