Rogue Device Detection Through Network Interface Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing environments are vulnerable to unauthorized electronic devices that can passively monitor or actively inject malicious traffic, compromising security by gaining access to sensitive information or attacking weak points, which are not effectively detected in a timely manner.

Innovation Solution

A cross-comparison method is employed to verify the connectivity and trustworthiness of interfaces between computing devices and network devices using attestation and cross-comparison of network addresses, identifying any unauthorized devices by checking for mismatches or unattested connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network monitoring methods are used, then device connectivity can be monitored, but unauthorized devices cannot be effectively detected in a timely manner

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary attestation of devices before they are fully integrated into the network. Attestation keys are pre-distributed to authorized devices, and the attestation mechanism is established in advance, enabling immediate detection of unauthorized devices as soon as they attempt to connect, rather than detecting them after they have already compromised the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where attestation information is constantly verified and updated. The attestation status of devices is monitored in real-time, and any changes in device identity or authorization status are immediately detected and reported, enabling timely response to unauthorized device connections.

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive device verification is implemented, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary attestation mechanism that mediates between devices and the network verification system. Instead of requiring direct complex verification between all network components, the attestation key system acts as an intermediary that simplifies the verification process while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the verification parameter from complex continuous monitoring to simplified discrete attestation key verification. By transforming the security verification into checking whether specific attestation keys are present and valid, the system maintains high security while significantly reducing computational and operational complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If all device connections are monitored and verified, then unauthorized access is prevented, but processing overhead and resource consumption increase

Engineering Contradiction:
Improveaccess controlVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Attestation keys are distributed to devices in advance before they need to be verified on the network. This preliminary action allows devices to self-verify their authorization status without requiring intensive real-time processing, reducing the processing overhead during actual network operations while maintaining strict access control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of verifying device identities through complex real-time analysis, the system uses simplified attestation key copies that devices present for verification. This copying approach allows rapid verification of device authorization without the need for resource-intensive continuous monitoring and analysis of device behaviors.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12363111B2Unauthorized device detection in a computing environment
Publication Date: 2025.07.15 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12363111B2 patent drawing
  • US12363111B2 patent drawing
  • US12363111B2 patent drawing

AI summary

In some examples, a system receives information from electronic devices comprising network devices and computing devices in a computing environment that are subject to attestations of interfaces of the network devices and the computing devices. For each interface of a given computing device being attested, the system verifies that the interface of the given computing device is connected to an interface of a corresponding network device that is being attested. For each interface of a given network device being attested, the system verifies that the interface of the given network device is connected to an interface of a corresponding computing device that is being attested or an interface of another network device that is being attested. The system detects a presence of an unauthorized electronic device in the computing environment in response to determining that an interface of a computing device being attested or an interface of a network device being attested is not connected to a corresponding interface of an electronic device being attested.