IP Library Granted Patent US 12,676,898
Granted Patent B2
US 12,676,898 · App. 17/572,782 · Granted Jul 7, 2026

Method and framework for internet of things network security

Inventors: Umamaheswar Kakinada (Centennial, CO); Hossam Hmimy (Aurora, CO); Manish Jindal (Lone Tree, CO); Satyanarayana Parimi (Cos Cob, CT); Patricia Zullo (Indio, CA)
Assignee: Charter Communications Operating, LLC
H04L63/205H04L41/0894H04L43/065H04L47/781H04L67/12H04L67/303G16Y30/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,676,898
App. No.
17/572,782
Filed
Jan 11, 2022
Granted
Jul 7, 2026
Kind
B2
Art Unit
2431
USPC
726/1
Abstract

A method for Internet of Things (IoT) network security includes collecting information for each network device (device), determining a minimum viable resource allocation for each device based on the information, which defines the minimum resources needed by each device to engage the IoT network and handle data, and for each device, distributing minimum viable resource allocations and rules, determining monitoring sets, monitoring using the monitoring set, collecting updated information based partially on the monitoring set, analyzing the updated information to determine trends and insights relative to the devices and the IoT network, updating the monitoring set, minimum viable resource allocation, and rules based on the analyzed updated information, checking compliance with a current minimum viable resource allocation and rules, identifying devices having violations, and performing same on a continuous as it and automatic basis. The method establishes and maintains a chain of custody for data traversing through multiple network segments.

Claims (47)

1 . A method for network security, the method comprising:

determining, by a rules node, a minimum viable resource allocation for each network device in or comprising a network, wherein the minimum viable resource allocation defines, for each network device, minimum resources needed to engage the network and to handle data collected by network devices on the network;

updating, by the rules node, the minimum viable resource allocation for at least one network device based on updated information associated with each of the at least one network device and the network;

detecting, by the rules node, one or more network devices having violations and under threat based on non-compliance of the one or more network devices with an applicable minimum viable resource allocation;

configuring, by the rules node, the detected network devices based on non-compliance with the applicable minimum viable resource allocation;

establishing, by applicable associated network devices of the network devices using applicable sets of rules, security associations and mutual trust with other associated network devices of the network device;

wherein compliance with the applicable sets of rules and the applicable minimum viable resource allocations establishes a chain of custody between the associated network devices, and

wherein the chain of custody differs based on traffic flow direction by using different sets of rules and minimum viable resource allocations for different traffic flow directions between the associated network devices.

2 . The method of claim 1 , wherein the applicable sets of rules, security associations and mutual trust with other associated network devices of the network devices are at interfaces between two network segments in the network, and wherein successful establishment of the security associations and the mutual trust provide end-to-end security between the two network segments.

3 . The method of claim 2 , wherein the set of rules includes at least security rules, transmission rules, access rules, authorization rules, security authorization rules, communication rules, and security rules.

4 . The method of claim 3 , further comprising:

checking, by at least one of the rules node and each pair of the network devices at the interfaces, compliance of other network devices at the interfaces using the applicable minimum viable resource allocations and the applicable sets of rules to establish the chains of custody.

5 . The method of claim 4 , further comprising:

continuously monitoring, by the rules node, changes in information associated with each of the network device and the network.

6 . The method of claim 1 , wherein the minimum viable resource allocation for each of the network device is based on at least connectivity, bandwidth, amount of transmitted data, frequency of transmission, authorization to connect to other network devices and network functions, level of and access to data by the network device, time when access to data is permitted for the network device, and location where access to data is permitted by the network device.

7 . The method of claim 6 , wherein a type of the network device includes at least devices, network edge devices, network access devices, network core devices, and application devices or servers.

8 . The method of claim 1 , further comprising:

automatically and continuously performing minimum viable resource allocation determinations, compliance confirmations for each of the network device, and configuration of the network devices and of the network.

9 . The method of claim 1 , wherein insights of the network are determined by a machine learning model.

