Adjacent-Node Remote Attestation for Credible Network Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network attestation methods are inefficient and vulnerable to attacks due to indirect communication links and unpredictable response times, especially in networks with many distributed nodes, leading to increased computing and timing costs and potential security breaches.

Innovation Solution

A method where adjacent nodes in a network collectively attest a first node, generating multiple attestation results that are combined to determine credibility, using a challenge-response strategy with response time thresholds and credit values to quickly identify and disconnect untrustworthy nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If indirect communication links are used for node attestation, then network coverage can be extended, but response time becomes unpredictable and security vulnerability increases

Engineering Contradiction:
Improvenetwork coverageVSAvoidresponse time uncertainty
Core Design Contradiction:
Area of stationary objectVSLoss of time

Solution Approach 1:

The patent introduces adjacent nodes as intermediaries that directly communicate with the target node for attestation purposes. Instead of remote nodes performing attestation through multiple hops, the adjacent nodes act as mediators that can directly verify the target node's credentials and transmit results to remote nodes, thereby maintaining extended network coverage while ensuring predictable and secure response times through direct communication links.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple adjacent nodes perform attestation collectively, then credibility determination becomes more accurate, but communication overhead and system complexity increase

Engineering Contradiction:
Improvecredibility determination accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges the attestation results from multiple adjacent nodes through a standardized protocol that aggregates their individual assessments. By combining the verification outcomes from multiple independent adjacent nodes, the system achieves more accurate credibility determination while managing complexity through a unified result aggregation mechanism that processes multiple inputs into a single comprehensive attestation result.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If response time thresholds are enforced in challenge-response strategy, then security against attacks is improved, but legitimate communication may be blocked due to timing constraints

Engineering Contradiction:
Improvesecurity against attacksVSAvoidcommunication reliability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic adjustment of response time thresholds based on the specific attestation context, node types, and network conditions. Rather than applying a fixed timing constraint, the system adapts the time threshold parameters to balance security requirements with operational needs, allowing legitimate communications with reasonable processing times to succeed while still blocking maliciously slow responses that indicate attacks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3769470B1Remote attestation in network
Publication Date: 2026.02.18 NOKIA TECHNOLOGIES OY
  • EP3769470B1 patent drawingFigure 1
  • EP3769470B1 patent drawingFigure 2
  • EP3769470B1 patent drawingFigure 3

AI summary

The present disclosure relates to a remote attestation in a network. Embodiments provide a method comprising: attesting a first node in a network, by a node adjacent to the first node in the network; and generating an attestation result of the first node. A plurality of attestation results of the first node generated by a plurality of nodes adjacent to the first node in the network are combined to determine a credibility of the first node. In such embodiments, a fixed verifier for other nodes is eliminated, and a risk of a collapse due to a failure of such fixed verifier may be avoided.