Optical Transport Network Attestation Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In optical transport networks (OTNs), existing technologies lack effective solutions for secure, real-time reporting of active trustworthiness measurements, making it challenging to validate the integrity of devices and ensure secure data transmission.

Innovation Solution

The implementation of attestation protocols in OTNs, where a relying node receives attestation information from an attester node, verifies its trustworthiness, and controls network service access based on identified trust levels, using techniques like TPM-integrated capabilities and metadata elements to provide verifiable proof of integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If active measurements are implemented to validate device trustworthiness in real-time, then network security and reliability are improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvedevice trustworthiness validationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary attestation mechanism where trust measurements are collected and verified through a standardized protocol framework. This intermediary layer handles the complexity of trust validation, allowing network devices to maintain reliability without each device implementing complex verification logic independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The attestation protocol is designed as a universal framework that can be applied across multiple network device types and scenarios. By creating a multi-functional protocol that handles various trust validation requirements through a unified approach, the system reduces overall complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If secure real-time reporting of trustworthiness measurements is implemented, then network integrity verification is improved, but communication overhead and processing requirements increase

Engineering Contradiction:
Improvenetwork integrity verificationVSAvoidprocessing requirements
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the computationally intensive trust measurement calculations from the reporting path and performs them locally at the source. Only the essential verification results are transmitted through the network, significantly reducing communication overhead and processing requirements while maintaining comprehensive integrity verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The protocol implements partial verification where only critical trust attributes are validated in real-time, while less critical attributes are verified asynchronously or on-demand. This selective approach maintains network integrity verification effectiveness while reducing immediate processing requirements and energy consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If attestation protocols are integrated into optical transport networks, then device authentication and security are improved, but protocol adaptation and implementation complexity increase

Engineering Contradiction:
Improvedevice authenticationVSAvoidprotocol adaptation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The attestation protocol is segmented into distinct functional modules that can be independently implemented and configured for different optical transport network scenarios. This modular segmentation allows selective deployment of authentication capabilities, reducing overall implementation complexity while maintaining robust device authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The protocol incorporates configurable parameters that allow adaptation to different optical transport network environments without changing the core authentication mechanism. By enabling parameter adjustment rather than protocol redesign, the system achieves flexible deployment across diverse scenarios while maintaining consistent security standards.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11122346B1Attestation in optical transport network environments
Publication Date: 2021.09.14 CISCO TECHNOLOGY INC
  • US11122346B1 patent drawing
  • US11122346B1 patent drawing
  • US11122346B1 patent drawing

AI summary

The present technology discloses methods, systems, and non-transitory computer-readable media for receiving, by a relying node in an optical transport network environment, attestation information in a trail trace identifier of an optical unit from an attester node in the optical transport network environment; verifying a trustworthiness of the attester node by identifying a level of trust of the attester node from the attestation information; and controlling network service access of the attester node through the relying node in the network environment based on the level of trust of the attester node identified from the attestation information.