Wireless Network Quarantine Zone for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security methods struggle to effectively isolate devices connected via wireless links that pose security risks to computer and communication networks, particularly in the context of the Internet of Things where many devices do not meet IT security requirements.

Innovation Solution

The method involves creating a network with a 'trust zone' and a 'quarantine zone', where devices are initially connected to the quarantine zone and only granted access to the trust zone after compliance with security rules is verified. This is achieved through the use of wireless connection devices and an access controller that manages network access based on security parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If devices are connected via wireless link to the network, then ease of connection is improved, but network security is worsened due to inability to verify security compliance before access

Engineering Contradiction:
Improveease of connectionVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network is segmented into two distinct zones: a trust zone for verified secure devices and a quarantine zone for devices pending security verification. This segmentation allows new devices to connect wirelessly to the quarantine zone immediately while preventing them from accessing the trust zone until security compliance is confirmed, thus maintaining both ease of connection and network security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A network access controller acts as an intermediary between the wireless connection device and the network resources. This controller monitors and controls access requests, determining whether to grant access to the trust zone or restrict to the quarantine zone based on security verification, thereby enabling secure automated access control without complicating the connection process for end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If isolation of risky devices is implemented, then network security is improved, but device complexity increases due to need for separate network configurations

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The wireless connection device broadcasts a single SSID that provides universal access to both the trust zone and quarantine zone. This multi-functionality eliminates the need for devices to be pre-configured with multiple network identifiers or undergo manual configuration steps, reducing device complexity while maintaining the security benefits of isolation through automated controller-based access management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If common SSID is used for both zones, then ease of operation is improved, but network security is worsened due to potential unauthorized access

Engineering Contradiction:
Improvenetwork identificationVSAvoidaccess control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network access controller serves as a security intermediary that intercepts and evaluates all access requests regardless of which zone (trust or quarantine) is targeted. It verifies device security compliance and enforces zone-specific access policies, ensuring that the common SSID does not compromise security by preventing unauthorized access to the trust zone while allowing convenient single-SSID connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the access controller continuously monitors device behavior and security parameters, dynamically adjusting access permissions based on verified security compliance. This feedback loop ensures that even with a common SSID, access control remains secure by granting or revoking trust zone access rights based on real-time security assessment.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3836590B1Method of rendering access to a network secure, associated system and device
Publication Date: 2025.06.04 SAGEMCOM BROADBAND SAS
  • EP3836590B1 patent drawingFigure 1~2
  • EP3836590B1 patent drawingFigure 3
  • EP3836590B1 patent drawingFigure 4

AI summary

The invention relates to a method for securing a computer or communication network, specifically a method for isolating a station connected to a wireless access device from the network and identified as not meeting the security requirements defined for the network. The isolation of the connected station is achieved automatically by connecting it to a network quarantine zone, excluded from a so-called trusted zone. The device identified as not meeting the security requirements may, for example, access a wide area network, such as the internet, but not access a secure local area network.