Cloud Marketplace VM Image Security via Electronic Signature Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a security technology that enables cloud service customers to safely use virtual machine (VM) images provided by various vendors, as there is a desire to identify whether the VM images are forged or falsified during registration with a marketplace or during operation by a cloud service customer.

Innovation Solution

A marketplace security method and apparatus that involves downloading a VM image selected by a cloud service customer, obtaining and verifying an electronic signature associated with the VM image, and determining whether to operate a VM instance based on the verification result. Additionally, the method includes obtaining and verifying an authentication certificate associated with the VM service provider to determine whether to download the VM image.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VM images are downloaded and operated from marketplace without verification, then ease of operation is improved, but security and reliability deteriorate due to inability to identify forged images

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by verifying the electronic signature of the VM image before it is operated. The cloud service provider downloads the VM image from the marketplace, verifies its electronic signature to ensure authenticity, and only then allows operation. This pre-verification prevents forged images from being executed, resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If electronic signature verification is performed on VM images, then reliability and security are improved, but device complexity increases due to additional verification operations

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by having the VM image carry its own electronic signature, which serves as self-verification evidence. When the cloud service provider receives a VM image, it automatically verifies the embedded electronic signature without requiring external authentication services. This self-contained verification mechanism improves security while minimizing additional system complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If authentication certificate verification is performed on VM service providers, then reliability is improved, but loss of time increases due to additional verification steps

Engineering Contradiction:
ImprovesecurityVSAvoidtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the VM service provider obtain and embed their authentication certificate in advance when creating the VM image. The cloud service provider then verifies this pre-embedded certificate automatically during the download process. This preliminary preparation of authentication credentials reduces the time penalty of verification by eliminating real-time authentication overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4379585B1Method for securing marketplace in cloud and apparatus thereof
Publication Date: 2025.04.09 SAMSUNG SDS CO LTD
  • EP4379585B1 patent drawingFigure 1
  • EP4379585B1 patent drawingFigure 2A
  • EP4379585B1 patent drawingFigure 2B

AI summary

Disclosed is a marketplace security method performed by a cloud service provider (CSP), and the method includes an operation of downloading a virtual machine (VM) image selected by a cloud service customer from the marketplace into a cloud space of the corresponding cloud service customer, an operation of obtaining an electronic signature associated with the downloaded VM image in response to an operation request from the cloud service customer, an operation of verifying the obtained electronic signature, and an operation of determining, based on a verification result, whether to operate a VM instance corresponding to the downloaded VM image.