Trusted Edge Network Ports for Unauthorized Device Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data centers face challenges in securing network access at geographically distributed edge sites, where unauthorized devices can compromise network security, leading to vulnerabilities such as sniffing and passive monitoring, due to varying levels of security at these smaller sites.

Innovation Solution

Implementing trusted network devices at edge sites that establish a root of trust via TPM-based secure boot, enabling a distributed chain of trust to authenticate devices and control access at each port, disabling unauthorized connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If trusted network devices with root of trust are deployed at edge sites, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the network security function by deploying trusted network devices (TNDs) at each edge site independently. Each TND operates as a separate security domain with its own root of trust, isolating security functions from centralized control. This segmentation allows each edge site to be secured autonomously without requiring complex centralized management of every security detail.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The TND acts as an intermediary between the edge device and the network. It establishes a root of trust locally and mediates all communication by validating credentials and enforcing access control policies. This intermediary role simplifies the overall system architecture by concentrating security complexity in a dedicated component rather than distributing it across multiple systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If granular access control at each port is implemented, then network security is improved, but computational resource consumption increases

Engineering Contradiction:
Improvenetwork securityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The TND performs preliminary authentication and credential validation before allowing any network access. By establishing trust relationships and validating credentials in advance at the port level, the system prevents unauthorized access before it can consume computational resources. This preliminary action reduces the need for continuous heavy computational verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The TND implements self-service security mechanisms where the device automatically manages its own authentication and access control without requiring constant external intervention. The root of trust enables the TND to autonomously validate credentials and enforce policies, reducing the computational burden on centralized systems and minimizing overall resource consumption.

Inventive Principle:
Principle #25Self-service

3Reliability

If distributed chain of trust is established at edge sites, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The distributed chain of trust is segmented into independent trust domains at each edge site. Each TND maintains its own root of trust and creates a separate chain of trust for devices connecting to that site. This segmentation allows the complex trust verification process to be distributed across multiple independent units rather than requiring a single complex centralized system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each edge site implements local quality trust mechanisms tailored to its specific requirements. The TND at each site establishes a root of trust and chain of trust locally, allowing trust verification to be performed with locally relevant credentials and policies. This local quality approach reduces the complexity of maintaining a single global trust system across all edge sites.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4268416B1Securing network access at edge sites using trusted network devices
Publication Date: 2026.02.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4268416B1 patent drawingFigure 1
  • EP4268416B1 patent drawingFigure 2A
  • EP4268416B1 patent drawingFigure 2B

AI summary

Techniques are described for securely managing computing resources in a computing environment comprising a computing service provider and a remote computing network. The remote computing network includes computing and network devices configured to extend computing resources of the computing service provider to remote users of the computing service provider. The network devices include a trusted network device that includes a root of trust. The trusted network device detects that a new device is communicatively coupled to a port on the trusted network device. The trusted network device determines that the new device is not authorized to access computing resources at the remote computing network. The port is isolated at the trusted network device.