Controlling workload execution on trusted execution environments
The method addresses security risks in confidential computing by generating an execution requirement that enforces multiple entity constraints, ensuring secure and verifiable workload execution on trusted execution environments, thereby preventing data compromise and leakage.
Patent Information
- Application Number
- GB2024006371
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-08
- Publication Date
- 2025-11-12
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing confidential computing approaches face challenges in securely managing workloads across multiple entities due to potential security risks and data leakage when constraints are not effectively enforced, leading to vulnerabilities.
A method and system for automatically controlling workload execution on trusted execution environments by generating an execution requirement that enforces compliance with multiple constraints from various entities, using identifiers and secrets to ensure secure and verifiable execution, and resolving conflicts among these constraints.
Ensures secure, collaborative control of workloads across multiple entities by preventing data compromise and leakage, while ensuring all constraints are met, providing a flexible and cryptographically secured mechanism for workload execution.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to the field of digital computer systems, and more specifically, to a computer-implemented method for controlling an execution of a workload on one or more trusted execution environments. BACKGROUND
[0002] Protecting workloads and sensitive data throughout their lifecycle is a great concern across all industries and organizations. Sensitive data may not only be needed to be protected, when being stored or transmitted, but also when being processed. To protect sensitive data during processing, e.g., confidential computing is used. Confidential computing may, e.g., be used, when processing data using cloud computing technology. Confidential computing technology isolates the sensitive data in a protected CPU enclave, i.e., a trusted execution environment, during processing. Access to content of the trusted execution environment, which may, e.g., include data being processed and / or techniques being used to processing the respective data, is restricted. However, confidential computing may become challenging, when multiple entities are involved. Trivial approaches, like simply running what is defined by multiple entities taking part in a confidential computing may cause serious security risks.
[0003] Thus, there is a need for an improved approach in confidential computing. SUMMARY
[0004] Various embodiments provide a computer-implemented method for automatically controlling an execution of a workload on one or more trusted execution environments, while compliance with a plurality of constraints required by a plurality of entities is enforced, a computer program product for automatically controlling an execution of a workload on one or more trusted execution environments, and a computer system for automatically controlling an execution of a workload on one or more trusted execution environments as described by the subject matter of the independent claims. Advantageous embodiments are described in the dependent claims. Embodiments of the present invention can be freely combined with each other if they are not mutually exclusive.
[0005] In one aspect, the invention relates to a computer-implemented method for automatically controlling an execution of a workload on one or more trusted execution environments, while compliance with a plurality of constraints required by a plurality of entities is enforced. The method comprises receiving the plurality of constraints for the execution of the workload from the plurality of entities. The received constraints form a constraint space. An execution requirement for controlling the one or more trusted execution environments is automatically generated using the constraints of the constraint space. The execution requirement defines parameters for the execution of the workload in compliance with the respective constraints. The generating comprises adding identifiers of the constraints to the execution requirement for an attestation of the constraints, with which the one or more trusted execution environments comply with, when the workload is executed in compliance with the execution requirement. The one or more trusted execution environments are controlled in compliance with the execution requirement. The controlling comprises providing the one or more trusted execution environments with the execution requirement enabling the one or more trusted execution environments to provide one or more attestation records for the attestation of the execution of the workload comprising the identifiers of the constraints.
[0006] In another aspect the invention relates to a computer program product for automatically controlling an execution of a workload on one or more trusted execution environments, while enforcing compliance with a plurality of constraints required by a plurality of entities. The computer program product comprises a computer-readable storage medium having computer-readable program code embodied therewith. The computer-readable program code is configured to implement a method, which comprises receiving the plurality of constraints for the execution of the workload from the plurality of entities. The received constraints form a constraint space. An execution requirement for controlling the one or more trusted execution environments is automatically generated using the constraints of the constraint space. The execution requirement defines parameters for the execution of the workload in compliance with the respective constraints. The generating comprises adding identifiers of the constraints to the execution requirement for an attestation of the constraints, with which the one or more trusted execution environments comply with, when the workload is executed in compliance with the execution requirement. The one or more trusted execution environments are controlled in compliance with the execution requirement. The controlling comprises providing the one or more trusted execution environments with the execution requirement enabling the one or more trusted execution environments to provide one or more attestation records for the attestation of the execution of the workload comprising the identifiers of the constraints.
[0007] In another aspect the invention relates to a computer system for automatically controlling an execution of a workload on one or more trusted execution environments, while enforcing compliance with a plurality of constraints required by a plurality of entities. The computer system is configured for receiving the plurality of constraints for the execution of the workload from the plurality of entities. The received constraints form a constraint space. An execution requirement for controlling the one or more trusted execution environments is automatically generated using the constraints of the constraint space. The execution requirement defines parameters for the execution of the workload in compliance with the respective constraints. The generating comprises adding identifiers of the constraints to the execution requirement for an attestation of the constraints, with which the one or more trusted execution environments comply with, when the workload is executed in compliance with the execution requirement. The one or more trusted execution environments are controlled in compliance with the execution requirement. The controlling comprises providing the one or more trusted execution environments with the execution requirement enabling the one or more trusted execution environments to provide one or more attestation records for the attestation of the execution of the workload comprising the identifiers of the constraints. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] In the following embodiments of the invention are explained in greater detail, by way of example only, making reference to the drawings in which:
[0009] Fig. 1 is a flowchart of an exemplary method for controlling an execution of a workload on a trusted execution environment.
[0010] Fig. 2 is a flowchart of an exemplary method for controlling an execution of a workload on a trusted execution environment.
[0011] Fig. 3 is a flowchart of an exemplary method for resolving conflicts between constraints.
[0012] Fig. 4 is a flowchart of an exemplary method for controlling an execution of a workload on a trusted execution environment.
[0013] Fig. 5 is an exemplary computing environment for controlling an execution of a workload on a trusted execution environment.
[0014] Fig. 6 is a flowchart of an exemplary method for checking a preliminary execution requirement.
[0015] Fig. 7 is a flowchart of an exemplary method for resolving conflicts between constraints.
[0016] Fig. 8 is an exemplary computing environment for controlling an execution of a workload on a trusted execution environment.
[0017] Fig. 9 is an exemplary cloud computing environment.
[0018] Fig. 10 depicts exemplary abstraction model layers. DETAILED DESCRIPTION
[0019] The descriptions of the various embodiments of the present invention will be presented for purposes of illustration but are not intended to be exhaustive or limited to the embodiments disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terminology used herein was chosen to best explain the principles of the embodiments, the practical application or technical improvement over technologies found in the marketplace, or to enable others of ordinary skill in the art to understand the embodiments disclosed herein.
[0020] The method may, e.g., be executed by a confidential computing control service. The confidential computing control service receives the plurality of constraints for the execution of the workload from the plurality of entities, e.g., from three or more entities. The confidential computing control service may use all the received constraints for generating the execution requirement for controlling the one or more trusted execution environments. Thus, an execution of the workload in compliance with the execution requirement may ensure an execution on compliance with all the constraints required by all the entities. The added identifiers of the constraints furthermore enable an attestation of the constraints, with which the one or more trusted execution environments comply with, when the workload is executed in compliance with the execution requirement. Thus, execution in compliance with the constraints by the plurality of entities is implemented in a verifiable manner.
[0021] Examples may enable a secure, collaborative control of confidential computing workloads. Examples may provide a viable solution for enabling control to a plurality of entities over an execution of a workload on one or more trusted execution environments. The controlling may, e.g., comprise a selecting of integrable components used for the execution of the workload.
[0022] Thus, trivial solutions in confidential computing environments, like a simply running of what is defined by multiple entities, may be avoided. Thereby, security risks, like compromising of a components and / or leaking of data by a malicious component, may be prevented.
[0023] Examples may also enable entities to delegate subsets of workload specification to other entities. Examples may provide for a flexible and cryptographically secured mechanism to specify workload and environment properties for an execution of a workload on one or more trusted execution environments. The plurality of entities may, e.g., comprise one or more workload providers.
[0024] Examples utilize constraints provided by the entities for controlling workload specification in an execution requirement. The execution requirement may enable a highly distributed multiparty definition of the workload execution.
[0025] Examples may take into account all the constraints defined by the plurality of entities and enforce these constraints defined by the entities to be non-circumventable by other entities, including other entities of the plurality of entities. In case conflicts between constraints received from different entities are detected, these constraints may be resolved involving the entities defining the conflicting entities. Thus, it may be ensured that any adjustments applied to the constraints, in order to resolve a conflict, between constraints is approved by the entity or entities, which have defined the adjusted constraints. As a result, constraints defined for the execution of the workload by one or the entities cannot be deviated from or even circumvented without said entities consent.
[0026] The generated execution requirement may ensure completeness and consistency against all constr aints received from the plurality of entities. A viable implementation for the constraints may, e.g., utilize a policy language.
[0027] Rather than trying to avoid conflicts between constraints from the start through limitation applied to the execution requirement, examples may allow a non-limited number of entities to contribute constraints, e.g., expressive and / or flexible constraints, for the execution requirement and provide an automatic generation of the execution requirement from the constraints being provided, while enabling a handling and / or resolving of potential conflicts between these constraints, if any such conflicts are detected.
[0028] Example may provide a method for automatically controlling a set of one or more trusted execution environments. A plurality of constraints for an execution of a workload on the one or more trusted execution workloads from a plurality of entities is received. The plurality of constraints may form a constraint space defining constraints for the execution of the workload. These constraints may, e.g., comprise constraints on properties of applications utilized for executing the workload. These constraints may, e.g., comprise constraints on properties of the execution environments used for executing the workload. These constraints may, e.g., comprise constraints on constraints. The constraint space may, e.g., be kept conflict-free. In case a conflict between constraints of the constraint space is detected, the same may, e.g., be resolved.
[0029] For example, an execution requirement for controlling the trusted execution environment is generated using the received constraints forming the constraint space. The generated execution requirement may ensure that all the constraints of the constraint space are satisfied.
[0030] For each of the constraints of the constraint space an identifier may be determined and assigned to the respective constraint. The identifiers of the constraints may be added to the execution requirement for an attestation of the constraints. The identifiers may be configured to uniquely identify the individual constraints comprised by the execution requirement and their respective contents. The identifiers may, e.g., be fingerprints, like checksums of the respective constrains. The checksums may, e.g., be implemented in form of hash values. Such a checksum may result from applying a oneway checksum function, e.g., a hash function to the respective constraint.
[0031] In addition, e.g., at least one secret may be received or generated. For example, a secret per entity is received or generated. For example, a secret per constraint is received or generated. The one or more secrets are, e.g., added to the execution requirement. For example, the one or more secrets may be used for encrypting data of the execution of the workload on the one or more trusted execution environments. For example, the one or more secrets may be used for encrypting data resulting from the execution of the workload on the one or more trusted execution environments. In order to gain access to the encrypted data, it may be necessary to decrypt the data. For example, the one or more secrets may be used for decrypting the encrypted data. For example, the one or more secrets may be used for enabling an encrypted communication between the one or more trusted execution environments and the one or more entities.