10 . A network for transferring data, comprising:

functional network slices, each functional network slice including devices which have visibility and authorization limited to the functional network slice; and

a network security processor configured to allocate a minimum viable resource allocation and a set of rules to each of the devices, wherein the minimum viable resource allocation is a threshold for each of the devices to use the network and process data collected by the devices on the network,

wherein appropriate pairs of the devices form, between pairs of the functional network slices, security associations, minimum viable resource allocation confirmation, and mutual trust between the appropriate pairs of the devices, which provide end-to-end security between a source functional network slice and a destination functional network slice in the network upon successful establishment of the security associations and establishment of the mutual trust by all of the appropriate pairs of the devices, and wherein the appropriate pairs of the devices transfer data upon successful confirmation of the security associations and device and data compliance, the device and data compliance establishing a chain of custody between the appropriate pairs of the devices at each of the functional network slices, and

wherein the chain of custody and the security associations and the mutual trust between the appropriate pairs of the devices differ based on traffic flow direction by using different sets of rules and minimum viable resource allocations for different traffic flow directions between the appropriate pairs of the devices.

11 . The network of claim 10 , the network security processor further configured to:

identify at least one device or data having violations based on at least one of unsuccessful security association and the mutual trust.

12 . The network of claim 11 , the network security processor further configured to:

correlate metrics in the network to detect and mitigate suspicious activity; and

isolate the devices, applications, and functional network slices impacted by detected suspicious activity at a point of impact.

13 . The network of claim 11 , the network security processor further configured to:

detect the devices in violation of an appropriate minimum viable resource allocation and appropriate set of rules for the device; and

configure the identified devices based on non-compliance with the appropriate minimum viable resource allocations and the appropriate sets of rules.

14 . The network of claim 10 , wherein the chain of custody is an end-to-end chain of custody and includes at least establishment of the mutual trust, mutual authentication, and data security.

15 . The network of claim 10 , wherein the minimum viable resource allocation for the device is based on information gathered for the device.

16 . The network of claim 15 , wherein the information for each of the devices includes at least connectivity, bandwidth, amount of transmitted data, frequency of transmission, authorization to connect to other devices and network functions, level of and access to data by the device, timing parameters related to the device, location parameters related to the device, device type, security protocols, transmission protocols, access protocols, authorization protocols, security authorization protocols, transmission protocols, communication protocols, and security protocols.

17 . The network of claim 15 , wherein the set of rules is based on the information, the set of rules including at least security rules, transmission rules, access rules, authorization rules, security authorization rules, transmission rules, communication rules, and security rules.

18 . A network comprising:

network devices;

a memory;

a processor in communication with the network devices, the processor configured to:

determine a minimum viable resource allocation for each of the network devices in or comprising a network, wherein the minimum viable resource allocation defines, for each of the network devices, minimum resources needed to engage the network and to handle data collected by network devices on the network;

update the minimum viable resource allocation for at least one of the network devices based on updated information associated with each of the at least one network devices and the network;

detect one or more network devices having violations and under threat based on non-compliance of the one or more network devices with an applicable minimum viable resource allocation;

configure the detected network devices based on non-compliance with the applicable minimum viable resource allocation;

establish, by applicable associated network devices of the network devices using applicable sets of rules, security associations and mutual trust with other associated network devices of the network devices;

wherein a compliance with the applicable sets of rules and the applicable minimum viable resource allocations establishes a chain of custody between the associated network devices, and

wherein the chain of custody differs based on traffic flow direction by using different sets of rules and minimum viable resource allocations for different traffic flow directions between an appropriate pairs of the devices.

