Network Segmentation for Secure Remote Work

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Working from home compromises network security due to weak home network configurations, malware infections, and vulnerabilities in IoT devices, which existing VPN solutions cannot adequately address, leading to increased cyber risks for businesses.

Innovation Solution

A computing device that provides advanced firewall protection, AI-enabled risk monitoring, and VPN tunneling capabilities to create a secure network segment, segregating work activities from unsecure home networks, and incorporating multi-factor authentication and biometric authentication for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If employees connect to corporate network from home networks, then remote work capability is improved, but network security deteriorates due to weak home network configurations

Engineering Contradiction:
Improveremote work capabilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements network segmentation by creating a dedicated secure network segment for corporate devices within the home network. The computing device acts as a network gateway that separates corporate traffic from general home network traffic, allowing remote work connectivity while maintaining security isolation. This resolves the contradiction by enabling remote access while preventing compromise of the entire home network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The computing device serves as an intermediary between the home network and corporate network resources. It provides a secure gateway that mediates all corporate traffic, implementing authentication, encryption, and security policies. This intermediary role allows employees to work remotely from home networks while the computing device protects against security vulnerabilities in the home network environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If VPN is used to secure online connections, then data transmission protection is improved, but protection against malware infection deteriorates as VPN cannot secure the local device

Engineering Contradiction:
Improvedata transmission protectionVSAvoidmalware infection risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The computing device implements preliminary security measures before devices connect to the corporate network. It performs device authentication, security posture assessment, and threat detection prior to granting network access. This preliminary anti-action prevents malware-infected devices from connecting to corporate resources, addressing the limitation of traditional VPN solutions that only protect data in transit.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The computing device acts as a security intermediary that sits between the home network and corporate network. It provides local security enforcement including malware scanning, device authentication, and traffic filtering before traffic enters the corporate network. This intermediary function extends security protection from just data transmission to include device-level security validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If network segmentation is implemented to isolate work activities, then security is improved, but network complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The computing device is designed as a multi-functional universal platform that combines network gateway, security enforcement, device authentication, and corporate resource access in a single device. This universality simplifies the network architecture by consolidating multiple security functions into one device rather than requiring separate systems for each function, thereby reducing overall network complexity while maintaining security improvements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The computing device implements automated security policies and self-configuring network segmentation. It automatically authenticates devices, enforces security rules, and manages network segment configuration without requiring manual intervention from employees or IT staff. This self-service capability reduces the operational complexity that would otherwise accompany network segmentation implementation.

Inventive Principle:
Principle #25Self-service

4Object-affected harmful factors

If advanced security measures are deployed, then cyber risk protection is improved, but ease of installation deteriorates

Engineering Contradiction:
Improvecyber risk protectionVSAvoidease of installation
Core Design Contradiction:
Object-affected harmful factorsVSEase of manufacture

Solution Approach 1:

The computing device is pre-configured with security policies, authentication mechanisms, and network segmentation settings before deployment to the employee's home. Advanced security measures including encryption keys, security rules, and device credentials are established in advance, eliminating the need for complex on-site configuration and making installation straightforward for employees regardless of their technical expertise.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20220021654A1Multi-network system architecture with electronic segmentation
Publication Date: 2022.01.20 CYBERLUCENT INC
  • US20220021654A1 patent drawing
  • US20220021654A1 patent drawing
  • US20220021654A1 patent drawing

AI summary

Systems and methods for establishing a secure communication network at a first location are provided. For example, a risk mitigation computing device may deploy, at the first location, a pre-configuration routine to access a risk assessment computer system that is remote from the first location. Based on the pre-configuration routine, the risk mitigation computing device may automatically generate a virtual private network (VPN) with the risk assessment computer system. The risk mitigation computing device may initiate an authentication process to confirm an identity of a user operating the risk mitigation computing device. Upon receiving an authentication approval associated with the authentication process, the risk mitigation computing device may establish a segmented home network that includes the secure communication network via VPN to access the risk assessment computer system and a second communication network that does not access the secure communication network.