Micronet Segmentation for Quarantining Vulnerable Home Network Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems struggle to effectively isolate and manage devices that are no longer supported by security patches or are infected with malware, leading to potential network infections and compromised security.
Innovation Solution
Dynamic Software Defined Networking (DSDN) is used to quarantine or limit network traffic of vulnerable devices, create VPN tunnels for secure connections, and dynamically segment networks into micronets based on trust levels, ensuring secure communication and isolation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If devices are isolated or traffic is limited to protect the network, then network security is improved, but device functionality and user experience deteriorate
Solution Approach 1:
The network is segmented into multiple micronets (e.g., first micronet, second micronet, third micronet, fourth micronet) with different trust levels. Infected devices are placed in isolated micronets while trusted devices access resources through less restricted micronets, allowing selective isolation that preserves functionality for legitimate devices while protecting the network.
Solution Approach 2:
Different quality levels of service are provided to different devices based on their trust status. Trusted devices receive full service quality and access to all network resources, while untrusted or infected devices receive limited service quality and restricted access, creating local differentiation that balances security and functionality.
2Object-affected harmful factors
If network traffic is limited or devices are quarantined, then harmful factors are reduced, but productivity and network efficiency deteriorate
Solution Approach 1:
The network is divided into separate micronets that can be independently managed. Infected devices are confined to isolated micronets (third and fourth micronets in the example) that cannot propagate malware to other segments, while trusted devices continue operating in less restricted micronets, thus containing harmful factors without impacting overall network productivity.
Solution Approach 2:
The system converts the presence of infected devices into a benefit by using their isolation as a mechanism to demonstrate the effectiveness of the micronet segmentation approach, while simultaneously protecting the broader network from their harmful effects through controlled confinement to specific micronets.
3Adaptability or versatility
If dynamic network segmentation is implemented, then adaptability and security are improved, but device complexity and system overhead increase
Solution Approach 1:
Devices automatically receive assigned micronet identifiers and configure their own network behavior based on their trust level. The network controller dynamically assigns micronets to devices based on their trust status, and devices autonomously adjust their communication parameters without requiring complex manual configuration, thus reducing operational complexity while maintaining adaptability.
Solution Approach 2:
The system dynamically changes network parameters such as allowed communication ranges, access permissions, and traffic routing based on device trust levels. Trusted devices operate with broader parameter ranges and higher permissions, while untrusted devices have restricted parameters, enabling flexible adaptation without requiring complex infrastructure changes.
Data Source
AI summary
A wireless communication system includes an external provider subsystem and an electronic network subsystem in operable communication with the external provider subsystem. The electronic network subsystem is configured to provide a first microservice and a second microservice different from the first microservice. The wireless communication system further includes an in-home subsystem (i) separate from the external provider subsystem, (ii) in operable communication with the electronic network subsystem, and (iii) including a first micronet and a second micronet different from the first micronet. The first micronet is configured to operably interact with the first microservice, and the second micronet is configured to operably interact with the second microservice. The wireless communication system further includes at least one electronic device configured to operably connect with one of the first micronet and the second micronet.