[0032] For example, the one or more trusted execution environments are facilitated to encrypt and decrypt data in the one or more trusted execution environment using the one or more secrets. For example, the generated execution requirement comprises more than one secret, which are used in combination for encrypting and decrypting data of the execution of the workload on the one or more trusted execution environments. For example, the secrets may be combined to derive a symmetric cryptographic key for encrypting and decrypting the respective data.
[0033] An execution of the workload on the one or more trusted execution environments may be controlled according to execution requirement, i.e., using the constraints comprised and / or defined by the execution requirement.
[0034] For example, the one or more trusted execution environments are facilitated to provide attestation records of the constraints used to control the respective trusted execution environment. These attention records may comprise the identifiers of the respective constraints. Thus, using the identifiers comprised by the attestation records being provided, it may be checked, whether the one or more trusted execution environments are indeed controlled using the constraints comprised by the execution requirement.
[0035] This may, e.g.. allow the entities to independently verify, whether the one or more trusted execution environments execute the workload in accordance with their constraints. Any of the entities may be enabled to check, whether the one or more trusted execution environments are indeed controlled using the one or more constraints provided by the respective entity. For this purpose, the respective entity may check, whether the attestation record comprises the identifier of the constraints provided by the respective entity.
[0036] An execution requirement may define in a machine-readable way, constraints to be satisfied by a trusted execution environment used for confidential computing, when executing a workload. These constraints comprised by the execution requirement may, e.g., define properties of one or more applications and / or of their environment, which are to be executed using the trusted execution environment. In addition, the execution requirement may define one or more secrets to be used for securing the data processing using the trusted execution environment.
[0037] The trusted execution environment may execute the one or more applications according to the properties specified by the constraints in the execution requirement. The trusted execution environment may furthermore make the one or more secrets available to the one or more applications for securing the data being processed by the respective applications on the trusted execution environments.
[0038] Examples may take into account a plurality of constraints provided by a plurality of entities for generating the execution requirement and thus for controlling the execution of the workload. Examples may, e.g., provide a process for automatically bringing together the constraints received from different entities to control provisioned or ready-to-be-provisioned applications on one or more trusted execution environments.
[0039] Examples may detect conflicts between received constraints and provide means for resolving these conflicts. Thereby, examples may provide an approach for automatically ensuring that an execution requirement is consistent prior to a deployment using one or more trusted execution requirements. Rather than initially minimizing potential conflicts by restricting constraints definable by the entities, examples may provide a way to verify and thus ensure consistency of the constraints of the execution requirement.
[0040] Examples may provide a lifecycle control for an execution requirement. The constraint space used for generating the execution requirement may be monitored and the execution requirement updated in response to an update of the constraint space. The execution requirement may, e.g., be amended or even revoked due to an amending and / or revoking of constraints provided by one or more entities of the plurality of entities.
[0041] Application instances that are provisioned based on a generated execution requirement may, e.g., be automatically deprovisioned or controlled using an updated execution requirement in response to an entity’s requirements as described by the respective entity’s constraints being amended.
[0042] The examples may e.g., be based on one or more of the following assumptions: A constraint provided by an entity may define one or more requirements on one or more allowed properties of one or more applications and / or on one or more their environment, which are to be executed in one or more trusted execution environments. Furthermore, a constraint may comprise one or more secrets to be passed to the one or more applications. Constraints may be received form a plurality of different entities. A constraint may, e.g., be related to one or more other constraints. For example, such a constraint may define syntactical or semantical requirements on the one or more other constraints. A constraint may, e.g., be expressed using a constraint language.
[0043] The trusted execution requirements may be hardware-based trusted execution requirements. A hardware-based trusted execution environment is an execution environment that provides hardware-based technical assurance of the following properties: data confidentiality, data integrity, code confidentiality, code integrity, programmability, attestation. Data confidentiality ensures that unauthorized entities are prevented from viewing data, while it is in use within the trusted execution environment. Data integrity ensures that unauthorized entities are prevented from adding, removing, or altering data, while it is in use within the trusted execution environment. Code integrity ensures that unauthorized actors are prevented from adding, removing, or altering code that is running in the trusted execution environment.
[0044] Code confidentiality ensures that the trusted execution environment protects the code, while in use from being viewed or accessed by unauthorized entities. Programmability ensures that the trusted execution environment can be programmed with arbitrary code. Attestation refers to a process with which the trusted execution environment can provide evidence or measurements, like identifiers, of its origin and current state. This evidence is verifiable by other entities, which are enable by the evidence provided to decide, whether to trust an application running in the trusted execution environment or not. The evidence may be provided in form of an attestation record. The contents of this attestation record may be verified against workload and / or environment expectations. The attestation record may be signed using a cryptographical key, which may be anchored in hardware that may, e.g., be vouched for by a trusted manufacturer. This signature provides assurance that the attestation record was generated by the correct component and was not altered by an unauthorized entity.
[0045] Due to the code and data confidentiality as well as integrity implemented by the trusted execution environment, the trusted execution environment isolates application code and data provided as workload to the trusted execution environment from access and modification by unauthorized entities. The application code and data are isolated from access and modification by other privileged as well as non-privileged entities, which includes potentially malicious administrators as well as other tenants.
[0046] Confidential computing refers to a protection of data in use by performing computation in a hardware-based, attested trusted execution environment. Confidential computing may provide a trusted execution environment for applications, even in an untrusted environment. The hardware-based security mechanism that is offered by confidential computing enables a processing and storing of sensitive data in a safe enclave provided by one or more trusted execution environments that is isolated from the host system and other potentially vulnerable components.
[0047] The execution requirement, sometimes also referred to as a contract, is a document comprising constraints for an execution of a workload on one or more trusted execution environments. The execution requirement may define parameters for the execution of the workload in compliance with the constraints comprising constraints. It may, e.g., define properties of one or more applications to be executed in the one or more trusted execution environment and properties of the environments, in which applications are to be executed. The execution requirement may be a document, which, e.g., comprises a plurality of sections. Each of these sections may, e.g., be assigned to one of the entities of the plurality of entities and / or comprise the constraints received from the respective entity. For example, the different sections of the plurality of section may be encrypted independently.
[0048] An execution requirement may, e.g., comprise application parameter defining an application workload to be executed on a trusted workload as well as environment parameter describing the environment, in which the application workload is to be executed. The application parameter may, e.g., define one or more virtual machines, also referred to as images, on which the application is to be executed, a virtual machine registry, where it resides, and / or the information and credentials that are required to download and validate the virtual machine. Environment parameter may describe an environment for the application. They may define information about logging, such as where logs should be sent to. The execution requirement may further comprise information about data volumes, seeds for deriving a volume encryption passphrase, and / or a public part of an execution requirement signing key. The execution requirement may comprise a cryptographic key, e.g., a public cryptographic key to be used to encrypt an attestation record.
[0049] An attestation record comprises identifiers, like checksums, of constraints complied with by the one or more trusted execution environments executing the workload. It may further comprise identifiers, like checksums, of an original base virtual machine used to execute the workload, of a compressed root filesystem, and / or of cloud initialization options. The attestation record may be signed. A signature verification key configured for verifying the signature of the attention record may be provided. The attestation record may, e.g., be encrypted.
[0050] Identifiers, like checksums, of the data elements of the attestation record may, e.g., be compared against identifiers of the expected execution requirement. If this validation succeeds, because the identifiers being compared are identical, this may prove that the trusted execution environment uses the expected execution requirement for the execution of the workload. This means that the trusted execution environment may run the expected environment and virtual machines that are defined in the execution requirement.
[0051] Data of the execution of the workload on the trusted execution environment may be encrypted using a passphrase derived using secrets, e.g., cryptographic seeds, provided by and / or assigned to different entities of the plurality of entities. This means, e.g., that no entity of the plurality entities can individually re-create the passphrase, because each of the entities may only know its own cryptographic seed.
[0052] For implementing a secure handling of cryptographic keys, one or more hardware security modules (HSMs) may be used. A HSM is a device or service that safeguards and manages secrets, such as cryptographic keys, and performs cryptographic functions such as key creation, key derivation, encryption, decryption, and a signature. An HSM may, e.g., contains one or more cryptographic processors. A cloud HSM is a cloud service that provides the same functions as a physical HSM.
[0053] For example, the method further comprises determining the plurality of identifiers of the constraints of the constraint space.
[0054] For example, the identifiers are checksums of the constraints. The determining of the plurality of identifiers comprises calculating the checksums of the respective constraints of the constraint space. For example, a checksum is calculated for each of the constraints of the constraints of the constraint space.
[0055] The checksums may enable a checking, which constraints are taken into account and / or comprised by the execution environment. The checksums may, e.g., be calculated using a one-way function. The checksums may, e.g., be hash values calculated using a hash function.
[0056] For example, the constraints of the constraint space define the parameters for the execution of the workload on the one or more trusted execution environments. These parameters may define the workload, e.g., an application to be executed on one or more of the trusted execution environments. The parameters may, e.g., define a version of the application and / or setup parameters of the application. The parameters may, e.g., define features of an environment within which the application is to be executed. These features may, e.g., comprise certificates, cryptographic algorithms, authentication parameter, communication parameter, API-keys, initialisation data, resources, quota on filesystems, filesystem size, message buses etc. to be provided by the environment for the execution of the workload.
[0057] For example, the constraints of the constraint space comprise one or more first constraints and one or more second constraints. The one or more first constraints comprise one or more additional constraints on one or more of the parameters defined by the one or more second constr aints for the execution of the workload. Thus, the constraints may also comprise constraints on other constraints.
[0058] For example, the method further comprises checking the constraints of the constraint space for conflicts between each other. In response to detecting one or more conflicts, the detected conflicts are flagged. By checking the constraint space for conflicts, it may be determined, whether the constrains space is conflict-free. In case the constraint space is free of conflicts between constraints, no further conflict related actions may be required. In case a conflict is detected, the conflict may have to be dealt with. Dealing with the conflict may comprise flagging the respective conflict and / or resolving the flagged conflict. By resolving all the conflicts, a conflict-free constraint space may be provided as a basis generating the execution requirement.
[0059] For example, the method further comprises resolving the detected conflicts of the constraint space. By resolving the flagged conflicts, a conflict-free constraint space may be provided as a basis generating the execution requirement. Using a conflict-free constraint space for generating the execution requirement, may ensure that all the constraints defined by all the different entities are complied with, when the workload is executed according to the execution requirement.
[0060] For example, the resolving of at least one of the detected conflicts of the constraint space comprises generating a priority list of conflicting constraints of the constraint space, between which the respective conflict is detected. The priority list assigns priorities to the respective constraints. A proposal is generated using a constraint assigned with a highest priority for resolving the detected conflict. The proposal is sent to one or more entities assigned to a constraint with a lowest priority. In response to receiving approvals of the proposal from all entities assigned to the constraint with the lowest priority, the method continues with sending the proposal to one or more entities assigned to a constraint with a next higher priority. The sending of the proposal is continued, until approvals of the proposal are received from all entities assigned to a constraint with a second highest priority. In response to receiving approvals of the proposal from all entities assigned to the constraint with the second highest priority, the detected conflict is resolved using the proposal.
