Wireless Network Quarantine Zone for IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security methods struggle to effectively isolate devices connected via wireless links that pose security risks to computer and communication networks, particularly in the context of the Internet of Things where many devices do not meet IT security requirements.
Innovation Solution
The method involves creating a network with a 'trust zone' and a 'quarantine zone', where devices are initially connected to the quarantine zone and only granted access to the trust zone after compliance with security rules is verified. This is achieved through the use of wireless connection devices and an access controller that manages network access based on security parameters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If devices are connected via wireless link to the network, then ease of connection is improved, but network security is worsened due to inability to verify security compliance before access
Solution Approach 1:
The network is segmented into two distinct zones: a trust zone for verified secure devices and a quarantine zone for devices pending security verification. This segmentation allows new devices to connect wirelessly to the quarantine zone immediately while preventing them from accessing the trust zone until security compliance is confirmed, thus maintaining both ease of connection and network security.
Solution Approach 2:
A network access controller acts as an intermediary between the wireless connection device and the network resources. This controller monitors and controls access requests, determining whether to grant access to the trust zone or restrict to the quarantine zone based on security verification, thereby enabling secure automated access control without complicating the connection process for end users.
2Reliability
If isolation of risky devices is implemented, then network security is improved, but device complexity increases due to need for separate network configurations
Solution Approach 1:
The wireless connection device broadcasts a single SSID that provides universal access to both the trust zone and quarantine zone. This multi-functionality eliminates the need for devices to be pre-configured with multiple network identifiers or undergo manual configuration steps, reducing device complexity while maintaining the security benefits of isolation through automated controller-based access management.
3Ease of operation
If common SSID is used for both zones, then ease of operation is improved, but network security is worsened due to potential unauthorized access
Solution Approach 1:
The network access controller serves as a security intermediary that intercepts and evaluates all access requests regardless of which zone (trust or quarantine) is targeted. It verifies device security compliance and enforces zone-specific access policies, ensuring that the common SSID does not compromise security by preventing unauthorized access to the trust zone while allowing convenient single-SSID connectivity.
Solution Approach 2:
The system implements feedback mechanisms where the access controller continuously monitors device behavior and security parameters, dynamically adjusting access permissions based on verified security compliance. This feedback loop ensures that even with a common SSID, access control remains secure by granting or revoking trust zone access rights based on real-time security assessment.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The invention relates to a method for securing a computer or communication network, specifically a method for isolating a station connected to a wireless access device from the network and identified as not meeting the security requirements defined for the network. The isolation of the connected station is achieved automatically by connecting it to a network quarantine zone, excluded from a so-called trusted zone. The device identified as not meeting the security requirements may, for example, access a wide area network, such as the internet, but not access a secure local area network.