Trusted Execution Environment Verification of Software Packages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The frequent installation of software packages in OS environments poses a risk of compromised software packages implementing undesired functionality, and determining validity is challenging, especially when the OS itself is compromised.
Innovation Solution
A trusted execution environment (TEE) verification process is initiated to determine the validity of software packages before installation, using a software package verification process that executes in a hardware-implemented protected environment, ensuring that the process cannot be compromised by a compromised OS.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If software packages are frequently installed to provide new functionality and upgrades, then the OS environment gains additional capabilities, but the risk of compromised software packages implementing undesired functionality increases
Solution Approach 1:
The patent implements preliminary verification of software packages before installation by executing verification code in a trusted execution environment (TEE). The TEE measures and records the software package's code and data in a secure manner before the package is installed into the OS environment, creating a trusted baseline measurement that prevents compromised packages from being installed.
Solution Approach 2:
The patent introduces a trusted execution environment (TEE) as an intermediary between the software package and the OS environment. The TEE acts as a secure mediator that verifies the software package's integrity through cryptographic measurements and trusted verification processes, isolating the verification process from potential OS compromise and ensuring reliable validity checks.
2Reliability
If the OS itself is compromised, then the OS can no longer reliably determine software package validity, but traditional verification methods depend on the OS integrity
Solution Approach 1:
The patent segments the verification system into two distinct parts: a trusted execution environment (TEE) that performs secure verification operations, and the general OS environment that handles normal software installation. This segmentation isolates the critical verification function in a protected TEE that cannot be compromised by OS-level attacks, while maintaining the OS's ability to handle routine operations.
Solution Approach 2:
The TEE serves as an intermediary verification layer that operates independently of the OS's trustworthiness. The TEE performs cryptographic measurements and verification operations that are isolated from OS compromise, providing a reliable verification mechanism even when the OS itself is compromised. The TEE's trusted status is established through hardware-based security mechanisms that prevent OS-level attacks from affecting verification accuracy.
Data Source
AI summary
Trusted execution environment verification of a software package. An operating system (OS) initiates a software package verification process in a trusted execution environment, the OS being part of an OS environment comprising a file system. It is determined that a first software package in a software repository is to be installed into the OS environment. The first software package is downloaded to a storage device. The OS sends, to the software package verification process, first location information that identifies a location of the first software package. The OS receives, from the software package verification process, information that indicates that the first software package on the storage device is trusted.


