Network Segmentation for IoT Security Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of network-capable devices has heightened the risks of network security breaches, as 'smart' devices like IoT devices can be vulnerable to malicious attacks and access secure information from other network devices, necessitating improved network security measures that account for varied operations.

Innovation Solution

The implementation of network segmentation, where new computing devices are initially assigned to a provisioning network to determine their properties, and then assigned to either a trusted or IoT network segment based on their characteristics, providing different access privileges to restrict or allow interactions with other devices and external networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network segmentation is implemented to separate IoT devices from trusted devices, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies network segmentation by dividing the network into multiple segments including a provisioning network and at least two operational network segments (trusted devices segment and IoT devices segment). This segmentation isolates potentially vulnerable IoT devices from trusted devices, limiting the spread of malicious attacks while maintaining network security. The provisioning network further segments new devices during the evaluation phase, preventing them from directly accessing operational segments before security assessment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The provisioning network serves as an intermediary segment between new devices and operational network segments. New devices must pass through the provisioning network where their security properties are evaluated before being assigned to appropriate operational segments. This intermediary structure enables security verification without requiring direct modification of operational network segments, resolving the contradiction by adding a mediating layer rather than fundamentally restructuring the entire network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If new devices are assigned to provisioning network for property evaluation, then security assessment is improved, but access time increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoiddevice access time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The provisioning network enables preliminary security assessment of new devices before they gain access to operational network segments. By evaluating device properties, security credentials, and threat indicators in advance during the provisioning phase, the system ensures that only authenticated and authorized devices are assigned to operational segments. This preliminary action prevents security breaches while maintaining efficient access once devices are properly authorized.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network access system dynamically adjusts device access based on security evaluation results. Devices transition from the static provisioning network to appropriate operational network segments based on their security credentials and property assessment. This dynamic assignment optimizes access time by allowing devices that pass security checks to immediately join operational segments without prolonged delays, while maintaining strict security control.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11165778B1Segmentation based network security
Publication Date: 2021.11.02 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US11165778B1 patent drawing
  • US11165778B1 patent drawing
  • US11165778B1 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for receiving, by a network device, a request from a computing device to join a network, where the network is segmented to include a provisioning network, a first network segment, and a second network segment, and the second network segment provides limited network access privileges to computing devices compared to network access privileges provided by the first network segment. Providing the computing device access to the provisioning network. Determining, while the computing device is connected to the provisioning network, properties of the computing device. Selecting which of the first network segment and the second network segment to assign access to the computing device based on the properties of the computing device. Providing security credentials to the computing device for accessing the selected one of the first network segment or the second network segment.