Automated Network Policy Assignment via Device Type Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The scalability of deploying devices in networking systems is hindered by the need for individualized attention in configuring network policies for each device, user, and connection, making it difficult to ensure appropriate access to resources while preventing inappropriate access.

Innovation Solution

Automating the creation and assignment of network policies based on device and user attributes, such as roles and groups, using a system that identifies device types and applies corresponding policies, including authentication processes to determine authorization status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individualized network policy configuration is performed for each device, then security and access control are improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal network policy template that can be applied to multiple devices of the same type. Instead of configuring individual policies for each device, a single policy template serves multiple devices, reducing configuration complexity while maintaining security. The template includes device type identification, policy parameters, and authorization rules that can be universally applied.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments network policies into device-type-specific templates. By categorizing devices into types (e.g., IoT devices, smartphones, laptops) and creating separate policy templates for each type, the system simplifies configuration while ensuring appropriate security controls for each device category.

Inventive Principle:
Principle #1Segmentation

2Manufacturing precision

If manual network policy configuration is performed for each device and user, then access control precision is improved, but productivity and scalability deteriorate

Engineering Contradiction:
Improveaccess control precisionVSAvoiddeployment speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent performs preliminary actions by pre-configuring network policy templates with all necessary security parameters and authorization rules before devices connect to the network. When a device connects, the system automatically matches it to the appropriate pre-configured template, eliminating manual configuration time and maintaining precise access control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by automatically identifying device types and applying appropriate policy templates without human intervention. The network infrastructure itself performs the configuration task, matching devices to policies based on device type identification, which maintains precision while dramatically improving deployment speed.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive authentication processes are implemented for all devices, then network security is improved, but system complexity and processing time increase

Engineering Contradiction:
Improveauthorization securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing different authentication requirements for different device types. Instead of uniform comprehensive authentication for all devices, the system tailors authentication processes to specific device types and their security requirements, reducing unnecessary complexity while maintaining security where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12047421B2Methods, systems, and devices for assigning policies in networking systems
Publication Date: 2024.07.23 RUCKUS IP HOLDINGS LLC
  • US12047421B2 patent drawing
  • US12047421B2 patent drawing
  • US12047421B2 patent drawing

AI summary

The continued usage of manual & static configurations as the number of network-connected devices has increased has resulted in administrative difficulties for operators and/or administrators of computer networks. To provide more automated configurations, methods, systems, and electronic devices are described that include identifying, based on received network traffic from an end electronic device, a device type of the end electronic device; and applying a network policy to subsequent network traffic between the end electronic device and network equipment (such as a switch) based on the identified device type of the end electronic device.