Trusted Isolated Computing Environments for Supervisory Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As computer programs become more autonomous and complex, there is a growing concern about their potential to exhibit aberrant or harmful behavior, either due to malicious control or unanticipated actions, which can impede their acceptance and usage, as they may operate uncontrollably and be difficult to supervise effectively.

Innovation Solution

The method involves creating trusted and isolated computing environments that partition application code into encrypted groups, with a control logic managing the decryption keys, allowing for supervisory control through a 'kill switch' mechanism that prevents further execution and ensures only authorized entities can access the decryption keys, thereby preventing override by the computer program or external agents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If computer programs operate autonomously with complex capabilities, then their functionality and productivity are improved, but their controllability and reliability deteriorate due to difficulty in supervision and potential for aberrant behavior

Engineering Contradiction:
Improveprogram functionalityVSAvoidprogram controllability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the computer program into multiple isolated computing environments, each with controlled access to decryption keys. The program code is divided into partition groups that are encrypted separately, and decryption keys are distributed selectively to different environments. This segmentation allows the program to maintain complex autonomous functionality while enabling supervisory control through the ability to selectively deny or revoke access to specific code partitions, thereby resolving the contradiction between productivity and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary control mechanism that manages decryption keys as a mediator between the autonomous program and its execution environment. This intermediary layer can selectively provide or withhold decryption keys to control which parts of the program execute, enabling supervision and termination of aberrant behavior without directly interfering with the program's autonomous operation. This resolves the contradiction by maintaining program functionality while adding a controllable intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If decryption keys are made accessible to computer programs for execution, then program operation is enabled, but security and reliability worsen due to potential malicious access or override by external agents

Engineering Contradiction:
Improveprogram executionVSAvoidmalicious access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-distributing decryption keys to multiple isolated computing environments before program execution begins. Each environment receives specific key portions in advance, but cannot access the complete set of keys needed to execute the full program. This preliminary distribution enables legitimate program operation while preventing malicious access, because even if one environment is compromised, the attacker cannot obtain all decryption keys needed to execute harmful code.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a nested structure where decryption keys are distributed hierarchically across multiple isolated computing environments. Each environment contains a subset of keys nested within its isolation boundary, and no single environment has access to all keys. This nested arrangement enables program execution through coordinated access across environments while protecting against malicious access, as compromising one nested level does not expose the complete key set.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Productivity

If complete program code is provided to computing environments for execution, then program functionality is achieved, but control and supervision worsen due to inability to prevent aberrant behavior

Engineering Contradiction:
Improveprogram execution completenessVSAvoidsupervisory control complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the complete program code into multiple encrypted partition groups distributed across isolated computing environments. Each environment receives only the specific partition groups it needs for its designated function, not the complete program. This segmentation maintains overall program functionality while simplifying supervisory control, as supervisors can selectively control which partitions are distributed to which environments, enabling granular supervision without managing the entire program as a single complex unit.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11409846B2User controlled trusted and isolated computing environments
Publication Date: 2022.08.09 SAFELISHARE INC
  • US11409846B2 patent drawing
  • US11409846B2 patent drawing
  • US11409846B2 patent drawing

AI summary

Systems and techniques described herein are concerned with providing supervisory control of computer programs. In particular, a method for executing application code defining a computer program includes providing a “kill switch” to the operator, which allows the operator to disable the computer program. The kill switch is configured so that the computer program is incapable of over-riding it.