Management Server Credential Verification for Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
It is challenging for authentication entities to maintain accurate reference data representing the system integrity of computing devices, particularly when these devices access networks or resources, as existing methods lack a centralized and trustworthy mechanism for verifying the integrity of software and hardware components.
Innovation Solution
A management server provisions and maintains credential reference data for client machines, which are then used to authenticate the devices by transmitting trusted platform credentials through a network access control protocol, ensuring system integrity verification is conducted by an independent authentication entity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication entities maintain reference data for system integrity verification, then authentication reliability is improved, but the complexity of maintaining accurate reference data increases
Solution Approach 1:
The patent introduces a management server as an intermediary between the authentication entity and the client machine. The management server maintains the credential reference data (hash values of software components) and provides it to the authentication entity when needed. This mediator approach resolves the contradiction by centralizing the complex task of maintaining accurate reference data in a trusted location, improving authentication reliability without burdening the authentication entity with data maintenance complexity.
Solution Approach 2:
The client machine autonomously measures the integrity of its own software components using a trusted measuring unit, generating credential data that reflects its current system state. This self-service mechanism allows the client to independently verify its own integrity without requiring the authentication entity to maintain or update reference data, thereby improving reliability while reducing the complexity of reference data management at the authentication entity.
2Measurement precision
If credential reference data is maintained at the authentication entity, then verification accuracy is improved, but the difficulty of keeping reference data synchronized with system updates increases
Solution Approach 1:
The management server acts as a synchronized intermediary that maintains credential reference data in alignment with software components it provisions to client machines. When software updates are deployed, the management server automatically updates the corresponding hash values in its database. This intermediary approach ensures measurement precision for integrity verification while eliminating the synchronization difficulty that would arise if each authentication entity had to independently track and update reference data.
Solution Approach 2:
The management server pre-computes and stores the hash values of software components at the time of provisioning or updating them on client machines. This preliminary action ensures that the credential reference data is already accurate and synchronized before authentication occurs, eliminating the need for real-time synchronization during authentication operations and maintaining high verification accuracy.
3Reliability
If system integrity verification is performed during network access, then network security is improved, but the authentication process time increases
Solution Approach 1:
The client machine continuously measures the integrity of its software components and maintains current credential data (hash values) ready for authentication. This preliminary measurement ensures that when network access is requested, the integrity verification can be performed immediately by comparing pre-computed hash values, thereby improving network security through rigorous verification while minimizing authentication process time.
Solution Approach 2:
The client machine generates a copy of its credential data (hash values of software components) and transmits it to the authentication entity for verification. This copying approach allows the authentication process to proceed quickly by comparing the transmitted credential copy against the reference data, rather than requiring complex real-time analysis of the entire system state, thus balancing network security with efficient authentication timing.
Data Source
AI summary
A request is received from a client for accessing a resource provided in a network, the request including credential data representing system integrity of at least one component running on the client. In response to the request, one or more credential identifiers identifying the credential data is transmitted to a management server that provisioned the client. Credential reference data is received from the management server based on the one or more credential identifiers. The client is authenticated based on a comparison of the credential data received from the client and credential reference data received from the management server.


