Cloud Attestation Component For Project Plan Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based project planning systems face security vulnerabilities where customers' project planning software and data are not adequately isolated, leading to potential data integrity violations and loss of know-how, especially in multi-tenant architectures, which can result in automation system failures and significant damage.

Innovation Solution

An attestation component is introduced to determine trustworthiness information about the cloud-based execution environment and application instances, linking this information with project plans, ensuring integrity and confidentiality through cryptographic hashes and signatures, and providing this information to project planning systems for verification before execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If multiple customers share the same cloud infrastructure server hardware and runtime environment to reduce costs, then infrastructure costs are reduced and scalability is improved, but security isolation between customers is weakened and data integrity is compromised

Engineering Contradiction:
Improveinfrastructure costVSAvoiddata integrity
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent segments the cloud infrastructure into isolated execution environments for each customer. Each customer's project planning software runs in a separate virtualized container on the shared server hardware, creating logical separation that maintains security isolation while allowing physical resource sharing. This segmentation prevents one customer from accessing another's data while still utilizing the same underlying infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security module as an intermediary between the shared infrastructure and customer applications. This module acts as a mediator that verifies the integrity of execution environments, manages security policies, and ensures that customers can only access their own designated resources. The intermediary layer maintains trust in the multi-tenant architecture by enforcing isolation rules and detecting potential security violations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If customer-specific execution instances or servers are provided to enhance security and trustworthiness, then data integrity and security isolation are improved, but hardware provision costs and operational costs increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidhardware provision cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges multiple customer execution environments onto a single shared server infrastructure while maintaining logical separation through virtualization. Instead of provisioning separate physical servers for each customer, the system combines multiple virtualized instances on shared hardware, reducing overall infrastructure costs while preserving security boundaries through software-based isolation mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal cloud infrastructure platform that serves multiple customers simultaneously. The shared server hardware and runtime environment are designed to handle multiple tenants with different security requirements, making the infrastructure multi-functional. A single infrastructure setup can serve numerous customers with varying workloads, eliminating the need for dedicated hardware per customer while maintaining appropriate security levels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If operating system means are used to protect and isolate customer project planning software and data on the same system, then implementation simplicity is maintained, but protection strength is insufficient against determined attackers

Engineering Contradiction:
Improveisolation implementation complexityVSAvoidattack vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent employs a composite security architecture that combines multiple layers of protection: virtualization technology for basic isolation, security modules for integrity verification, and cryptographic mechanisms for data protection. This composite approach layers different security techniques together, creating a defense-in-depth strategy that is more resilient to attacks than any single mechanism alone, while maintaining manageable complexity through automated enforcement.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS20240022591A1Attestation Of A Cloud-Based Execution Environment For Project Planning
Publication Date: 2024.01.18 SIEMENS AG
  • US20240022591A1 patent drawing
  • US20240022591A1 patent drawing

AI summary

Various embodiments of the teachings herein include an attestation component configured to attest a cloud-based execution environment. The cloud-based execution environment comprises at least one application instance and a project plan assigned to the at least one application instance. The attestation component may include: a determination component configured to determine at least one piece of trustworthiness information indicating a trustworthiness of the cloud-based execution environment and of the at least one application instance; and a linking component configured to establish a link between the trustworthiness information and the project plan.