Cloud-Based Traffic Isolation for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of IoT devices in DDoS attacks poses a significant threat, as they can generate massive traffic directly to targets, overwhelming networks and compromising security, especially since many IoT devices lack proper security measures and are easily compromised due to vulnerabilities such as shared secrets and default passwords.

Innovation Solution

A cloud-based service forms a virtual network overlay in a local area network to redirect and manage traffic from IoT devices, profiling the nodes to determine authorized destinations and isolating them from unauthorized sites, using machine learning to analyze traffic patterns and create secure 'bubbles' that only allow communication with trusted services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are allowed direct network access for communication, then network functionality and connectivity are improved, but security risk and vulnerability to DDoS attacks increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud-based service as an intermediary between IoT devices and the network. This service acts as a mediator that receives traffic from IoT devices, profiles them, and routes traffic only to authorized destinations. The intermediary prevents direct access while maintaining necessary connectivity, thus resolving the contradiction between network functionality and security risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into isolated virtual networks for different IoT devices. Each device operates in its own segmented environment with controlled access to specific destinations. This segmentation prevents a compromised device from affecting the entire network, addressing the security risk while preserving individual device connectivity needs.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traffic from IoT devices is monitored and profiled to identify authorized destinations, then security control is improved, but network complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service through automated traffic profiling and destination identification. The cloud-based service automatically analyzes traffic patterns, profiles IoT devices, and determines authorized destinations without manual intervention. This automation maintains high security control while minimizing the operational complexity burden on network administrators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The cloud-based service serves as an intermediary that centralizes the complex profiling and routing logic. By moving this complexity to an external service rather than embedding it in network infrastructure or devices, the system achieves strong security control while keeping the local network relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a virtual network overlay is implemented to redirect and manage IoT traffic, then traffic control and security are improved, but network infrastructure complexity increases

Engineering Contradiction:
Improvetraffic controlVSAvoidinfrastructure complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The virtual network overlay is implemented as a service layer rather than requiring changes to physical network infrastructure. The cloud-based service acts as an intermediary that creates virtual networking functionality through software, simplifying traffic control while avoiding the need to redesign physical network components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a virtualization dimension to the network by implementing a virtual network overlay. This allows traffic control and security management in a software layer above the physical infrastructure, enabling sophisticated traffic management without increasing physical infrastructure complexity. The virtual overlay provides an additional dimension for controlling traffic flow.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10693671B2Distributing traffic to multiple destinations via an isolation network
Publication Date: 2020.06.23 CISCO TECHNOLOGY INC
  • US10693671B2 patent drawing
  • US10693671B2 patent drawing
  • US10693671B2 patent drawing

AI summary

In one embodiment, a cloud-based service instructs one or more networking devices in a local area network (LAN) to form a virtual network overlay in the LAN that redirects traffic associated with a particular node in the LAN to the service. The service receives multicast or broadcast traffic sent by the particular node in the LAN and redirected to the service via the virtual network overlay. The service identifies a group of nodes in the network that are to receive the traffic sent by the particular node, based in part by profiling the traffic associated with the particular node. The service sends the traffic sent by the particular node to at least one networking device in the LAN with an indication of the identified group of nodes in the network that are to receive the traffic sent by the particular node. The at least one networking device forwards the traffic sent by the particular node to the nodes in the identified group.