Quarantine Network for Zigbee Device Joining Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

ZIGBEE networks lack effective control over device joining, leading to unintentional or malicious device connections, which can compromise network security and data integrity.

Innovation Solution

Implementing a temporary quarantine network that allows devices to join initially, enabling users to identify and filter wanted devices while stranding unwanted devices, thereby controlling network access and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If ZIGBEE networks allow devices to join freely using ad hoc networking, then device connectivity and ease of operation are improved, but network security and data integrity are compromised due to unintentional or malicious device connections

Engineering Contradiction:
Improvedevice joiningVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network joining process is segmented into two distinct phases: a quarantine network phase where devices can join freely, and a main network phase where only authorized devices connect. This segmentation allows free device joining to be separated from secure network access, resolving the contradiction between ease of operation and network security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A quarantine network acts as an intermediary between the external environment and the main ZIGBEE network. This intermediate layer filters and validates devices before they can access the main network, enabling secure authorization while maintaining ease of device joining through the quarantine phase.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a quarantine network is implemented to filter devices, then network security is improved, but device complexity and setup time increase due to the additional network layer

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically managing device authorization and transition between quarantine and main networks. The network controller automatically identifies authorized devices, facilitates their transition from quarantine to main network, and isolates unauthorized devices, reducing manual configuration complexity despite the added security layer.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The quarantine network performs preliminary actions by pre-filtering and validating devices before they join the main network. This preliminary authorization process automates security checks and device verification, improving network security while reducing the complexity of manual device management through automated preliminary filtering.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10701536B1Quarantine network for wireless devices
Publication Date: 2020.06.30 AMAZON TECH INC
  • US10701536B1 patent drawing
  • US10701536B1 patent drawing
  • US10701536B1 patent drawing

AI summary

A system and method for a quarantine network for a personal rea network are provided. A plurality of devices that are connected to a first personal area network are identified. A first device is designated as being authorized to communicate using the first personal area network and a second device of the plurality of devices is designated as not being authorized to communicate using the first personal area network. The first device is instructed to disconnect from the first personal area network. Communications with the second device are ceased. After ceasing communication with the second device, the second device continues to be connected to the first personal area network. It is then determined that the first device is connected to a second personal area network. The first device is instructed the first device to use a network key for communications with a network controller.