Tri-element Peer Authentication Network Connect Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security protection techniques, such as TCG-TNC, fail to effectively evaluate the integrity of the policy enforcement point, making them unreliable against malicious attacks, particularly from rootkits.

Innovation Solution

A Tri-element Peer Authentication (TePA)-based Trusted Network Connect architecture is established, which includes specific interfaces and protocols like IF-TNT, IF-APS, IF-TNCCAP, and IF-EPS, enabling endpoint integrity measurement, authentication, and policy enforcement through a trusted third-party authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TCG-TNC architecture is used for network access control, then endpoint integrity can be protected, but the policy enforcement point integrity cannot be evaluated

Engineering Contradiction:
Improveendpoint integrity protectionVSAvoidpolicy enforcement point integrity evaluation
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system is segmented into three distinct authentication elements: the network access requestor (NAR), the network access controller (NAC), and the authentication policy server (APS). Each element performs integrity measurement and authentication independently, allowing the policy enforcement point (NAC) to be evaluated separately from the endpoint, thus resolving the inability to measure policy enforcement point integrity in traditional TCG-TNC.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication policy server acts as a trusted intermediary that receives integrity measurements from both the endpoint and the policy enforcement point, performs verification, and makes authentication decisions. This intermediary enables independent evaluation of the policy enforcement point's integrity without compromising endpoint protection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional security protection techniques are used, then basic transmission security can be maintained, but protection against rootkits and malicious attacks is insufficient

Engineering Contradiction:
Improvetransmission securityVSAvoidrootkit attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs integrity measurement and authentication actions before network access is granted. The endpoint and policy enforcement point must prove their integrity status in advance through cryptographic verification, preventing rootkits and malicious software from establishing compromised connections. This preliminary verification blocks harmful factors before they can affect the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces conventional mechanical security protections (firewalls, antivirus) with a trust-based cryptographic authentication mechanism. By using TPM-based integrity measurements and cryptographic verification, the system can detect and block rootkits that would otherwise evade traditional security software, providing stronger protection against sophisticated malicious attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If Tri-element Peer Authentication architecture is implemented, then policy enforcement point integrity can be evaluated, but system complexity increases

Engineering Contradiction:
Improvepolicy enforcement point integrity evaluationVSAvoidauthentication system structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The three authentication elements (NAR, NAC, APS) are designed with universal interfaces and standardized protocols that can handle multiple authentication scenarios. The same integrity measurement and verification mechanisms are reused across different authentication contexts, reducing overall system complexity despite the multi-element architecture. The modular design allows each component to perform multiple functions within the authentication framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2421215B1Method for establishing trusted network connect framework of tri-element peer authentication
Publication Date: 2020.04.22 CHINA IWNCOMM
  • EP2421215B1 patent drawingFigure 1~2
  • EP2421215B1 patent drawingFigure 3
  • EP2421215B1 patent drawingFigure 4

AI summary

The present invention provides a method for establishing the trusted network connect framework of tri-element peer authentication. The method includes: the implement of trusted network transport interface (IF-TNT); the implement of authentication policy service interface (IF-APS); the implement of trusted network connect (TNC) client -TNC access point interface (IF-TNCCAP); the implement of evaluation policy service interface (IF-EPS); the implement of integrity measurement collector interface (IF-IMC); the implement of integrity measurement verifier interface (IF-IMV); and the implement of integrity measurement (IF-IM). The embodiments of the present invention can establish the trust of the terminals, implement the trusted network connect of the terminals, implement the trusted authentication among the terminals, implement the trusted management of the terminals, and establish the TNC framework based on tri-element peer authentication (TePA) by defining the interfaces.