Isolated Computing Environments with Trusted Integrity Metrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for running multiple applications on a single host computing platform face challenges with compatibility and trustworthiness between applications, as one application's environment may be incompatible or untrusted by another.
Innovation Solution
A method is provided to create multiple isolated computing environments on a single host platform using a host operating system, obtaining integrity metrics for both the host and guest operating systems, and employing a trusted device to store and verify these metrics, ensuring each environment is independently trustworthy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple applications are run on a single host computing platform, then resource utilization is improved, but compatibility and trustworthiness between applications deteriorates
Solution Approach 1:
The patent divides the computing platform into multiple isolated computing environments (containers, virtual machines, or secure enclaves), each with its own integrity metrics and trust boundaries. This segmentation allows multiple applications to run simultaneously on the same host while maintaining compatibility and trustworthiness through isolation mechanisms. Each environment can be verified independently through integrity metrics without affecting other environments.
2Reliability
If computing environments are isolated from each other, then trustworthiness and integrity are improved, but system complexity increases
Solution Approach 1:
The patent introduces integrity metrics as intermediary verification mechanisms that mediate between isolated computing environments and the host system. These metrics (such as hardware security module measurements, cryptographic hashes, or trust anchors) provide a standardized interface for verifying trustworthiness without requiring complex isolation implementations. The intermediary metrics simplify the verification process while maintaining strong isolation guarantees.
3Reliability
If integrity metrics are obtained for both host and guest operating systems, then verification of trustworthiness is improved, but measurement and detection complexity increases
Solution Approach 1:
The patent performs integrity metric measurement during the boot-up or initialization phase of both host and guest operating systems, before the actual computing work begins. By obtaining integrity metrics (such as cryptographic hashes of system files, memory contents, or hardware configuration) at this preliminary stage, the system establishes trust boundaries early. This approach simplifies ongoing verification, as the metrics are already captured and stored without requiring continuous complex measurement during operation.
Data Source
AI summary
A computing platform 20 provides multiple computing environments 24 each containing a guest operating system 25 provided by a virtual machine application 26. Optionally, each computing environment 24 is formed in a compartment 220 of a compartmented host operating system 22. A trusted device 213 verifies that the host operating system 22 and each guest operating system 25 operates in a secure and trusted manner by forming integrity metrics which can be interrogated by a user 10. Each computing environment is isolated and secure, and can be verified as trustworthy independent of any other computing environment.


