Trusted Container Management via TEE and DeftT
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for managing software containers in energy delivery infrastructure face challenges such as inadequate cybersecurity, lack of granular access control, and inefficient software distribution, leading to increased risks of cyber attacks and compromised security.
Innovation Solution
A Trusted Container Management System (TCMS) that employs a Trusted Execution Environment (TEE) to securely manage software containers, utilizing DeftT protocol for secure data flow and access control, and Information Centric Networking (ICN) for efficient communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software containers are deployed in energy delivery infrastructure without a trusted execution environment, then device complexity and ease of operation are maintained at acceptable levels, but cybersecurity reliability and access control precision deteriorate
Solution Approach 1:
The patent introduces a Trusted Execution Environment (TEE) as an intermediary layer between the software containers and the underlying hardware. This TEE acts as a mediator that provides secure isolation and trusted operations without requiring complete system redesign. The TEE creates a secure boundary that protects container operations while maintaining manageable system architecture through layered security.
Solution Approach 2:
The system segments the execution environment into trusted and untrusted zones using the TEE. Software containers run in isolated segments within the TEE, each with defined security boundaries. This segmentation allows individual container security to be managed independently while maintaining overall system reliability, resolving the contradiction between security and complexity.
2Measurement precision
If traditional access control methods are used without DeftT protocol, then ease of operation is maintained, but measurement precision of access rights and security control deteriorate
Solution Approach 1:
The DeftT protocol implements self-service access control where the system automatically verifies credentials, manages security tokens, and enforces access policies without requiring manual intervention. This automated self-service approach maintains ease of operation while achieving precise access control measurements through cryptographic verification and policy enforcement embedded in the protocol itself.
Solution Approach 2:
The DeftT protocol incorporates continuous feedback mechanisms that monitor access requests, verify credentials, and enforce security policies in real-time. This feedback loop ensures precise access control by continuously validating operations while maintaining ease of operation through automated decision-making that eliminates manual security checks.
3Reliability
If software containers are managed without continuous supervision, then device complexity and use of energy are reduced, but reliability and speed of detecting infected processes deteriorate
Solution Approach 1:
The system performs preliminary actions by pre-configuring security policies, authentication credentials, and monitoring rules within the TEE before container deployment. This preliminary setup enables continuous supervision without requiring complex real-time decision-making, as the supervision system follows pre-established security protocols and automated response procedures.
Solution Approach 2:
The container management system implements self-service monitoring where containers automatically report their status, security events, and operational metrics to the supervision system. This self-reporting mechanism reduces the complexity of continuous supervision by eliminating the need for intrusive monitoring agents, while maintaining high reliability through automated detection and reporting of infected processes.
Data Source
AI summary
A trusted container management system provides process supervision, such as for software or other executable processes. In an embodiment, a particular edge controller can include a Rich Execution Environment (REE) and a Trusted Execution Environment (TEE). In an example, an application executes in a container of the REE and generates communication data and a signature identifier. A DeftT publication is generated and includes the communication data. An untrusted validator in the REE evaluates the DeftT publication according to a trust rule associated with the communication data and publishes the DeftT publication. A secure validator executing in a Trusted Execution Environment (TEE) further evaluates the DeftT publication. The further evaluation can include subscribing to the certificate identified by the signature identifier, determining the public key and the role of the certificate, and validating the DeftT publication based on the public key. The further evaluation can further include subscribing to a particular trust rule.


