Enriching TPM Queries with SDN Augmented Information

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face inefficiencies and additional attack vectors due to the need for multiple queries to verify the integrity of virtual machines (VMs) running on compromised networking devices, leading to communication inefficiencies and potential man-in-the-middle attacks.

Innovation Solution

A managed network controller intercepts and augments TPM query responses with security information, including trust verification data and network trust certifications, to provide VMs with accurate and enriched security query responses, minimizing attack vectors and network traffic by embedding signed integrity verification results directly into TPM responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple queries are performed to verify VM integrity, then verification reliability is improved, but communication efficiency deteriorates and attack vectors increase

Engineering Contradiction:
Improveverification reliabilityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple verification queries into a single enriched query response. The network controller collects trust verification data from multiple sources (physical host, virtual host, network segment) and bundles this information into one enhanced response that includes both the original TPM data and additional security context, eliminating the need for separate verification queries.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network controller acts as an intermediary between the VM and the trust verification system. It intercepts TPM queries, enriches them with security information from multiple sources, and returns comprehensive responses. This mediator consolidates what would otherwise require multiple direct queries to different systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple queries are performed to verify VM integrity, then verification reliability is improved, but the number of attack vectors increases

Engineering Contradiction:
Improveverification reliabilityVSAvoidattack vectors
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

By combining multiple verification functions into a single enriched response mechanism, the patent reduces the number of separate communication channels that could be exploited. The network controller consolidates trust verification, security context collection, and integrity checking into one coordinated operation, limiting the attack surface.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network controller as an intermediary controls and secures the verification process centrally. It manages the collection and transmission of trust verification data, reducing the number of direct query-response cycles that could be intercepted or manipulated by attackers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If trust verification data is collected from multiple sources, then verification accuracy is improved, but network traffic increases

Engineering Contradiction:
Improveverification accuracyVSAvoidnetwork traffic
Core Design Contradiction:
Measurement precisionVSLoss of substance

Solution Approach 1:

The network controller performs preliminary collection and aggregation of trust verification data from multiple sources before the actual verification query is processed. By pre-gathering security context, host status information, and network segment data, the system can provide comprehensive verification without requiring multiple separate network transactions during the verification process itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges multiple data collection operations into a single network transaction. The network controller aggregates trust verification data from physical hosts, virtual hosts, and network segments into one consolidated response structure, reducing the total network traffic compared to making separate queries to each source.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11438151B2Enriching local cryptoprocessor queries with sdn augmented information
Publication Date: 2022.09.06 CISCO TECHNOLOGY INC
  • US11438151B2 patent drawing
  • US11438151B2 patent drawing
  • US11438151B2 patent drawing

AI summary

The present technology discloses a method for enriching local crypto-processor queries with software-defined networking augmented information, comprising sending, from a virtual machine installed on a physical host, a request for trust verification data; augmenting, by an identity verification system on the physical host, the request for trust verification data with encrypted information from an external entity; receiving, at a trusted processor module on the physical host, the request for trust verification data; receiving, at the virtual machine, the trust verification data; and assessing, at the virtual machine, a state of the physical host based on the trust verification data.