Network Security Device for Automatic IoT Device Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computer networks, vulnerable internet-connected devices can pose risks to other devices or the entire network, as they can be compromised by malicious actors to launch attacks or interfere with operations, especially in industrial settings where the consequences of such attacks can be severe.

Innovation Solution

Implementing a security device that categorizes devices into different categories based on their functions or effects, and applying rules to prohibit unauthorized communication between these categories, using a method that involves receiving requests, determining device categories, and dropping unauthorized packets or requests, with the aid of an AI categorizer and operator input to define permissions and update categorizations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If devices are allowed to communicate freely on the network, then network functionality and ease of operation are improved, but network security and reliability deteriorate due to vulnerable devices being compromised

Engineering Contradiction:
Improvenetwork communicationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network is segmented into multiple categories of devices (e.g., industrial control devices, IT devices, OT devices, administrative devices) with different security requirements and communication permissions. This segmentation allows vulnerable devices to be isolated from critical network components while maintaining functionality within their own category, resolving the contradiction between network openness and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security device acts as an intermediary between devices of different categories, mediating communication requests by evaluating security policies and allowing or blocking traffic based on the categories involved. This intermediary enforces communication rules without preventing necessary communication within categories, thus maintaining both security and operational functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If vulnerable devices are isolated from critical network components, then network security is improved, but network functionality may be restricted

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork communication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Different communication permissions are assigned to different device categories based on their specific security requirements and functional needs. Critical network components have restricted access to vulnerable device categories, while non-critical communications within categories remain unrestricted. This local quality approach maintains security by applying restrictions only where necessary while preserving functionality where safe.

Inventive Principle:
Principle #3Local quality

3Reliability

If device categorization and communication rules are implemented, then network security is improved, but device complexity and system configuration complexity increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Devices automatically determine their own category based on their type and characteristics, and the security device automatically evaluates communication requests against security policies without requiring manual configuration for each device. This self-service approach reduces the complexity burden on network administrators while maintaining comprehensive security categorization and rule enforcement.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240073217A1Systems and methods for automatic isolation of electronic devices
Publication Date: 2024.02.29 CENTURYLINK INTELLECTUAL PROPERTY LLC
  • US20240073217A1 patent drawing
  • US20240073217A1 patent drawing
  • US20240073217A1 patent drawing

AI summary

Computer networks may include various devices including computing devices (such as laptop computers or tablets), file servers, and printers. Also connected to such networks may be other internet-capable devices such as Internet of Things devices and Industrial Internet of Things devices. As such, systems and methods for automatic isolation of electronic devices are provided based on categorization of such devices.