Isolated Computing Environment for Pay-Per-Use Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Developing a computer operating system that is backward-compatible yet secure enough to ensure tamper resistance is challenging, especially with the rise of pay-per-use business models requiring high assurance of compliance and security.

Innovation Solution

A computer adapted for pay-per-use models employs an isolated computing environment with secure memory, processing capabilities, and cryptographic functions to monitor and enforce compliance with usage policies, invoking sanctions if non-compliance is detected, including disabling the operating system to ensure security and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If operating system complexity is increased to support backward compatibility with numerous computer applications, then adaptability is improved, but security and tamper resistance deteriorate

Engineering Contradiction:
Improvebackward compatibilityVSAvoidtamper resistance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system is divided into two distinct segments: a secure isolated computing environment (ICE) that handles security-critical functions, and a standard operating system that provides application compatibility. The ICE contains a trusted computing base with cryptographic capabilities that operates independently from the main OS, allowing the OS to remain complex and compatible while the ICE maintains security and tamper resistance.

Inventive Principle:
Principle #1Segmentation

2Reliability

If an isolated computing environment is introduced to monitor and enforce compliance, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The isolated computing environment is implemented as a nested structure within the overall computing system. The ICE contains a trusted computing base that is further nested with cryptographic modules and compliance monitoring functions. This nested architecture allows security functions to be contained within the ICE while the outer system maintains standard operating functionality, managing complexity through hierarchical organization.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If compliance monitoring is continuously performed to detect non-compliant usage, then reliability is improved, but use of energy increases

Engineering Contradiction:
Improvecompliance assuranceVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The compliance monitoring in the isolated computing environment operates periodically rather than continuously. The ICE periodically checks compliance status, evaluates usage patterns, and enforces policies at scheduled intervals. This periodic operation maintains compliance assurance while significantly reducing power consumption compared to continuous monitoring, as the monitoring functions are activated only when needed rather than running constantly.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8176564B2Special PC mode entered upon detection of undesired state
Publication Date: 2012.05.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8176564B2 patent drawing
  • US8176564B2 patent drawing
  • US8176564B2 patent drawing

AI summary

A system and method for monitoring a computer, particularly a pay-per-use computer, uses an isolated computing environment or supervisor. The isolated computing environment boots prior to any boot device associated with an operating system, runs concurrently with the operating system and monitors and measures the computer in operation. Once the isolated computing environment determines the computer is not in compliance with the required policies, the isolated computing environment may either impose an impediment to use such as slowing clock speed or completely disable the operating system. The user may have to return the computer to a service provider to restore it from the offending condition and reset the computer to an operational state.