Network Segmentation for IoT Security Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of network-capable devices has heightened the risks of network security breaches, as 'smart' devices like IoT devices can be vulnerable to malicious attacks and access secure information from other network devices, necessitating improved network security measures that account for varied operations.
Innovation Solution
The implementation of network segmentation, where new computing devices are initially assigned to a provisioning network to determine their properties, and then assigned to either a trusted or IoT network segment based on their characteristics, providing different access privileges to restrict or allow interactions with other devices and external networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network segmentation is implemented to separate IoT devices from trusted devices, then network security is improved, but device complexity increases
Solution Approach 1:
The patent applies network segmentation by dividing the network into multiple segments including a provisioning network and at least two operational network segments (trusted devices segment and IoT devices segment). This segmentation isolates potentially vulnerable IoT devices from trusted devices, limiting the spread of malicious attacks while maintaining network security. The provisioning network further segments new devices during the evaluation phase, preventing them from directly accessing operational segments before security assessment.
Solution Approach 2:
The provisioning network serves as an intermediary segment between new devices and operational network segments. New devices must pass through the provisioning network where their security properties are evaluated before being assigned to appropriate operational segments. This intermediary structure enables security verification without requiring direct modification of operational network segments, resolving the contradiction by adding a mediating layer rather than fundamentally restructuring the entire network.
2Reliability
If new devices are assigned to provisioning network for property evaluation, then security assessment is improved, but access time increases
Solution Approach 1:
The provisioning network enables preliminary security assessment of new devices before they gain access to operational network segments. By evaluating device properties, security credentials, and threat indicators in advance during the provisioning phase, the system ensures that only authenticated and authorized devices are assigned to operational segments. This preliminary action prevents security breaches while maintaining efficient access once devices are properly authorized.
Solution Approach 2:
The network access system dynamically adjusts device access based on security evaluation results. Devices transition from the static provisioning network to appropriate operational network segments based on their security credentials and property assessment. This dynamic assignment optimizes access time by allowing devices that pass security checks to immediately join operational segments without prolonged delays, while maintaining strict security control.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for receiving, by a network device, a request from a computing device to join a network, where the network is segmented to include a provisioning network, a first network segment, and a second network segment, and the second network segment provides limited network access privileges to computing devices compared to network access privileges provided by the first network segment. Providing the computing device access to the provisioning network. Determining, while the computing device is connected to the provisioning network, properties of the computing device. Selecting which of the first network segment and the second network segment to assign access to the computing device based on the properties of the computing device. Providing security credentials to the computing device for accessing the selected one of the first network segment or the second network segment.


