Secure Enclaves for Modular IoT Application Tamper Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing and monitoring modular applications on IoT devices is challenging due to potential hostile environments and authenticity issues, especially when developed by untrusted third parties, and resource metering is difficult in such settings.

Innovation Solution

A system that generates secure enclaves on local devices using hardware encryption, such as Trusted Platform Modules (TPMs), to protect modular applications and resource utilization, and employs a secure digital ledger or distributed ledger for accurate metering and tamper detection, utilizing proof of work or consensus techniques to ensure integrity and authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If modular applications are executed on local IoT devices to enable local decisions and protect sensitive information, then execution speed and data protection are improved, but security risks and monitoring difficulties increase due to potential hostile environments and untrusted sources

Engineering Contradiction:
Improveexecution speedVSAvoidsecurity reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system segments the execution environment by creating isolated secure enclaves within the IoT device. Each modular application runs in its own sandboxed environment with restricted access to system resources, preventing malicious code from compromising the entire device while maintaining fast local execution

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cloud-based accreditation service as an intermediary that verifies the authenticity of modular applications before deployment. The service issues digital certificates that the device uses to validate application sources, creating a trusted execution path without sacrificing local processing speed

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If modular applications from third parties are deployed on IoT devices to perform device-specific functions, then application versatility and functionality are improved, but security risks and authenticity verification challenges increase

Engineering Contradiction:
Improveapplication versatilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary accreditation and verification of modular applications in the cloud before they are deployed to IoT devices. The accreditation service checks application authenticity, signs digital certificates, and validates security requirements in advance, preventing malicious applications from being installed while maintaining device versatility

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous feedback mechanisms where the device periodically reports application execution status and system state to the cloud accreditation service. The service monitors for anomalies, validates application behavior, and can remotely revoke access credentials if security threats are detected, enabling safe third-party application deployment

Inventive Principle:
Principle #23Feedback

3Reliability

If secure enclaves are generated using hardware encryption to protect modular applications, then security and tamper protection are improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvetamper protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements nested secure enclaves where cryptographic operations and key management are embedded within the device's existing hardware security module. The secure enclave contains virtualized execution environments that are further nested within the physical hardware boundaries, providing multiple layers of protection without requiring separate hardware components

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The system uses a unified hardware encryption platform that serves multiple functions: key generation, secure storage, cryptographic operations, and enclave management. This multi-functional approach consolidates security operations into a single hardware module, reducing overall device complexity while maintaining strong tamper protection

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If distributed ledgers are used for resource metering and tamper detection, then measurement accuracy and integrity are improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvemetering accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the complex distributed ledger operations from the resource-constrained IoT device and relocates them to cloud-based infrastructure. The device only needs to report lightweight metrics and receive verification tokens, while the heavy computational tasks of consensus, hashing, and chain validation are performed remotely, maintaining measurement accuracy without increasing device complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3695335B1Secure application monitoring
Publication Date: 2024.09.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3695335B1 patent drawingFigure 1
  • EP3695335B1 patent drawingFigure 2
  • EP3695335B1 patent drawingFigure 3

AI summary

Example of secure monitring of modular applications and associated edge devices are described herein. In an example, an accreditation request is initiated to accredit at least one of a modular application and an edge device hosting the modular application. The edge device may a device coupling an IoT device to a cloud server. Based on initiating, accreditation information corresponding to at least one of the modular application and the edge device may be received. The accreditation information are generated by a hardware encryption device associated with the edge device. Further, an accreditation status of the modular application may be monitored during execution of the modular application to ascertain whether the modular application and the edge device have been tampered. In case tampering is detected, a remedial action to address the tampering may be performed.