MUD Controller Dynamic Policy Delegation for IoT Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control systems struggle to efficiently manage temporary communication sessions between network devices and external devices, particularly for devices with unique operational requirements, as they rely on static policies that restrict access without accommodating dynamic needs.

Innovation Solution

Implementing a process that utilizes manufacturer usage descriptions (MUDs) to identify delegated controllers, which generate dynamic policies for network devices, allowing temporary access rules to be established and managed through a MUD controller and access control devices, enabling secure and flexible communication sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static policies are used to control network access, then network security is maintained, but flexibility and adaptability to dynamic communication needs are reduced

Engineering Contradiction:
Improvenetwork securityVSAvoidflexibility for dynamic communication
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic policy generation where access control rules are automatically created and updated based on real-time communication sessions. The system transitions from static predetermined policies to dynamic policies that adapt to actual device communication needs, allowing network access rules to change automatically during device operation without manual intervention

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a controller as an intermediary component between network devices and access control mechanisms. This controller receives manufacturer usage descriptions, generates dynamic policies, and coordinates with access control devices to enforce them. The intermediary manages the complexity of dynamic policy generation while maintaining security, bridging the gap between static security requirements and dynamic communication needs

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If manufacturer usage descriptions are used to generate dynamic policies, then adaptability to device-specific requirements is improved, but system complexity increases

Engineering Contradiction:
Improvedevice-specific policy adaptationVSAvoidpolicy management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent enables devices to self-configure network access by incorporating manufacturer usage descriptions directly into the device. The device automatically provides its MUD file to the controller, which then automatically generates and enforces appropriate policies without requiring manual configuration. This self-service approach reduces operational complexity while maintaining high adaptability to device-specific requirements

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameter of policy representation from static rule sets to dynamic parameters derived from manufacturer usage descriptions. By using MUD files that contain device-specific operational characteristics, the system automatically adjusts policy parameters based on actual device needs rather than relying on complex manual policy configurations

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10595320B2Delegating policy through manufacturer usage descriptions
Publication Date: 2020.03.17 CISCO TECHNOLOGY INC
  • US10595320B2 patent drawing
  • US10595320B2 patent drawing
  • US10595320B2 patent drawing

AI summary

A process for implementing temporary rules for network devices is described. In one embodiment, the process includes a controller receiving a manufacturer usage description (MUD) identifier from a first device. The controller retrieves a MUD file associated with the MUD identifier. The controller registers a device identifier associated with the first device with a delegated controller determined based on the MUD file. The delegated controller is configured to generate a dynamic policy for the first device. The controller receives a dynamic policy from the delegated controller for the first device. The dynamic policy may be configured to permit a communication session between the first device and a second device. The controller forwards the dynamic policy to an access control device in communication with the first device to enable the access control device to permit the communication session between the first device and the second device.