Network Device Virtual Network Segmentation for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of connected computing devices in networks, particularly IoT devices, poses security challenges due to open access policies, making it difficult to secure networks and prevent the spread of viruses and malware, as well as unauthorized access and data breaches.

Innovation Solution

Implementing virtual networks where each computing device is isolated by default, with access granted only through explicit rules, using network devices like switches or routers to manage and enforce permissions, and a device management system to categorize and manage devices and their permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If open access policies are used in networks, then ease of operation is improved, but network security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network is segmented into multiple virtual networks (VLANs) that isolate different computing devices from each other. Each virtual network creates separate broadcast domains and security zones, allowing devices to be grouped by function or security requirements while preventing unauthorized cross-access. This resolves the contradiction by maintaining operational ease through virtualization while improving security through isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A network device (switch or router) acts as an intermediary that enforces access control policies between computing devices. The intermediary monitors and controls traffic flow, applying security rules to permit or deny communications. This resolves the contradiction by providing automated security mediation without requiring manual configuration at each device, thus maintaining ease of operation while enhancing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If virtual networks are implemented to isolate devices, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network device (switch or router) is designed to perform multiple functions including basic networking, virtual network creation, security policy enforcement, and device categorization. By consolidating these functions into a single multi-functional device, the system achieves improved security without proportionally increasing overall device complexity, as the same hardware platform handles multiple tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements automated device categorization and policy assignment where the network device automatically detects new devices, categorizes them based on predefined criteria, and assigns appropriate security policies without manual intervention. This self-service capability reduces the operational complexity that would otherwise arise from manual virtual network configuration, resolving the contradiction between security and complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12074873B2Managing permissions for computing devices in computer networks
Publication Date: 2024.08.27 YIKES SECURE INC
  • US12074873B2 patent drawing
  • US12074873B2 patent drawing
  • US12074873B2 patent drawing

AI summary

In one embodiment, a method is provided. The method includes receiving a registration message from a network device. The registration request indicates that a first computing device has connected to the computing devices. The method also includes determining a category for the first computing device based on the registration message. The method further includes determining a set of rules for the computing device based on the category. The method further includes transmitting the set of rules to the network device. The set of rules indicates permissions for the first computing device. Each network of the set of networks is initially isolated from other networks of the set of networks when the network is created. Each network of the set of networks comprises a respective computing device of the set of computing devices.