SD-WAN IoT Security Posture Management by Device Type

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems in enterprise networks struggle to manage security posture effectively due to the increasing variety of network traffic from web-based applications and IoT devices, often enforcing policies based on application type rather than device type, leading to potential cybersecurity risks.

Innovation Solution

A security posture management system that leverages application identification and device discovery from network traffic data analysis to configure SD-WAN construct-based policies at device granularity, allowing tailored security management and implementing a SASE security model with zero trust principles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If policies are enforced based on application type rather than device type, then traffic management is simplified, but cybersecurity risk increases due to inability to distinguish device-specific threats

Engineering Contradiction:
Improvepolicy managementVSAvoidcybersecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments policy enforcement from application-level to device-level granularity. Instead of applying uniform policies to all devices running the same application, the system divides traffic management into device-specific policy groups, allowing distinct security rules for each device type (IoT, mobile, fixed) while maintaining application-aware classification. This segmentation enables targeted security measures without sacrificing operational simplicity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning different security policy characteristics to different device types based on their specific security requirements. IoT devices receive policies tailored to their vulnerability profiles, mobile devices get policies appropriate for transient connections, and fixed devices receive policies for stable infrastructure. Each device type receives locally optimized security treatment rather than uniform application-based policies.

Inventive Principle:
Principle #3Local quality

2Reliability

If device granularity policies are implemented, then security posture management improves, but system complexity increases due to multiple policy configurations

Engineering Contradiction:
Improvesecurity posture managementVSAvoidpolicy configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal policy management framework that handles multiple device types and applications through a single system. The device granularity policy group structure serves multiple functions: it classifies traffic, enforces security policies, and adapts to different device types automatically. This multi-functional approach reduces the need for separate configuration systems for each device type, managing complexity through consolidation rather than proliferation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces dynamic policy assignment where security policies are automatically assigned and adjusted based on real-time device identification and classification. Rather than requiring static, manual configuration for each device type, the system dynamically determines the appropriate policy group based on device characteristics, application context, and security requirements. This dynamic approach reduces configuration complexity while maintaining high security posture management capability.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If traditional network security approaches are used, then infrastructure simplicity is maintained, but adaptability to diverse IoT and web-based application traffic decreases

Engineering Contradiction:
ImproveinfrastructureVSAvoidtraffic management
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent changes the fundamental parameters of network security from application-based classification to device-type-based classification with application awareness as a secondary parameter. This parameter change enables the infrastructure to adapt to diverse traffic types (IoT, mobile, fixed, web-based applications) by using device characteristics as the primary sorting criterion. The system maintains infrastructure simplicity by using these parameter changes within the existing SD-WAN framework rather than requiring complete architectural overhaul.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12388874B2SD-WAN IOT security posture management
Publication Date: 2025.08.12 PALO ALTO NETWORKS INC
  • US12388874B2 patent drawing
  • US12388874B2 patent drawing
  • US12388874B2 patent drawing

AI summary

Increasing use of web-based applications or Software-as-a-Service and IoT devices within enterprise networks increases the variety of network traffic and variables for consideration in managing security posture, which includes policy management. A security posture management system as disclosed herein leverages application identification and device discovery from ongoing collection and analysis of network traffic data to manage policies at device granularity allowing tailored security posture management. The system can tailor policies to handle network traffic depending on identified application and device type inputs obtained from the ongoing collection and analysis. The security posture management system can configure SD-WAN construct based parameters of a policy to tailor policies for different application traffic from different types of devices.