Tri-element Network Access Control via Peer Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing TCG-TNC architecture faces issues with poor expansibility, complex key negotiation processes, security vulnerabilities due to master key transmission, and lack of peer-to-peer platform integrity evaluation, which compromises network security and trustworthiness verification.

Innovation Solution

A trusted network access control system based on tri-element peer authentication, comprising an access requestor, an access controller, and a policy manager, which performs bidirectional authentication and platform trustworthiness verification using a trustworthiness measurement collector and verifier, eliminating the need for secondary session key negotiation and enhancing security by ensuring platform integrity evaluation is peer-to-peer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the existing TCG-TNC architecture is used for network access control, then network security protection is provided, but the architecture has poor expansibility and complex key negotiation processes

Engineering Contradiction:
Improvenetwork security protectionVSAvoidkey negotiation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key negotiation process into distinct phases: initial key establishment between access requestor and policy manager, and subsequent session key derivation. This segmentation simplifies the overall process by breaking down the complex TCG-TNC key negotiation into manageable, reusable components that can be executed efficiently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary key establishment between the access requestor and policy manager before actual network access control operations. This preliminary action creates a trusted foundation that eliminates the need for repeated complex key negotiations during subsequent access control decisions, thereby reducing overall process complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If master key transmission is implemented in the TCG-TNC architecture, then authentication is achieved, but security vulnerabilities are introduced

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the master key transmission step from the authentication process. Instead of transmitting the master key across the network, the system uses local key derivation and verification mechanisms. This extraction eliminates the security vulnerability of networked key transmission while preserving authentication capability through alternative cryptographic verification methods.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic intermediaries (hash functions, key derivation functions) that mediate between the need for authentication and the risk of key exposure. These intermediaries transform sensitive keys into secure verification data, allowing authentication to proceed without exposing the actual master key over the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If centralized policy decision point architecture is used, then access control policies are enforced, but the system lacks peer-to-peer trust verification

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidpeer-to-peer trust verification
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges centralized policy enforcement with distributed peer-to-peer verification mechanisms. The policy manager maintains centralized control for policy decisions, while simultaneously enabling direct trust verification between access requestors and policy enforcement points through shared cryptographic credentials. This combination preserves the advantages of both centralized and decentralized approaches.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent adds a new dimension of trust verification by implementing cryptographic credential validation between peers at the network access layer. This dimensional addition allows the system to maintain centralized policy management while simultaneously enabling distributed trust verification, effectively operating in both centralized and decentralized dimensions concurrently.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP2222014B1A trusted network access control system based on tri-element peer authentication
Publication Date: 2017.01.04 CHINA IWNCOMM
  • EP2222014B1 patent drawing
  • EP2222014B1 patent drawing
  • EP2222014B1 patent drawing

AI summary

A trusted network access control system based on ternary equal identification is provided. The system includes access requestor AR, access controller AC and policy manager PM as well as the protocol interface among them. The protocol interface between the AR and AC includes a trusted network transmission interface (IF-TNT) and IF-TNACCS interface between TNAC client and TNAC server. The protocol interface between the AC and PM includes an identification policy service interface IF-APS, evaluation policy service interface IF-EPS and a trust measurement interface IF-TM. The protocol interface between the AR and PM includes a trust measurement interface IF-TM.