Isolated Computing Environments with Trusted Integrity Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for running multiple applications on a single host computing platform face challenges with compatibility and trustworthiness between applications, as one application's environment may be incompatible or untrusted by another.

Innovation Solution

A method is provided to create multiple isolated computing environments on a single host platform using a host operating system, obtaining integrity metrics for both the host and guest operating systems, and employing a trusted device to store and verify these metrics, ensuring each environment is independently trustworthy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple applications are run on a single host computing platform, then resource utilization is improved, but compatibility and trustworthiness between applications deteriorates

Engineering Contradiction:
Improveresource utilizationVSAvoidcompatibility and trustworthiness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the computing platform into multiple isolated computing environments (containers, virtual machines, or secure enclaves), each with its own integrity metrics and trust boundaries. This segmentation allows multiple applications to run simultaneously on the same host while maintaining compatibility and trustworthiness through isolation mechanisms. Each environment can be verified independently through integrity metrics without affecting other environments.

Inventive Principle:
Principle #1Segmentation

2Reliability

If computing environments are isolated from each other, then trustworthiness and integrity are improved, but system complexity increases

Engineering Contradiction:
Improvetrustworthiness and integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces integrity metrics as intermediary verification mechanisms that mediate between isolated computing environments and the host system. These metrics (such as hardware security module measurements, cryptographic hashes, or trust anchors) provide a standardized interface for verifying trustworthiness without requiring complex isolation implementations. The intermediary metrics simplify the verification process while maintaining strong isolation guarantees.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If integrity metrics are obtained for both host and guest operating systems, then verification of trustworthiness is improved, but measurement and detection complexity increases

Engineering Contradiction:
Improveverification of trustworthinessVSAvoidmeasurement complexity
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs integrity metric measurement during the boot-up or initialization phase of both host and guest operating systems, before the actual computing work begins. By obtaining integrity metrics (such as cryptographic hashes of system files, memory contents, or hardware configuration) at this preliminary stage, the system establishes trust boundaries early. This approach simplifies ongoing verification, as the metrics are already captured and stored without requiring continuous complex measurement during operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7865876B2Multiple trusted computing environments
Publication Date: 2011.01.04 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7865876B2 patent drawing
  • US7865876B2 patent drawing
  • US7865876B2 patent drawing

AI summary

A computing platform 20 provides multiple computing environments 24 each containing a guest operating system 25 provided by a virtual machine application 26. Optionally, each computing environment 24 is formed in a compartment 220 of a compartmented host operating system 22. A trusted device 213 verifies that the host operating system 22 and each guest operating system 25 operates in a secure and trusted manner by forming integrity metrics which can be interrogated by a user 10. Each computing environment is isolated and secure, and can be verified as trustworthy independent of any other computing environment.