Attestation-Based Route Reflector for Network Device Trust Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security measures, such as Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols, are insufficient in validating the integrity of network devices like routers, especially when compromised, and traditional verification methods are expensive and lack accuracy.
Innovation Solution
Implementing a route reflector within an autonomous system to gather validation tokens from network devices, generate a validation token nest, and advertise this information through BGP update messages, ensuring the trustworthiness of network devices along a network path.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional verification methods (TLS/SSL) are used to establish secure communication channels, then communication security is improved, but device integrity validation is insufficient when devices are compromised
Solution Approach 1:
The patent implements preliminary verification by obtaining validation tokens for each network device in the path before routing traffic. The route reflector gathers validation tokens from network devices and generates a validation token nest that is advertised through BGP update messages, allowing verification to occur in advance rather than during active traffic flow.
Solution Approach 2:
The patent introduces a route reflector as an intermediary component that mediates between network devices and verifies their integrity. The route reflector obtains validation tokens, generates the validation token nest, and advertises it to relevant routers, acting as a trusted third party that simplifies the verification process for other devices.
2Measurement precision
If active measurement verification is used to validate router processing traffic, then validation accuracy is improved, but verification cost and complexity increase significantly
Solution Approach 1:
Instead of performing expensive active measurements during traffic flow, the patent obtains validation tokens in advance from network devices. These tokens are gathered by the route reflector and stored in a validation token repository, allowing verification to occur without disrupting normal traffic or requiring complex active measurement systems.
Solution Approach 2:
The patent creates a validation token nest that is a simplified representation or copy of the actual device validation state. This token nest can be advertised and verified through standard BGP protocols without requiring the complexity of active measurement systems, while still providing accurate validation information.
3Reliability
If validation tokens are gathered for all network devices and advertised through BGP, then trustworthiness assessment is improved, but information overhead and processing load increase
Solution Approach 1:
The patent merges individual validation tokens from multiple network devices into a single validation token nest structure. This consolidated representation is then advertised through BGP update messages, reducing the information overhead compared to transmitting separate validation data for each device while maintaining the ability to assess trustworthiness of the entire path.
Data Source
AI summary
A verifier peer system transmits a request to an application of another peer system to obtain integrity data of the application. In response to the request, the verifier peer system obtains a response that includes kernel secure boot metrics of the other peer system and integrity data of the application and of any application dependencies. If the verifier peer system determines that the response is valid, the verifier peer system evaluates the integrity data and the kernel secure boot metrics against a set of Known Good Values to determine whether the integrity data and the kernel secure boot metrics are valid. If the integrity data and the kernel secure boot metrics are valid, the verifier peer system determines that the other peer system is trustworthy.


