PoE Device Identification and Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing network access for authorized devices is challenging due to the proliferation of network-connected devices, and existing technologies struggle to effectively identify and enforce policies for devices connected via Power over Ethernet (PoE), which complicates network security and monitoring.

Innovation Solution

The implementation of systems and methods that utilize Power over Ethernet (PoE) to monitor network activity, identify device characteristics, and enforce access policies by determining device types and power consumption patterns, allowing for precise control of network resources and power supply to connected devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number of network-connected devices is increased to support Internet of Things developments, then device connectivity and functionality are improved, but network security and device management complexity increase

Engineering Contradiction:
Improvedevice connectivityVSAvoidnetwork management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a network access control system as an intermediary between devices and network resources. This system automatically identifies devices via PoE, determines their authorization status, and enforces access policies without requiring manual configuration or complex user management, thereby simplifying network management despite increased device connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables devices to self-identify and self-authenticate through PoE detection and characterization. Authorized devices automatically gain network access based on their identified characteristics, while unauthorized devices are automatically blocked, eliminating the need for complex manual device management and authorization processes

Inventive Principle:
Principle #25Self-service

2Ease of operation

If Power over Ethernet (PoE) is used to provide both data and power via a single cable, then ease of connection and device mobility are improved, but difficulty in identifying device characteristics and enforcing policies increases

Engineering Contradiction:
Improveconnection simplicityVSAvoiddevice identification difficulty
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system continuously monitors PoE devices for characteristic feedback signals that identify device type and authorization status. By analyzing these feedback characteristics (such as device responses to identification protocols), the system can accurately distinguish between authorized and unauthorized devices while maintaining the simplicity of PoE connectivity

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces complex mechanical or manual device identification methods with electronic and protocol-based detection mechanisms. The system uses network protocols and electrical signal analysis to automatically characterize PoE devices, eliminating the need for physical tags, manual configuration, or complex hardware identification systems

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If network activity monitoring is implemented to prevent unauthorized access, then network security is improved, but system complexity and monitoring overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary device identification and authorization determination before allowing network access. By characterizing devices and enforcing access policies at the point of connection through PoE, the system prevents unauthorized access attempts before they can occur, reducing the need for complex post-intrusion detection and response mechanisms

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a multi-functional network access control system that simultaneously performs device identification, authorization determination, and access enforcement through a single integrated framework. This universal approach consolidates multiple security functions into one system, reducing overall complexity compared to separate specialized security systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240267242A1Device identification and policy enforcement using power over ethernet (POE)
Publication Date: 2024.08.08 FORESCOUT TECHNOLOGIES INC
  • US20240267242A1 patent drawing
  • US20240267242A1 patent drawing
  • US20240267242A1 patent drawing

AI summary

Systems, methods, and related technologies for device identification and policy enforcement using Power over Ethernet (PoE) are described. In certain aspects, receiving a communication that originates from a Power over Ethernet (PoE) enabled device is received, wherein the PoE enabled device receives electrical power from an Ethernet port. The communication is processed to determine identifying information of the PoE enabled device from which the communication originates and a network access policy enforcement action is initiated based on the identifying information of the PoE enabled device.