Network Element Authentication for Field Replaceable Units

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Counterfeit removable components in network elements, such as transceivers and field replaceable units, pose a significant threat as they can be illicitly produced or cloned, compromising network security and integrity.

Innovation Solution

A network element authenticates transceivers and field replaceable units by generating and comparing signatures using a nonce and secure storage keys, ensuring only authentic components are used for communication and operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic authentication mechanisms are implemented to detect counterfeit components, then network security and integrity are improved, but device complexity increases due to additional authentication hardware and software components

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-storing authentication data (public keys, signatures) in secure hardware locations within the network element before operation. The authentication process then involves comparing pre-computed signatures with stored reference data, eliminating the need for complex real-time cryptographic computations and reducing operational complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating cryptographic copies (signatures) of authentication data that can be stored and compared. Instead of requiring complex live verification, the system creates pre-computed signature copies that are stored in secure memory, allowing simple comparison operations during authentication that reduce computational complexity while ensuring security.

Inventive Principle:
Principle #26Copying

2Difficulty of detecting and measuring

If signature verification using nonces and secure storage is implemented, then counterfeit component detection capability is improved, but manufacturing complexity increases due to additional authentication data storage requirements

Engineering Contradiction:
Improvecounterfeit detection capabilityVSAvoidmanufacturing complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSEase of manufacture

Solution Approach 1:

The patent applies preliminary action by pre-computing and storing authentication signatures during the manufacturing process. The network element's secure storage is pre-loaded with reference authentication data before deployment, so that during operation the system only needs to perform simple comparison operations rather than complex cryptographic computations, thereby maintaining high counterfeit detection capability while simplifying manufacturing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses self-service by having the authentication system serve its own verification needs through pre-stored reference data. The system's secure storage automatically provides authentication references without requiring external computational resources or complex verification procedures, allowing the system to verify counterfeit components using simple built-in comparison operations.

Inventive Principle:
Principle #25Self-service

3Reliability

If transceiver authentication is implemented before allowing communication, then network integrity is improved, but communication setup time increases due to additional authentication verification steps

Engineering Contradiction:
Improvenetwork integrityVSAvoidcommunication setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing authentication verification before the transceiver is allowed to communicate. The system pre-stores authentication signatures and reference data in secure memory, enabling rapid comparison operations that can be completed quickly. This preliminary preparation of authentication data allows the system to verify transceiver authenticity before communication begins without requiring time-consuming real-time cryptographic computations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10256980B2System and method for authentication for field replaceable units
Publication Date: 2019.04.09 ARISTA NETWORKS INC
  • US10256980B2 patent drawing
  • US10256980B2 patent drawing
  • US10256980B2 patent drawing

AI summary

A method and apparatus of a network element that authenticates a field replaceable unit of the network element is described. The network element authenticates a field replaceable unit of the network element by generating a nonce. In addition, the network element generates a signature using a nonce and a private encryption key that is securely stored in the field replaceable unit. The network element further verifies the signature using a public encryption key that is a pair to the private encryption key and is not securely stored in the field replaceable unit. If the field replaceable unit is verified, the network element uses the field replaceable unit to operate the network element. Otherwise, the network element disables the field replaceable unit.