Automatic Security VLAN Segmentation for IoT Device Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Consumer Wi-Fi networks lack effective management and security, leading to insecure communication between trusted and untrusted devices, including non-secure IoT products, due to the complexity of setting up and managing secure networks for non-technical users.

Innovation Solution

An automatic security network configuration system creates a virtual local area network (VLAN) for security devices, such as IP cameras and alarm systems, independent from the consumer's network, using a separate SSID and firewall rules managed by a service provider, enabling self-healing and stronger encryption without requiring consumers to share their Wi-Fi SSID or password.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If consumer Wi-Fi networks use a single unified network for all devices, then network simplicity is maintained, but security and communication reliability deteriorate due to mixing trusted and untrusted devices

Engineering Contradiction:
Improvecommunication securityVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the consumer Wi-Fi network into multiple Virtual LANs (VLANs) with distinct SSIDs (e.g., Guest Network, IoT Network, Primary Network). Each VLAN isolates specific device types, allowing trusted devices to communicate securely while preventing unauthorized access. This segmentation resolves the contradiction by providing network security without requiring complex manual configuration from consumers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs automatic device classification and VLAN assignment where the router autonomously identifies device types (consumers, IoT devices, guests) and assigns appropriate VLANs without user intervention. The self-healing mechanism automatically reconnects devices after network changes, eliminating the need for consumers to manually manage network security while maintaining reliable communication.

Inventive Principle:
Principle #25Self-service

2Reliability

If existing security products monitor and intercept data traffic to secure consumer networks, then network security improves, but user experience and ease of operation deteriorate due to increased complexity

Engineering Contradiction:
Improvenetwork securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of monitoring and intercepting traffic through complex security products, the patent segments the network into isolated VLANs where security is built into the network architecture itself. Each VLAN acts as an independent secure zone, providing network security through structural design rather than complex monitoring and interception mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the security management function from complex stand-alone security products and integrates it directly into the router's network architecture through VLAN tagging and automatic device classification. This eliminates the need for separate security devices that monitor and intercept traffic, simplifying the user experience while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If consumers manually configure firewall rules and network settings to secure their networks, then security control improves, but ease of operation deteriorates due to technical complexity

Engineering Contradiction:
Improvesecurity controlVSAvoidsetup simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs automatic device classification, VLAN assignment, and firewall rule generation without requiring consumer input. The router autonomously identifies device types, determines appropriate network segmentation, and configures security rules automatically, providing strong security control while maintaining ease of operation for non-technical consumers.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent dynamically adjusts network parameters (VLAN assignments, firewall rules, routing tables) based on real-time device identification and network conditions. This automated parameter changes approach provides adaptive security control without requiring consumers to manually configure settings, resolving the contradiction between security control and ease of operation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11979401B2Automatic security device network
Publication Date: 2024.05.07 THE ADT SECURITY CORPORATION
  • US11979401B2 patent drawing
  • US11979401B2 patent drawing
  • US11979401B2 patent drawing

AI summary

A method, node, wireless device and installation device are disclosed. In one or more embodiments, a node configured to operate a security virtual local area network (VLAN) and a customer VLAN independent from the security VLAN is provided. The security VLAN is configured to operate using a first network partition different from a second network partition used by the customer VLAN. The node includes processing circuitry configured to receive information from a first device requesting access to the node, determine whether to add a first device to the security VLAN based at least on the received information from the first device meeting a predefined criterion, and configure the first device to access one of the security VLAN and customer VLAN based at least on the determination.