[0061] Using a constraint assigned with a highest priority for resolving the detected conflict, the entities assigned to this constraint with the highest priority are assigned to the proposal, Le., have requested this constraint and thus approved of it. Thus, as soon as approvals of the proposal from all entities assigned to the constraint with the second highest priority have been received, approvals for using the proposal for resolving the conflict have been provided by all the entities involved in the conflict.
[0062] For example, all the detected conflicts may be resolved according to the aforementioned method. Thus, all the detected conflicts may be resolved resulting in a conflict-free consttaint space.
[0063] For example, the priorities assigned to the respective constraints by the priority list are determined using one or more of the following: levels of security determined for the respective constraints, levels of restriction determined for the respective constraints, numbers of entities assigned to the respective constraints. The higher the level of security of a constraint, the higher its priority may be. For example, in view of security of application, the newer a version of an application is, the higher its level of security may be. The higher a level of restriction of a constraint, the higher its priority may be. The more restrictive an execution of an application is, the more difficult it may be to successfully attack and compromise the execution of this application. The higher a number of entities assigned to a constraint, the higher its priority may be. The more entity is requiring a constraint, the more important it may be. Taking into account a number of entities assigned to a constraint, when determining a proposal to resolve a conflict, may implement a kind of consensus model.
[0064] For example, the priority list of the constraints comprises at least two constraints received from two different entities. For example, the priority list of the constraints comprises a plurality of constraints, i.e., two or more constraints received from two or more different entities.
[0065] For example, the priority list sorts the constraints, for which the respective conflict is detected, according to the assigned priorities.
[0066] For example, the sending of the proposal to more than one entity assigned to a constraint comprises generating a priority list of entities for the respective more than one entities. The priority list may assign priorities to the respective entities. For example, such a priority list of the entities may be used for resolving conflicts. For example, a constraint received from the entity with the highest priority may be used as a proposal for resolving the conflict. For example, the proposal is sent an entity assigned with a lowest priority. In response to receiving an approval of the proposal from the entity with the lowest priority, the method continues with sending the proposal to an entity with a next higher priority. The sending of the proposal being continued, until an approval of the proposal is received from an entity assigned with a second highest priority.
[0067] The priorities assigned to the respective entities are, e.g., determined using one or more of the following: levels of security determined for constraints received from the respective entities, levels of restriction determined for constraints received from the respective entities, numbers of constraints assigned to the respective entities. The higher the levels of constraints received from an entity, the higher its priority may be. The higher the levels of restriction determined for constraints received from an entity, the higher its priority may be. The higher a number of constraints assigned to an entity, the higher its priority may be.
[0068] For example, the method further comprises monitoring the constraint space. When monitoring the constraint space, adjustments of the constraint space may be detected, and suitable measures may be taken into account the detected adjustments. Monitoring the constraint space may, e.g., comprise maintaining the constraint space comprising conflict-free. In case an adjustment of the constraint space resulting in a conflict is detected, the respective conflict may be resolved, in order to keep the constraint space conflict-free.
[0069] For example, the method further comprises receiving one or more adjustments of the constraint space from one or more of the entities. The adjustments of the constraint space may, e.g., comprise one or more additional constraints to be added to the constraint space. The adjustments of the constraint space may, e.g., comprise one or more constraints being removed from the constraint space. The adjustments of the constraint space may, e.g., comprise one or more updated, i.e., adjusted constraints replacing one or more constraints of the constraint space.
[0070] For example, the monitoring of constraint space comprises checking the constraints of the adjusted constraint space for conflicts between each other resulting from the received adjustments. In response to detecting one or more conflicts, the detected conflicts are flagged.
[0071] For example, the method further comprises sending information about the flagged conflicts of the adjusted constraint space to the one or more trusted execution environments controlled in compliance with the execution requirement to abort execution of the workload. For example, the one or more trusted execution environments may abort execution of the workload in response to receiving the information about the flagged conflicts.
[0072] For example, the method further comprises resolving the detected conflicts of the adjusted constraint space.
[0073] For example, the resolving of at least one of the detected conflicts of the adjusted constraint space comprises generating a priority list of constraints of the adjusted constraint space, between which the respective conflict is detected. The priority list assigns priorities to the respective constraints. A proposal is generated using a constraint assigned with a highest priority for resolving the detected conflict. The proposal is sent to one or more entities assigned to a constraint with a lowest priority. In response to receiving approvals of the proposal from all entities assigned to the constraint with the lowest priority, sending the proposal is continued to one or more entities assigned to a constraint with a next higher priority. The sending of the proposal is continued, until approvals of the proposal are received from all entities assigned to a constraint with a second highest priority. In response to receiving approvals of the proposal from all entities assigned to the constraint with the second highest priority, the detected conflict is resolved using the proposal.
[0074] For example, the method further comprises, in response to the receiving of the one or more adjustments, generating an adjusted execution requirement for controlling the one or more trusted execution environments using the constraints of the adjusted constraint space. The adjusted execution requirement defines adjusted parameters for the execution of the workload in compliance with the respective constraints. The generating comprises adding identifiers of the constraints to the adjusted execution requirement for an attestation of the constraints, which the one or more trusted execution environments comply with, when executing the workload in compliance with the adjusted execution requirement. The one or more trusted execution environments are controlled in compliance with the adjusted execution requirement. The controlling comprises providing the one or more trusted execution environments with the adjusted execution requirement as a replacement for the execution requirement.
[0075] Thus, the workload may be executed on the one or more trusted execution environments in compliance with the adjusted execution requirement. Thereby the adjustments of the constraint space may be taken into account for the execution of the workload.
[0076] For example, the adjustments comprise one or more of the following: a revocation of a constraint, an adjusted constraint, an additional constraint.
[0077] The revocation of a constraint of the constraint space may result in a removal of the respective constraint from the constraint space. The adjustments of the constraint space may, e.g., comprise one or more constraints being removed from the constraint space.
[0078] The adjusted constraint may be used to replace a constraint comprised by the constraint space. The adjustments of the consttaint space may, e.g., comprise one or more updated, i.e., adjusted constraints replacing one or more constraints of the constraint space.
[0079] The additional constraint may be added to the constraint space. The adjustments of the constraint space may, e.g., comprise one or more additional constraints to be added to the constraint space.
[0080] For example, the generating of the execution requirement further comprises adding at least one secret to the execution requirement to be used for encrypting and decrypting data of the execution of the workload on the one or more trusted execution environments. For example, the secret is received. For example, the secret is generated and sent to the entities.
[0081] For example, a secret may comprise a certificate, a cryptographic key, and / or a cryptographic seed configured to be used for a key derivation.
[0082] For example, the generating of the execution requirement further comprises adding at least one secret per entity to the execution requirement to be used in combination for encrypting and decrypting data of the execution of the workload on the one or more trusted execution environments.
[0083] For example, each of the secrets is assigned to one or more of the entities of the plurality of entities. For example, the secrets are received from the entities. For example, the secret is generated and sent to the entities, to which they are assigned.
[0084] For example, the generating of the execution requirement further comprises adding at least one secret per entity to the execution requirement, which is assigned to the respective entity and configured to be used for encrypting and decrying a communication with the respective entity.
[0085] For example, the generating of the execution requirement further comprises adding one secret per constraint to the execution requirement to be used in combination for encrypting and decrypting data of the execution of the workload on the one or more trusted execution environments.
[0086] The secrets may be combined and used together to derive a cryptographical key for the encrypting and decrypting data of the execution of the workload on the one or more trusted execution environments.
[0087] For example, the method further comprises generating a report of the generating and deploying of the execution requirement. The report is sent to the entities. For example, the report of the generating and deploying of the execution requirement is sent to the entities in reply to the receiving of the constraints for the execution of the workload from the plurality of entities.
[0088] For example, the execution requirement comprises a verifiable reference, like a signature, to the confidential computing control service generating the execution requirement.
[0089] In a first exemplary scenario, which is provided for illustrative purposes, an execution requirement may be generated using constraints received from three different entities.
[0090] The three entities may, e.g., comprise a workload provider (WP1) as a first entity, a DevSecOps (Development, Security and Operations) provider (DS1) as a second entity, and a workload deployer (WD1) as a third entity.
[0091] The constraints received from the first entity WP1 may, e.g., comprise: require: play: resources: - apiVersion: vl kind: Pod metadata: name: paynow spec: hostNetwork: true hostPID: true containers: - name: paynow image: ghcr.io / ibm-hyper-protect / paynow-website@sha256:ddba7 ports: - containerPort: 8443 volumeMounts: - mountPath: / var / hyperprotect / name: hyper seed: AAA...999
[0092] The constraints received from the second entity DS 1 may, e.g., comprise: require: play: resources: - apiVersion: vl kind: Pod metadata: name: sysdig-cspm spec: containers: - name: sysdig-cspm-agent image: us .icr. io / sysdig-for-hp vs / kspm-analyzer@ sha256:21b47 env: - name: ACCESS_KEY value: xxxxxxxxxxxxxxxxxx - name: API_ENDPOINT value: us-east.security-compliance-secure.cloud.ibm.com logging: logDNA: hostname: *.logging.cloud.ibm.com
[0093] The constraints received from the third entity WD1 may, e.g., comprise: require: logging: logDNA: ingestionKey: xxxxxxxxxxxxxxx hostname: syslog-a.eu-gb.logging.cloud.ibm.com 7 seed: BBB...888
[0094] The constraints received from three different entities are used for generating an execution requirement. Generating the execution requirement may, e.g., comprise combining the received constraints into an intermediary representation of the form: WPl’s constraints - DSl’s constraints - WD l’s constraints.
[0095] As all constraints can be resolved successfully without conflicts being detected, it may be determined that there is no conflict, and an execution requirement may be generated in a format suitable for the trusted execution environment. The generated execution requirement may, e.g., have the form: workload: I type: workload PlaY: resources: - apiVersion: vl kind: Pod metadata: name: paynow-sysdig-cspm spec: hostNetwork: true hostPID: true containers: - name: paynow image: ghcr.io / ibm-hyper-protect / paynow-website@sha256:ddba7 ports: - containerPort: 8443 volumeMounts: - mountPath: / var / hyperprotect / name: hyper - name: sysdig-cspm-agent image: us.icr.io / sysdig-for-hpvs / kspm-analyzer@sha256:21b47 env: - name: ACCESS_KEY value: xxxxxxxxxxxxxxxx - name: API_ENDPOINT value: us-east.security-compliance-secure.cloud.ibm.com volumes: - name: hyper hostPath: path: / var / hyperprotect / type: Directory env: I type: env logging: logDNA: ingestionKey: xxxxxxxxxxxxxxxxxx hostname: syslog-a.eu-gb.logging.cloud.ibm.com seed: AAA...999BBB...888
[0096] In a second exemplary scenario, which is provided for illustrative purposes, in addition to the aforementioned constraints received from the three entities WP1, DS1, and WD1, further constraints may be received from a fourth entity. The fourth entity may, e.g., be a second DevSecOps provider (DS2). The execution requirement may be generated using the constraints received from the fourth different entities.
