Edge Server Program Code Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication devices face challenges in running secure applications due to the resource-intensive task of providing and managing security environments for program code integrity checks, which are difficult to remotely manage and are less resistant to external attacks.

Innovation Solution

A wireless communication device and edge server configuration that enables a low latency communication connection for program code integrity checks, where the edge server verifies the integrity of the code and communicates the result back to the device, eliminating the need for local security environments and enhancing protection against external attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a local security environment is provided on the wireless communication device to perform program code integrity checks, then security protection is achieved, but device resources are consumed and the system becomes more complex

Engineering Contradiction:
Improveprogram code integrity protectionVSAvoidsecurity environment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security environment and program code integrity check functionality from the wireless communication device and relocates it to the edge server. The processor sends program code to the edge server for integrity verification, and executes the code only after receiving confirmation. This extraction eliminates the need for complex local security environments while maintaining security protection.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If program code integrity checks are performed locally on the wireless communication device, then security is improved, but resource consumption increases

Engineering Contradiction:
Improveprogram code integrity protectionVSAvoiddevice resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The computationally intensive task of program code integrity verification is extracted from the wireless communication device and performed remotely on the edge server. The device only needs to send the program code and receive verification results, significantly reducing local resource consumption while maintaining security protection.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If security environments are provided on wireless communication devices, then program code execution security is achieved, but remote manageability deteriorates

Engineering Contradiction:
Improveprogram code execution securityVSAvoidremote manageability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By moving the security environment to the edge server, the system becomes centrally manageable. The edge server can remotely verify program code integrity and control execution, eliminating the difficulty of managing distributed local security environments across multiple devices.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If local security environments are implemented on wireless communication devices, then program code verification is achieved, but vulnerability to external attacks increases

Engineering Contradiction:
Improveprogram code verification capabilityVSAvoidexternal attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the security verification function from vulnerable local device environments and relocates it to a protected edge server infrastructure. This centralization reduces the attack surface and protects against external threats that could compromise local security environments.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3713267A1Communication device and edge server for communication network
Publication Date: 2020.09.23 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • EP3713267A1 patent drawingFigure 1
  • EP3713267A1 patent drawingFigure 2
  • EP3713267A1 patent drawing

AI summary

The invention relates to a wireless communication device (120) for a communication network (100), wherein the communication network (100) is configured to provide one or more communication services to the wireless communication device (120) and comprises at least one edge server (140) having a low latency communication connection with the wireless communication device (120). The wireless communication device (120) comprises: a memory (123) configured to store executable program code; a processor (121) configured to execute the program code; and a communication interface (125) configured to send a request for an integrity check of the program code via the low latency communication connection to the edge server (140). The processor (121) is configured to execute the program code, once the edge server (140) has indicated that the integrity of the program code has been verified by the edge server (140). Moreover, the invention relates to a correspondingly configured edge server (140) and a communication network (100).