Trusted Co-Processor for Cloud Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, customers face challenges in verifying the security and integrity of resources, as they lack control over hardware and data, making it difficult to trust reports about malware or intrusion detection, especially when resources are shared and potentially compromised.

Innovation Solution

A trusted co-processor is introduced as a peripheral card connected to a high-speed bus within the host machine, allowing customers to perform trusted scans and notifications independently of the host machine's malware, using APIs and out-of-band channels for secure communication and updates, ensuring the co-processor's integrity and preventing malware manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud computing resources are used to provide access to electronic resources, then scalability and accessibility are improved, but security and integrity verification becomes difficult

Engineering Contradiction:
ImprovescalabilityVSAvoidsecurity verification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A trusted co-processor is introduced as an intermediary component between the cloud provider's hardware and the customer's software. This co-processor operates in a trusted execution environment that is isolated from the host machine's malware, allowing it to perform security scans and generate verified reports. The co-processor acts as a mediator that maintains trust relationships while enabling cloud computing functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If resources are shared with other customers, then resource utilization is improved, but data and software security may be compromised

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity compromise
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system segments the computing environment into isolated trusted execution environments for each customer. Each customer's workloads run in separate virtual machines with their own trusted co-processor, creating security boundaries that prevent malware from one customer's environment from affecting another customer's resources, even though resources are shared at the infrastructure level.

Inventive Principle:
Principle #1Segmentation

3Difficulty of detecting and measuring

If malware scanning is performed on shared resources, then detection capability is improved, but trust in scan reports deteriorates when resources are compromised

Engineering Contradiction:
Improvemalware detectionVSAvoidscan report trust
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The malware scanning functionality is extracted from the host machine and placed in a separate trusted co-processor. This extraction ensures that the scanning process itself is not vulnerable to host machine malware, as the co-processor operates in an isolated trusted execution environment. The co-processor can scan memory and disk of virtual machines while maintaining its own security integrity.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If a trusted co-processor is added to perform independent scans, then security verification is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted co-processor is nested within the cloud provider's hardware infrastructure but operates as a separate, customer-accessible entity. The co-processor is integrated at the hardware level with virtualization support, allowing it to access memory and storage of virtual machines without requiring complex software configurations. This nested architecture provides security functionality while minimizing complexity at the customer level.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10685119B2Trusted malware scanning
Publication Date: 2020.06.16 AMAZON TECH INC
  • US10685119B2 patent drawing
  • US10685119B2 patent drawing
  • US10685119B2 patent drawing

AI summary

A trusted co-processor can provide a hardware-based observation point into the operation of a host machine owned by a resource provider or other such entity. The co-processor can be installed via a peripheral card on a fast bus, such as a PCI bus, on the host machine. The co-processor can execute malware detection software, and can use this software to analyze data and/or code obtained from the relevant resources of the host machine. The trusted co-processor can notify the customer or another appropriate entity of the results of the scan, such that an appropriate action can be taken if malware is detected. The results of the scan can be trusted, as malware will be unable to falsify such a notification or modify the operation of the trusted co-processor.