[0097] The constraints received from the fourth entity DS2 may, e.g., comprise: require: logging: logDNA: hostname: syslog-a.us*.logging.cloud.ibm.com
[0098] It may, e.g., be tried to resolve all the constraints received from the four entities, e.g. in the following order: WPl’s constraints - DSl’s constraints - WDTs constraints -DS2’s constraints. When comparing the DS2’s constraints with the WDTs constraints or with a temporary result from evaluating WPl’s, DSl’s and WDl’s constraints, a conflict may be detected, since WD1 requires as a constraint for the “hostname” “syslog-a.eu-gb”, whereas DS2 requires “syslog-a.us*”. In response to detecting the conflict, the detected conflict may, e.g., be flagged. In addition, the generating of the execution requirement may, e.g., be paused. The generating may, e.g., be paused until the conflict is resolved. In order to resolve the conflict, e.g., an interaction and / or a negotiation between DS2 and WD1 may be initiated and / or moderated.
[0099] Subsequently, e.g., WD1 may update the previously provided constraints, as follows: require: logging: logDNA: ingestionKey: xxxxxxxxxxxxxxx hostname: syslog-a.us-south.logging.cloud.ibm.com seed: BBB...888
[0100] The updated constraint “syslog-a.us-south” required by WD1 for the “hostname” complies with the constrain “syslog-a.us*” required by DS2. Thus, e.g., the flag for die conflict may be removed and the generating of the execution requirement may be resumed using the updated constraints received from DS2.
[0101] The resulting execution requirement may, e.g., have the form: workload: I type: workload play: resources: - apiVersion: vl kind: Pod metadata: name: timotest-sysdig-cspm spec: hostNetwork: true hostPID: true containers: - name: paynow image: ghcr. io / ibm-hyper-protect / paynow-website @ sha256: ddba7 ports: - containerPort: 8443 volumeMounts: - mountPath: / var / hyperprotect / name: hyper - name: sysdig-cspm-agent image: us.icr.io / sysdig-for-hpvs / kspm-analyzer@sha256:21b47 env: - name: ACCESS_KEY value: xxxxxxxxxxx - name: API_ENDPOINT value: us-east.security-compliance-secure. cloud.ibm.com volumes: - name: hyper hostPath: path: / var / hyperprotect / type: Directory env: I type: env logging: logDNA: ingestionKey: 79271030d533ca3157f0cf4617 8d9a66 hostname: syslog-a.us-south.logging.cloud.ibm.com seed: AAA...999BBB...888
[0102] Figure 1 is a flowchart of an exemplary method for automatically controlling an execution of a workload on one or more trusted execution environments, while compliance with a plurality of constraints required by a plurality of entities is enforced. In block 100, the plurality of constraints for the execution of the workload is received from the plurality of entities. The received constraints form a constraint space. In block 108, an execution requirement for controlling the one or more trusted execution environments is automatically generated using the constraints of the constraint space. The execution requirement defines parameters for the execution of the workload in compliance with the respective constraints. The generating comprises adding identifiers of the constraints to the execution requirement for an attestation of the constraints, with which the one or more trusted execution environments comply with, when the workload is executed in compliance with the execution requirement. In block 110, the one or more trusted execution environments are controlled in compliance with the execution requirement. The controlling comprises providing the one or more trusted execution environments with the execution requirement enabling the one or more trusted execution environments to provide one or more attestation records for the attestation of the execution of the workload comprising the identifiers of the constraints.
[0103] Figure 2 is a flowchart of an exemplary method for automatically controlling an execution of a workload on one or more trusted execution environments, while compliance with a plurality of constraints required by a plurality of entities is enforced. In block 200, the plurality of constraints for the execution of the workload is received from the plurality of entities. The received constraints form a constraint space. In block 202, the constraints of the constraint space are checked for conflicts between each other. In response to no conflicts being detected between the constraints of the constraint space, the method continues with block 208. In response to one or more conflicts being detected between the constraints of the constraint space, the method continues with block 204. In block 204, the one or more conflicts detected in block 202 are flagged. In block 206, the one or more conflicts flagged in block 204 are resolved. In response to all the flagged conflicts having been resolved in block 206, the method is continued in block 208. In block 208, an execution requirement for controlling the one or more trusted execution environments is automatically generated using the constraints of the constraint space. The execution requirement defines parameters for the execution of the workload in compliance with the respective constraints. The generating comprises adding identifiers of the constraints to the execution requirement for an attestation of the constraints, with which the one or more trusted execution environments comply with, when the workload is executed in compliance with the execution requirement. In block 210, the one or more trusted execution environments are controlled in compliance with the execution requirement. The controlling comprises providing the one or more trusted execution environments with the execution requirement enabling the one or more trusted execution environments to provide one or more attestation records for the attestation of the execution of the workload comprising the identifiers of the constraints.
[0104] Figure 3 is a flowchart of an exemplary method for resolving conflicts between consttaints. The method of Figure 3 may, e.g., used in block 206 of Figure 2 to resolve the one or more flagged conflicts. In block 300, a priority list is generated of conflicting constraints of a constraint space, between which a conflict is detected. The priority list assigns priorities to the respective constraints. For example, the priorities assigned to the respective constraints by the priority list are determined using one or more of the following: levels of security determined for the respective constraints, levels of restriction determined for the respective constraints, numbers of entities assigned to the respective constraints. In block 302, a proposal is generated using a constraint assigned with a highest priority for resolving the detected conflict. In block 304, the proposal is sent to one or more entities starting with the one or more entities assigned to a constraint with a lowest priority. In block 306, one or more responses from the one or more entities are received. In block 308, it is checked, whether the received responses are approvals. In case one of the responses received in block 306 is no approval, the method ends in block 314. In case all the responses received in block 306 are approvals, the method continues in block 310. In block 310 it is checked, whether approvals of the proposal have been received from all entities assigned to a constraint with a second highest priority according to the priority list. In case approvals of the proposal have not been received from all entities assigned to a constraint with a second highest priority according to the priority list, the method continues in block 304 with sending the proposal to one or more entities assigned to a constraint with a next higher priority. The sending of the proposal is continued, until in block 310 it is determined that approvals of the proposal have been received from all entities assigned to a constraint with a second highest priority. In response to having receiving approvals of the proposal from all entities assigned to the constraint with the second highest priority, the detected conflict is resolved in block 312 using the proposal.
[0105] Figure 4 is a flowchart of an exemplary method for controlling an execution of a workload on a trusted execution environment. In block 400, a constraint space is monitored. The constraint space is formed by a plurality of constraints for an execution of a workload received from a plurality of entities. In block 402, one or more adjustments of the constraint space are received from one or more of the entities. The one or more adjustments may, e.g., comprise one or more adjusted constraints as replacements for one or more of the constraints of the constraint space, a deletion of one or more of the constraints of the constraint space, and / or one or more additional constraints to be added to the constraint space. The constraint space is adjusted using the one or more received adjustments.
[0106] In block 404, the constraints of the adjusted constraint space are checked for conflicts between each other resulting from the received adjustments. In response to no conflicts being detected, the method is continued in block 410. In response to detecting one or more conflicts, the method is continued in block 406. In block 406, the one or more detected conflicts are flagged. In block 408, the one or more flagged conflicts of the adjusted constraint space may be resolved. For resolving the flagged conflicts, e.g., the method of Figure 3 may be used. For resolving one of the flagged conflicts of the adjusted consttaint space, a priority list of constraints of the adjusted constraint space may be generated, between which the flagged conflict is detected. The priority list assigns priorities to the respective constraints. A proposal may be generated using a constraint assigned with a highest priority for resolving the detected conflict. The proposal may be sent to one or more entities assigned to a constraint with a lowest priority. In response to receiving approvals of the proposal from all entities assigned to the constraint with the lowest priority, sending the proposal may be continued to one or more entities assigned to a constraint with a next higher priority. The sending of the proposal may be continued, until approvals of the proposal are received from all entities assigned to a constraint with a second highest priority. In response to receiving approvals of the proposal from all entities assigned to the constraint with the second highest priority, the detected conflict may finally be resolved using the proposal.
[0107] In block 410, an adjusted execution requirement for controlling the one or more trusted execution environments is generated using the constraints of the adjusted constraint space. The adjusted execution requirement defines adjusted parameters for the execution of the workload in compliance with the respective constraints. The generating comprises adding identifiers of the constraints to the adjusted execution requirement for an attestation of the constraints being complied with by the one or more trusted execution environments, when executing the workload in compliance with the adjusted execution requirement. In block 412, the one or more trusted execution environments are controlled in compliance with the adjusted execution requirement. The controlling comprises providing the one or more trusted execution environments with the adjusted execution requirement as a replacement for the execution requirement.
[0108] Figure 5 is an exemplary computing environment 501 for controlling an execution of a workload on one or more trusted execution environments (TEEs) 510 of a deployment infrastructure 508. The computing environment 501 comprises a confidential computing control service (CCCS). The CCCS 500 is, e.g., provided on a server, e.g., in form of a cloud service, like a SaaS. The CCCS 500 implements a method for automatically controlling an execution of a workload on one or more TEEs 510 of the TEEs 510 provided by the deployment infrastructure 508, while compliance with a plurality of constraints required by a plurality of entities 504 is enforced. The plurality of constraints for the execution of the workload is received by the CCCS 500 from the plurality of entities 504. Each of the entities 506 of the plurality of entities 504 may sent one or more constraints to the CCCS 500 to be complied with by the TEEs 510, when executing the workload. The entities 506 may defined their constraints sent to the CCCS independently of each other. For example, the individual entities 506 may have no knowledge of the constraints defined by the other entities 506 of the plurality of entities. The entities 506 may be different entities related to the workload to be executed using confidential computing. The plurality of entities 504 may, e.g., comprise one or more entities 506 of one or more developers. The plurality of entities 504 may, e.g., comprise one or more entities 506 of one or more cloud infrastructure administrators. The plurality of entities 504 may, e.g., comprise one or more entities 506 of one or more administrators of one or more services used for developing, managing and / or deploying the workload to be executed using the confidential computing provided by the CCCS 500 and the TEEs 510. The one or more services may, e.g., comprise kubernetes (K8s). K8s is an open-source container orchestration system for automating software deployment, scaling, and management. K8s is configured to assemble one or more computers, either virtual or physical machines, into a cluster which is enabled to run workloads in containers. K8s may work with various container runtimes and is configured for running and managing workloads of different sizes and styles. K8s defines a set of building blocks, so called "primitives", that collectively provide mechanisms that are configured to deploy, maintain, and / or scale applications based on CPU, memory and / or custom metrics. The plurality of entities 504 may, e.g., comprise one or more entities 506 of one or more consumers. The plurality of entities 504 may, e.g., comprise one or more entities 506 of one or more third party representatives.
