IoT Device Detection via PRACH Repetition Rate Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rapid growth of IoT devices in enterprise networks poses a significant security risk due to their lack of authorization, authentication, and encryption capabilities, potentially allowing malicious entities to exploit them for attacking the network, and existing methods struggle to differentiate and isolate these devices from authorized mobile devices.

Innovation Solution

A method is introduced to identify IoT devices by monitoring their WWAN transmissions, specifically analyzing the repetition rate of physical random access channel (PRACH) transmissions, and then isolating them into a separate network segment within the enterprise network, using a network controller and monitoring radio receiver to decode WWAN configurations and assign them to a virtual extensible local area network (VxLAN) for quarantine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are allowed to connect to the enterprise network, then network functionality and device connectivity are improved, but security risks increase due to lack of authorization and authentication capabilities

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the enterprise network into different Virtual LANs (VLANs) based on device type. IoT devices are assigned to a separate VLAN from authorized mobile devices, allowing both to coexist on the network while isolating security risks. The network controller automatically creates VLANs and assigns devices to appropriate segments based on their identification characteristics.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts IoT devices from the main enterprise network by identifying them through their WWAN transmission characteristics (PRACH repetition rates) and moving them to a separate network segment. This extraction removes the security vulnerability source from the critical network infrastructure while maintaining controlled access.

Inventive Principle:
Principle #2Taking out (Extraction)

2Loss of information

If traditional network monitoring methods are used, then network traffic is monitored, but IoT devices cannot be differentiated from authorized mobile devices

Engineering Contradiction:
Improvedevice identification accuracyVSAvoiddevice differentiation capability
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent replaces traditional mechanical/network-layer device identification methods with radio-frequency-based detection. By monitoring WWAN physical layer characteristics (PRACH transmission repetition rates) through a monitoring radio receiver, the system can identify IoT devices without relying on network authentication credentials that both device types share.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent uses distinct transmission characteristics as identifying markers for different device types. IoT devices exhibit specific PRACH repetition rate patterns (e.g., 2x, 4x, 8x repetitions) that differ from authorized mobile devices, allowing the monitoring system to distinguish between them based on these unique 'signatures' in the radio transmissions.

Inventive Principle:
Principle #32Color changes

3Object-affected harmful factors

If IoT devices are isolated to a separate network segment, then security risks are reduced, but network management complexity increases

Engineering Contradiction:
Improvesecurity risksVSAvoidnetwork management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements automatic device identification and network segmentation through the network controller. When a new device connects, the controller monitors its WWAN transmissions, identifies it as an IoT device based on PRACH characteristics, and automatically assigns it to the appropriate VLAN without requiring manual intervention. This self-service approach reduces management complexity despite the increased security measures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary network segmentation and device classification during the initial connection phase. By identifying IoT devices through their WWAN characteristics before they can access the main network and pre-assigning them to isolated VLANs, the system proactively prevents security risks rather than reacting to threats after they materialize.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10999738B2Detection of internet-of-things devices in enterprise networks
Publication Date: 2021.05.04 CISCO TECHNOLOGY INC
  • US10999738B2 patent drawing
  • US10999738B2 patent drawing
  • US10999738B2 patent drawing

AI summary

Techniques for identification and isolation of Internet-of-Things devices in an enterprise network are described. In one embodiment, a method includes detecting a plurality of devices having a first network interface to connect to a wireless wide area network and a second network interface to connect to an enterprise network. The method also includes identifying a first subset of the plurality of devices as Internet-of-Things (IoT) devices based on at least a detected repetition rate on a physical random access channel of a transmission made by a device of the plurality of devices. The method includes assigning the IoT devices to a separate network segment within the enterprise network.