Enriching TPM Queries with SDN Augmented Information
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face inefficiencies and additional attack vectors due to the need for multiple queries to verify the integrity of virtual machines (VMs) running on compromised networking devices, leading to communication inefficiencies and potential man-in-the-middle attacks.
Innovation Solution
A managed network controller intercepts and augments TPM query responses with security information, including trust verification data and network trust certifications, to provide VMs with accurate and enriched security query responses, minimizing attack vectors and network traffic by embedding signed integrity verification results directly into TPM responses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple queries are performed to verify VM integrity, then verification reliability is improved, but communication efficiency deteriorates and attack vectors increase
Solution Approach 1:
The patent merges multiple verification queries into a single enriched query response. The network controller collects trust verification data from multiple sources (physical host, virtual host, network segment) and bundles this information into one enhanced response that includes both the original TPM data and additional security context, eliminating the need for separate verification queries.
Solution Approach 2:
The network controller acts as an intermediary between the VM and the trust verification system. It intercepts TPM queries, enriches them with security information from multiple sources, and returns comprehensive responses. This mediator consolidates what would otherwise require multiple direct queries to different systems.
2Reliability
If multiple queries are performed to verify VM integrity, then verification reliability is improved, but the number of attack vectors increases
Solution Approach 1:
By combining multiple verification functions into a single enriched response mechanism, the patent reduces the number of separate communication channels that could be exploited. The network controller consolidates trust verification, security context collection, and integrity checking into one coordinated operation, limiting the attack surface.
Solution Approach 2:
The network controller as an intermediary controls and secures the verification process centrally. It manages the collection and transmission of trust verification data, reducing the number of direct query-response cycles that could be intercepted or manipulated by attackers.
3Measurement precision
If trust verification data is collected from multiple sources, then verification accuracy is improved, but network traffic increases
Solution Approach 1:
The network controller performs preliminary collection and aggregation of trust verification data from multiple sources before the actual verification query is processed. By pre-gathering security context, host status information, and network segment data, the system can provide comprehensive verification without requiring multiple separate network transactions during the verification process itself.
Solution Approach 2:
The patent merges multiple data collection operations into a single network transaction. The network controller aggregates trust verification data from physical hosts, virtual hosts, and network segments into one consolidated response structure, reducing the total network traffic compared to making separate queries to each source.
Data Source
AI summary
The present technology discloses a method for enriching local crypto-processor queries with software-defined networking augmented information, comprising sending, from a virtual machine installed on a physical host, a request for trust verification data; augmenting, by an identity verification system on the physical host, the request for trust verification data with encrypted information from an external entity; receiving, at a trusted processor module on the physical host, the request for trust verification data; receiving, at the virtual machine, the trust verification data; and assessing, at the virtual machine, a state of the physical host based on the trust verification data.


