Network Device Trust Verification via Protected Data Forwarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote attestation methods are complex and only verify trustworthiness at a specific point in time, failing to provide a simple, reliable, and versatile approach for establishing trust in network devices, particularly in distributed networks handling sensitive data.
Innovation Solution
A system and method that generate trust information data, apply modification protection, and forward it between network devices, allowing stored trust information to be used for verifying the trustworthiness of devices, including using previous trust information to protect current data, potentially leveraging blockchain for authenticity confirmation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If remote attestation is performed using complex approaches such as TM-Coin, then trust verification reliability is improved, but device complexity and implementation difficulty increase
Solution Approach 1:
The patent extracts the trust verification function into a separate remote attestation module that operates independently from the main device operations. This module specifically handles trust information generation, protection, and verification, separating complex security functions from general device functionality, thereby improving reliability without unnecessarily complicating the entire system.
Solution Approach 2:
The patent introduces an intermediary trust information structure that mediates between the device and the verification system. This trust information, which includes device identity, capability information, and status data, serves as a standardized intermediary representation that simplifies the verification process while maintaining high reliability through structured and protected trust data.
2Speed
If trust verification is performed only at a specific point in time, then verification speed is improved, but trust reliability over time deteriorates
Solution Approach 1:
The patent performs preliminary actions by generating and protecting trust information in advance before actual verification is needed. The device continuously maintains updated trust information that reflects its current state, so when verification is required, the process is rapid because the trust data is already prepared and protected, yet it remains reliable because it reflects the device's state at the time of verification.
Solution Approach 2:
The patent implements dynamic trust verification where trust information is not static but updates based on device state changes. The trust information includes temporal elements and can be regenerated when device capabilities or status change, allowing the system to maintain both speed (by using cached trust data when unchanged) and reliability (by updating when necessary).
3Ease of operation
If trust information is not protected against manipulation, then ease of operation is improved, but security and trustworthiness deteriorate
Solution Approach 1:
The patent replaces manual or simple trust information handling with automated cryptographic protection mechanisms. Trust information is automatically signed, encrypted, and verified using cryptographic algorithms, eliminating the need for manual security management while ensuring high trustworthiness. The system handles protection transparently, maintaining ease of operation despite the sophisticated security measures in place.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
The present invention relates to establishing trust of a network device. For this purpose, trust information data referring to a first network device are generated and protected. The protected trust information data are forwarded to a second network device. The second network device stores the protected trust information of the first network device. Further, the second network device may forward the stored trust information data to a further network device upon request. In particular, a request for protected trust information data may refer to trust information data referring to a point in time or a period of time in the past. In this way, protected trust information data can be provided by a network device which is separated from the network device on which trust has to be established. By providing trust information data of previous point in time, the protection of the trust information data may make reference to previous trust information data. Thus, protection approaches such as blockchain can be applied.