Contextual IoT Security Lexicon for OT Policy Translation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Low-Power and Lossy Networks (LLNs), such as IoT networks, face challenges in network security configuration due to the lack of expertise among Operations Technology (OT) personnel, who manage devices primarily for non-network operations, and existing solutions require knowledge of networking and security policies.
Innovation Solution
A method and apparatus that allow OT personnel to manage network security by loading a selectable security lexicon, interpreting security commands, and generating network security policies for nodes in the network, enabling secure access control without requiring knowledge of underlying networking or security policies, using a contextually aware architecture that translates OT policies into IT policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional network security configuration methods are used by IT professionals, then network security policies can be properly configured, but OT personnel managing IoT devices cannot configure security mechanisms due to lack of expertise
Solution Approach 1:
The patent introduces a network translator as an intermediary component that receives security policy configurations from OT personnel in operational technology terms and automatically translates them into corresponding IT network security policies. This mediator bridges the knowledge gap between OT and IT domains, allowing OT personnel to configure security without needing networking expertise while maintaining proper security policy generation.
2Ease of operation
If OT personnel are empowered to configure security policies directly, then ease of operation improves, but configuration accuracy deteriorates due to lack of networking knowledge
Solution Approach 1:
The network translator acts as an intelligent intermediary that preserves configuration accuracy by automatically converting OT personnel's high-level security intent into precise, technically correct network security policies. The translator ensures that the semantic meaning of OT policies is accurately mapped to corresponding IT policy parameters, maintaining configuration precision without requiring OT personnel to understand complex networking protocols and syntax.
3Ease of operation
If a unified security configuration system is implemented for both IT and OT personnel, then ease of operation improves, but the system complexity increases
Solution Approach 1:
The patent segments the security configuration system into distinct functional components: an OT policy configuration interface for OT personnel, a network translator for policy conversion, and an IT policy enforcement interface for network devices. This segmentation allows each component to be optimized independently, with the translator handling the complexity of policy mapping while presenting simple interfaces to both OT and IT users, thereby managing overall system complexity through modular design.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In one embodiment, a device in a network loads a selectable security lexicon. The device receives a security command that uses the loaded lexicon. The device interprets the security command using the loaded lexicon. The device generates a network security policy for one or more network nodes in the network based on the interpreted security command. The device causes the one or more network nodes to implement the generated network security policy.