Zoned Mesh Network Isolation for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing the security and scalability of large mesh networks of IoT devices is challenging due to their interconnected nature, which makes it difficult to isolate vulnerabilities and minimize damage when a node device is compromised, especially in decentralized networks with non-hierarchical topologies.

Innovation Solution

Implementing a mesh network architecture that isolates compromised nodes by identifying associated client devices based on proximity or common features, and using cryptographic means to disrupt communication, such as rotating cryptographic keys without the compromised nodes' participation, to restrict their access and prevent the spread of attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If nodes are interconnected in a mesh network to enable decentralized communication, then network reliability and communication capability are improved, but when a node is compromised it becomes difficult to isolate vulnerabilities and minimize damage

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidvulnerability spread
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the mesh network into isolated segments or zones using virtual routing tables. When a compromised node is detected, the system creates separate routing zones that prevent communication between the compromised node and other network segments, effectively segmenting the network to contain the vulnerability while maintaining overall network functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network controller as an intermediary that manages communication between nodes. The controller monitors node behavior, detects compromises, and mediates communication by updating virtual routing tables to block suspicious nodes, thereby protecting the network without requiring direct intervention from compromised nodes themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic keys are rotated to secure communications, then security is improved, but nodes that have not updated their keys cannot communicate with the mesh network

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic key management where the network controller can rotate cryptographic keys for specific zones or segments independently. This allows the network to adaptively update security credentials for compromised areas while maintaining compatibility with nodes that have not yet updated, enabling gradual security enhancement without forcing complete network-wide key rotation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent establishes a preliminary communication channel between the network controller and nodes that allows the controller to push security updates and new cryptographic keys to nodes proactively. This preliminary action enables nodes to update their credentials on their own schedule while maintaining network security, preventing communication breakdowns that would occur with simultaneous mandatory key rotation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11652696B1Zoned mesh network isolation
Publication Date: 2023.05.16 RED HAT LLC
  • US11652696B1 patent drawing
  • US11652696B1 patent drawing
  • US11652696B1 patent drawing

AI summary

Embodiments of the present disclosure include a processing device that determines that a first node device of a plurality of node devices in a network is non-compliant with a network policy, identifies a subset of the plurality of node devices that is associated with the first node device, and disrupts, by the processing device, a communication path of the subset of the plurality of node devices and the first node device within the network.