Unidirectional Device Attestation for Network Trust Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network environments lack effective methods to determine the trustworthiness of devices using unidirectional device discovery and authentication protocols, which are insufficient in ensuring security against evolving threats.

Innovation Solution

Implementing systems and methods for discovering trustworthy devices through attestation and authenticating devices via mutual attestation using unidirectional link layer communication schemes, such as IEEE 802.1×, to verify the trustworthiness of nodes by exchanging attestation information and controlling network service access based on identified trust levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If unidirectional device discovery protocols (LLDP, CDP) are used for device advertisement, then device connectivity management is enabled, but trustworthiness verification capability is lost

Engineering Contradiction:
Improvedevice connectivity managementVSAvoidtrustworthiness verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines device discovery functionality with trustworthiness verification by integrating attestation information exchange into existing unidirectional discovery protocols like LLDP and CDP. The attestation data is embedded within the discovery protocol messages, allowing nodes to simultaneously discover devices and verify their trustworthiness without requiring separate communication channels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent enhances unidirectional discovery protocols to serve multiple functions: device advertisement, connectivity management, and trustworthiness verification. By making these protocols multi-functional, the system eliminates the need for separate verification mechanisms while maintaining ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional unidirectional authentication protocols (EAP, WPA, 802.1×) are used, then client-server authentication is enabled, but mutual trust verification is insufficient

Engineering Contradiction:
Improveauthentication capabilityVSAvoidmutual trust verification
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent inverts the traditional authentication model by enabling both parties (client and server) to simultaneously authenticate each other through mutual attestation. Instead of only the client being authenticated by the server, both nodes exchange and verify attestation information, creating a bidirectional trust relationship from unidirectional protocols.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces feedback mechanisms where authentication outcomes are mutually verified. Both client and server receive and validate attestation information from the other party, creating a feedback loop that ensures mutual trust. This allows the system to adapt to evolving threats by requiring reciprocal verification.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If device trustworthiness is not actively verified, then network access is simplified, but security against evolving threats deteriorates

Engineering Contradiction:
Improvenetwork access simplicityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent performs trustworthiness verification as a preliminary action before granting network access. Attestation information is exchanged and validated during the initial connection establishment phase, ensuring that only trustworthy devices gain access while maintaining simplified network entry procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses attestation information as an intermediary mechanism to bridge simplicity and security. The attestation data serves as a mediator that automatically verifies device trustworthiness without requiring complex manual security procedures, thus maintaining ease of operation while mitigating security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11956273B2Discovering trustworthy devices using attestation and mutual attestation
Publication Date: 2024.04.09 CISCO TECHNOLOGY INC
  • US11956273B2 patent drawing
  • US11956273B2 patent drawing
  • US11956273B2 patent drawing

AI summary

Systems, methods, and computer-readable media for discovering trustworthy devices through attestation and authenticating devices through mutual attestation. A relying node in a network environment can receive attestation information from an attester node in the network environment as part of a unidirectional push of information from the attester node according to a unidirectional link layer communication scheme. A trustworthiness of the attester node can be verified by identifying a level of trust of the attester node from the attestation information. Further, network service access of the attester node through the relying node in the network environment can be controlled based on the level of trust of the attester node identified from the attestation information.