DEVICE ATTESTATION IN MANAGED NETWORKS
Inventors
Meni Orenbach, Michael Tahar, Fritz Daniel Alder, Ahmad Atamli, Dmitri Shiffrin
Abstract
Approaches presented herein provide for the attestation of devices in managed networks, in order to verify state and establish trust in those devices as well as in the managed network and/or subnets. The devices in a network, including devices such as network switches, can perform self-attestation by transmitting attestation evidence using one or more network messages. One or more verifiers can verify the attestation evidence and determine which devices or subnets are trusted. Data and messages can then be routed along trusted paths through a trusted network or subnet, such that all devices along those paths are trusted devices. In order to reduce the volume of attestation traffic for large networks, a network device can provide attestation evidence to a verifier that is connected to that device, rather than propagating all evidence for all devices to a single verifier. Once verified, a list of trusted devices can be propagated rather than the instances of evidence that were used for the verification.
CPC Classifications
Filing Date
2024-09-30
Application No.
18901515