Network Device Usage Profile Management for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rapid rise of IoT devices with limited security capabilities poses a risk of malicious attacks, as they often lack authorization, authentication, and encryption, making them vulnerable to exploitation, and there is a need to determine appropriate access and network capabilities for these devices to ensure they follow their intended manufacturer-driven use.

Innovation Solution

The solution involves network devices retrieving usage profiles from IoT devices through indirect references like URIs, which include predetermined usage descriptions set by the manufacturer, to configure and enforce networking policies, ensuring only intended access and communication paths are allowed, and auditing operations to verify compliance with manufacturer-intended use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If IoT devices are deployed with minimal security capabilities to reduce device complexity and cost, then device complexity is reduced, but security vulnerability increases

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network device as an intermediary that enforces usage descriptions and policies for IoT devices. The network device retrieves usage profiles, interprets manufacturer-intended usage, and controls network access accordingly, thereby providing security protection without adding complexity to the IoT devices themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by pre-configuring usage descriptions and policies in the network device before IoT devices connect. The network device proactively retrieves and stores manufacturer-defined usage profiles, enabling immediate enforcement of security policies without requiring security capabilities on the IoT devices.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If network devices enforce strict usage policies to improve security, then security is improved, but network accessibility decreases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork accessibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making network access policies flexible and adaptive based on device type and usage context. The network device dynamically retrieves and applies appropriate usage descriptions from manufacturer profiles, allowing different levels of access control for different IoT devices while maintaining overall security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements local quality by applying specific usage policies tailored to each device type or manufacturer. Rather than uniform restrictions, the network device retrieves manufacturer-specific usage profiles that define appropriate access rights for each device category, allowing necessary communications while blocking unauthorized access.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If manufacturer-driven usage descriptions are enforced to prevent malicious use, then security is improved, but device autonomy decreases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice autonomy
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies segmentation by separating security policy enforcement from device operation. The network device handles policy interpretation and access control based on manufacturer usage descriptions, while IoT devices continue to operate autonomously within their defined usage boundaries without needing built-in security decision-making capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10547503B2Network connected device usage profile management
Publication Date: 2020.01.28 CISCO TECHNOLOGY INC
  • US10547503B2 patent drawing
  • US10547503B2 patent drawing
  • US10547503B2 patent drawing

AI summary

Presented herein are techniques in which one or more network devices can use information provided by a special purpose network connected device to retrieve a usage profile (i.e., configuration file) associated with the special purpose network connected device. The retrieved usage profile, which includes/describes preselected (predetermined) usage descriptions associated with the special purpose network connected device, can then be used to configure one or more network devices. For example, the predetermined usage descriptions associated with the special purpose network connected device can be instantiated and enforced at a network device or the predetermined usage descriptions can be used for auditing the special purpose network connected device (e.g., monitoring of traffic within the network).