Network Device Virtual Network Segmentation for IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of connected computing devices in networks, particularly IoT devices, poses security challenges due to open access policies, making it difficult to secure networks and prevent the spread of viruses and malware, as well as unauthorized access and data breaches.
Innovation Solution
Implementing virtual networks where each computing device is isolated by default, with access granted only through explicit rules, using network devices like switches or routers to manage and enforce permissions, and a device management system to categorize and manage devices and their permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If open access policies are used in networks, then ease of operation is improved, but network security deteriorates
Solution Approach 1:
The network is segmented into multiple virtual networks (VLANs) that isolate different computing devices from each other. Each virtual network creates separate broadcast domains and security zones, allowing devices to be grouped by function or security requirements while preventing unauthorized cross-access. This resolves the contradiction by maintaining operational ease through virtualization while improving security through isolation.
Solution Approach 2:
A network device (switch or router) acts as an intermediary that enforces access control policies between computing devices. The intermediary monitors and controls traffic flow, applying security rules to permit or deny communications. This resolves the contradiction by providing automated security mediation without requiring manual configuration at each device, thus maintaining ease of operation while enhancing security.
2Reliability
If virtual networks are implemented to isolate devices, then network security is improved, but device complexity increases
Solution Approach 1:
The network device (switch or router) is designed to perform multiple functions including basic networking, virtual network creation, security policy enforcement, and device categorization. By consolidating these functions into a single multi-functional device, the system achieves improved security without proportionally increasing overall device complexity, as the same hardware platform handles multiple tasks.
Solution Approach 2:
The system implements automated device categorization and policy assignment where the network device automatically detects new devices, categorizes them based on predefined criteria, and assigns appropriate security policies without manual intervention. This self-service capability reduces the operational complexity that would otherwise arise from manual virtual network configuration, resolving the contradiction between security and complexity.
Data Source
AI summary
In one embodiment, a method is provided. The method includes receiving a registration message from a network device. The registration request indicates that a first computing device has connected to the computing devices. The method also includes determining a category for the first computing device based on the registration message. The method further includes determining a set of rules for the computing device based on the category. The method further includes transmitting the set of rules to the network device. The set of rules indicates permissions for the first computing device. Each network of the set of networks is initially isolated from other networks of the set of networks when the network is created. Each network of the set of networks comprises a respective computing device of the set of computing devices.


