Network Equipment Enclave Attestation for Secure Credential Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for providing Vendor Hardware Credentials (VCs) to network equipment are costly and operationally complex, requiring extensive personnel vetting, secure environment maintenance, and frequent inspections to ensure security and authenticity.

Innovation Solution

The method involves network equipment performing measurements on its properties using an enclave, attesting these measurements, and then requesting a VC certificate from a server. The server provides the VC certificate, which is stored securely within the network equipment, reducing the need for on-site inspections and complex security protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional PKI service access control is used with personnel vetting and secure environment maintenance, then security and authenticity of VC credentials are ensured, but operational costs and complexity increase significantly

Engineering Contradiction:
Improvesecurity and authenticityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network equipment performs self-attestation by measuring its own properties and generating cryptographic proofs of its authentic state, eliminating the need for manual personnel vetting and secure environment maintenance while maintaining security and authenticity guarantees

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual administrative security controls (personnel vetting, physical secure environments, inspections) with automated cryptographic mechanisms (enclave measurements, attestation protocols, certificate validation) that provide equivalent security guarantees without operational complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If frequent inspections and secure environment maintenance are performed, then security of VC provisioning is maintained, but productivity and efficiency decrease

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidprovisioning efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The network equipment performs measurements and attestation of its authentic state before VC certificate issuance, pre-validating its security posture so that no post-provisioning inspections are needed, thereby enabling immediate provisioning without delaying efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The attestation mechanism provides continuous feedback about the authentic state of the network equipment to the PKI service, enabling automated trust decisions without manual inspections and allowing rapid provisioning cycles while maintaining security

Inventive Principle:
Principle #23Feedback

3Reliability

If centralized PKI service with access control is used, then credential security is ensured, but operational costs increase due to personnel management and secure environment requirements

Engineering Contradiction:
Improvecredential securityVSAvoidoperational costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The network equipment autonomously generates measurements and attestation proofs of its own authentic state, eliminating the need for costly manual verification processes and secure physical environment maintenance while maintaining credential security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses cryptographic copies (hashes, measurements, attestation tokens) of the network equipment's state that can be verified remotely without requiring physical access or expensive secure environments, replacing costly in-person verification with low-cost digital validation

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3688948B1Provisioning of vendor credentials
Publication Date: 2025.04.30 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3688948B1 patent drawingFigure 1
  • EP3688948B1 patent drawingFigure 2
  • EP3688948B1 patent drawingFigure 3

AI summary

There is provided mechanisms for obtaining a VC certificate from a server. A method is performed by network equipment. The method comprises performing (S104), by an enclave of the network equipment, measurements on at least one property of the network equipment. The method comprises providing (S108), by the enclave, a request for the VC certificate from the server upon having attested the measurements. The method comprises receiving (S110), from the server, the VC certificate in response to the request and storing the VC certificate in the network equipment.