Network Access Authentication via System Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network access authentication methods only verify the presence of passwords or keys, failing to ensure that a device is secure from internal threats like Trojan Horse viruses, which can compromise network security.
Innovation Solution
A method where a network access authentication device pre-stores system integrity values for devices, with the device calculating and sending its current integrity value for verification, ensuring that only matching integrity values allow network access, and using secure storage and cryptographic techniques to authenticate credibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication protocols (password, key, certificate) are used to verify device identity, then network access control is achieved, but the device cannot be protected from internal threats such as Trojan Horse viruses that compromise system integrity
Solution Approach 1:
The patent applies preliminary action by pre-calculating and storing the system integrity value (first hash value) of the device's system files, kernel, and other critical components before network access. This pre-computed integrity baseline is stored securely and used during authentication to detect any unauthorized modifications or malware infections, thereby preventing internal threats before they can compromise network security.
Solution Approach 2:
The patent introduces an intermediary mechanism - a trusted authentication server that mediates between the device and the network. The server receives the device's integrity proof (second hash value), compares it with the pre-stored first hash value, and makes the authentication decision. This intermediary verifies system integrity without requiring the device to expose sensitive credentials, enhancing security while maintaining manageable authentication complexity.
2Reliability
If system integrity verification is added to authentication process, then device security is ensured, but authentication processing complexity increases
Solution Approach 1:
The patent replaces traditional mechanical authentication mechanisms (password entry, key exchange, certificate verification) with a cryptographic hash-based integrity verification system. Instead of relying on secret credentials that can be stolen or compromised, the system uses cryptographic hashing to verify system integrity. This substitution simplifies the authentication process by eliminating complex credential management while providing stronger security guarantees against internal threats.
Data Source
AI summary
A method for realizing network access authentication, wherein a network access authentication device pre-storing a system integrity value of a device waiting to access and a correspondence between each device waiting to access and its system integrity value. When the device waiting to access needs to access the network, it acquires its current system integrity value, and sends the current system integrity value to the network access authentication device; the network access authentication device judges whether the received current system integrity value of the device waiting to access and its stored integrity value of the device waiting to access are identical or not, and in a case where the received current system integrity value of the device waiting to access and its stored integrity value of the device waiting to access are identical, it determines that the network access is authenticated. As such, the network access device could determine the real status of the device waiting to access, and ensure the device accessing to the network is really secure, thereby ensuring the security of the network.


