Identity-Based Application Verification in Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing platforms face challenges in managing network control policies, leading to complexity, misconfigurations, and vulnerabilities due to dynamic virtual instance identifiers and masked network addresses, which hinder effective security and incident management.
Innovation Solution
Establishing application identities through signing artifacts and generating runtime hashes to create a secure application identity that includes both static and dynamic properties, allowing for accurate verification and policy enforcement without relying on network control policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network control policies are implemented to protect cloud applications, then security is improved, but device complexity increases due to managing thousands of rules
Solution Approach 1:
The patent introduces an intermediary identity verification system that sits between applications and network control policies. Instead of directly managing thousands of network rules, the system uses application identities as intermediaries to enforce security. The identity verification mechanism translates complex network policy requirements into simpler identity-based access control, reducing the burden of managing numerous network control rules while maintaining security.
Solution Approach 2:
The patent segments the security management approach by separating application identification from network policy enforcement. It divides the system into distinct components: application identity generation, identity verification, and policy enforcement. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while maintaining comprehensive security coverage.
2Reliability
If network control policies are enforced to limit access, then security is improved, but ease of operation deteriorates due to misconfigurations and blind spots
Solution Approach 1:
The patent implements preliminary action by generating and verifying application identities before network policy enforcement. Instead of configuring complex network rules first, the system pre-establishes application identities that encode security requirements. This preliminary identity verification step simplifies subsequent policy enforcement and reduces configuration errors, as identities serve as pre-configured security credentials.
Solution Approach 2:
The patent incorporates feedback mechanisms through identity verification results that provide immediate information about application authenticity. The verification process feeds back security status to the system, enabling dynamic adjustment of access control decisions. This feedback loop reduces blind spots by continuously verifying application identities and providing visibility into access control status.
3Adaptability or versatility
If dynamic protection is implemented for virtual instances, then adaptability is improved, but measurement precision deteriorates due to masked network addresses
Solution Approach 1:
The patent uses application identities as intermediaries that decouple address identification from security verification. Instead of relying on masked network addresses for identification, the system introduces identity tokens as mediators that carry security information independently of network addressing. This allows dynamic address changes while maintaining precise identification through immutable identity markers.
Solution Approach 2:
The patent transitions from network address-based identification to identity-based identification, adding a new dimension to the security model. Instead of relying solely on the network address dimension, the system introduces an identity dimension that provides precise measurement and verification capabilities independent of address masking or translation.
4Reliability
If application identities are established through artifact signing and runtime hashing, then reliability is improved, but use of energy increases due to cryptographic operations
Solution Approach 1:
The patent applies preliminary action by performing artifact signing during application deployment or build time, rather than during runtime operations. Cryptographic hashes of application artifacts are pre-computed and stored as part of the application identity. This shifts the energy-intensive cryptographic operations to a preliminary phase, reducing real-time energy consumption while maintaining security verification capabilities during execution.
Data Source
AI summary
A system and method for establishing application identities including application runtime properties. A method includes signing at least one artifact of a first application communicating with a second application, wherein each of the at least one artifact includes data used for executing the first application, wherein a signing result of each artifact is a signed cryptographic hash of the artifact; monitoring events related to communications between the first application and the second application to identify a file event; generating at least one runtime hash for the file event, wherein the at least one runtime hash represents runtime properties of the first application; and generating an application identity for the first application, the application identity for the first application including the signed cryptographic hash of each of the at least one artifact and the at least one runtime hash of the file event.


