Tri-element Network Access Control via Peer Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing TCG-TNC architecture faces issues with poor expansibility, complex key negotiation processes, security vulnerabilities due to master key transmission, and lack of peer-to-peer platform integrity evaluation, which compromises network security and trustworthiness verification.
Innovation Solution
A trusted network access control system based on tri-element peer authentication, comprising an access requestor, an access controller, and a policy manager, which performs bidirectional authentication and platform trustworthiness verification using a trustworthiness measurement collector and verifier, eliminating the need for secondary session key negotiation and enhancing security by ensuring platform integrity evaluation is peer-to-peer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the existing TCG-TNC architecture is used for network access control, then network security protection is provided, but the architecture has poor expansibility and complex key negotiation processes
Solution Approach 1:
The patent segments the key negotiation process into distinct phases: initial key establishment between access requestor and policy manager, and subsequent session key derivation. This segmentation simplifies the overall process by breaking down the complex TCG-TNC key negotiation into manageable, reusable components that can be executed efficiently.
Solution Approach 2:
The patent implements preliminary key establishment between the access requestor and policy manager before actual network access control operations. This preliminary action creates a trusted foundation that eliminates the need for repeated complex key negotiations during subsequent access control decisions, thereby reducing overall process complexity.
2Reliability
If master key transmission is implemented in the TCG-TNC architecture, then authentication is achieved, but security vulnerabilities are introduced
Solution Approach 1:
The patent extracts the master key transmission step from the authentication process. Instead of transmitting the master key across the network, the system uses local key derivation and verification mechanisms. This extraction eliminates the security vulnerability of networked key transmission while preserving authentication capability through alternative cryptographic verification methods.
Solution Approach 2:
The patent introduces cryptographic intermediaries (hash functions, key derivation functions) that mediate between the need for authentication and the risk of key exposure. These intermediaries transform sensitive keys into secure verification data, allowing authentication to proceed without exposing the actual master key over the network.
3Reliability
If centralized policy decision point architecture is used, then access control policies are enforced, but the system lacks peer-to-peer trust verification
Solution Approach 1:
The patent merges centralized policy enforcement with distributed peer-to-peer verification mechanisms. The policy manager maintains centralized control for policy decisions, while simultaneously enabling direct trust verification between access requestors and policy enforcement points through shared cryptographic credentials. This combination preserves the advantages of both centralized and decentralized approaches.
Solution Approach 2:
The patent adds a new dimension of trust verification by implementing cryptographic credential validation between peers at the network access layer. This dimensional addition allows the system to maintain centralized policy management while simultaneously enabling distributed trust verification, effectively operating in both centralized and decentralized dimensions concurrently.
Data Source
AI summary
A trusted network access control system based on ternary equal identification is provided. The system includes access requestor AR, access controller AC and policy manager PM as well as the protocol interface among them. The protocol interface between the AR and AC includes a trusted network transmission interface (IF-TNT) and IF-TNACCS interface between TNAC client and TNAC server. The protocol interface between the AC and PM includes an identification policy service interface IF-APS, evaluation policy service interface IF-EPS and a trust measurement interface IF-TM. The protocol interface between the AR and PM includes a trust measurement interface IF-TM.


