Actor Migration Using Security Attributes for Trusted Runtime Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current implementations of runtime environments in communications networks lack support for secure handling of distributed applications, as they do not verify the trustworthiness of runtime environments beyond certificate possession, leading to inefficiencies and security vulnerabilities.

Innovation Solution

A method and system for migrating an instance of an actor of an application by selecting a target runtime environment based on security attributes, ensuring secure migration and instantiation by verifying trustworthiness and authorization policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If runtime environments only verify certificate possession for applet security, then the verification process is simple and fast, but security trustworthiness is insufficient

Engineering Contradiction:
Improvesecurity trustworthinessVSAvoidverification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having runtime environments pre-advertise their security attributes and policies before actor migration occurs. This allows initiating runtime environments to evaluate target trustworthiness in advance, performing security verification before the migration decision is made, thus resolving the contradiction between thorough verification and operational simplicity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces security attributes as an intermediary mechanism that mediates between the initiating runtime environment and target runtime environment. These attributes act as verifiable credentials that enable trust evaluation without requiring complex direct verification protocols, thus improving security trustworthiness while maintaining verification simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If actors are distributed across multiple runtime environments, then application capacity and performance are improved, but security control and trust verification become more difficult

Engineering Contradiction:
Improveapplication capacityVSAvoidsecurity control complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a standardized security attribute framework that works across all runtime environments in the distributed system. The common security attribute structure and verification mechanism enable consistent security control throughout the distributed architecture, allowing application capacity to scale without proportionally increasing security control complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the security verification parameter from simple certificate presence to comprehensive security attributes including policies, capabilities, and trust relationships. This parameter transformation enables automated evaluation of target runtime environments, making security control manageable in distributed settings while maintaining high application capacity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security verification is performed before actor migration, then migration security is improved, but migration time and processing overhead increase

Engineering Contradiction:
Improvemigration securityVSAvoidmigration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having target runtime environments pre-compute and advertise their security attributes and policies before migration requests arrive. This advance preparation allows initiating runtime environments to perform quick evaluation decisions without time-consuming verification during the actual migration process, thus maintaining high migration security while minimizing migration time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by performing security verification only on the specific security attributes relevant to the migration decision, rather than comprehensive verification of all security parameters. This selective verification approach maintains adequate migration security while reducing processing overhead and migration time.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3411786B1Actor migration
Publication Date: 2025.10.15 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3411786B1 patent drawingFigure 1a~3
  • EP3411786B1 patent drawingFigure 1b(a)~1b(f)
  • EP3411786B1 patent drawingFigure 2a~2b

AI summary

A method and a corresponding runtime environment for migrating an instance of an actor of an application are provided. An initiating runtime environment performs a method comprising selecting, based on obtained security attributes for a set of target runtime environments, a target runtime environment from the set of target runtime environments for migration of the instance of the actor. The method further comprises migrating the instance of the actor to the selected target runtime environment once the target runtime environment has been selected.