Idle Computing Device Container Execution via Security Chip Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed computing systems face challenges in efficiently utilizing existing resources during idle states and mitigating security risks associated with workload distribution and execution, particularly due to the need for additional computing devices and potential exposure to malicious code.

Innovation Solution

A distributed system that identifies and utilizes idle computing devices within an organization by assigning certificates of authority specific to each device, verified by a security chip, to ensure authorized and secure execution of tasks within containers, thereby preventing malicious containers and optimizing resource utilization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Power

If additional computing devices are purchased to satisfy computational needs, then processing power and computational capacity are improved, but cost and device complexity increase

Engineering Contradiction:
Improvecomputational capacityVSAvoidsystem complexity
Core Design Contradiction:
PowerVSDevice complexity

Solution Approach 1:

The patent enables computing devices to serve multiple functions by allowing idle devices to be dynamically recruited into the distributed computing network. The same hardware resources (CPU, memory, storage) that perform local tasks also provide computational power for distributed workloads when idle, eliminating the need for dedicated additional devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system utilizes idle computational resources that would otherwise be wasted. By automatically detecting and incorporating idle devices into the distributed network, the system makes use of existing unused capacity rather than requiring new investments in hardware infrastructure.

Inventive Principle:
Principle #25Self-service

2Productivity

If computing devices are utilized during idle states for distributed computing, then resource utilization and computational efficiency are improved, but security risks and exposure to malicious code increase

Engineering Contradiction:
Improvecomputational efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary security verification by checking the idle device's trust state and security credentials before allowing container execution. The system performs advance validation of the device's cryptographic keys and security posture, preventing malicious devices from joining the distributed network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces a security intermediary layer that mediates between the distributed computing network and idle devices. This intermediary verifies device credentials, manages cryptographic keys, and enforces security policies, isolating the core system from direct exposure to potentially compromised devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security verification and certificate authentication are implemented for idle devices, then security and protection from malicious code are improved, but system complexity and verification overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses cryptographic key pairs and digital certificates as verifiable copies of device identity. Instead of complex continuous monitoring, the system relies on these cryptographic copies to authenticate devices, providing simple yet robust security verification that scales efficiently.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12026286B2Executing containers during idle states
Publication Date: 2024.07.02 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US12026286B2 patent drawing
  • US12026286B2 patent drawing
  • US12026286B2 patent drawing

AI summary

In some examples, non-transitory computer-readable storage stores machine-readable instructions that, when executed by a processor, cause the processor to identify an idle state of a computing device; evaluate a root of trust between a security chip and a container system to verify that the container system is a trusted container system; enable the trusted container system; receive a container during the idle state; and execute the container during the idle state using the trusted container system.