Network Device Authentication via TPM and CA Certificate
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Counterfeit network devices compromise network security by allowing unauthorized access, as they can be configured to embed malicious code or unauthorized access points, necessitating a method to verify their authenticity before integrating them into a network.
Innovation Solution
Integration of a Trusted Platform Module (TPM) with a unique endorsement key (EK) and a certification authority (CA) certificate, which verifies the device's authenticity through local or remote attestation processes using attestation identity keys (AIKs) and authentication tokens, ensuring the device's origin and legitimacy before allowing network operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If network devices are deployed without authentication, then device deployment speed is improved, but network security deteriorates due to counterfeit devices with malicious code
Solution Approach 1:
The patent implements preliminary authentication of network devices before they are deployed into the network. The remote server verifies the authenticity of devices using cryptographic credentials (such as digital certificates or hardware-based authentication) before allowing them to join the network. This preliminary action ensures that only genuine devices can be deployed, preventing counterfeit devices with malicious code from compromising network security while still enabling efficient device onboarding through automated verification processes.
2Object-affected harmful factors
If authentication verification is performed on all devices, then network security is improved, but device complexity increases due to additional authentication components
Solution Approach 1:
The patent introduces a remote server as an intermediary that handles the complex authentication and verification processes. Instead of embedding complex authentication logic within each network device, the authentication credentials are stored in the devices, but the verification process is performed by the remote server. This mediator approach maintains network security through thorough verification while keeping individual devices relatively simple in structure.
3Object-affected harmful factors
If remote attestation is required before network access, then unauthorized access is prevented, but access time increases due to verification delays
Solution Approach 1:
The patent performs remote attestation and authentication verification as a preliminary action before devices gain network access. The remote server verifies device credentials, checks for malicious code, and validates device authenticity before granting network entry. This preliminary verification prevents unauthorized access while the automated nature of the process minimizes access time delays.
4Measurement precision
If cryptographic verification is performed on device credentials, then device authenticity is ensured, but processing overhead increases
Solution Approach 1:
The patent uses a remote server as an intermediary to perform computationally intensive cryptographic verification operations. The network devices store cryptographic credentials but delegate the verification process to the remote server, which has the computational resources to handle complex cryptographic operations efficiently. This distribution of processing load ensures high accuracy in authenticity verification while minimizing the processing overhead on individual network devices.
Data Source
AI summary
A method for authenticating an origin of a network device. The method includes reading one or more encrypted parameters from a memory of the network device, decoding the one or more encrypted parameters, and determining whether one or more of the decoded parameters match parameters obtained from a trusted platform module (TPM) installed in the network device and/or a read only memory (ROM) of the network device. In response to a mismatch between the decoded parameters and the parameters obtained from the TPM or the ROM, at least one of suspending operation of the device or transmitting a report of an authentication failure across a network on which the device is operating.


