Quantum-Immune Keyless Signatures for Virtual Machine Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for ensuring the integrity of virtual machines in cloud computing deployments, such as those based on Public Key Infrastructure, face challenges in large-scale implementations due to complexity in certificate management, including certificate renewal, revocation, and long-term storage, and are vulnerable to quantum computing attacks.

Innovation Solution

The use of Quantum-Immune Keyless Signatures Infrastructure (QSI) eliminates the need for key and certificate management by employing hash-tree based data protection and one-time secret keys for digital signatures, ensuring the integrity of virtual machines without relying on traditional public-key technology or certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Public Key Infrastructure is used for virtual machine integrity verification, then security and trust establishment are improved, but system complexity and certificate management overhead increase significantly

Engineering Contradiction:
Improvevirtual machine integrity verificationVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and eliminates the certificate management component from the trust establishment process. Instead of using traditional PKI certificates, the system uses quantum-immune keyless signatures that directly provide integrity verification without requiring certificate issuance, renewal, or revocation management, thus removing the complex certificate lifecycle management while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the fundamental parameter of trust establishment from certificate-based asymmetric cryptography to quantum-immune keyless signatures. This parameter change transitions the system from a model requiring complex certificate management to one providing direct integrity verification through cryptographic signatures that are immune to quantum computing attacks

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional public-key signatures are used, then digital signature functionality is provided, but vulnerability to quantum computing attacks increases

Engineering Contradiction:
Improvedigital signature securityVSAvoidquantum computing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the potential harm of quantum computing capability into a benefit by using quantum-immune cryptographic algorithms. These algorithms are specifically designed to be secure against both classical and quantum computing attacks, transforming the quantum threat into an opportunity to implement more robust security that maintains digital signature functionality while eliminating quantum vulnerability

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If certificate renewal and revocation mechanisms are implemented, then security maintenance is improved, but operational complexity and time consumption increase

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidcertificate lifecycle management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a self-service mechanism where the keyless signature system automatically maintains security without requiring manual certificate renewal or revocation. The cryptographic system inherently provides ongoing security through its quantum-immune properties, eliminating the need for time-consuming certificate lifecycle management operations while maintaining continuous security

Inventive Principle:
Principle #25Self-service

4Reliability

If PKI-based solutions are deployed at large scale, then security coverage is improved, but scalability and manageability deteriorate due to certificate management overhead

Engineering Contradiction:
Improvesecurity coverageVSAvoiddeployment scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the burden of certificate management from the deployment process, enabling large-scale deployment of quantum-immune keyless signatures without the proportional increase in management complexity that plagues PKI systems. This extraction allows security coverage to scale with deployment size while maintaining manageable operations

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The keyless signature system provides universal security functionality that works across all deployment scales without requiring different management approaches. The same quantum-immune cryptographic mechanism serves both small and large deployments equally effectively, providing multi-functional security coverage that scales linearly with deployment size

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3317875B1Keyless signature infrastructure based virtual machine integrity
Publication Date: 2022.10.26 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3317875B1 patent drawingFigure 1
  • EP3317875B1 patent drawingFigure 2~3
  • EP3317875B1 patent drawingFigure 4~5

AI summary

A method of verifying the integrity of a virtual machine in a cloud computing deployment comprises: creating a virtual machine image derived from a trusted virtual machine, wherein the trusted virtual machine has a Keyless Signature Infrastructure signature stored in a signature store; and verifying that a computation resource can be trusted. If it is verified that a computation resource can be trusted, the method further comprises: submitting the virtual machine image to the trusted computation resource; checking a signature of the virtual machine image against the stored signature of the trusted virtual machine; launching the virtual machine image on the trusted computation resource, and creating a Keyless Signature Infrastructure signature of the virtual machine image; and storing the signature of the virtual machine image in a signature store.