METHOD AND APPARATUS FOR MULTI-DIMENSIONAL ATTESTATION FOR A SOFTWARE APPLICATION

    公开(公告)号:EP4459485A1

    公开(公告)日:2024-11-06

    申请号:EP23216237.0

    申请日:2023-12-13

    申请人: INTEL Corporation

    IPC分类号: G06F21/51 G06F21/57 G06F21/64

    摘要: A method and apparatus for multi-dimensional attestations for a software application. A multi-dimensional attestation is generated for at least one component of the software application. The multi-dimensional attestation includes a signed attestation for the at least one component and an attestation reference to at least one other related component. A verifier obtains multi-dimensional attestations for the components of the software application and obtains the signed attestation for the related components of the software application based on the attestation reference and verifies integrity of at least part of the software application based on the obtained signed attestations. The multi-dimensional attestation for a given component of a software application can link attestations across spatial and temporal dimensions including other microservice(s) that communicates directly with the subject microservice, imported code dependencies on which the subject microservice is dependent, and/or the underlying software layer of the subject microservice.

    APPARATUS, DEVICE, METHOD, AND COMPUTER PROGRAM FOR A NETWORK ELEMENT

    公开(公告)号:EP4456479A1

    公开(公告)日:2024-10-30

    申请号:EP23216333.7

    申请日:2023-12-13

    申请人: INTEL Corporation

    IPC分类号: H04L9/40

    摘要: Various examples of the present disclosure relate to an apparatus, device, method, and computer program for a network element, to a corresponding network element and to a system. The apparatus comprises interface circuitry, machine-readable instructions, and processing circuitry to execute the machine-readable instructions to obtain a first request to establish an encrypted data connection between a client device and a server from the client device, forward the first request to the server, obtain a first response from the server, with the first response being based on the first request, provide a second request to establish an encrypted data connection to the server, obtain a second response from the server, with the second response being based on the second request, determine an application categorization for the encrypted data connection between the client device and the server based on the second response, and handle the encrypted data connection between the client and the device based on the application categorization.