Dynamic Micro Network Segmentation Using DSDN for Device Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems fail to effectively isolate and manage devices that are no longer supported by security patches or are infected with malware, posing a risk to the network and compromising the security of other devices.

Innovation Solution

Dynamic Software Defined Networking (DSDN) is used to create microservices and micronets that isolate infected or vulnerable devices, limiting their network traffic to approved destinations and creating VPN tunnels for enhanced security, while allowing trusted devices to maintain connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are isolated or quarantined to protect network security, then network security is improved, but device connectivity and functionality are reduced

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice connectivity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network is segmented into multiple virtual networks or subnets, allowing infected devices to be isolated in specific segments while other segments remain fully functional. This enables selective isolation of vulnerable devices without disrupting overall network connectivity for trusted devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A network controller or gateway acts as an intermediary that manages traffic flow between isolated devices and the rest of the network. This mediator enables controlled connectivity for devices that need limited access while maintaining security isolation, allowing critical functions to continue operating.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If network traffic is limited for vulnerable devices, then security risk is reduced, but device functionality and access to services are restricted

Engineering Contradiction:
Improvesecurity riskVSAvoiddevice functionality
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

Different quality of service policies are applied to different devices based on their security status and criticality. Critical devices receive enhanced protection and monitoring, while less critical devices receive standard isolation. This localized approach ensures that security measures are tailored to specific device needs rather than applying uniform restrictions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The network isolation policy is dynamically adjusted based on device security status, traffic patterns, and threat levels. Devices can be moved between isolation levels as their security posture changes, allowing functionality to be restored when devices are cleaned or updated while maintaining protection when threats are detected.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If microservices are created to manage different device types, then network management flexibility is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork management flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A set of standardized microservices provides universal functionality for managing diverse device types. These microservices handle common tasks such as authentication, traffic routing, and security policy enforcement across all device categories, reducing the need for device-specific management logic while maintaining flexibility through configurable parameters.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12407672B1Systems and method for micro network segmentation
Publication Date: 2025.09.02 CABLE TELEVISION LAB INC
  • US12407672B1 patent drawing
  • US12407672B1 patent drawing
  • US12407672B1 patent drawing

AI summary

A wireless communication system includes an external provider subsystem and an electronic network subsystem in operable communication with the external provider subsystem. The electronic network subsystem is configured to provide a first microservice and a second microservice different from the first microservice. The wireless communication system further includes an in-home subsystem (i) separate from the external provider subsystem, (ii) in operable communication with the electronic network subsystem, and (iii) including a first micronet and a second micronet different from the first micronet. The first micronet is configured to operably interact with the first microservice, and the second micronet is configured to operably interact with the second microservice. The wireless communication system further includes at least one electronic device configured to operably connect with one of the first micronet and the second micronet.