Software Container Validation Using Device Root of Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software containers retrieved from websites can be compromised with nefarious or erroneous code, and their validation relies on vulnerable developer, vendor, and distributor keys, making them susceptible to unauthorized execution.

Innovation Solution

A system utilizing a hardware controller embedded in the computing device, employing a Root of Trust mechanism, validates and securely stores software containers locally, ensuring authenticity and authorization through unique cryptographic keys and certificates, allowing secure instantiation into the operating system without network reliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software containers are retrieved from websites over network connections, then ease of deployment is improved, but security and reliability deteriorate due to vulnerability to compromised code and unauthorized execution

Engineering Contradiction:
Improveease of deploymentVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a hardware-based Root of Trust as an intermediary between the software container and the validation system. This Root of Trust, embedded in the computing device, provides a secure cryptographic verification mechanism that mediates the trust relationship, ensuring that containers are genuinely signed by authorized entities before execution, thus resolving the security vulnerability inherent in network-based container retrieval.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If developer, vendor, and distributor keys are used for validation, then ease of deployment is improved, but security deteriorates due to vulnerability of these keys to compromise

Engineering Contradiction:
Improveease of deploymentVSAvoidvulnerability to compromised code
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent transitions the security model from a software-based key validation system to a hardware-based Root of Trust system. This dimensional shift from software to hardware embedding creates a new layer of security that is resistant to conventional software attacks and key compromise, as the cryptographic verification capability is physically embedded in the computing device itself.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Device complexity

If software containers are stored remotely in computing clouds, then device complexity is reduced, but reliability deteriorates due to dependency on network connections and external storage

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements preliminary validation of software containers against the hardware-based Root of Trust before they are executed or fully deployed. This advance verification ensures that only genuinely signed and authorized containers are instantiated, preventing compromised code from executing even if containers are retrieved from remote sources, thus maintaining security without requiring continuous network dependency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12498989B2Software containers
Publication Date: 2025.12.16 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US12498989B2 patent drawing
  • US12498989B2 patent drawing
  • US12498989B2 patent drawing

AI summary

An example system may include a processor and a non-transitory machine-readable storage medium storing instructions executable by the processor to validate a software container, stored on a hardware controller embedded in a computing device, utilizing an encryption mechanism specific to the computing device; insert an instance of the software container, responsive to a successful validation of the software container, from the hardware controller into an operating system of the computing device.