Trusted Network Management via TPM Integrity Measurement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network management systems face security risks due to mutual attacks between agents, hosts, and manager systems, leading to inefficiencies and loss of control, particularly as networks scale and become more complex.
Innovation Solution
Implementing a trusted network management method using trusted management agents and systems on hosts and management hosts, respectively, with TPMs for integrity measurement and authentication, enabling mutual authentication and key agreement to ensure trustworthiness and secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a centralized management model is adopted, then network management function is concentrated and simplified, but network security is compromised due to mutual attacks between agents, hosts, and manager systems
Solution Approach 1:
The patent implements preliminary security actions by establishing trust relationships and authentication mechanisms before network management operations occur. Trusted management agents are pre-configured with digital certificates and cryptographic keys, enabling them to authenticate themselves and other components before any management operations take place, thereby preventing security breaches from the outset
Solution Approach 2:
The patent introduces trusted management agents as intermediary components that reside on managed hosts and act as secure mediators between the manager system and the host. These agents use cryptographic mechanisms to verify the authenticity of management operations and prevent unauthorized access, thereby enhancing security while maintaining the centralized management architecture
2Adaptability or versatility
If the network scale is expanded and more users are added, then network coverage is improved, but management efficiency deteriorates due to increased polling operations and bandwidth overhead
Solution Approach 1:
The patent implements event-triggered notifications as a preliminary action mechanism where managed hosts proactively notify the manager system of significant events rather than waiting for periodic polling. This allows the system to scale efficiently as the manager only processes actual events rather than continuously querying all hosts, thereby maintaining management efficiency while supporting larger network scales
Solution Approach 2:
The patent optimizes periodic polling by making it optional and selective rather than mandatory for all hosts. The manager system can configure polling intervals based on host criticality and event types, allowing less critical hosts to use event-triggered notifications while maintaining periodic polling only where necessary, thereby reducing overall bandwidth overhead while supporting network expansion
3Reliability
If distributed network management is implemented, then network security is improved through mutual authentication, but system complexity increases
Solution Approach 1:
The patent implements a universal authentication framework using digital certificates and cryptographic mechanisms that can be applied across both centralized and distributed management scenarios. The trusted management agents use the same authentication protocols regardless of the management architecture, providing consistent security while avoiding the need for separate complex authentication systems for different management modes
Solution Approach 2:
The patent uses digital certificate copying and verification mechanisms where trusted identities are replicated through cryptographic signatures rather than physical duplication. The manager system verifies agent authenticity by checking digital certificates that contain copied identity information, enabling secure distributed authentication without requiring complex physical verification processes
Data Source
AI summary
A method for realizing trusted network management is provided. A trusted management agent resides on a managed host, and a trusted management system resides on a management host. The trusted management agent and the trusted management system are software modules, which are both based on a trusted computing platform and signed after being authenticated by a trusted third party of the trusted management agent and the trusted management system. Trusted platform modules of the managed host and the management host can perform integrity measurement, storage, and report for the trusted management agent and the trusted management system. Therefore, the managed host and the management host can ensure that the trusted management agent and the trusted management system are trustworthy. Then, the trusted management agent and the trusted management system execute a network management function, thus realizing the trusted network management. Therefore, the technical problem in the prior art that the network management security cannot be ensured due to the mutual attack between an agent, a host where the agent resides, and a manager system is solved, and trusted network management is realized.


