Tri-Element Peer Authentication Protocol for TNC Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Trusted Computing Group (TCG)-based Trusted Network Connect (TNC) architecture lacks a suitable platform authentication protocol for the Tri-element Peer Authentication (TePA)-based TNC architecture, which is necessary for enhanced network security and integrity verification.

Innovation Solution

A platform authentication method is developed for a TePA-based TNC architecture, involving a tri-element peer authentication protocol where the TNC client, TNC access point, and evaluation policy server interact to request and verify integrity measurement values and platform identity certificates, facilitating centralized management and diverse deployments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the TCG-TNC architecture is used with conventional platform authentication protocols, then the architecture can be implemented with existing standards, but the policy enforcement point cannot be relied upon for integrity verification

Engineering Contradiction:
Improveintegrity verification reliabilityVSAvoidauthentication architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into three distinct components: the TNC client, the TNC access point, and the evaluation policy server. Each component has specific responsibilities - the client initiates authentication, the access point verifies integrity through IMC/IMV interfaces, and the evaluation policy server enforces policies. This segmentation allows each component to be optimized for its specific function while maintaining overall system reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The evaluation policy server acts as an intermediary between the TNC access point and the authentication policy server. It receives integrity measurement values from the access point, evaluates them against predefined policies, and makes authentication decisions. This intermediary layer enhances reliability by adding an additional verification step while managing complexity through centralized policy evaluation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a Tri-element Peer Authentication (TePA) architecture is implemented to improve integrity verification, then platform authentication reliability is enhanced, but a new platform authentication protocol must be designed

Engineering Contradiction:
Improveplatform authentication reliabilityVSAvoidprotocol implementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system performs preliminary integrity measurements of the platform before authentication. The Integrity Measurement Collector (IMC) continuously monitors platform integrity and prepares measurement values in advance. When authentication is required, these pre-collected measurements are immediately available for verification, streamlining the authentication process while maintaining high reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication protocol uses configurable parameters including different integrity measurement thresholds, policy evaluation criteria, and trust levels. These parameters can be adjusted based on specific security requirements and deployment scenarios, allowing the system to adapt to different security contexts while maintaining a consistent architectural framework.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If centralized policy evaluation is implemented through an evaluation policy server, then authentication management is simplified, but the system requires additional communication interfaces and message exchanges

Engineering Contradiction:
Improveauthentication management easeVSAvoidcommunication interface complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The evaluation policy server performs multiple functions: it evaluates integrity measurement values, makes authentication decisions, and communicates with both the TNC access point and the authentication policy server. This multi-functionality simplifies management by consolidating policy evaluation capabilities in a single component while reducing the need for separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback loops where the evaluation policy server continuously receives integrity measurement values from the TNC access point, evaluates them against current policies, and adjusts authentication decisions based on the results. This feedback mechanism enables dynamic authentication management while maintaining centralized control through standardized message exchanges.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2426853B1Platform authentication method suitable for trusted network connect architecture based on tri-element peer authentication
Publication Date: 2020.09.02 CHINA IWNCOMM
  • EP2426853B1 patent drawingFigure 1~2
  • EP2426853B1 patent drawingFigure 3

AI summary

The invention discloses a platform authentication method suitable for trusted network connect (TNC) architecture based on tri-element peer authentication (TePA). The method relates to a platform authentication protocol of tri-element peer authentication, and the protocol improves network security as compared with prior platform authentication protocols; in the platform authentication protocol of the TNC architecture based on TePA, a policy manager plays a role as a trusted third party, which is convenient for concentrated management, thus enhancing manageability; the invention relates to the platform authentication protocol of the TNC architecture based on TePA, has different implementation methods and is beneficial for different dispositions and realizations.