IPsec Trust Verification via Remote Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Internet Protocol Security (IPsec) protocol ensures communication security but fails to determine if communication entities are in a trusted execution state, leaving the security of the communication process vulnerable if any entity is in an untrusted state.

Innovation Solution

A communication method and apparatus that perform trustworthiness measurement by sending a data packet with request information to verify if a second network element is trusted, using remote attestation to initiate a verification request and respond with attestation information or results, thereby ensuring the security of the communication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPsec protocol is used to ensure communication security, then communication security is improved, but the ability to determine trusted execution state of communication entities deteriorates

Engineering Contradiction:
Improvecommunication securityVSAvoidtrust verification capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines IPsec protocol with remote attestation technology into a unified communication framework. The trust verification process is merged with the existing IPsec authentication mechanism, allowing both security encryption and trustworthiness verification to occur within the same communication channel without requiring separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The communication protocol is designed to serve multiple functions simultaneously: it provides both traditional IPsec security services (confidentiality, integrity) and trust verification services (execution state validation). The same data packet structure supports both encryption authentication and remote attestation, making the system multi-functional.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If trustworthiness measurement is performed during communication establishment, then security of communication entities is improved, but resource overheads worsen

Engineering Contradiction:
Improvesecurity of communication entitiesVSAvoidresource overheads
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The trust verification process is performed in advance during the communication establishment phase, specifically during IKE (Internet Key Exchange) negotiation. By completing the remote attestation and trust verification before actual data transmission begins, the system ensures security without adding overhead to the ongoing communication process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verifying device autonomously performs trust verification by independently obtaining and validating the attestation report from the verified device. The system uses self-contained cryptographic proof mechanisms where the verified device signs its own execution state, eliminating the need for continuous external verification services.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If challenge value is included in every verification request, then verification accuracy is improved, but data packet size and transmission overhead worsen

Engineering Contradiction:
Improveverification accuracyVSAvoiddata packet size
Core Design Contradiction:
Measurement precisionVSVolume of moving object

Solution Approach 1:

The patent applies challenge values selectively rather than universally. Challenge values are included in verification requests only when specifically needed for certain types of trust verification scenarios. The protocol supports both challenge-based verification and challenge-free verification modes, allowing the system to adapt the verification approach to the specific security requirements of each communication context.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240364542A1Communication method integrated with trustworthiness measurement and apparatus
Publication Date: 2024.10.31 HUAWEI TECH CO LTD
  • US20240364542A1 patent drawing
  • US20240364542A1 patent drawing
  • US20240364542A1 patent drawing

AI summary

A communication method integrated with trustworthiness measurement, including: a first network element sends a first data packet, where the first data packet includes first request information, and the first request information is used to request to verify whether a second network element is trusted. The first network element receives a second data packet, where the second data packet includes first response information, and the first response information is used to verify whether the second network element is trusted.