Embedded Trust Agent for Legacy Protocol Compatibility in Secure Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Deploying 802.1X network access control in large enterprises breaks existing legacy protocols like Preboot Execution Environment (PXE), preventing clients from obtaining network access and disrupting remote booting capabilities.
Innovation Solution
The use of an embedded trust agent, such as Active Management Technology (AMT), which operates independently of the operating system to establish a secure network connection, allowing PXE traffic during remote booting and then terminating the connection to prevent unauthorized access, utilizing firmware agents and circuit breakers to manage network access based on operational conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If 802.1X network access control is deployed, then network security is improved, but legacy protocols like PXE are broken and remote booting is prevented
Solution Approach 1:
The patent introduces a trusted platform module (TPM) and firmware-based authentication intermediary that mediates between 802.1X security requirements and legacy PXE protocols. The TPM creates a trusted execution environment that allows PXE traffic to pass through authenticated channels while maintaining 802.1X security controls, effectively acting as a bridge between the two conflicting systems.
Solution Approach 2:
The patent segments network access control into multiple layers: firmware-level authentication for boot processes, OS-level 802.1X authentication for network access, and application-level security policies. This segmentation allows legacy PXE protocols to operate at the firmware layer while 802.1X security is enforced at higher layers, resolving the conflict between security and compatibility.
2Reliability
If 802.1X access control is enforced, then unauthorized device access is prevented, but remote booting capabilities are disrupted
Solution Approach 1:
The patent implements preliminary authentication actions in the firmware/BIOS layer before the operating system loads. The trusted platform module performs pre-authentication of remote boot requests, establishing security credentials in advance. This allows remote booting to proceed smoothly while security is already enforced, eliminating the need to choose between security and ease of operation.
3Reliability
If firmware agents are used to manage network access, then unauthorized access is prevented, but system complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where the trusted platform module automatically manages its own authentication credentials, cryptographic keys, and security policies without requiring manual firmware agent configuration. The system performs self-authentication and automatically enforces access control decisions, reducing operational complexity while maintaining strong security controls.
Data Source
AI summary
In network access control networks, it may be difficult to provide certain remote accesses such as remote boot or remote storage access. An available network connection established through chipset firmware (e.g. active management technology (AMT)) may be utilized to establish a connection and to enable the remote access. Then as soon the completion of the activity is detected, such as remote booting, then the connection may be immediately terminated to prevent access by improper agents.


