Tenant Container Information Transparency via Endpoint Agent Signing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud security systems, tenants face challenges in verifying that cloud service providers are fulfilling service level agreements, as there is a risk of rogue insiders breaching security and the lack of transparency in information collection from tenant containers, with sensitive information being potentially mismanaged.

Innovation Solution

A method and system that uses an endpoint agent to collect information from tenant containers, extract a summary, and sign it with a secure key inaccessible to other processes, allowing transparent and secure transmission to tenants and vendors for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the CSP collects information from tenant containers without transparency mechanisms, then the CSP can monitor and detect security threats effectively, but the tenant cannot verify whether the CSP is fulfilling service level agreements and may suffer from rogue insider breaches

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidinformation collection transparency
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an information identification module as an intermediary component that sits between the endpoint agent and the tenant. This module extracts and identifies specific information elements from the collected data, making the information collection process transparent to the tenant while allowing the CSP to maintain security monitoring capabilities. The intermediary enables verification of service level agreements without compromising threat detection effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the CSP collects unlimited information from tenant containers, then the CSP can perform comprehensive security analysis and forensics, but sensitive information may be mismanaged and tenants lose control over their data

Engineering Contradiction:
Improvesecurity analysis capabilityVSAvoidsensitive information mismanagement
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and identifies specific information elements from the vast amount of collected data using the information identification module. Instead of treating all collected information uniformly, the system extracts only the relevant information elements needed for security analysis and forensics, while separating sensitive information that requires special handling. This extraction process enables comprehensive security analysis while reducing the risk of sensitive information mismanagement by clearly delineating what data is collected and how it is used.

Inventive Principle:
Principle #2Taking out (Extraction)

3Difficulty of detecting and measuring

If the endpoint agent collects and transmits all information from tenant containers, then the CSP can detect cyber-threats and perform forensics, but the transmission of sensitive information increases security risks

Engineering Contradiction:
Improvecyber-threat detectionVSAvoiddata transmission security risk
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The information identification module extracts and identifies specific information elements before transmission to the cloud service provider. This extraction process filters out sensitive information that does not need to be transmitted, while maintaining the essential information needed for cyber-threat detection and forensics. By extracting only the necessary information elements for security analysis, the system reduces the data transmission volume and minimizes security risks associated with transmitting sensitive information, while still enabling effective threat detection.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250007957A1Transparency of information collected from tenant container
Publication Date: 2025.01.02 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250007957A1 patent drawing
  • US20250007957A1 patent drawing
  • US20250007957A1 patent drawing

AI summary

Embodiments of the present disclosure provide a method, a computing device and a computer program product for achieving transparency of information collected from a tenant container. The method is performed by the computing device. The method includes identifying collection of information from the tenant container by an endpoint agent resident on the computing device during execution of the tenant container and extracting a summary of collected information. Further, the method includes signing the extracted information using a signing key. The signing key is not accessible to one or more processes that are being executed on the computing device. Corresponding computing device and computer program products are also disclosed.