MUD Controller IoT SASE Security Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions struggle to efficiently integrate Internet-of-Things (IoT) devices with Secure Access Service Edge (SASE) frameworks, particularly in managing security policies and leveraging SASE capabilities effectively.

Innovation Solution

The method involves a MUD controller associated with a SASE service receiving a MUD file from an IoT device's manufacturer server, parsing it to determine security recommendations, and generating a SASE security profile. This profile is then used to configure SASE services, enabling IoT devices to connect securely to a gateway device associated with the SASE service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual integration methods are used for IoT devices with SASE frameworks, then security policy management can be performed, but the integration process becomes complex and time-consuming

Engineering Contradiction:
Improveintegration processVSAvoidintegration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The MUD file is generated and configured in advance by the device manufacturer, containing pre-defined security policies and service requirements. This preliminary configuration eliminates the need for manual security policy creation during integration, allowing IoT devices to be automatically onboarded to SASE frameworks by simply providing the MUD file identifier.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service integration where the MUD controller automatically retrieves the MUD file, parses security requirements, and configures SASE service profiles without human intervention. The IoT device itself can provide its MUD file identifier, triggering automatic integration processes that configure security policies and service routing autonomously.

Inventive Principle:
Principle #25Self-service

2Reliability

If customized security profiles are created for each IoT device, then security requirements are met, but the complexity of managing security policies increases

Engineering Contradiction:
Improvesecurity configurationVSAvoidsecurity policy management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security policy management is segmented into device-specific MUD files that contain individual security requirements. Each IoT device has its own MUD file with tailored security policies, while the MUD controller manages these segmented policies centrally. This segmentation allows customized security profiles without overwhelming complexity, as each device's requirements are isolated in its own MUD file.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The MUD file format serves as a universal standard that can represent security requirements for diverse IoT devices from different manufacturers. This multi-functional approach allows a single standardized mechanism to handle various security scenarios, eliminating the need for multiple custom policy management systems and reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional network access methods are used for IoT devices, then device connectivity is achieved, but security services cannot be effectively leveraged

Engineering Contradiction:
Improvesecurity service integrationVSAvoidservice configuration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The MUD controller continuously monitors and enforces security policies defined in MUD files, providing feedback to the SASE framework about device compliance and service requirements. This feedback mechanism ensures that security services are effectively leveraged by automatically routing device traffic through appropriate security functions and adjusting configurations based on real-time policy requirements.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables dynamic security configuration where SASE service profiles are automatically adjusted based on MUD file contents. Security policies, service routing, and access permissions are not static but dynamically configured according to each device's specific requirements, allowing the system to adapt to changing security needs while maintaining reliable service integration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12206646B2Manufacturer usage description (MUD) extensions for secure access service edge (SASE) services
Publication Date: 2025.01.21 CISCO TECHNOLOGY INC
  • US12206646B2 patent drawing
  • US12206646B2 patent drawing
  • US12206646B2 patent drawing

AI summary

Techniques for associating manufacturer usage description (MUD) security profiles for Internet-of-Things (IoT) device(s) with secure access service edge (SASE) solutions, providing for automated and scalable integration of IoT devices with SASE frameworks. A MUD controller may utilize a MUD uniform resource identifier (URI) emitted by an IoT device to fetch an associated MUD file from a MUD file server associated with a manufacturer of the IoT device. The MUD controller may determine that a security recommendation included in the MUD file is to be implemented by a cloud-based security service provided by the SASE service and cause the IoT device to establish a connection with a secure internet gateway associated with the cloud-based security service. Additionally, or alternatively, the MUD file may include SASE extensions indicating manufacturer recommended cloud-based security services. Further, cloud-based security services may be implemented if local services are unavailable.