TPM-Based Credentials for Automated Network Security Policy Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing secure communications in cloud computing environments is challenging due to the time-consuming process of obtaining digital certificates and implementing network security policies across multiple server computers, which can lead to security breaches.

Innovation Solution

The implementation of TPM-based credentials for creating secure host-based network endpoints, using provisioning of SSL and IPSec secure cryptographic keys, Access Control Lists (ACLs), and firewall settings, which are encrypted and decrypted using TPM-based keys, enabling automated and secure network security policy management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates are used for entity authentication, then authentication can be established, but the process of obtaining and managing certificates is time-consuming and may lead to security breaches due to extended certificate validity periods

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-provisioning TPM-based credentials (cryptographic keys) to computing devices during manufacturing or initial setup, before they are needed for authentication. This eliminates the time-consuming process of obtaining digital certificates at runtime, while maintaining strong security through hardware-based key protection that doesn't require extended validity periods.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If network security policies are implemented across multiple server computers, then secure communications can be established, but the setup process is challenging and time-consuming

Engineering Contradiction:
Improvecommunication securityVSAvoidpolicy implementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges network security policies into unified policy packages that are encrypted with and signed by TPM-based credentials. This consolidation allows multiple security policies to be deployed simultaneously across multiple servers through a single automated process, rather than implementing them individually, thereby reducing setup time while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements self-service through automated policy deployment mechanisms where the policy administration service automatically distributes, installs, and configures security policies on target computing devices without requiring manual intervention. The TPM-based credentials enable automatic verification and enforcement of policies, eliminating the time-consuming manual configuration process.

Inventive Principle:
Principle #25Self-service

3Extent of automation

If TPM-based credentials are used for automated security policy management, then setup time is reduced and automation is enhanced, but the device complexity increases due to TPM integration requirements

Engineering Contradiction:
Improvepolicy management automationVSAvoidTPM integration complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent introduces a policy administration service as an intermediary that manages TPM-based credentials and security policies centrally. This mediator handles the complexity of TPM interactions, key management, and policy deployment, shielding end users and simplifying the interface while enabling automated policy management. The intermediary absorbs the technical complexity, making the system easier to use despite the underlying TPM integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9935937B1Implementing network security policies using TPM-based credentials
Publication Date: 2018.04.03 AMAZON TECH INC
  • US9935937B1 patent drawing
  • US9935937B1 patent drawing
  • US9935937B1 patent drawing

AI summary

A method for implementing network security policies in a multi-tenant network environment may include receiving a request for implementation of at least one network security policy on one or more computing devices of a service provider cloud environment. The network security policy identified by the request may be retrieved. The network security policy may be encrypted using encrypting credentials of the one or more computing devices. Decrypting credentials corresponding to the encrypting credentials are stored in a Trusted Platform Module (TPM) within the one or more computing devices. The encrypted network security policy may be pushed to the one or more computing devices, for decryption and implementation at the one or more computing devices.