TLS Connection Attestation for Trusted Network Device Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Transport Layer Security (TLS) protocol does not ensure the trustworthiness of communication parties, leading to potential data leakage when either party is in an untrusted state, compromising network and device security.

Innovation Solution

Integrate trustworthiness measurement into the communication process by using attestation identity information and challenge values to verify the trustworthiness of network devices during TLS/SSL protocol-based connections, ensuring secure communication channels are established only with trusted devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional communication protocols are used without trusted measurement integration, then device compatibility and ease of operation are maintained, but security and reliability are compromised due to inability to verify device authenticity and message integrity

Engineering Contradiction:
ImprovesecurityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds trusted measurement mechanisms within existing communication protocol structures. The measurement report is nested as an optional parameter within message exchanges, allowing security verification to be integrated without fundamentally altering the protocol architecture. This nesting approach enables security enhancement while maintaining protocol compatibility.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces a measurement report as an intermediary element that mediates between communication parties. This report contains verified measurement data that acts as a trusted intermediary to establish device authenticity and message integrity, reducing the need for complex direct verification mechanisms between communicating entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If trusted measurement mechanisms are integrated into communication protocols, then reliability and security are improved through device verification and message integrity checks, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improvedevice verificationVSAvoidimplementation difficulty
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent performs measurements and generates measurement reports in advance of communication operations. By pre-establishing the trusted measurement state and generating reports before actual communication occurs, the system eliminates the need for complex real-time verification mechanisms during message exchange, simplifying implementation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the measurement report that can be transmitted and verified independently. This copied verification data allows receiving devices to verify authenticity without needing to perform complex real-time measurements or maintain synchronized trust states, reducing implementation complexity.

Inventive Principle:
Principle #26Copying

3Loss of information

If measurement reports are transmitted in communication messages, then information integrity and authenticity are improved, but communication overhead and loss of time increase

Engineering Contradiction:
Improveinformation integrityVSAvoidcommunication overhead
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent implements selective transmission of measurement reports based on security requirements. Rather than transmitting verification data with every message, the system transmits measurement reports only when needed for specific security contexts or when security attributes indicate potential risks, reducing overhead while maintaining integrity where necessary.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4443927B1Trusted measurement-integrated communication method and apparatus
Publication Date: 2026.05.06 HUAWEI TECH CO LTD
  • EP4443927B1 patent drawingFigure 1~2
  • EP4443927B1 patent drawingFigure 3~4
  • EP4443927B1 patent drawingFigure 5

AI summary

This application provides a communication method integrated with trustworthiness measurement and an apparatus. The method includes: A first network device sends a transmission request message, where the transmission request message is used to request to establish a TLS/SSL protocol-based connection, and the transmission request message is further used to request to verify whether a second network device is trusted. The first network device receives a transmission response message, where the transmission response message is used to respond to the transmission request message. The technical solutions provided in this application help determine execution states of network devices while a secure communication channel is established between the network devices, and help improve security of the network devices and security of communication between the network devices.