Attestation-Based Peering Validation for Critical Infrastructure Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for validating the integrity and trustworthiness of devices within a network, particularly in critical infrastructure, are inadequate, as they often rely on insufficient security measures like TLS and L2/L3 encryption, which can be compromised, and lack accurate verification of device trustworthiness over time.

Innovation Solution

An attestation-based scheme is implemented to validate peering setups for critical infrastructure protocols, using TPM measurement validation tokens and Known Good Values (KGVs) to verify the integrity of applications and kernels, enhancing protocols like ARP, NDP, DHCP, and SSH with attestation mechanisms to ensure trustworthiness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional protection methods like TLS and L2/L3 encryption are used, then secure communication channels are established, but they can be compromised by root access exploits and do not provide adequate verification of device trustworthiness

Engineering Contradiction:
Improvedevice trustworthinessVSAvoidcompromise risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs integrity verification of device binaries and components before establishing communication channels. Attestation measurements are collected and validated in advance, ensuring that only devices with verified trustworthiness can communicate, thereby preventing compromise before it occurs

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary attestation validation mechanism that acts as a mediator between devices. This intermediary verifies integrity measurements and trustworthiness credentials, providing an additional layer of verification beyond direct TLS encryption between endpoints

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If active measurements are used for validation of device processing traffic, then verification accuracy improves, but the cost and complexity of validation increases

Engineering Contradiction:
Improveverification accuracyVSAvoidvalidation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts and validates only the critical integrity measurements and attestation data needed for verification, rather than performing comprehensive active measurements of all device operations. This selective approach maintains verification accuracy while reducing validation complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs partial validation by focusing on key integrity measurements and attestation credentials rather than complete active monitoring of all device processes, achieving adequate verification accuracy without the full complexity of exhaustive validation

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12363191B2Attestation-based scheme for validating peering setups for critical infrastructure protocols
Publication Date: 2025.07.15 CISCO TECHNOLOGY INC
  • US12363191B2 patent drawing
  • US12363191B2 patent drawing
  • US12363191B2 patent drawing

AI summary

A verifier peer system transmits a request to an application of another peer system to obtain integrity data of the application. In response to the request, the verifier peer system obtains a response that includes kernel secure boot metrics of the other peer system and integrity data of the application and of any application dependencies. If the verifier peer system determines that the response is valid, the verifier peer system evaluates the integrity data and the kernel secure boot metrics against a set of Known Good Values to determine whether the integrity data and the kernel secure boot metrics are valid. If the integrity data and the kernel secure boot metrics are valid, the verifier peer system determines that the other peer system is trustworthy.