Host Context Engine for Attribute-Based Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing middlebox solutions do not effectively utilize rich contextual data for data message flows on hosts, lacking an efficient distributed scheme to filter and process contextual attributes, which limits their ability to implement context-based services.
Innovation Solution
A novel architecture that executes a guest-introspection agent, context engine, and attribute-based service engines on host computers to capture and consume contextual attributes from network and process events, using these attributes to identify and enforce context-based service rules for network and process operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional hardware appliances are used for middlebox services, then service processing capability is maintained, but flexibility and control are reduced
Solution Approach 1:
The patent replaces traditional hardware appliances with software-based middlebox services running on virtualized hosts. The context engine and service engines are implemented as software components that can be deployed and managed through SDN controllers, substituting physical hardware with flexible software implementations while maintaining processing capabilities through virtualization.
Solution Approach 2:
The system enables dynamic service deployment and configuration through SDN controllers that can programmatically manage middlebox services. Service rules can be dynamically updated, and the context engine can adapt to changing network conditions and security requirements in real-time, providing both flexibility and maintained processing capability.
2Measurement precision
If all contextual attributes are captured for every data message flow, then context-based service accuracy is improved, but processing overhead increases
Solution Approach 1:
The context engine extracts only the specific contextual attributes needed for particular service rules rather than capturing all possible attributes for every flow. The system selectively collects attributes based on service requirements, reducing processing overhead while maintaining the precision needed for accurate context-based service enforcement.
Solution Approach 2:
The system implements partial attribute collection by gathering only the necessary contextual information required for each specific service rule. Rather than excessively collecting all possible attributes, the context engine performs partial actions tailored to each service's needs, optimizing the balance between accuracy and processing efficiency.
3Productivity
If context engine filters thousands of contextual attributes, then service rule processing efficiency is improved, but attribute filtering complexity increases
Solution Approach 1:
The context engine serves as an intermediary component between attribute collection and service rule processing. It manages the filtering and organization of contextual attributes, absorbing the complexity of attribute management while presenting simplified, relevant attributes to service engines for efficient rule processing.
4Quantity of substance
If middlebox services are migrated to hosts, then hardware resource utilization is improved, but loss of rich-contextual data utilization occurs
Solution Approach 1:
The host system is designed with multi-functionality, serving both as a compute resource for virtual machines and as a platform for context-based middlebox services. The context engine and service engines run alongside VM workloads, enabling the host to simultaneously utilize hardware resources for general computing while also capturing and processing rich contextual data from network and process events.
Data Source
AI summary
Some embodiments provide a context engine that supplies contextual-attributes to several context-based service engines on its host computer. Different embodiments use different types of context-based service engines. For instance, in some embodiments, the attribute-based service engines include an encryption engine that performs context-based encryption or decryption operations to encrypt data messages from the machines, or to decrypt data messages received for the machines.


