Smart Home Gateway Segmentation for Corporate Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home networks are more vulnerable to attacks due to increased device connectivity and sophistication, posing a risk to corporate assets stored in residential environments, which are not adequately secured by conventional methods.

Innovation Solution

A system utilizing a smart home gateway with a processor and memory to create a secured connection between the home and corporate networks, detecting and authenticating authorized devices, updating software, and automatically connecting them to a remote corporate VPN, while segregating corporate assets from non-corporate devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security methods (secure credentials, anti-virus software, data encryption) are used to protect corporate assets, then basic security is provided, but home networks remain vulnerable to attacks due to increased device connectivity and sophistication

Engineering Contradiction:
Improvesecurity of corporate assetsVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the home network into two distinct zones: a corporate network zone for authorized devices and a personal network zone for non-corporate devices. The gateway device creates separate virtual network interfaces (e.g., VLANs) that isolate corporate traffic from personal devices, preventing lateral movement of attacks while maintaining security boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway device serves as an intermediary between corporate devices and the broader home network. It implements policy-based routing and traffic filtering, acting as a mediator that enforces security policies, controls device communications, and prevents unauthorized access between network segments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple devices are connected to the home network for internet access, then connectivity and convenience are improved, but the number of attack vectors increases

Engineering Contradiction:
Improvedevice connectivityVSAvoidattack vectors
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The network is segmented into corporate and personal zones, allowing multiple devices to connect simultaneously while restricting communication between zones based on policy. Corporate devices can access corporate resources, while personal devices remain isolated from sensitive corporate assets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security policies and network characteristics are applied to different device types and network zones. Corporate devices receive enhanced security protections and priority routing, while personal devices operate under different policies, creating localized security characteristics appropriate for each device category.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If automatic device connection to corporate network is implemented, then ease of access is improved, but security control may be compromised

Engineering Contradiction:
Improvedevice connectionVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Devices undergo preliminary authentication and authorization checks before being allowed to connect to the corporate network. The gateway device evaluates device credentials, security posture, and policy compliance in advance, automatically enrolling compliant devices while blocking non-compliant ones before they can access corporate resources.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous monitoring and feedback mechanisms that track device behavior, security status, and policy compliance. Devices that violate security policies or exhibit suspicious behavior are automatically disconnected or have their access restricted, providing dynamic security control based on real-time conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12058138B2Securing corporate assets in the home
Publication Date: 2024.08.06 AT&T INTELLECTUAL PROPERTY I L P
  • US12058138B2 patent drawing
  • US12058138B2 patent drawing
  • US12058138B2 patent drawing

AI summary

A method includes creating a secured connection between a home network and a remote corporate network via a smart home gateway; detecting a plurality of devices are connected with the smart home gateway, wherein the plurality of devices are within the home network; determining that a first device of the plurality of devices is indicated as an authorized corporate device; determining that the first device has software updated to a threshold version of software; and based on the indication that the first device is an authorized corporate device or the first device has software update to the threshold version of software, automatically connecting the first device to the remote corporate network.