Assignments (4)
SECURITY INTEREST Recorded Sep 22, 2022
From: CHARTER COMMUNICATIONS OPERATING, LLC; TIME WARNER CABLE ENTERPRISES, LLC
To: WELLS FARGO TRUST COMPANY, N.A.
Reel/Frame 061503/0937 →
SECURITY INTEREST Recorded Sep 22, 2022
From: CHARTER COMMUNICATIONS OPERATING, LLC; TIME WARNER CABLE ENTERPRISES, LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 061504/0307 →
SUPPLEMENTAL SECURITY AGREEMENT Recorded Aug 10, 2022
From: CHARTER COMMUNICATIONS OPERATING, LLC; TIME WARNER CABLE ENTERPRISES LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 061633/0069 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2022
From: KAKINADA, UMAMAHESWAR; HMIMY, HOSSAM; JINDAL, MANISH; PARIMI, SATYANARAYANA; ZULLO, PATRICIA
To: CHARTER COMMUNICATIONS OPERATING, LLC
Reel/Frame 058617/0187 →
Continuity (2)
Continuation 16897597 · Jun 10, 2020
Related Publication 20220131905A1 · Apr 28, 2022
References Cited (53)
US 7930403B2 · Saffre · 2011 [cited by examiner]
US 9565227B1 · Helter et al. · 2017 [cited by applicant]
US 10104104B1 · Juels et al. · 2018 [cited by applicant]
US 10616934B2 · Talebi Fard et al. · 2020 [cited by applicant]
US 10797934B1 · Akman et al. · 2020 [cited by applicant]
US 10949939B2 · Achtermann · 2021 [cited by examiner]
US 10963435B1 · McAlister et al. · 2021 [cited by applicant]
US 11934525B2 · Sheth · 2024 [cited by examiner]
US 20070136263A1 · Williams · 2007 [cited by applicant]
US 20130304903A1 · Mick et al. · 2013 [cited by applicant]
US 20140189484A1 · Fountenberry · 2014 [cited by applicant]
US 20140280595A1 · Mani · 2014 [cited by examiner]
US 20160070611A1 · Kim · 2016 [cited by examiner]
US 20160156715A1 · Larouche et al. · 2016 [cited by applicant]
US 20160353456A1 · Gilson et al. · 2016 [cited by applicant]
US 20170279620A1 · Kravitz · 2017 [cited by examiner]
US 20180123878A1 · Li et al. · 2018 [cited by applicant]
US 20180191563A1 · Farmanbar et al. · 2018 [cited by applicant]
US 20180219863A1 · Tran · 2018 [cited by examiner]
US 20180241842A1 · Kumar et al. · 2018 [cited by applicant]
US 20190053147A1 · Qiao et al. · 2019 [cited by applicant]
US 20190182177A1 · Bugenhagen et al. · 2019 [cited by applicant]
US 20190207912A1 · Nielson et al. · 2019 [cited by applicant]
US 20190223055A1 · Bor Yaliniz et al. · 2019 [cited by applicant]
US 20190327149A1 · Sun · 2019 [cited by examiner]
US 20190379530A1 · Suthar et al. · 2019 [cited by applicant]
US 20200006944A1 · Fife et al. · 2020 [cited by applicant]
US 20200007584A1 · Dixit · 2020 [cited by examiner]
US 20200374339A1 · Billore · 2020 [cited by examiner]
US 20210014046A1 · Ivkushkin · 2021 [cited by examiner]
US 20210051070A1 · Akman et al. · 2021 [cited by applicant]
US 20210232574A1 · Kvochko et al. · 2021 [cited by applicant]
CN 108965289A · 2018 [cited by applicant]
CN 109906637B · 2020 [cited by applicant]
CN 113127187A · 2021 [cited by applicant]
DE 102019000823A1 · 2019 [cited by examiner]
EP 3147786A1 · 2017 [cited by applicant]
EP 3220605A1 · 2017 [cited by applicant]
EP 3304824B1 · 2019 [cited by applicant]
WO 0078057A1 · 2000 [cited by applicant]
WO 2017200978A1 · 2017 [cited by applicant]
Caputo, “DVS Archiving and Storage”, 2014 (Year: 2014). [cited by applicant]
Cognizant, “The Five Essential IoT Requirements and How to Achieve Them”, 2019 (Year: 2019). [cited by applicant]
Haroon et al., “Constraints in the IoT: The World in 2020 and Beyond”, 2016 (Year: 2016). [cited by applicant]
Kobo et al., “A Survey on Software-Defined Wireless Sensor Networks: Challenges and Design Requirements”, 2017 (Year: 2017). [cited by applicant]
Lawinsider, “minimum network requirements”, 2021 (Year: 2021). [cited by applicant]
Mocnej et al., “Decentralised IoT Architecture for Efficent Resources Utilisation”, 2018 (Year: 2018). [cited by applicant]
Rullo et al., “A Game of Things: Strategic Allocation of Security Resources for IoT”, 2017 (Year: 2017). [cited by applicant]
Sethi et al., “Internet of Things: Architecture, Protocols, and Applications”, 2017 (Year: 2017). [cited by applicant]
Srinidhi et al., “Network optimizations in the Internet ofThings: a review”, 2019 (Year: 2019). [cited by applicant]
Wikipedia, “system requirements”, 2021 (Year: 2021). [cited by applicant]
Wikipedia, “minimum viable product”, 2021 (Year: 2021). [cited by applicant]
Zahoor et al., “Resource Management in pervasive Internet of Things: a survey”, 2018 (Year: 2018). [cited by applicant]