Network Element Verification via Trust Engine Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software-defined networks (SDNs), verifying the configuration of individual network elements while protecting sensitive information from clients is challenging, as direct verification may expose configuration details.

Innovation Solution

An intermediary device, such as a trust engine on a front-end server, verifies network elements on behalf of clients, using a trusted component to obtain and obfuscate configuration data, ensuring integrity and source verification without revealing sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If direct verification of network element configuration is performed, then verification completeness is improved, but information security deteriorates due to exposure of sensitive configuration details

Engineering Contradiction:
Improveverification completenessVSAvoidinformation security
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary device (trust engine) that acts as a mediator between the verification system and network elements. This intermediary obtains configuration information from network elements, verifies it against expected values, and presents only verification results without exposing sensitive configuration details to clients, thus resolving the contradiction between verification completeness and information security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts only the essential verification information from complete network element configurations. The trust engine retrieves specific configuration parameters needed for verification while leaving sensitive details behind, obtaining only the necessary information to perform verification without exposing the full configuration to clients

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If an intermediary device is introduced to protect sensitive information, then information security is improved, but system complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The trust engine performs multiple functions: it acts as a configuration verifier, an information filter, and a communication intermediary. By consolidating these functions into a single multi-functional component, the patent protects sensitive information while minimizing the increase in system complexity that would result from adding multiple separate components

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If configuration information is obfuscated to protect sensitive details, then information security is improved, but verification capability may deteriorate

Engineering Contradiction:
Improveinformation securityVSAvoidverification capability
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent applies partial obfuscation rather than complete hiding of configuration information. The trust engine obfuscates only the sensitive portions of configuration data while preserving the essential verification-critical information, thereby maintaining verification capability while protecting sensitive details from exposure

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11757717B2Verifying network elements
Publication Date: 2023.09.12 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11757717B2 patent drawing
  • US11757717B2 patent drawing
  • US11757717B2 patent drawing

AI summary

Examples relate to verifying network elements. In one example, a computing device may: receive, from a client device, a request for attestation of a back-end network, the request including back-end configuration requirements; obtain, from a network controller that controls the back-end network, a controller configuration that specifies each network element included in the back-end network; provide each network element included in the back-end network with a request for attestation of a network element configuration of the network element; receive, from each network element, response data that specifies the network element configuration of the network element; verify that the response data received from each network element meets the back-end configuration requirements included in the request for attestation of the back-end network; and provide the client device with data verifying that the back-end network meets the back-end configuration requirements.