SASE Function with Configured Telemetry Intelligence for IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies lack a dedicated IoT security function in the cloud to process and apply service chains for IoT device traffic, failing to provide end-to-end visibility and security requirements for enterprises, especially for IoT devices in motion with varying connectivity needs.
Innovation Solution
A Secure Access Service Edge (SASE) function with configured telemetry intelligence, utilizing a dynamic telemetry manufacturer usage description (MUD) and IoT cloud access security broker (CASB) to create and manage telemetry configuration files based on edge location inputs, enabling secure data processing and distribution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a dedicated IoT security function is implemented in the cloud to process and apply service chains for IoT device traffic, then security and visibility for enterprises are enhanced, but device complexity and system cost increase
Solution Approach 1:
The patent introduces a SASE function with configured telemetry intelligence as an intermediary component between IoT devices and cloud consumers. This intermediary collects telemetry data, applies service chains, and provides security enforcement, thereby enhancing security without requiring direct complex interactions between devices and cloud systems. The SASE function acts as a security broker that simplifies the overall system architecture while providing dedicated security capabilities.
Solution Approach 2:
The patent segments the security function into a dedicated SASE component with telemetry intelligence, separating security enforcement from general cloud processing. This segmentation allows the security function to be independently configured, managed, and optimized, reducing the complexity burden on the overall system while providing specialized security capabilities for IoT device traffic.
2Loss of information
If telemetry data is collected and processed in real-time with dynamic configuration based on edge location inputs, then visibility and security monitoring are improved, but data processing complexity and resource consumption increase
Solution Approach 1:
The patent implements dynamic telemetry configuration where the SASE function adapts its data collection and processing behavior based on edge location inputs and device context. The telemetry configuration file is dynamically generated and updated, allowing the system to optimize visibility requirements based on current operational conditions, thereby reducing unnecessary data processing complexity while maintaining required visibility levels.
Solution Approach 2:
The patent changes key parameters of telemetry data processing based on dynamic inputs, including collection frequency, data types, and processing intensity. By adjusting these parameters according to edge location and device state, the system achieves improved visibility where needed while reducing processing complexity in situations where full visibility is not required, thereby optimizing the balance between information completeness and processing burden.
3Adaptability or versatility
If dynamic telemetry configuration files are generated and applied based on device behavior and location, then security responsiveness is improved, but configuration management complexity increases
Solution Approach 1:
The patent implements feedback mechanisms where the SASE function continuously monitors device behavior, location, and security events, using this information to dynamically update telemetry configuration files. The feedback loop enables automatic adaptation of security configurations based on observed device patterns and threat indicators, improving security responsiveness while reducing manual configuration management complexity through automated decision-making algorithms.
Solution Approach 2:
The system enables self-service configuration management where the SASE function autonomously generates, updates, and applies telemetry configuration files based on device behavior analysis and security requirements. This self-service capability reduces the burden on external configuration management systems while maintaining high adaptability and security responsiveness through automated configuration generation and validation processes.
Data Source
AI summary
In one embodiment, a method herein comprises: receiving, at a device, a registration request from a telemetry exporter that transmits telemetry data; generating, by the device, a telemetry configuration file for the telemetry exporter, the telemetry configuration file defining a policy for transmission of telemetry data from the telemetry exporter and an authentication token for the telemetry exporter; sharing, by the device, the policy with a security enforcer; and sending, by the device, the telemetry configuration file to the telemetry exporter, wherein the telemetry exporter is caused to connect with the security enforcer using the authentication token, send the telemetry configuration file to the security enforcer, and transmit collected telemetry data to the security enforcer, and wherein the security enforcer is caused to create a dynamic publish-subscribe stream for publishing the collected telemetry data received from the telemetry exporter based on the telemetry configuration file and the policy.


