Network Device Usage Profile Management for IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The rapid rise of IoT devices with limited security capabilities poses a risk of malicious attacks, as they often lack authorization, authentication, and encryption, making them vulnerable to exploitation, and there is a need to determine appropriate access and network capabilities for these devices to ensure they follow their intended manufacturer-driven use.
Innovation Solution
The solution involves network devices retrieving usage profiles from IoT devices through indirect references like URIs, which include predetermined usage descriptions set by the manufacturer, to configure and enforce networking policies, ensuring only intended access and communication paths are allowed, and auditing operations to verify compliance with manufacturer-intended use.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If IoT devices are deployed with minimal security capabilities to reduce device complexity and cost, then device complexity is reduced, but security vulnerability increases
Solution Approach 1:
The patent introduces a network device as an intermediary that enforces usage descriptions and policies for IoT devices. The network device retrieves usage profiles, interprets manufacturer-intended usage, and controls network access accordingly, thereby providing security protection without adding complexity to the IoT devices themselves.
Solution Approach 2:
The patent implements preliminary action by pre-configuring usage descriptions and policies in the network device before IoT devices connect. The network device proactively retrieves and stores manufacturer-defined usage profiles, enabling immediate enforcement of security policies without requiring security capabilities on the IoT devices.
2Object-affected harmful factors
If network devices enforce strict usage policies to improve security, then security is improved, but network accessibility decreases
Solution Approach 1:
The patent applies dynamics by making network access policies flexible and adaptive based on device type and usage context. The network device dynamically retrieves and applies appropriate usage descriptions from manufacturer profiles, allowing different levels of access control for different IoT devices while maintaining overall security.
Solution Approach 2:
The patent implements local quality by applying specific usage policies tailored to each device type or manufacturer. Rather than uniform restrictions, the network device retrieves manufacturer-specific usage profiles that define appropriate access rights for each device category, allowing necessary communications while blocking unauthorized access.
3Object-affected harmful factors
If manufacturer-driven usage descriptions are enforced to prevent malicious use, then security is improved, but device autonomy decreases
Solution Approach 1:
The patent applies segmentation by separating security policy enforcement from device operation. The network device handles policy interpretation and access control based on manufacturer usage descriptions, while IoT devices continue to operate autonomously within their defined usage boundaries without needing built-in security decision-making capabilities.
Data Source
AI summary
Presented herein are techniques in which one or more network devices can use information provided by a special purpose network connected device to retrieve a usage profile (i.e., configuration file) associated with the special purpose network connected device. The retrieved usage profile, which includes/describes preselected (predetermined) usage descriptions associated with the special purpose network connected device, can then be used to configure one or more network devices. For example, the predetermined usage descriptions associated with the special purpose network connected device can be instantiated and enforced at a network device or the predetermined usage descriptions can be used for auditing the special purpose network connected device (e.g., monitoring of traffic within the network).


