Tri-element Peer Authentication Protocol for Trusted Network Connect
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Trusted Network Connect (TNC) architecture faces issues with low security, complex key negotiation, poor extensibility, and lack of peer-to-peer platform integrity evaluation, which compromises network security and management complexity.
Innovation Solution
A trusted network connect method that employs a tri-element peer authentication protocol for bidirectional user and platform integrity evaluation, simplifying key management and enhancing security by allowing mutual verification of platform integrity between the access requestor and the access authority, using a pre-established secure channel for key negotiation and AIK certificate validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional TCG-TNC architecture is used, then network connection security is provided, but security is relative low and key negotiation is complex
Solution Approach 1:
The patent merges user authentication and platform integrity evaluation into a unified tri-element peer authentication protocol. The access requestor, access authority, and policy manager work together in a single authentication framework, eliminating the need for separate key negotiation procedures and reducing overall system complexity while maintaining security.
Solution Approach 2:
The policy manager serves as an intermediary that facilitates both user authentication and platform integrity evaluation. By introducing this mediator, the system can perform multiple security functions through a single authentication exchange, simplifying the key negotiation process while enhancing security coverage.
2Reliability
If conventional TCG-TNC architecture is used, then access control is implemented, but extensibility is poor due to pre-defined secure channels
Solution Approach 1:
The patent introduces dynamic authentication requirements where the access authority can specify which platform components need integrity verification based on current security needs. This dynamic approach allows the system to adapt to different security scenarios without requiring pre-defined secure channels for every possible case, thereby improving extensibility.
Solution Approach 2:
The system allows selective verification of specific platform components (such as BIOS, operating system, applications) rather than requiring comprehensive verification of all components. This local quality approach enables flexible access control policies that can be adapted to different security requirements while maintaining system extensibility.
3Reliability
If conventional TCG-TNC architecture is used, then platform integrity verification is performed, but peer-to-peer evaluation is missing
Solution Approach 1:
The patent implements asymmetric verification where the access requestor verifies the access authority's platform integrity, and the access authority verifies the access requestor's platform integrity. This mutual verification mechanism provides peer-to-peer evaluation capability while maintaining the asymmetric role relationships necessary for secure access control.
Data Source
AI summary
A trusted network connect method for enhancing security, it pre-prepares platform integrity information, sets an integrity verify demand. A network access requestor initiates an access request, a network access authority starts a process for bi-directional user authentication, begins to perform the triplex element peer authentication protocol with a user authentication service unit. After the success of the bi-directional user authentication, a TNC server and a TNC client perform bi-directional platform integrity evaluation. The network access requestor and the network access authority control ports according to their respective recommendations, implement the mutual access control of the access requestor and the access authority. The present invention solves the technical problems in the background technologies: the security is lower relatively, the access requestor may be unable to verify the validity of the AIK credential and the platform integrity evaluation is not parity. The present invention may simplify the management of the key and the mechanism of integrity verification, expand the application scope of the trusted network connect.


