Trusted Edge Network Ports for Unauthorized Device Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data centers face challenges in securing network access at geographically distributed edge sites, where unauthorized devices can compromise network security, leading to vulnerabilities such as sniffing and passive monitoring, due to varying levels of security at these smaller sites.
Innovation Solution
Implementing trusted network devices at edge sites that establish a root of trust via TPM-based secure boot, enabling a distributed chain of trust to authenticate devices and control access at each port, disabling unauthorized connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If trusted network devices with root of trust are deployed at edge sites, then network security is improved, but device complexity increases
Solution Approach 1:
The system segments the network security function by deploying trusted network devices (TNDs) at each edge site independently. Each TND operates as a separate security domain with its own root of trust, isolating security functions from centralized control. This segmentation allows each edge site to be secured autonomously without requiring complex centralized management of every security detail.
Solution Approach 2:
The TND acts as an intermediary between the edge device and the network. It establishes a root of trust locally and mediates all communication by validating credentials and enforcing access control policies. This intermediary role simplifies the overall system architecture by concentrating security complexity in a dedicated component rather than distributing it across multiple systems.
2Reliability
If granular access control at each port is implemented, then network security is improved, but computational resource consumption increases
Solution Approach 1:
The TND performs preliminary authentication and credential validation before allowing any network access. By establishing trust relationships and validating credentials in advance at the port level, the system prevents unauthorized access before it can consume computational resources. This preliminary action reduces the need for continuous heavy computational verification.
Solution Approach 2:
The TND implements self-service security mechanisms where the device automatically manages its own authentication and access control without requiring constant external intervention. The root of trust enables the TND to autonomously validate credentials and enforce policies, reducing the computational burden on centralized systems and minimizing overall resource consumption.
3Reliability
If distributed chain of trust is established at edge sites, then network security is improved, but device complexity increases
Solution Approach 1:
The distributed chain of trust is segmented into independent trust domains at each edge site. Each TND maintains its own root of trust and creates a separate chain of trust for devices connecting to that site. This segmentation allows the complex trust verification process to be distributed across multiple independent units rather than requiring a single complex centralized system.
Solution Approach 2:
Each edge site implements local quality trust mechanisms tailored to its specific requirements. The TND at each site establishes a root of trust and chain of trust locally, allowing trust verification to be performed with locally relevant credentials and policies. This local quality approach reduces the complexity of maintaining a single global trust system across all edge sites.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Techniques are described for securely managing computing resources in a computing environment comprising a computing service provider and a remote computing network. The remote computing network includes computing and network devices configured to extend computing resources of the computing service provider to remote users of the computing service provider. The network devices include a trusted network device that includes a root of trust. The trusted network device detects that a new device is communicatively coupled to a port on the trusted network device. The trusted network device determines that the new device is not authorized to access computing resources at the remote computing network. The port is isolated at the trusted network device.