Trusted Isolated Computing Environments for Supervisory Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As computer programs become more autonomous and complex, there is a growing concern about their potential to exhibit aberrant or harmful behavior, either due to malicious control or unanticipated actions, which can impede their acceptance and usage, as they may operate uncontrollably and be difficult to supervise effectively.
Innovation Solution
The method involves creating trusted and isolated computing environments that partition application code into encrypted groups, with a control logic managing the decryption keys, allowing for supervisory control through a 'kill switch' mechanism that prevents further execution and ensures only authorized entities can access the decryption keys, thereby preventing override by the computer program or external agents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If computer programs operate autonomously with complex capabilities, then their functionality and productivity are improved, but their controllability and reliability deteriorate due to difficulty in supervision and potential for aberrant behavior
Solution Approach 1:
The patent segments the computer program into multiple isolated computing environments, each with controlled access to decryption keys. The program code is divided into partition groups that are encrypted separately, and decryption keys are distributed selectively to different environments. This segmentation allows the program to maintain complex autonomous functionality while enabling supervisory control through the ability to selectively deny or revoke access to specific code partitions, thereby resolving the contradiction between productivity and reliability.
Solution Approach 2:
The patent introduces an intermediary control mechanism that manages decryption keys as a mediator between the autonomous program and its execution environment. This intermediary layer can selectively provide or withhold decryption keys to control which parts of the program execute, enabling supervision and termination of aberrant behavior without directly interfering with the program's autonomous operation. This resolves the contradiction by maintaining program functionality while adding a controllable intermediary layer.
2Ease of operation
If decryption keys are made accessible to computer programs for execution, then program operation is enabled, but security and reliability worsen due to potential malicious access or override by external agents
Solution Approach 1:
The patent applies preliminary action by pre-distributing decryption keys to multiple isolated computing environments before program execution begins. Each environment receives specific key portions in advance, but cannot access the complete set of keys needed to execute the full program. This preliminary distribution enables legitimate program operation while preventing malicious access, because even if one environment is compromised, the attacker cannot obtain all decryption keys needed to execute harmful code.
Solution Approach 2:
The patent implements a nested structure where decryption keys are distributed hierarchically across multiple isolated computing environments. Each environment contains a subset of keys nested within its isolation boundary, and no single environment has access to all keys. This nested arrangement enables program execution through coordinated access across environments while protecting against malicious access, as compromising one nested level does not expose the complete key set.
3Productivity
If complete program code is provided to computing environments for execution, then program functionality is achieved, but control and supervision worsen due to inability to prevent aberrant behavior
Solution Approach 1:
The patent segments the complete program code into multiple encrypted partition groups distributed across isolated computing environments. Each environment receives only the specific partition groups it needs for its designated function, not the complete program. This segmentation maintains overall program functionality while simplifying supervisory control, as supervisors can selectively control which partitions are distributed to which environments, enabling granular supervision without managing the entire program as a single complex unit.
Data Source
AI summary
Systems and techniques described herein are concerned with providing supervisory control of computer programs. In particular, a method for executing application code defining a computer program includes providing a “kill switch” to the operator, which allows the operator to disable the computer program. The kill switch is configured so that the computer program is incapable of over-riding it.