[0109] The entities 506 of the plurality of entities 504 providing constraints to be taken account in combination for generating a common execution requirement may, e.g., be registered, e.g., using a registration service 520. The registration service 520 may manage a database 522 with registration data of registered entities 506. Furthermore, e.g., activity of the registered entities 506 may be logged using log data.
[0110] The constraints received by the CCCS 500 from the entities 506 form a constraint space, which may, e.g., be stored in a database 502, to which the CCCS 500 has access. The CCCS 500 may, e.g., be configured to detect conflicts between the constraints received. The CCCS 500 may, e.g., be configured to resolve detected conflicts between constraints. The resolving of conflicts between constraints provided by the entities 506 may, e.g., comprise negotiating one or more adjustments of the constraints with the entities 506. The CCCS 500 may, e.g., be configured to provide feedback about the constraints being used for generating the execution requirement to the entities 506, from which the respective constraints are received. The CCCS 500 may further be configured to monitor the constraint space of the database 502 and update it in response to receiving updates for constraints from the entities 506.
[0111] The CCCS 500 is configured to automatically generate an execution requirement for controlling one or more TEEs 510 of deployment infrastructure 508 using the constraints of the constraint space 502. The execution requirement defines parameters for the execution of the workload in compliance with the respective constraints. The generating may comprise adding identifiers of the constraints, like checksums, to the execution requirement for an attestation of the constraints, with which the one or more TEEs 510 comply with, when the workload is executed in compliance with the execution requirement. The execution requirement may be provided to a deployment pipeline of the deployment infrastructure 508 and used to control one or more of the TEEs 510 of the deployment infrastructure 508 in compliance with the execution requirement. The controlling may comprises providing the one or more TEEs 510 with the execution requirement. Providing the TEEs 510 with the execution requirement may, inter alia, enable the TEEs 510 to provide one or more attestation records for the attestation of the execution of the workload to the entities 506 comprising the identifiers of the constraints. Using the identifiers comprised by the attention record, the entities 506 are enabled to verify, whether their constraints provided to CCCS 500 are actually used by the TEEs 510 for the execution of the workload. The identifiers may be provided in form of checksums, e.g., hash values of the constraints. Thus, each of the entities 506 may be enabled to verify that their own constraints are complied with by calculating checksums, like hash values, of their own constraints for the purpose of comparison with the attention record. On the other hand, the entities 506 may be prevented from gaining insight in the constraints defined by the other entities 506 of the plurality of entities 504, when one-way functions, like hash functions, are used to determine the identifiers of the constraints.
[0112] The entities 506, e.g., entities of one or more developer, of one or more cloud infrastructure providers, of one or more service providers, like kubernetes administrators, of one or more third party representatives and / or of one or more consumers, may register with the registration service 520 to use a cloud service. The registration service 520 may register the entities 506 and create a database entry in database 522 for each entity 506 and / or of the persona represented by the respective entity 506.
[0113] Each entity 506 may generate a set of one or more constraints to be complied with by the TEEs 510, when executing a workload related to entity 506. The respective set of constraints may, e.g., comprise constraints on a set of aspects defining one or more applications to be made operatable in one or more TEEs 510 of the deployment infrastructure 508. The respective set of constraints may, e.g., further comprise one or more constraints relating to other constraints.
[0114] The CCCS 500 may generated an execution requirement for controlling a set of one or more TEEs 510 of the deployment infrastructure 508 according to the constraints received from the entities 506. Each entity 506 may, e.g., encrypt its constraints being made available, e.g., sent to the CCCS 500 using a public key of the CCCS 500 and / or a symmetric key agreed upon with the CCCS 500. There are different possibilities, how the respective constraints may be made available to the CCCS 500. The constraints may be sent to the CCCS 500 by the entities 506. The constraints may alternatively be retrieved by the CCCS 500 using, e.g., a registration-based or crawler-like auto-discovery.
[0115] The CCCS 500 uses the constraints to build the constraint space stored in database 502. Building the constraint space may comprise determining and / or receiving constraints represented in a constraint language and generated by the different entities 506. The constraints may, e.g., be received by the CCCS 500 via an API. According to an example, before accepting an additional constraint a test for conflicts may be performed by the CCCS 500 against the current constraint space. For example, a test evaluation of the constraints may be performed.
[0116] The constraints from the constraint space may, e.g., be evaluated and resolved by the CCCS 500 into a consistent execution requirement for use by at least one TEE 510 of the deployment infrastructure 508, while detecting potential conflicts between the constraints. Conflicts between constraints in the constraint space, which are detected, e.g., during constraint resolution, may, e.g., be flagged. Optionally, an additional conflict resolution protocol (CRP) may be executed by the CCCS 500, in order to resolve the flagged conflicts.
[0117] For each constraint of the constraint space, e.g., a measurement in form of an identifier, e.g., a hash value, like a sha256 checksum, of a canonical representation of the constraint, e.g., in a human-readable data serialization language, like YAML, may be generated. These identifiers may be added to the execution requirement generated by the CCCS 500.
[0118] In addition, the CCCS 500 may, e.g., generate and / or deriving at least one secret. For example, for each of the entities 506 a secret associated with the respective entity may be determined. The resulting on or more secrets may in addition be added to the execution requirement generated by the CCCS 500.
[0119] For example, the CCCS 500 may in addition generate and provide feedback about the resolution and / or the resolution results to the entities 506. The feedback may, e.g., comprise feedback about the resulting execution requirement and / or about which TEE 510 implements the execution requirement resulting from the constraints of the respective entities 506.
[0120] The CCCS provides the resulting execution requirements, e.g., via a deployment pipeline, for use to at least one TEE 510 of the deployment infrastructure 508. In addition, e.g., a verifiable reference to the CCCS, like a digital signature by the CCCS 500, may be added.
[0121] The TEE 510 receiving the execution requirement may be facilitated to provide attestation records including identifiers of the constraints complied with by the TEE 510, when executing the workload according to execution requirement. This may allow the entities 506 to validate the attestation records for their constraints by checking the identifiers. Furthermore, the one or more secrets comprised by the execution requirement may enable the TEE 510 to encrypt and decrypt of data in the TEE 510, when executing the workload according to the execution requirement.
[0122] The CCCS 500 may, e.g.. further be configured for monitoring the constraint space and determining constraint changes or additional constraints being added. Such amendments of the constraint space may, e.g., result from updated and / or additional constraints generated by one or more of the entities 506 and, e.g., sent to the CCCS 500 via an API. Such amendments of the constraint space may, e.g., result from updated and / or additional constraints automatically generated by one or more of the entities 506. These updated and / or additional constraints may, e.g., define measurements to eliminate newly discovered vulnerabilities, replace time-bound constraints, where a duration of the respective time-bound constraints has elapsed, and / or take into account a change in geopolitical state.
[0123] Upon detecting a change in the constraint space, the CCCS 500 may, e.g., re-run and / or simulate an evaluation and resolving on basis of the updated constraint space. For example, the execution requirement may be updated and / or re-generated using the updated constraint space. Information about the updated execution requirement and / or conflicts may be provided by the CCCS 500 to TEEs 510. The TEEs 510 may, e.g., in turn stop running previously deployed workloads based on the previously generated execution requirement. For example, detected conflicts may be flagged. For example, in response to flagged conflicts TEEs 510, that are using previously created execution requirements, may be automatically and / or actively undeployed. The flagged conflicts may, e.g., be resolved by the CCCS 500 and the updated execution requirement may be generated using the updated constraint space, for which the conflicts have been resolved. The resulting updated execution requirement may be provided to the TEEs 506 for deployment.
[0124] Figure 6 is a flowchart of an exemplary method for checking a preliminary execution requirement. The preliminary execution requirement is generated using a plurality of constraints received from a plurality of entities. The execution requirement defines parameters for the execution of the workload in compliance with the respective constraints. In block 600, the method starts. In block 602, it is checked, whether an agreement regarding the content of the execution requirement has been reached. An agreement has been reached, in case the constraints comprised by the preliminary execution requirement are conflict-free, i.e., do not comprise conflicts between each other. In response to an agreement having been reached, the method is continued in block 618 with approving the execution requirement as being ready for use, i.e., for controlling one or more trusted execution environments.
[0125] In response to determining that no agreement has been reached yet, the method is continued in block 604. The constraints comprised by the preliminary execution requirement may successively be checked and in case conflicts between constraints are detected, actions may be taken to resolve these conflicts. In block 604, a next constraint of the execution requirement is gotten for checking. In block 606, it is determined, whether the constraint gotten in block 604 has been compared with all the other constraints of the preliminary execution requirement, in order to check for conflicts. In response to having been compared to all constraints of the preliminary execution requirement, the method is continued in block 602. In response to not having been compared to all constraints of the preliminary execution requirement yet, the method is continued in block 608. In block 608, the constraint gotten in block 604 is compared against a next constraint of the other constraints of the preliminary execution requirement. In block 610, it is determined, whether there is a conflict between the constraint gotten in block 604 and the constraint, to which it is compared. In response to no conflict being determined, the method is continued in block 606. In response to a conflict being determined, the method is continued in block 612. In block 612, actions are taken to resolve the resolve the conflict. For resolving the conflict, e.g.. the method of Figure 3 or the method of Figure 7 may be used. In block 614 it is checked, whether the conflict detected in block 610 has been resolved successfully. In response to determining that the conflict has not been resolved, the check of the preliminary execution requirement fails in block 616. Consequently, the preliminary execution requirement may be excluded from being used for controlling the one or more trusted execution requirement. In response to determining that the conflict has been resolved, the method is continued in block 606.
[0126] Figure 7 is a flowchart of an exemplary method for resolving conflicts between constraints. In block 700, the method stalls. In block 702, conflicting constraints to be fulfilled are determined. In block 704, a priority list of the conflicting constraints determined in block 702 is generated. The priority list assigns priorities to the respective constraints. In block 706, it is checked, whether the conflict has been resolved. In response to determining that the conflict has been resolved, the method is continued in block 716. In block 716, the resolving attempt is set to “pass”. In block 720, the method ends with the conflict having been successfully resolved.
[0127] In response to determining that the conflict has not been resolved yet, the method is continued in block 708. In block 708, one or more next entities assigned to a constraint of the constraints determined in block 702, which is assigned with a next higher priority according to the priority list generated in block 704, are determined. In block 710, a proposal for resolving the conflict is sent to the one or more entities determined in block 708. The proposal is, e.g., generated using a constraint of the constraints determined in block 702 assigned with a highest priority for resolving the conflict. For example, the constraint assigned with a highest priority is used as the proposal. For example, the priorities assigned to the respective constraints by the priority list are determined using one or more of the following: levels of security determined for the respective constraints, levels of restriction determined for the respective constraints, numbers of entities assigned to the respective constraints.
[0128] In block 712, it is checked, whether an approval is received in response to the sending of the proposal in block 710. In response to no approval being received, the method is continued in block 718. In block 718, the resolving attempt is set to “fail”. In block 720, the method ends with the conflict not having been resolved.
