TEE Workload Compliance Verification With Triggered Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing trusted execution environments lack continuous integrity verification and remediation mechanisms to ensure compliance with predefined security requirements during workload execution, exposing them to potential security breaches.
Innovation Solution
A control program with control elements and trigger events is implemented to continuously verify workload compliance, executing remediation actions if non-compliance is detected, and generating attestation and remediation records to maintain integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional trusted execution environments are used without continuous verification, then the system structure remains simple, but security reliability deteriorates due to lack of ongoing integrity checks
Solution Approach 1:
The control program is segmented into multiple control elements, each responsible for specific compliance verification tasks. This segmentation allows the system to achieve comprehensive integrity verification through modular components, resolving the contradiction by organizing complexity into manageable segments that collectively enhance reliability.
Solution Approach 2:
The patent implements preliminary action by establishing control elements and trigger events before workload execution begins. The control program is configured in advance with predefined compliance checks and remediation actions, enabling continuous verification without adding operational complexity during runtime.
2Reliability
If control elements are executed multiple times in response to trigger events, then compliance verification reliability improves, but processing time increases
Solution Approach 1:
The system employs periodic action through trigger events that initiate control element execution at specific intervals or under specific conditions. This periodic verification approach ensures compliance reliability while optimizing processing time by avoiding continuous execution, executing controls only when triggered by meaningful events.
Solution Approach 2:
The patent implements feedback mechanisms where control elements monitor workload compliance and trigger remediation actions when violations are detected. This feedback loop ensures continuous compliance verification reliability while minimizing time loss by only executing remediation when actually needed, based on real compliance status.
3Reliability
If automated remediation actions are implemented, then security reliability improves through automatic correction, but system complexity increases
Solution Approach 1:
The system implements self-service through automated remediation actions that automatically correct compliance violations without external intervention. Control elements are configured with predefined remediation logic that executes automatically when trigger events indicate compliance failures, enhancing security reliability while managing complexity through automation of previously manual processes.
Solution Approach 2:
The patent uses parameter changes to implement remediation by modifying workload parameters or configuration settings when compliance violations are detected. This approach achieves security reliability through automatic correction while managing complexity by changing parameters rather than restructuring the entire system.
Data Source
AI summary
Provided are a computer program product, system, and method for verifying compliance of a workload executing in a trusted execution environment. A control program for a trusted execution environment has a plurality of control elements provided by users. A control element of the control elements includes a command to execute to verify compliance of an element in a workload in the trusted execution environment with a requirement. A trigger event, associated with a triggered control element of the control elements, is detected during execution of the workload in the trusted execution environment. The command for the triggered control element is executed to verify compliance of an element in the workload. The triggered control element is executed multiple times during execution of the workload to verify compliance of the element in the workload in response to multiple instances of detecting the trigger event.


