Routing Platform Access Control via Tag Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional routers and IoT management devices have complex user interfaces, making them difficult for non-tech savvy users to set up and manage, and lack efficient access control mechanisms, particularly in blocking malicious websites, which increases security concerns as users are often unaware of connected devices and require professional configuration.

Innovation Solution

A hardware-agnostic platform for transparent access control of Internet of Everything (IoE) destinations via correlation, classification, and tagging, using a routing platform with a user-friendly interface that allows users to manage devices and block access to malicious sites by assigning tags and policies, enabling easy configuration and management of IoT devices and networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional routers and firewalls use traditional user interfaces for access control, then security policies can be implemented, but the interfaces become extremely complex and difficult for non-tech users to configure

Engineering Contradiction:
Improvesecurity policy implementationVSAvoiduser interface complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a cloud-based management platform as an intermediary between users and the complex firewall/router systems. This platform provides a simplified web interface that automatically generates and manages access control policies, eliminating the need for users to directly configure complex network security settings while maintaining effective security policy implementation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual mechanical configuration processes with automated system-generated policies. Instead of requiring users to manually create, modify, and manage complex firewall rules through traditional interfaces, the system automatically generates access control policies based on user selections in a simplified cloud interface, substituting manual operations with automated mechanisms

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If administrators manually configure firewall policies for each blocked website, then access control can be achieved, but the process becomes time-consuming and requires repeated reconfiguration for any changes

Engineering Contradiction:
Improveaccess controlVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring security policies and threat intelligence databases in the cloud platform before deployment. The system pre-establishes frameworks for access control, threat detection, and policy generation, allowing rapid deployment and updates without requiring administrators to manually reconfigure policies when new threats emerge or network conditions change

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where the system continuously monitors network traffic, threat intelligence feeds, and policy effectiveness. This feedback enables automatic policy updates and adjustments, eliminating the need for manual reconfiguration when new threats are detected or network conditions change, thereby reducing configuration time while maintaining reliable access control

Inventive Principle:
Principle #23Feedback

3Reliability

If users are provided with detailed information about connected devices and websites, then security awareness can be improved, but the information overload makes it more difficult for non-tech users to understand and manage

Engineering Contradiction:
Improvesecurity awarenessVSAvoidinformation manageability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies segmentation by dividing complex network information into discrete, user-friendly categories and levels. The cloud interface presents security information in segmented sections (e.g., device profiles, website categories, threat levels) that can be individually managed and understood, preventing information overload while maintaining comprehensive security awareness through organized, digestible presentations of data

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11704422B2Hardware agnostic platform for transparent access control of internet of everything (IoE) destinations via correlation, classification, and/or tagging
Publication Date: 2023.07.18 YESHOG LLC
  • US11704422B2 patent drawing
  • US11704422B2 patent drawing
  • US11704422B2 patent drawing

AI summary

Simplified and/or user friendly interfaces can be employed to facilitate administration of a routing platform that couples devices of a local area network (LAN) to an external communication network (e.g., the Internet). In one aspect, the routing platform comprises a firewall that can be employed to perform access control and/or an Internet of Things (IoT) hub that can be employed to control operations of IoT devices of the LAN, for example, based on domain information, user-defined tags and peer-defined criteria to make correlations that are leveraged to implement access control policies. A search and command interface is employable to issue textual (e.g., natural language) commands to configure access control policies, tags for devices and/or websites, and/or search for data.