[0129] In response to an approval being received, the method is continued in block 714. In block 714, the priority according to the priority list, for which entities are to be provided with the proposal, is advanced to the next higher priority and the method is continued in block 706.
[0130] Referring now to Figure 8, illustrative computing environment 800 is depicted. Computing environment 800 contains an example of an environment for the execution of at least some of the computer code 900 involved in performing the inventive methods. Computer-readable program code 902 is, e.g., configured to implement a method for automatically controlling an execution of a workload on one or more trusted execution environments, while enforcing compliance with a plurality of constraints required by a plurality of entities. Computer-readable program code 900 may be executed by a computer 801 comprised by the computing environment 800.
[0131] For example, the computer-readable program code 902 implements a confidential computing control service (CCCS). For example, computer 801 of computing environment 800 may be configured as a server providing the CCCS as service, e.g., as a cloud service, like a SaaS. The CCCS may be a CCCS in accordance with the present subject matter, e.g., as described with reference to Figure 5 and, e.g., configured to implement the methods described with reference to Figures 1 to 4, 6 and / or 7.
[0132] The CCCS may be configured to receiving the plurality of constraints for the execution of the workload from the plurality of entities. Constraints may be received, e.g., via WAN 802. The plurality of entities may, e.g., be comprise one or more end user devices, like end user devices 803. The received constraints form a constraint space. An execution requirement for controlling the one or more trusted execution environments is automatically generated using the constraints of the constraint space. The trusted execution environments may, e.g., be provided by a cloud, like public cloud 805 using virtual machines, like virtual machines 843, and / or containers, like containers 844. The trusted execution environment may, e.g., be implemented as trusted execution environment for containerized applications in a cloud environment 805. The execution requirement defines parameters for the execution of the workload in compliance with the respective constraints. The generating comprises adding identifiers of the constraints to the execution requirement for an attestation of the constraints, with which the one or more trusted execution environments comply with, when the workload is executed in compliance with the execution requirement. The one or more trusted execution environments are controlled in compliance with the execution requirement. The controlling comprises providing the one or more trusted execution environments with the execution requirement enabling the one or more trusted execution environments to provide one or more attestation records for the attestation of the execution of the workload comprising the identifiers of the constraints.
[0133] In addition to block 900, computing environment 800 includes, for example, computer 801, wide area network (WAN) 802, end user device (EUD) 803, remote server 804, public cloud 805, and private cloud 806. In this embodiment, computer 801 includes processor set 810 (including processing circuitry 820 and cache 821), communication fabric 811, volatile memory 812, persistent storage 813 (including operating system 822 and block 900, as identified above), peripheral device set 814 (including user interface (UI) device set 823, storage 824, and Internet of Things (loT) sensor set 825), and network module 815. Remote server 804 includes remote database 830. Public cloud 805 includes gateway 840, cloud orchestration module 841, host physical machine set 842, virtual machine set 843, and container set 844.
[0134] COMPUTER 801 may take the form of a desktop computer, laptop computer, tablet computer, smart phone, smart watch or other wearable computer, mainframe computer, quantum computer or any other form of computer or mobile device now known or to be developed in the future that is capable of running a program, accessing a network or querying a database, such as remote database 830. As is well understood in the art of computer technology, and depending upon the technology, performance of a computer-implemented method may be distributed among multiple computers and / or between multiple locations. On the other hand, in this presentation of computing environment 800, detailed discussion is focused on a single computer, specifically computer 801, to keep the presentation as simple as possible. Computer 801 may be located in a cloud, even though it is not shown in a cloud in Figure 4. On the other hand, computer 801 is not required to be in a cloud except to any extent as may be affirmatively indicated.
[0135] PROCESSOR SET 810 includes one, or more, computer processors of any type now known or to be developed in the future. Processing circuitry 820 may be distributed over multiple packages, for example, multiple, coordinated integrated circuit chips. Processing circuitry 820 may implement multiple processor threads and / or multiple processor cores. Cache 821 is memory that is located in the processor chip package(s) and is typically used for data or code that should be available for rapid access by the threads or cores running on processor set 810. Cache memories are typically organized into multiple levels depending upon relative proximity to the processing circuitry. Alternatively, some, or all, of the cache for the processor set may be located “off chip.” In some computing environments, processor set 810 may be designed for working with qubits and performing quantum computing.
[0136] Computer readable program instructions are typically loaded onto computer 801 to cause a series of operational steps to be performed by processor set 810 of computer 801 and thereby effect a computer-implemented method, such that the instructions thus executed will instantiate the methods specified in flowcharts and / or narrative descriptions of computer-implemented methods included in this document (collectively referred to as “the inventive methods”). These computer readable program instructions are stored in various types of computer readable storage media, such as cache 821 and the other storage media discussed below. The program instructions, and associated data, are accessed by processor set 810 to control and direct performance of the inventive methods. In computing environment 800, at least some of the instructions for performing the inventive methods may be stored in block 900 in persistent storage 813.
[0137] COMMUNICATION FABRIC 811 is the signal conduction path that allows the various components of computer 801 to communicate with each other. Typically, this fabric is made of switches and electrically conductive paths, such as the switches and electrically conductive paths that make up buses, bridges, physical input I output ports and the like. Other types of signal communication paths may be used, such as fiber optic communication paths and / or wireless communication paths.
[0138] VOLATILE MEMORY 812 is any type of volatile memory now known or to be developed in the future. Examples include dynamic type random access memory (RAM) or static type RAM. Typically, volatile memory 812 is characterized by random access, but this is not required unless affirmatively indicated. In computer 801, the volatile memory 812 is located in a single package and is internal to computer 801, but, alternatively or additionally, the volatile memory may be distributed over multiple packages and / or located externally with respect to computer 801.
[0139] PERSISTENT STORAGE 813 is any form of non-volatile storage for computers that is now known or to be developed in the future. The non-volatility of this storage means that the stored data is maintained regardless of whether power is being supplied to computer 801 and / or directly to persistent storage 813. Persistent storage 813 may be a read only memory (ROM), but typically at least a portion of the persistent storage allows writing of data, deletion of data and re-writing of data. Some familiar forms of persistent storage include magnetic disks and solid-state storage devices. Operating system 822 may take several forms, such as various known proprietary operating systems or open-source Portable Operating System Interface-type operating systems that employ a kernel. The code included in block 900 typically includes at least some of the computer code involved in performing the inventive methods.
[0140] PERIPHERAL DEVICE SET 814 includes the set of peripheral devices of computer 801. Data communication connections between the peripheral devices and the other components of computer 801 may be implemented in various ways, such as Bluetooth connections, Near-Field Communication (NFC) connections, connections made by cables (such as universal serial bus (USB) type cables), insertion-type connections (for example, secure digital (SD) card), connections made through local area communication networks and even connections made through wide area networks such as the internet. In various embodiments, UI device set 823 may include components such as a display screen, speaker, microphone, wearable devices (such as goggles and smart watches), keyboard, mouse, printer, touchpad, game controllers, and haptic devices. Storage 824 is external storage, such as an external hard drive, or insertable storage, such as an SD card. Storage 824 may be persistent and / or volatile. In some embodiments, storage 824 may take the form of a quantum computing storage device for storing data in the form of qubits. In embodiments where computer 801 is required to have a large amount of storage (for example, where computer 801 locally stores and manages a large database) then this storage may be provided by peripheral storage devices designed for storing very large amounts of data, such as a storage area network (SAN) that is shared by multiple, geographically distributed computers. loT sensor set 825 is made up of sensors that can be used in Internet of Things applications. For example, one sensor may be a thermometer and another sensor may be a motion detector.
[0141] NETWORK MODULE 815 is the collection of computer software, hardware, and firmware that allows computer 801 to communicate with other computers through WAN 802. Network module 815 may include hardware, such as modems or Wi-Fi signal transceivers, software for packetizing and / or de-packetizing data for communication network transmission, and / or web browser software for communicating data over the internet. In some embodiments, network control functions and network forwarding functions of network module 815 are performed on the same physical hardware device. In other embodiments (for example, embodiments that utilize software-defined networking (SDN)), the control functions and the forwarding functions of network module 815 are performed on physically separate devices, such that the control functions manage several different network hardware devices. Computer readable program instructions for performing the inventive methods can typically be downloaded to computer 801 from an external computer or external storage device through a network adapter card or network interface included in network module 815.
[0142] WAN 802 is any wide area network (for example, the internet) capable of communicating computer data over non-local distances by any technology for communicating computer data, now known or to be developed in the future. In some embodiments, the WAN 802 may be replaced and / or supplemented by local area networks (LANs) designed to communicate data between devices located in a local area, such as a Wi-Fi network. The WAN and / or LANs typically include computer hardware such as copper transmission cables, optical transmission fibres, wireless transmission, routers, firewalls, switches, gateway computers and edge servers.
[0143] END USER DEVICE (EUD) 803 is any computer system that is used and controlled by an end user (for example, a customer of an enterprise that operates computer 801), and may take any of the forms discussed above in connection with computer 801. EUD 803 typically receives helpful and useful data from the operations of computer 801. For example, in a hypothetical case where computer 801 is designed to provide a recommendation to an end user, this recommendation would typically be communicated from network module 815 of computer 801 through WAN 802 to EUD 803. In this way, EUD 803 can display, or otherwise present, the recommendation to an end user. In some embodiments, EUD 803 may be a client device, such as thin client, heavy client, mainframe computer, desktop computer and so on.
[0144] REMOTE SERVER 804 is any computer system that serves at least some data and / or functionality to computer 801. Remote server 804 may be controlled and used by the same entity that operates computer 801. Remote server 804 represents the machine(s) that collect and store helpful and useful data for use by other computers, such as computer 801. For example, in a hypothetical case where computer 801 is designed and programmed to provide a recommendation based on historical data, then this historical data may be provided to computer 801 from remote database 830 of remote server 804.
[0145] PUBLIC CLOUD 805 is any computer system available for use by multiple entities that provides on-demand availability of computer system resources and / or other computer capabilities, especially data storage (cloud storage) and computing power, without direct active management by the user. Cloud computing typically leverages sharing of resources to achieve coherence and economies of scale. The direct and active management of the computing resources of public cloud 805 is performed by the computer hardware and / or software of cloud orchestration module 841. The computing resources provided by public cloud 805 are typically implemented by virtual computing environments that run on various computers making up the computers of host physical machine set 842, which is the universe of physical computers in and / or available to public cloud 805. The virtual computing environments (VCEs) typically take the form of virtual machines from virtual machine set 843 and / or containers from container set 844. It is understood that these VCEs may be stored as images and may be transferred among and between the various physical machine hosts, either as images or after instantiation of the VCE. Cloud orchestration module 841 manages the transfer and storage of images, deploys new instantiations of VCEs and manages active instantiations of VCE deployments. Gateway 840 is the collection of computer software, hardware, and firmware that allows public cloud 805 to communicate through WAN 802.
