Software Container Validation Using Device Root of Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software containers retrieved from websites can be compromised with nefarious or erroneous code, and their validation relies on vulnerable developer, vendor, and distributor keys, making them susceptible to unauthorized execution.
Innovation Solution
A system utilizing a hardware controller embedded in the computing device, employing a Root of Trust mechanism, validates and securely stores software containers locally, ensuring authenticity and authorization through unique cryptographic keys and certificates, allowing secure instantiation into the operating system without network reliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software containers are retrieved from websites over network connections, then ease of deployment is improved, but security and reliability deteriorate due to vulnerability to compromised code and unauthorized execution
Solution Approach 1:
The patent introduces a hardware-based Root of Trust as an intermediary between the software container and the validation system. This Root of Trust, embedded in the computing device, provides a secure cryptographic verification mechanism that mediates the trust relationship, ensuring that containers are genuinely signed by authorized entities before execution, thus resolving the security vulnerability inherent in network-based container retrieval.
2Ease of operation
If developer, vendor, and distributor keys are used for validation, then ease of deployment is improved, but security deteriorates due to vulnerability of these keys to compromise
Solution Approach 1:
The patent transitions the security model from a software-based key validation system to a hardware-based Root of Trust system. This dimensional shift from software to hardware embedding creates a new layer of security that is resistant to conventional software attacks and key compromise, as the cryptographic verification capability is physically embedded in the computing device itself.
3Device complexity
If software containers are stored remotely in computing clouds, then device complexity is reduced, but reliability deteriorates due to dependency on network connections and external storage
Solution Approach 1:
The patent implements preliminary validation of software containers against the hardware-based Root of Trust before they are executed or fully deployed. This advance verification ensures that only genuinely signed and authorized containers are instantiated, preventing compromised code from executing even if containers are retrieved from remote sources, thus maintaining security without requiring continuous network dependency.
Data Source
AI summary
An example system may include a processor and a non-transitory machine-readable storage medium storing instructions executable by the processor to validate a software container, stored on a hardware controller embedded in a computing device, utilizing an encryption mechanism specific to the computing device; insert an instance of the software container, responsive to a successful validation of the software container, from the hardware controller into an operating system of the computing device.


