IPsec Trust Verification via Remote Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Internet Protocol Security (IPsec) protocol ensures communication security but fails to determine if communication entities are in a trusted execution state, leaving the security of the communication process vulnerable if any entity is in an untrusted state.
Innovation Solution
A communication method and apparatus that perform trustworthiness measurement by sending a data packet with request information to verify if a second network element is trusted, using remote attestation to initiate a verification request and respond with attestation information or results, thereby ensuring the security of the communication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPsec protocol is used to ensure communication security, then communication security is improved, but the ability to determine trusted execution state of communication entities deteriorates
Solution Approach 1:
The patent combines IPsec protocol with remote attestation technology into a unified communication framework. The trust verification process is merged with the existing IPsec authentication mechanism, allowing both security encryption and trustworthiness verification to occur within the same communication channel without requiring separate systems.
Solution Approach 2:
The communication protocol is designed to serve multiple functions simultaneously: it provides both traditional IPsec security services (confidentiality, integrity) and trust verification services (execution state validation). The same data packet structure supports both encryption authentication and remote attestation, making the system multi-functional.
2Reliability
If trustworthiness measurement is performed during communication establishment, then security of communication entities is improved, but resource overheads worsen
Solution Approach 1:
The trust verification process is performed in advance during the communication establishment phase, specifically during IKE (Internet Key Exchange) negotiation. By completing the remote attestation and trust verification before actual data transmission begins, the system ensures security without adding overhead to the ongoing communication process.
Solution Approach 2:
The verifying device autonomously performs trust verification by independently obtaining and validating the attestation report from the verified device. The system uses self-contained cryptographic proof mechanisms where the verified device signs its own execution state, eliminating the need for continuous external verification services.
3Measurement precision
If challenge value is included in every verification request, then verification accuracy is improved, but data packet size and transmission overhead worsen
Solution Approach 1:
The patent applies challenge values selectively rather than universally. Challenge values are included in verification requests only when specifically needed for certain types of trust verification scenarios. The protocol supports both challenge-based verification and challenge-free verification modes, allowing the system to adapt the verification approach to the specific security requirements of each communication context.
Data Source
AI summary
A communication method integrated with trustworthiness measurement, including: a first network element sends a first data packet, where the first data packet includes first request information, and the first request information is used to request to verify whether a second network element is trusted. The first network element receives a second data packet, where the second data packet includes first response information, and the first response information is used to verify whether the second network element is trusted.