[0146] Some further explanation of virtualized computing environments (VCEs) will now be provided. VCEs can be stored as “images.” A new active instance of the VCE can be instantiated from the image. Two familiar’ types of VCEs are virtual machines and containers. A container is a VCE that uses operating-system-level virtualization. This refers to an operating system feature in which the kernel allows the existence of multiple isolated user-space instances, called containers. These isolated user-space instances typically behave as real computers from the point of view of programs running in them. A computer program running on an ordinary operating system can utilize all resources of that computer, such as connected devices, files and folders, network shares, CPU power, and quantifiable hardware capabilities. However, programs running inside a container can only use the contents of the container and devices assigned to the container, a feature which is known as containerization.
[0147] PRIVATE CLOUD 806 is similar to public cloud 805, except that the computing resources are only available for use by a single enterprise. While private cloud 806 is depicted as being in communication with WAN 802, in other embodiments a private cloud may be disconnected from the internet entirely and only accessible through a local / private network. A hybrid cloud is a composition of multiple clouds of different types (for example, private, community or public cloud types), often respectively implemented by different vendors. Each of the multiple clouds remains a separate and discrete entity, but the larger hybrid cloud architecture is bound together by standardized or proprietary technology that enables orchestration, management, and / or data / application portability between the multiple constituent clouds. In this embodiment, public cloud 805 and private cloud 806 are both part of a larger hybrid cloud.
[0148] Cloud computing is a model of service delivery for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with a provider of the service. This cloud model may include at least five characteristics, at least three service models, and at least four deployment models.
[0149] Characteristics are as follows:
[0150] On-demand self-service: a cloud consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with the service’s provider.
[0151] Broad network access: capabilities are available over a network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs).
[0152] Resource pooling: the provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to demand. There is a sense of location independence in that the consumer generally has no control or knowledge over the exact location of the provided resources but may be able to specify location at a higher level of abstraction (e.g., country, state, or datacenter).
[0153] Rapid elasticity: capabilities can be rapidly and elastically provisioned, in some cases automatically, to quickly scale out and rapidly released to quickly scale in. To the consumer, the capabilities available for provisioning often appear to be unlimited and can be purchased in any quantity at any time.
[0154] Measured service: cloud systems automatically control and optimize resource use by leveraging a metering capability at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized service.
[0155] Service Models are as follows:
[0156] Software as a Service (SaaS): the capability provided to the consumer is to use the provider’s applications running on a cloud infrastructure. The applications are accessible from various client devices through a thin client interface such as a web browser (e.g., web-based e-mail). The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.
[0157] Platform as a Service (PaaS): the capability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including networks, servers, operating systems, or storage, but has control over the deployed applications and possibly application hosting environment configurations.
[0158] Infrastructure as a Service (laaS): the capability provided to the consumer is to provision processing, storage, networks, and other fundamental computing resources where the consumer is able to deploy and run arbitrary software, which can include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, deployed applications, and possibly limited control of select networking components (e.g., host firewalls).
[0159] Deployment Models are as follows:
[0160] Private cloud: the cloud infrastructure is operated solely for an organization. It may be managed by the organization or a third party and may exist on-premises or off-premises.
[0161] Community cloud: the cloud infrastructure is shared by several organizations and supports a specific community that has shared concerns (e.g., mission, security requirements, policy, and compliance considerations). It may be managed by the organizations or a third party and may exist on-premises or off-premises.
[0162] Public cloud: the cloud infrastructure is made available to the general public or a large industry group and is owned by an organization selling cloud services.
[0163] Hybrid cloud: the cloud infrastructure is a composition of two or more clouds (private, community, or public) that remain unique entities but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load-balancing between clouds).
[0164] A cloud computing environment is service oriented with a focus on statelessness, low coupling, modularity, and semantic interoperability. At the heart of cloud computing is an infrastructure that includes a network of interconnected nodes.
[0165] Referring now to Figure 9, illustrative cloud computing environment 1050 is depicted. As shown, cloud computing environment 1050 includes one or more cloud computing nodes 1010 with which local computing devices used by cloud consumers, such as, for example, personal digital assistant (PDA) or cellular telephone 1054A, desktop computer 1054B, laptop computer 1054C, and / or automobile computer system 54N may communicate. Nodes 1010 may communicate with one another. They may be grouped (not shown) physically or virtually, in one or more networks, such as Private, Community, Public, or Hybrid clouds as described hereinabove, or a combination thereof. This allows cloud computing environment 1050 to offer infrastructure, platforms and / or software as services for which a cloud consumer does not need to maintain resources on a local computing device. It is understood that the types of computing devices 1054A-N shown in Figure 9 are intended to be illustrative only and that computing nodes 1010 and cloud computing environment 1050 can communicate with any type of computerized device over any type of network and / or network addressable connection (e.g., using a web browser).
[0166] Referring now to Figure 10, a set of functional abstraction layers provided by cloud computing environment 1050 (Figure 9) is shown. It should be understood in advance that the components, layers, and functions shown in Figure 10 are intended to be illustrative only and embodiments of the invention are not limited thereto. As depicted, the following layers and corresponding functions are provided:
[0167] Hardware and software layer 1060 includes hardware and software components. Examples of hardware components include: mainframes 1061; RISC (Reduced Instruction Set Computer) architecture based servers 1062; servers 1063; blade servers 1064; storage devices 1065; and networks and networking components 1066. In some embodiments, software components include network application server software 1067 and database software 1068.
[0168] Virtualization layer 1070 provides an abstraction layer from which the following examples of virtual entities may be provided: virtual servers 1071; virtual storage 1072; virtual networks 1073, including virtual private networks; virtual applications and operating systems 1074; and virtual clients 1075.
[0169] In one example, management layer 1080 may provide the functions described below. Resource provisioning 1081 provides dynamic procurement of computing resources and other resources that are utilized to perform tasks within the cloud computing environment. Metering and Pricing 1082 provide cost tracking as resources are utilized within the cloud computing environment, and billing or invoicing for consumption of these resources. In one example, these resources may include application software licenses. Security provides identity verification for cloud consumers and tasks, as well as protection for data and other resources. User portal 1083 provides access to the cloud computing environment for consumers and system administrators. Service level management 1084 provides cloud computing resource allocation and management such that required service levels are met. Service Level Agreement (SLA) planning and fulfillment 1085 provide prearrangement for, and procurement of, cloud computing resources for which a future requirement is anticipated in accordance with an SLA.
[0170] Workloads layer 1090 provides examples of functionality for which the cloud computing environment may be utilized. Examples of workloads and functions which may be provided from this layer include: mapping and navigation 1091; software development and lifecycle management 1092; virtual classroom education delivery 1093; data analytics processing 1094; transaction processing 1095; and a confidential computing control service 1096 in accordance with the present subject matter, e.g., as described with reference to Figure 5 and, e.g., configured to implement the methods described with reference to Figures 1 to 4, 6 and / or 7.
[0171] It is to be understood that although this disclosure includes a detailed description on cloud computing, implementation of the teachings recited herein are not limited to a cloud computing environment. Rather, embodiments of the present invention are capable of being implemented in conjunction with any other type of computing environment now known or later developed.
[0172] Various aspects of the present disclosure are described by narrative text, flowcharts, block diagrams of computer systems and / or block diagrams of the machine logic included in computer program product (CPP) embodiments. With respect to any flowcharts, depending upon the technology involved, the operations can be performed in a different order than what is shown in a given flowchart. For example, again depending upon the technology involved, two operations shown in successive flowchart blocks may be performed in reverse order, as a single integrated step, concurrently, or in a manner at least partially overlapping in time.
[0173] A computer program product embodiment ("CPP embodiment" or “CPP”) is a term used in the present disclosure to describe any set of one, or more, storage media (also called "mediums") collectively included in a set of one, or more, storage devices that collectively include machine readable code corresponding to instructions and / or data for performing computer operations specified in a given CPP claim. A "storage device" is any tangible device that can retain and store instructions for use by a computer processor. Without limitation, the computer readable storage medium may be an electronic storage medium, a magnetic storage medium, an optical storage medium, an electromagnetic storage medium, a semiconductor storage medium, a mechanical storage medium, or any suitable combination of the foregoing. Some known types of storage devices that include these mediums include: diskette, hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanically encoded device (such as punch cards or pits / lands formed in a major surface of a disc) or any suitable combination of the foregoing. A computer readable storage medium, as that term is used in the present disclosure, is not to be construed as storage in the form of transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide, light pulses passing through a fiber optic cable, electrical signals communicated through a wire, and / or other transmission media. As will be understood by those of skill in the art, data is typically moved at some occasional points in time during normal operations of a storage device, such as during access, de-fragmentation or garbage collection, but this does not render the storage device as transitory because the data is not transitory while it is stored.
[0174] Possible combination of features of examples described above may be the following:
[0175] Feature combination 1. A computer-implemented method for automatically controlling an execution of a workload on one or more trusted execution environments, while enforcing compliance with a plurality of constraints required by a plurality of entities, the method comprising: receiving the plurality of constraints for the execution of the workload from the plurality of entities, the received constraints forming a constraint space; automatically generating an execution requirement for controlling the one or more trusted execution environments using the constraints of the constraint space, the execution requirement defining parameters for the execution of the workload in compliance with the respective constraints, the generating comprising adding identifiers of the constraints to the execution requirement for an attestation of the constraints being complied with by the one or more trusted execution environments, when executing the workload in compliance with the execution requirement; controlling the one or more trusted execution environments in compliance with the execution requirement, the controlling comprising providing the one or more trusted execution environments with the execution requirement enabling the one or more trusted execution environments to provide one or more attestation records for the attestation of the execution of the workload comprising the identifiers of the constraints.
[0176] Feature combination 2. The method of feature combination 1, the method further comprising determining the plurality of identifiers of the constraints of the constraint space.
[0177] Feature combination 3. The method of feature combination 2, the identifiers being checksums of the constraints, the determining of the plurality of identifiers comprising calculating the checksums of the respective constraints of the constraint space.
[0178] Feature combination 4. The method of any of the preceding feature combinations, the constraints of the constraint space defining the parameters for the execution of the workload on the one or more trusted execution environments.
[0179] Feature combination 5. The method of any of the preceding feature combinations, the method further comprising: checking the constraints of the constraint space for conflicts between each other; in response to detecting one or more conflicts, flagging the detected conflicts.
[0180] Feature combination 6. The method of feature combination 5, the method further comprising resolving the detected conflicts of the constraint space.
[0181] Feature combination 7. The method of feature combination 6, the resolving of at least one of the detected conflicts of the constraint space comprising: generating a priority list of conflicting constraints of the constraint space, between which the respective conflict is detected, the priority list assigning priorities to the respective constraints; generating a proposal using a constraint assigned with a highest priority for resolving the detected conflict; sending the proposal to one or more entities assigned to a constraint with a lowest priority; in response to receiving approvals of the proposal from all entities assigned to the constraint with the lowest priority, continuing with sending the proposal to one or more entities assigned to a constraint with a next higher priority; the sending of the proposal being continued, until approvals of the proposal being received from all entities assigned to a constraint with a second highest priority; in response to receiving approvals of the proposal from all entities assigned to the constraint with the second highest priority, resolving the detected conflict using the proposal.
