Trusted Device Attestation for Secure Remote Network Extension
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote network administration methods for high-value information systems lack adequate security measures, relying heavily on on-site IT administrator expertise and resource allocation, which is costly and prone to network degradation or loss, especially in critical sectors like DoD, Financial, and Medical.
Innovation Solution
A network extension device with a CPU, memory, protected I/O, a trusted device for attestation, and a traffic encryption module, enabling robust centralized IT administration, ensuring secure operation and communication through tamper-proofing and secure interfaces, even in reduced bandwidth conditions, using trusted controller modules and cryptographic algorithms like AES and ECDH.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If on-site IT administrators are deployed to remote sites, then network security and functionality can be maintained, but costs increase significantly and security depends on individual administrator expertise
Solution Approach 1:
A trusted device acts as an intermediary between the remote network extension and the centralized IT administration. This device provides automated security attestation and verification, eliminating the need for physical on-site administrators while maintaining security through cryptographic verification of system state and integrity.
2Device complexity
If centralized IT administration is implemented without local security administration, then costs are reduced, but adequate security posture cannot be maintained
Solution Approach 1:
The trusted device continuously monitors system state, integrity, and security parameters, providing automated feedback to centralized administrators through cryptographic attestation. This enables centralized administrators to verify remote system security posture without physical presence, maintaining security through automated verification loops.
3Productivity
If remote sites are equipped with full network functionality, then operational capability is improved, but vulnerability to network degradation and loss increases
Solution Approach 1:
The system dynamically adapts its operational mode based on network conditions. The trusted device verifies and manages transitions between different operational states (full network connectivity, degraded connectivity, offline mode), ensuring that remote sites can operate with full functionality when available while maintaining security and integrity during network degradation or loss.
4Reliability
If security checks are performed continuously, then security assurance is improved, but system performance and bandwidth are reduced
Solution Approach 1:
Security attestation and verification are performed periodically rather than continuously. The trusted device generates cryptographic attestations at scheduled intervals and in response to specific events, providing sufficient security assurance while minimizing performance overhead and bandwidth consumption compared to continuous verification.
Data Source
AI summary
A network extension device comprising a CPU, memory, protected I/O connectable to local controls and peripherals, external communications port, a trusted device connected to the CPU such that it can provide attestation of the network extension device's trusted operation to a connected known external network, and a protected interface connected to at least one network extension module that includes a local network communications port. Optionally, a traffic encryption module may be provided, and the trusted device's attestation may include a check of its operation. Also, a method comprising connecting the network extension device to an external network, performing an operating mode check, causing the network extension device to operate in a mode and perform a security check that correspond to the result, causing the trusted device to attest trusted operation to the external network and thereafter causing the CPU to function fully and permitting access to the external network.


