Cloudlet Secure Boot via Trusted Execution Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud computing systems face challenges in ensuring the security and integrity of computing resources located at the edge of the network, where physical security cannot be assured, leading to risks of tampering and compromise.
Innovation Solution
The implementation of cloudlets that provide a hardware-enforced boot integrity scheme and chain of trust, utilizing components like Manageability Engines, Innovation Engines, and Secure Processors to ensure tamper-resistant security, enabling secure boot processes and protecting against unauthorized software execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If computing resources are distributed to the network edge to reduce latency and improve performance, then productivity and speed are improved, but physical security is compromised making the system vulnerable to tampering and compromise
Solution Approach 1:
The patent implements preliminary security actions during the boot process by establishing a chain of trust before the operating system loads. The trusted execution environment verifies the integrity of the BIOS and subsequent boot components in advance, preventing compromised code from executing. This preliminary verification ensures that even though devices are distributed to the edge, their security integrity is established before they can be tampered with during normal operation.
Solution Approach 2:
The patent introduces a trusted execution environment as an intermediary layer between the hardware and the operating system. This intermediary component acts as a security gatekeeper that verifies the integrity of boot components and enforces security policies, allowing distributed computing resources to maintain security integrity without requiring centralized physical security measures.
2Reliability
If hardware-enforced security mechanisms are implemented to protect against tampering, then reliability and security are improved, but device complexity increases
Solution Approach 1:
The patent extracts the complex security verification logic into a separate trusted execution environment that operates independently from the main operating system. This extraction allows the core security functions to be implemented with high reliability while keeping the rest of the system simple. The trusted execution environment handles all complex verification tasks, leaving the primary system unchanged and manageable.
Solution Approach 2:
The trusted execution environment performs self-verification and automatically establishes the chain of trust without requiring external intervention. The system self-service aspect reduces operational complexity by automatically verifying boot components and enforcing security policies, eliminating the need for manual security configuration and monitoring while maintaining high reliability.
Data Source
AI summary
Disclosed herein are embodiments related to security in cloudlet environments. In some embodiments, for example, a computing device (e.g., a cloudlet) may include: a trusted execution environment; a Basic Input/Output System (BIOS) to request a Key Encryption Key (KEK) from the trusted execution environment; and a Self-Encrypting Storage (SES) associated with the KEK; wherein the trusted execution environment is to verify the BIOS and provide the KEK to the BIOS subsequent to verification of the BIOS, and the BIOS is to provide the KEK to the SES to unlock the SES for access by the trusted execution environment.