[0182] Feature combination 8. The method of feature combination 7, the priorities assigned to the respective constraints by the priority list being determined using one or more of the following: levels of security determined for the respective constraints, levels of restriction determined for the respective constraints, numbers of entities assigned to the respective constraints.
[0183] Feature combination 9. The method of any of the preceding feature combinations, the method further comprising monitoring the constraint space.
[0184] Feature combination 10. The method of feature combination 9, the method further comprising receiving one or more adjustments of the constraint space from one or more of the entities.
[0185] Feature combination 11. The method of any of the feature combinations 9 to 10, the monitoring of constraint space comprising: checking the constraints of the adjusted constraint space for conflicts between each other resulting from the received adjustments; in response to detecting one or more conflicts, flagging the detected conflicts.
[0186] Feature combination 12. The method of feature combination 11, the method further comprising sending information about the flagged conflicts of the adjusted consttaint space to the one or more trusted execution environments controlled in compliance with the execution requirement to abort execution of the workload.
[0187] Feature combination 13. The method of any of the feature combinations 11 to 12, the method further comprising resolving the detected conflicts of the adjusted constraint space.
[0188] Feature combination 14. The method of feature combination 13, the resolving of at least one of the detected conflicts of the adjusted constraint space comprising: generating a priority list of constraints of the adjusted constraint space, between which the respective conflict is detected, the priority list assigning priorities to the respective constraints; generating a proposal using a constraint assigned with a highest priority for resolving the detected conflict; sending the proposal to one or more entities assigned to a consttaint with a lowest priority; in response to receiving approvals of the proposal from all entities assigned to the consttaint with the lowest priority, continuing with sending the proposal to one or more entities assigned to a constraint with a next higher priority; the sending of the proposal being continued, until approvals of the proposal being received from all entities assigned to a constraint with a second highest priority; in response to receiving approvals of the proposal from all entities assigned to the constraint with the second highest priority, resolving the detected conflict using the proposal.
[0189] Feature combination 15. The method of any of the feature combinations 10 to 14, the method further comprising in response to the receiving of the one or more adjustments: generating an adjusted execution requirement for controlling the one or more trusted execution environments using the constraints of the adjusted constraint space, the adjusted execution requirement defining adjusted parameters for the execution of the workload in compliance with the respective constraints, the generating comprising adding identifiers of the constraints to the adjusted execution requirement for an attestation of the constraints being complied with by the one or more trusted execution environments, when executing the workload in compliance with the adjusted execution requirement; controlling the one or more trusted execution environments in compliance with the adjusted execution requirement, the controlling comprising providing the one or more trusted execution environments with the adjusted execution requirement as a replacement for the execution requirement.
[0190] Feature combination 16. The method of any of the feature combinations 10 to 15, the adjustments comprising one or more of the following: a revocation of a constraint, an adjusted constraint, an additional constraint.
[0191] Feature combination 17. The method of any of the preceding feature combinations, the generating of the execution requirement further comprising adding at least one secret to the execution requirement to be used for encrypting and decrypting data of the execution of the workload on the one or more trusted execution environments.
[0192] Feature combination 18. The method of any of the preceding feature combinations, the generating of the execution requirement further comprising adding at least one secret per entity to the execution requirement to be used in combination for encrypting and decrypting data of the execution of the workload on the one or more trusted execution environments.
[0193] Feature combination 19. A computer program product for automatically controlling an execution of a workload on one or more trusted execution environments, while enforcing compliance with a plurality of constraints required by a plurality of entities, computer program product comprising a computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code being configured to implement the method of any of the preceding feature combinations.
[0194] Feature combination 20. A computer system for automatically controlling an execution of a workload on one or more trusted execution environments, while enforcing compliance with a plurality of constraints required by a plurality of entities, the computer system being configured for: receiving the plurality of constraints for the execution of the workload from the plurality of entities, the received constraints forming a constraint space; automatically generating an execution requirement for controlling the one or more trusted execution environments using the constraints of the constraint space, the execution requirement defining parameters for the execution of the workload in compliance with the respective constraints, the generating comprising adding identifiers of the constraints to the execution requirement for an attestation of the constraints being complied with by the one or more trusted execution environments, when executing the workload in compliance with the execution requirement; controlling the one or more trusted execution environments in compliance with the execution requirement, the controlling comprising providing the one or more trusted execution environments with the execution requirement enabling the one or more trusted execution environments to provide on or more attestation records for the attestation of the execution of the workload comprising the identifiers of the constraints.
Claims
1. A computer-implemented method for automatically controlling an execution of a workload on one or more trusted execution environments, while enforcing compliance with a plurality of constraints required by a plurality of entities, the method comprising:receiving the plurality of constraints for the execution of the workload from the plurality of entities, the received constraints forming a constraint space;automatically generating an execution requirement for controlling the one or more trusted execution environments using the constraints of the constraint space, the execution requirement defining parameters for the execution of the workload in compliance with the respective constraints, the generating comprising adding identifiers of the constraints to the execution requirement for an attestation of the constraints being complied with by the one or more trusted execution environments, when executing the workload in compliance with the execution requirement;controlling the one or more trusted execution environments in compliance with the execution requirement, the controlling comprising providing the one or more trusted execution environments with the execution requirement enabling the one or more trusted execution environments to provide one or more attestation records for the attestation of the execution of the workload comprising the identifiers of the constraints.
2. The method of claim 1, the method further comprising determining the plurality of identifiers of the constraints of the constraint space.
3. The method of claim 2, the identifiers being checksums of the constraints, the determining of the plurality of identifiers comprising calculating the checksums of the respective constraints of the constraint space.
4. The method of claim 1, the constraints of the constraint space defining the parameters for the execution of the workload on the one or more trusted execution environments.
5. The method of claim 1, the method further comprising:checking the constraints of the constraint space for conflicts between each other;in response to detecting one or more conflicts, flagging the detected conflicts.
6. The method of claim 5, the method further comprising resolving the detected conflicts of the constraint space.
7. The method of claim 6, the resolving of at least one of the detected conflicts of the constraint space comprising:generating a priority list of conflicting constraints of the constraint space, between which the respective conflict is detected, the priority list assigning priorities to the respective constraints;generating a proposal using a constraint assigned with a highest priority for resolving the detected conflict;sending the proposal to one or more entities assigned to a constraint with a lowest priority;in response to receiving approvals of the proposal from all entities assigned to the constraint with the lowest priority, continuing with sending the proposal to one or more entities assigned to a constraint with a next higher priority;the sending of the proposal being continued, until approvals of the proposal being received from all entities assigned to a constraint with a second highest priority;in response to receiving approvals of the proposal from all entities assigned to the constraint with the second highest priority, resolving the detected conflict using the proposal.
8. The method of claim 7, the priorities assigned to the respective constraints by the priority list being determined using one or more of the following: levels of security determined for the respective constraints, levels of restriction determined for the respective constraints, numbers of entities assigned to the respective constraints.
9. The method of claim 1, the method further comprising monitoring the constraint space.
10. The method of claim 9, the method further comprising receiving one or more adjustments of the constraint space from one or more of the entities.
11. The method of claim 9, the monitoring of constraint space comprising: checking the constraints of the adjusted constraint space for conflicts between each other resulting from the received adjustments;in response to detecting one or more conflicts, flagging the detected conflicts.
12. The method of claim 11, the method further comprising sending information about the flagged conflicts of the adjusted constraint space to the one or more trusted execution environments controlled in compliance with the execution requirement to abort execution of the workload.
13. The method of claim 11, the method further comprising resolving the detected conflicts of the adjusted constraint space.
14. The method of claim 13, the resolving of at least one of the detected conflicts of the adjusted constraint space comprising:generating a priority list of constraints of the adjusted constraint space, between which the respective conflict is detected, the priority list assigning priorities to the respective constraints;generating a proposal using a constraint assigned with a highest priority for resolving the detected conflict;sending the proposal to one or more entities assigned to a constraint with a lowest priority;in response to receiving approvals of the proposal from all entities assigned to the constraint with the lowest priority, continuing with sending the proposal to one or more entities assigned to a constraint with a next higher priority;the sending of the proposal being continued, until approvals of the proposal being received from all entities assigned to a constraint with a second highest priority;in response to receiving approvals of the proposal from all entities assigned to the constraint with the second highest priority, resolving the detected conflict using the proposal.
15. The method of claim 10, the method further comprising in response to the receiving of the one or more adjustments:generating an adjusted execution requirement for controlling the one or more trusted execution environments using the constraints of the adjusted constraint space, the adjusted execution requirement defining adjusted parameters for the execution of the workload in compliance with the respective constraints, the generating comprising adding identifiers of the constraints to the adjusted execution requirement for an attestation of theconstraints being complied with by the one or more trusted execution environments, when executing the workload in compliance with the adjusted execution requirement;controlling the one or more trusted execution environments in compliance with the adjusted execution requirement, the controlling comprising providing the one or more trusted execution environments with the adjusted execution requirement as a replacement for the execution requirement.
16. The method of claim 10, the adjustments comprising one or more of the following: a revocation of a constraint, an adjusted constraint, an additional constraint.
17. The method of claim 1, the generating of the execution requirement further comprising adding at least one secret to the execution requirement to be used for encrypting and decrypting data of the execution of the workload on the one or more trusted execution environments.
18. The method of claim 1, the generating of the execution requirement further comprising adding at least one secret per entity to the execution requirement to be used in combination for encrypting and decrypting data of the execution of the workload on the one or more trusted execution environments.
19. A computer program product for automatically controlling an execution of a workload on one or more trusted execution environments, while enforcing compliance with a plurality of constraints required by a plurality of entities, the computer program product comprising a computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code being configured to implement the method of claim 1.
20. A computer system for automatically controlling an execution of a workload on one or more trusted execution environments, while enforcing compliance with a plurality of constraints required by a plurality of entities, the computer system being configured for: receiving the plurality of constraints for the execution of the workload from the plurality of entities, the received constraints forming a constraint space;automatically generating an execution requirement for controlling the one or more trusted execution environments using the constraints of the constraint space, the execution requirement defining parameters for the execution of the workload in compliancewith the respective constraints, the generating comprising adding identifiers of the constraints to the execution requirement for an attestation of the constraints being complied with by the one or more trusted execution environments, when executing the workload in compliance with the execution requirement;controlling the one or more trusted execution environments in compliance with the execution requirement, the controlling comprising providing the one or more trusted execution environments with the execution requirement enabling the one or more trusted execution environments to provide on or more attestation records for the attestation of the execution of the workload comprising the identifiers of the constraints.
Citation Information
Patent Citations
Update coordination in a multi-tenant cloud computing environment
US20170364345A1
Enforcing policies
WO2022050930A1