Optical Transport Network Attestation Protocol
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In optical transport networks (OTNs), existing technologies lack effective solutions for secure, real-time reporting of active trustworthiness measurements, making it challenging to validate the integrity of devices and ensure secure data transmission.
Innovation Solution
The implementation of attestation protocols in OTNs, where a relying node receives attestation information from an attester node, verifies its trustworthiness, and controls network service access based on identified trust levels, using techniques like TPM-integrated capabilities and metadata elements to provide verifiable proof of integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If active measurements are implemented to validate device trustworthiness in real-time, then network security and reliability are improved, but system complexity and implementation difficulty increase
Solution Approach 1:
The patent introduces an intermediary attestation mechanism where trust measurements are collected and verified through a standardized protocol framework. This intermediary layer handles the complexity of trust validation, allowing network devices to maintain reliability without each device implementing complex verification logic independently.
Solution Approach 2:
The attestation protocol is designed as a universal framework that can be applied across multiple network device types and scenarios. By creating a multi-functional protocol that handles various trust validation requirements through a unified approach, the system reduces overall complexity while maintaining comprehensive security coverage.
2Reliability
If secure real-time reporting of trustworthiness measurements is implemented, then network integrity verification is improved, but communication overhead and processing requirements increase
Solution Approach 1:
The patent extracts the computationally intensive trust measurement calculations from the reporting path and performs them locally at the source. Only the essential verification results are transmitted through the network, significantly reducing communication overhead and processing requirements while maintaining comprehensive integrity verification.
Solution Approach 2:
The protocol implements partial verification where only critical trust attributes are validated in real-time, while less critical attributes are verified asynchronously or on-demand. This selective approach maintains network integrity verification effectiveness while reducing immediate processing requirements and energy consumption.
3Reliability
If attestation protocols are integrated into optical transport networks, then device authentication and security are improved, but protocol adaptation and implementation complexity increase
Solution Approach 1:
The attestation protocol is segmented into distinct functional modules that can be independently implemented and configured for different optical transport network scenarios. This modular segmentation allows selective deployment of authentication capabilities, reducing overall implementation complexity while maintaining robust device authentication.
Solution Approach 2:
The protocol incorporates configurable parameters that allow adaptation to different optical transport network environments without changing the core authentication mechanism. By enabling parameter adjustment rather than protocol redesign, the system achieves flexible deployment across diverse scenarios while maintaining consistent security standards.
Data Source
AI summary
The present technology discloses methods, systems, and non-transitory computer-readable media for receiving, by a relying node in an optical transport network environment, attestation information in a trail trace identifier of an optical unit from an attester node in the optical transport network environment; verifying a trustworthiness of the attester node by identifying a level of trust of the attester node from the attestation information; and controlling network service access of the attester node through the relying node in the network environment based on the level of trust of the attester node identified from the attestation information.


