MUD Controller Dynamic Policy Delegation for IoT Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network access control systems struggle to efficiently manage temporary communication sessions between network devices and external devices, particularly for devices with unique operational requirements, as they rely on static policies that restrict access without accommodating dynamic needs.
Innovation Solution
Implementing a process that utilizes manufacturer usage descriptions (MUDs) to identify delegated controllers, which generate dynamic policies for network devices, allowing temporary access rules to be established and managed through a MUD controller and access control devices, enabling secure and flexible communication sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static policies are used to control network access, then network security is maintained, but flexibility and adaptability to dynamic communication needs are reduced
Solution Approach 1:
The patent implements dynamic policy generation where access control rules are automatically created and updated based on real-time communication sessions. The system transitions from static predetermined policies to dynamic policies that adapt to actual device communication needs, allowing network access rules to change automatically during device operation without manual intervention
Solution Approach 2:
The patent introduces a controller as an intermediary component between network devices and access control mechanisms. This controller receives manufacturer usage descriptions, generates dynamic policies, and coordinates with access control devices to enforce them. The intermediary manages the complexity of dynamic policy generation while maintaining security, bridging the gap between static security requirements and dynamic communication needs
2Adaptability or versatility
If manufacturer usage descriptions are used to generate dynamic policies, then adaptability to device-specific requirements is improved, but system complexity increases
Solution Approach 1:
The patent enables devices to self-configure network access by incorporating manufacturer usage descriptions directly into the device. The device automatically provides its MUD file to the controller, which then automatically generates and enforces appropriate policies without requiring manual configuration. This self-service approach reduces operational complexity while maintaining high adaptability to device-specific requirements
Solution Approach 2:
The patent changes the parameter of policy representation from static rule sets to dynamic parameters derived from manufacturer usage descriptions. By using MUD files that contain device-specific operational characteristics, the system automatically adjusts policy parameters based on actual device needs rather than relying on complex manual policy configurations
Data Source
AI summary
A process for implementing temporary rules for network devices is described. In one embodiment, the process includes a controller receiving a manufacturer usage description (MUD) identifier from a first device. The controller retrieves a MUD file associated with the MUD identifier. The controller registers a device identifier associated with the first device with a delegated controller determined based on the MUD file. The delegated controller is configured to generate a dynamic policy for the first device. The controller receives a dynamic policy from the delegated controller for the first device. The dynamic policy may be configured to permit a communication session between the first device and a second device. The controller forwards the dynamic policy to an access control device in communication with the first device to enable the access control device to permit the communication session between the first device and the second device.


