Micronet Segmentation for Quarantining Vulnerable Home Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems struggle to effectively isolate and manage devices that are no longer supported by security patches or are infected with malware, leading to potential network infections and compromised security.

Innovation Solution

Dynamic Software Defined Networking (DSDN) is used to quarantine or limit network traffic of vulnerable devices, create VPN tunnels for secure connections, and dynamically segment networks into micronets based on trust levels, ensuring secure communication and isolation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are isolated or traffic is limited to protect the network, then network security is improved, but device functionality and user experience deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network is segmented into multiple micronets (e.g., first micronet, second micronet, third micronet, fourth micronet) with different trust levels. Infected devices are placed in isolated micronets while trusted devices access resources through less restricted micronets, allowing selective isolation that preserves functionality for legitimate devices while protecting the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different quality levels of service are provided to different devices based on their trust status. Trusted devices receive full service quality and access to all network resources, while untrusted or infected devices receive limited service quality and restricted access, creating local differentiation that balances security and functionality.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If network traffic is limited or devices are quarantined, then harmful factors are reduced, but productivity and network efficiency deteriorate

Engineering Contradiction:
Improvemalware infection spreadVSAvoidnetwork efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The network is divided into separate micronets that can be independently managed. Infected devices are confined to isolated micronets (third and fourth micronets in the example) that cannot propagate malware to other segments, while trusted devices continue operating in less restricted micronets, thus containing harmful factors without impacting overall network productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system converts the presence of infected devices into a benefit by using their isolation as a mechanism to demonstrate the effectiveness of the micronet segmentation approach, while simultaneously protecting the broader network from their harmful effects through controlled confinement to specific micronets.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Adaptability or versatility

If dynamic network segmentation is implemented, then adaptability and security are improved, but device complexity and system overhead increase

Engineering Contradiction:
Improvetrust level managementVSAvoidnetwork configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Devices automatically receive assigned micronet identifiers and configure their own network behavior based on their trust level. The network controller dynamically assigns micronets to devices based on their trust status, and devices autonomously adjust their communication parameters without requiring complex manual configuration, thus reducing operational complexity while maintaining adaptability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes network parameters such as allowed communication ranges, access permissions, and traffic routing based on device trust levels. Trusted devices operate with broader parameter ranges and higher permissions, while untrusted devices have restricted parameters, enabling flexible adaptation without requiring complex infrastructure changes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260025358A1Systems and methods for micro network segmentation
Publication Date: 2026.01.22 CABLE TELEVISION LAB INC
  • US20260025358A1 patent drawing
  • US20260025358A1 patent drawing
  • US20260025358A1 patent drawing

AI summary

A wireless communication system includes an external provider subsystem and an electronic network subsystem in operable communication with the external provider subsystem. The electronic network subsystem is configured to provide a first microservice and a second microservice different from the first microservice. The wireless communication system further includes an in-home subsystem (i) separate from the external provider subsystem, (ii) in operable communication with the electronic network subsystem, and (iii) including a first micronet and a second micronet different from the first micronet. The first micronet is configured to operably interact with the first microservice, and the second micronet is configured to operably interact with the second microservice. The wireless communication system further includes at least one electronic device configured to operably connect with one of the first micronet and the second micronet.