Edge Runtime Attestation for Secure Application Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial Edge environments face challenges in protecting sensitive data during processing, as existing solutions primarily focus on data encryption and transmission, leaving data in use vulnerable to security breaches, and application code integrity is compromised due to high-privilege access.
Innovation Solution
A system and method that utilizes an attestation service to verify the trust state of applications running in isolated runtime environments, ensuring data and application code integrity by encrypting data and using encryption keys, and decrypting only in trusted environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is processed in Industrial Edge environment with high-privilege access, then processing capability and workflow efficiency are improved, but data security and application code integrity are compromised
Solution Approach 1:
The system segments the execution environment into isolated runtime containers that separate application code, data, and execution context. This segmentation allows multiple applications to run concurrently with different privilege levels, enabling efficient processing while maintaining security boundaries that prevent unauthorized access to sensitive data and code
Solution Approach 2:
The patent introduces an intermediary attestation service that verifies the trust state of runtime environments before allowing data processing. This mediator component validates application integrity and runtime environment security without hindering processing efficiency, resolving the contradiction between security verification and workflow speed
2Reliability
If full disk encryption is used for data protection, then data confidentiality during storage is improved, but data processing speed and accessibility are reduced
Solution Approach 1:
The system applies different security measures to different data states: encrypted storage for data at rest, and isolated runtime environments with controlled access for data in use. This local quality approach ensures confidentiality where needed while maintaining processing efficiency during active operations
Solution Approach 2:
The patent implements preliminary verification of runtime environment trust states through attestation services before data is made accessible for processing. This preliminary action ensures security is established beforehand, eliminating the need for continuous encryption/decryption operations during processing and maintaining high data access speed
3Adaptability or versatility
If high-privilege users have root access to the platform, then system management and configuration flexibility are improved, but application code and sensitive data become vulnerable to compromise
Solution Approach 1:
The system segments privilege levels by implementing isolated runtime environments that separate management access from application execution. High-privilege users can manage system configuration outside containers while applications run in isolated environments with controlled privileges, preventing code compromise even when management access is compromised
Solution Approach 2:
The patent introduces an attestation service as an intermediary that verifies the trust state of runtime environments before allowing data processing. This mediator prevents high-privilege access from compromising application code by validating integrity independently of user privilege levels
4Reliability
If isolated runtime environments are implemented for secure execution, then data and code protection are improved, but system complexity and deployment overhead increase
Solution Approach 1:
The system implements a universal isolated runtime environment that can host multiple different applications with varying security requirements. This multi-functional approach consolidates security infrastructure into a single platform that handles diverse workloads, reducing overall system complexity compared to implementing separate secure environments for each application
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method (500) of enabling secure execution of one or more applications (220) on an edge platform (110) is described. The method comprises receiving (502), from the one or more applications configured to run within an isolated runtime environment (210) at the edge platform (110), an indicator indicative of a trust state of the one or more applications (220). Further, the method comprises sending (504) the received indicator to an attestation service entity (130) for verifying the indicator. Further, the method comprises receiving (506) a verification response from the attestation service entity (130), the verification response indicating that the one or more applications (220) are running in the trusted state within a trusted environment. Further, the method comprises, upon receiving the verification response from the attestation service entity (130), providing (508) the one or more applications with data for execution of the one or more applications (220).