Tri-element Peer Authentication Protocol for Trusted Network Connect

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Trusted Network Connect (TNC) architecture faces issues with low security, complex key negotiation, poor extensibility, and lack of peer-to-peer platform integrity evaluation, which compromises network security and management complexity.

Innovation Solution

A trusted network connect method that employs a tri-element peer authentication protocol for bidirectional user and platform integrity evaluation, simplifying key management and enhancing security by allowing mutual verification of platform integrity between the access requestor and the access authority, using a pre-established secure channel for key negotiation and AIK certificate validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional TCG-TNC architecture is used, then network connection security is provided, but security is relative low and key negotiation is complex

Engineering Contradiction:
Improvenetwork securityVSAvoidkey negotiation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges user authentication and platform integrity evaluation into a unified tri-element peer authentication protocol. The access requestor, access authority, and policy manager work together in a single authentication framework, eliminating the need for separate key negotiation procedures and reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The policy manager serves as an intermediary that facilitates both user authentication and platform integrity evaluation. By introducing this mediator, the system can perform multiple security functions through a single authentication exchange, simplifying the key negotiation process while enhancing security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional TCG-TNC architecture is used, then access control is implemented, but extensibility is poor due to pre-defined secure channels

Engineering Contradiction:
Improveaccess controlVSAvoidsystem extensibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic authentication requirements where the access authority can specify which platform components need integrity verification based on current security needs. This dynamic approach allows the system to adapt to different security scenarios without requiring pre-defined secure channels for every possible case, thereby improving extensibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system allows selective verification of specific platform components (such as BIOS, operating system, applications) rather than requiring comprehensive verification of all components. This local quality approach enables flexible access control policies that can be adapted to different security requirements while maintaining system extensibility.

Inventive Principle:
Principle #3Local quality

3Reliability

If conventional TCG-TNC architecture is used, then platform integrity verification is performed, but peer-to-peer evaluation is missing

Engineering Contradiction:
Improveplatform integrityVSAvoidpeer-to-peer evaluation capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements asymmetric verification where the access requestor verifies the access authority's platform integrity, and the access authority verifies the access requestor's platform integrity. This mutual verification mechanism provides peer-to-peer evaluation capability while maintaining the asymmetric role relationships necessary for secure access control.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS8271780B2Trusted network connect method for enhancing security
Publication Date: 2012.09.18 CHINA IWNCOMM
  • US8271780B2 patent drawing
  • US8271780B2 patent drawing
  • US8271780B2 patent drawing

AI summary

A trusted network connect method for enhancing security, it pre-prepares platform integrity information, sets an integrity verify demand. A network access requestor initiates an access request, a network access authority starts a process for bi-directional user authentication, begins to perform the triplex element peer authentication protocol with a user authentication service unit. After the success of the bi-directional user authentication, a TNC server and a TNC client perform bi-directional platform integrity evaluation. The network access requestor and the network access authority control ports according to their respective recommendations, implement the mutual access control of the access requestor and the access authority. The present invention solves the technical problems in the background technologies: the security is lower relatively, the access requestor may be unable to verify the validity of the AIK credential and the platform integrity evaluation is not parity. The present invention may simplify the management of the key and the mechanism of integrity verification, expand the application scope of the trusted network connect.