Trusted Network Management via TPM Integrity Measurement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network management systems face security risks due to mutual attacks between agents, hosts, and manager systems, leading to inefficiencies and loss of control, particularly as networks scale and become more complex.

Innovation Solution

Implementing a trusted network management method using trusted management agents and systems on hosts and management hosts, respectively, with TPMs for integrity measurement and authentication, enabling mutual authentication and key agreement to ensure trustworthiness and secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a centralized management model is adopted, then network management function is concentrated and simplified, but network security is compromised due to mutual attacks between agents, hosts, and manager systems

Engineering Contradiction:
Improvemanagement system complexityVSAvoidnetwork security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements preliminary security actions by establishing trust relationships and authentication mechanisms before network management operations occur. Trusted management agents are pre-configured with digital certificates and cryptographic keys, enabling them to authenticate themselves and other components before any management operations take place, thereby preventing security breaches from the outset

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces trusted management agents as intermediary components that reside on managed hosts and act as secure mediators between the manager system and the host. These agents use cryptographic mechanisms to verify the authenticity of management operations and prevent unauthorized access, thereby enhancing security while maintaining the centralized management architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the network scale is expanded and more users are added, then network coverage is improved, but management efficiency deteriorates due to increased polling operations and bandwidth overhead

Engineering Contradiction:
Improvenetwork scaleVSAvoidmanagement efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements event-triggered notifications as a preliminary action mechanism where managed hosts proactively notify the manager system of significant events rather than waiting for periodic polling. This allows the system to scale efficiently as the manager only processes actual events rather than continuously querying all hosts, thereby maintaining management efficiency while supporting larger network scales

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent optimizes periodic polling by making it optional and selective rather than mandatory for all hosts. The manager system can configure polling intervals based on host criticality and event types, allowing less critical hosts to use event-triggered notifications while maintaining periodic polling only where necessary, thereby reducing overall bandwidth overhead while supporting network expansion

Inventive Principle:
Principle #19Periodic action

3Reliability

If distributed network management is implemented, then network security is improved through mutual authentication, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework using digital certificates and cryptographic mechanisms that can be applied across both centralized and distributed management scenarios. The trusted management agents use the same authentication protocols regardless of the management architecture, providing consistent security while avoiding the need for separate complex authentication systems for different management modes

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses digital certificate copying and verification mechanisms where trusted identities are replicated through cryptographic signatures rather than physical duplication. The manager system verifies agent authenticity by checking digital certificates that contain copied identity information, enabling secure distributed authentication without requiring complex physical verification processes

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8230220B2Method for realizing trusted network management
Publication Date: 2012.07.24 CHINA IWNCOMM
  • US8230220B2 patent drawing
  • US8230220B2 patent drawing
  • US8230220B2 patent drawing

AI summary

A method for realizing trusted network management is provided. A trusted management agent resides on a managed host, and a trusted management system resides on a management host. The trusted management agent and the trusted management system are software modules, which are both based on a trusted computing platform and signed after being authenticated by a trusted third party of the trusted management agent and the trusted management system. Trusted platform modules of the managed host and the management host can perform integrity measurement, storage, and report for the trusted management agent and the trusted management system. Therefore, the managed host and the management host can ensure that the trusted management agent and the trusted management system are trustworthy. Then, the trusted management agent and the trusted management system execute a network management function, thus realizing the trusted network management. Therefore, the technical problem in the prior art that the network management security cannot be ensured due to the mutual attack between an agent, a host where the agent resides, and a manager system is solved, and trusted network management is realized.