Trust Assurance services in the PUZZLE framework

  • August 29, 2022
  • 3 min read

The heterogeneous infrastructure of businesses with products coming from various manufacturers makes it highly challenging for System Administrators to adequately monitor the security status of each device connected to their networks and establish a trustworthy environment among them. Also, it is tough to constantly control the integrity of the devices in terms of the correctness of running services, considering at the same time that most of them consist of hardware parts and modules produced by several vendors, even from unknown producers. Thus, diverse technologies can coexist, creating a complex and insecure environment.

The problem is getting worse in the case of SMEs, which lack the expertise and the trained personnel to identify and solve these issues on time. In general, the lack of security visibility is the primary precursor to security incidents since security gaps are extremely hard to detect, remediate, and address on time for every device deployed in the infrastructure. This is the motivation behind PUZZLE, which aims to satisfy the need for an automated solution that can easily monitor the interaction between the devices and ensure the trusted behaviour of the devices concurrently.

One of the main components of the PUZZLE framework is the “Trust Assurance Services” dedicated to the provision of end-to-end security and transparency to the SME environment.

Its ultimate goal is to ensure the secure operation of the business ecosystem in terms of data and asset integrity.

To accomplish this, an efficient runtime attestation mechanism has been designed and developed that can verify the state of the underlying assets and the exchanged data among them. The overall responsibility of the component is to ensure the integrity, trustworthiness, and operational assurance of the various assets of the target SME and the PUZZLE framework itself.

The role of the runtime attestation mechanism in PUZZLE is twofold:

  • (a) On the one hand is related to monitoring traffic between the devices by verifying a series of security properties such as cryptographic protocols, signature validity, and key length. This will ensure that the data transmitted from one device to another have not been tampered by a malicious actor (e.g., from a router to a local server), and will secure the system against man in the middle attacks and other network-based threats;
  • (b) On the other hand, the mechanism deployed on the devices verifies the security state of the device based on the integrity of the loaded binaries and libraries. This will allow the mechanism to confirm that the device “behaves” as it has been designed to and will guarantee that its software has not changed during its life cycle. This integrity check can be performed on all the underlying infrastructure assets, but it can also be extended beyond it and protect the PUZZLE framework itself.
Figure 1: Positioning of Trust Assurance services in PUZZLE framework

Author: UBITECH Greece
Featured Photo from Pixabay.