Signed Trust Evaluation Reports for Secure Network Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trust relationship models based on Public Key Infrastructure (PKI) and certificates are inadequate for evaluating the legitimacy and security posture of network entities, as they do not verify ownership or address potential security vulnerabilities, leading to risks in device communication.

Innovation Solution

A method involving a Trusted Network Entity (TNE) that collects and signs trust evaluation information (TEI) including secure boot information, remote attestation, CVE scores, trust indices, and risk indices, which are used by network entities to establish secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI and certificates are used to establish trust relationship, then authentication between network entities is achieved, but the ability to evaluate security posture and vulnerability is insufficient

Engineering Contradiction:
Improvetrust relationshipVSAvoidsecurity evaluation
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The trust evaluation report is segmented into multiple distinct components including security configuration data, vulnerability information, patch status, and trust metrics. Each component addresses a specific aspect of security posture, allowing comprehensive evaluation while maintaining modular structure for easier verification and processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted intermediary entity is introduced to generate and sign the trust evaluation report. This intermediary collects security data from network entities, performs comprehensive evaluation, and provides a signed report that both parties can trust. The intermediary acts as a neutral third party that bridges the trust gap between communicating entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive security evaluation data is collected and shared, then trust assessment accuracy is improved, but communication overhead and processing complexity increase

Engineering Contradiction:
Improvetrust assessmentVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Security evaluation data is collected and the trust report is generated in advance before actual communication occurs. The trusted intermediary performs comprehensive security assessment, vulnerability scanning, and patch verification beforehand, so that when communication is needed, the evaluation is already complete and ready for immediate use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trust evaluation report transforms complex security data into simplified parametric metrics including trust scores, vulnerability counts, and compliance indicators. These standardized parameters make it easier to process, compare, and act upon security information without dealing with the full complexity of raw security data.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12418528B2Establishment of secure communication
Publication Date: 2025.09.16 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12418528B2 patent drawing
  • US12418528B2 patent drawing
  • US12418528B2 patent drawing

AI summary

Methods and apparatus for establishing enhanced secure communication between two Network Entities. A method performed by a first Network Entity (NE1) to establish communication between the NE1 and a second Network Entity (NE2), wherein both NE1 and NE2 trust a Trusted Network Entity (TNE). The method comprises establishing an initial connection with the NE2, obtaining a report associated with NE1 from TNE, wherein the report is signed by the TNE and providing the report associated with NE1 to NE2.