Idle Computing Device Container Execution via Security Chip Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributed computing systems face challenges in efficiently utilizing existing resources during idle states and mitigating security risks associated with workload distribution and execution, particularly due to the need for additional computing devices and potential exposure to malicious code.
Innovation Solution
A distributed system that identifies and utilizes idle computing devices within an organization by assigning certificates of authority specific to each device, verified by a security chip, to ensure authorized and secure execution of tasks within containers, thereby preventing malicious containers and optimizing resource utilization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Power
If additional computing devices are purchased to satisfy computational needs, then processing power and computational capacity are improved, but cost and device complexity increase
Solution Approach 1:
The patent enables computing devices to serve multiple functions by allowing idle devices to be dynamically recruited into the distributed computing network. The same hardware resources (CPU, memory, storage) that perform local tasks also provide computational power for distributed workloads when idle, eliminating the need for dedicated additional devices.
Solution Approach 2:
The system utilizes idle computational resources that would otherwise be wasted. By automatically detecting and incorporating idle devices into the distributed network, the system makes use of existing unused capacity rather than requiring new investments in hardware infrastructure.
2Productivity
If computing devices are utilized during idle states for distributed computing, then resource utilization and computational efficiency are improved, but security risks and exposure to malicious code increase
Solution Approach 1:
The patent implements preliminary security verification by checking the idle device's trust state and security credentials before allowing container execution. The system performs advance validation of the device's cryptographic keys and security posture, preventing malicious devices from joining the distributed network.
Solution Approach 2:
The system introduces a security intermediary layer that mediates between the distributed computing network and idle devices. This intermediary verifies device credentials, manages cryptographic keys, and enforces security policies, isolating the core system from direct exposure to potentially compromised devices.
3Reliability
If security verification and certificate authentication are implemented for idle devices, then security and protection from malicious code are improved, but system complexity and verification overhead increase
Solution Approach 1:
The patent uses cryptographic key pairs and digital certificates as verifiable copies of device identity. Instead of complex continuous monitoring, the system relies on these cryptographic copies to authenticate devices, providing simple yet robust security verification that scales efficiently.
Data Source
AI summary
In some examples, non-transitory computer-readable storage stores machine-readable instructions that, when executed by a processor, cause the processor to identify an idle state of a computing device; evaluate a root of trust between a security chip and a container system to verify that the container system is a trusted container system; enable the trusted container system; receive a container during the idle state; and execute the container during the idle state using the trusted container system.


