Trusted Computing Organization(TCG) proposes the Trusted Network Connection(TNC) to ensure that a computing platform connecting to the internet satisfies the security requirements defined by the network administrator.However
TNC uses the traditional TCG-based binary attestation
which has the deficiencies of integrity management and exposing the configuration of a computing platform
to verify the integrity of the connecting platform.We propose a TNC schema based on property-based attestation
transferring the attestation to a trusted third party which issues security property certificates to remote platforms.That the network access server uses the property certificates issued by the TTP to enforce the connection decision in our schema resolves the problems of integrity managements and configuration exposure.Besides these benefits
our schema allows the network administrator segment the network into more than two separation VLAN domains
which is now used in TNC now.We implement the schema on the 802.1X framework
and the result shows that our schema can separate the platforms into different VLAN domains by their security property certificates.