IoT Network Segmentation for Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices present a vulnerable attack surface due to their widespread connectivity and varying security backgrounds of manufacturers, leading to challenges in comprehensive network protection, especially in home and mobile environments where enterprise-grade security solutions are not feasible.

Innovation Solution

The implementation of a segmented attack prevention system (SAPSIN) that creates partitioned network spaces for IoT devices, using a security database and request database to differentiate between service and configuration requests, and employs network segmentation to prevent malicious access and infection, thereby protecting devices from takeover and misuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional source file examination and vulnerability analysis are used to protect IoT devices, then targeted protection against known attacks is achieved, but comprehensive network protection is insufficient due to varying manufacturer security backgrounds

Engineering Contradiction:
Improveprotection effectivenessVSAvoidcomprehensive network protection
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal security gateway that provides multi-functional protection for diverse IoT devices from different manufacturers. The gateway performs authentication, authorization, encryption, and threat analysis across heterogeneous devices with varying security capabilities, creating a unified security layer that adapts to each device's specific requirements while maintaining comprehensive network protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If enterprise-grade security components like firewalls and access control lists are installed, then network hardening is achieved, but the solution does not scale to home networks and mobile environments

Engineering Contradiction:
Improvenetwork hardeningVSAvoidscalability to home and mobile environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security functionality into a distributed architecture where a central security gateway provides enterprise-grade protection while lightweight agent components are deployed on individual IoT devices. This segmentation allows the system to scale from small home networks to large enterprise deployments, as the security capabilities can be selectively activated and configured based on network size and requirements without requiring full enterprise infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security gateway acts as an intermediary between IoT devices and the network, providing enterprise-grade security functions without requiring direct installation on each device. The gateway mediates all communications, performing authentication, encryption, and threat analysis, which allows home and mobile environments to access enterprise-level protection through a single centralized component rather than requiring complex device-by-device configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If aggressive access rules and critical security component updates are implemented, then network security is improved, but device complexity and configuration requirements increase

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security gateway implements self-service capabilities by automatically performing authentication, authorization, and configuration of security policies for connected IoT devices. The system autonomously analyzes device identities, determines appropriate access rules, and configures security parameters without requiring manual intervention from administrators. This eliminates the need for complex manual configuration while maintaining aggressive security controls.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary security actions by pre-configuring access rules, authentication methods, and encryption parameters before devices connect to the network. The security gateway maintains predefined security policies and automatically applies them to devices based on their identity and purpose, eliminating the need for administrators to configure complex security settings at the time of device connection.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If device-specific knowledge and skilled consultants are required for regular security updates, then security maintenance is achieved, but ease of operation and update deployment are reduced

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidupdate deployment
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security gateway provides self-service security maintenance by automatically monitoring for vulnerabilities, downloading security updates, and applying patches to connected IoT devices. The system autonomously manages the entire update lifecycle including verification of update integrity and coordination of deployment timing, eliminating the need for skilled consultants or manual intervention while maintaining continuous security maintenance.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11973783B1Attack prevention in internet of things networks
Publication Date: 2024.04.30 ARCHITECTURE TECH CORP
  • US11973783B1 patent drawing
  • US11973783B1 patent drawing
  • US11973783B1 patent drawing

AI summary

Disclosed herein are embodiments of systems, methods, and products comprise a computing device, which allows in-network and network-border protection for Internet of things (IoT) devices by securely partitioning network space and defining service-based access to IoT devices. The disclosed segmented attack prevention system for IoT networks (SAPSIN) segments the IoT network into two virtual networks: a service network and a control network; and define access control rules for each virtual network. In the service network, SAPSIN utilizes a service-based approach to control device access, allowing only configured protocol, applications, network ports, or address groups to enter or exit the network. In control network, the SAPSIN provides the access control rules by defining a threshold for the number of configuration requests within a predetermined time. As a result, SAPSIN protects IoT devices against intrusion and misuse, without the need for device-specific software or device-specific security hardening.