TEE-Based Cloud Usage Counting with Cryptographic Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing environments face challenges in ensuring secure and efficient utilization of services, as customers may violate license terms by copying software, leading to security vulnerabilities and resource mismanagement.

Innovation Solution

Implementing a secure count mechanism using trusted execution environments (TEEs) with public-private key cryptography to enforce licensing compliance, where computing devices report operation counts to service providers, enabling real-time monitoring and disabling non-compliant actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software is made open source or disclosed to customers under license agreements, then service delivery and customer trust are improved, but security vulnerabilities arise from potential software copying and license term violations

Engineering Contradiction:
Improveservice delivery flexibilityVSAvoidsoftware copying and license violation
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by establishing secure count mechanisms and cryptographic verification systems before software distribution. The service provider pre-configures trusted execution environments and establishes cryptographic key pairs, creating a framework that prevents license violations before they can occur through proactive security measures rather than reactive enforcement

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism through trusted execution environments (TEEs) and cryptographic verification systems that act as mediators between the service provider and customer devices. These intermediaries securely verify device identities and enforce license terms without requiring the service provider to directly control or monitor customer systems continuously

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If frequent counting and reporting of service utilization is implemented, then real-time licensing control and security monitoring are improved, but network overhead and processing burden increase

Engineering Contradiction:
Improvelicensing compliance verificationVSAvoidnetwork overhead and processing resources
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements periodic action by allowing flexible reporting intervals for secure counts. Instead of continuous monitoring, the system can be configured to report at specific intervals or after certain thresholds are reached, reducing network overhead and processing burden while maintaining adequate licensing compliance verification through periodic snapshots of service utilization

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies self-service by enabling customer devices to autonomously generate and report secure counts using local cryptographic operations and trusted execution environments. The devices independently maintain accurate service utilization records and self-verify compliance, reducing the need for continuous remote monitoring and lowering overall system processing requirements

Inventive Principle:
Principle #25Self-service

3Reliability

If cryptographic verification processes are hardware-enforced in trusted execution environments, then integrity of reported counts is improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improvecount reporting integrityVSAvoidhardware and software integration requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex cryptographic verification processes into dedicated trusted execution environments (TEEs) that are isolated from the main system operations. By separating the security-critical counting and verification functions into a distinct hardware-enforced environment, the patent protects integrity while containing complexity within a specialized subsystem rather than distributing it throughout the entire device architecture

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4350554B1Secure count in cloud computing networks
Publication Date: 2025.10.15 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4350554B1 patent drawingFigure 1
  • EP4350554B1 patent drawingFigure 2
  • EP4350554B1 patent drawingFigure 3

AI summary

Inducements are provided to customers to regularly connect back to a service provider and report usage that is expressed using a count of requests from a local computing device for cloud-based operations such as packet routing, container instantiation, virtual machine (VM) utilization, calls to a service or application, and the like. The count information is reported within a secure context, such as a trusted execution environment (TEE), using public-private key pair cryptography by which key derivation is dependent on some form of counting. For example, a customer computing device that is subject to a usage license encrypts an operation count and reports it to the service provider.