Special pc mode entered upon detection of undesired state
Abstract
Systems and methods for monitoring computers, especially those that pay for each use, use a separate computing environment or supervisor. A separate computing environment boots before any boot device associated with an operating system, runs in parallel with the operating system, and monitors and evaluates operating computers. A separate computing environment can interfere with use, such as slowing the clock speed, or disable the operating system altogether if the computer determines that it does not comply with the required policy. it can. The user may have to return the computer to the service provider in order to recover the computer from the unpleasant state and reset it to a usable state.

Term
Term ended
Projected expiry passed 12 November 2025, 0.9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
20 claims: 5 independent, 15 dependent
- 1通常モードおよび代替モードにおけるオペレーションに適合されているコンピュータであって、 メモリと、 前記メモリに結合されているプロセッサと、 その他のブートデバイスに優先する第1のブートデバイスであって、前記その他のブートデバイスと並行して作動状態を維持する第1のブートデバイスとを含み、前記第1のブートデバイスは、 改ざんできない様式でデータを保存するためのメモリであって、前記データは、構成データ、暗号データ、ステータスデータ(status data)、または実行可能プログラムデータ(executable program data)のうちの少なくとも1つを含むメモリと、 単調に増加する時間の読み取り値を提供する回路と、 データ入力/出力回路と、 前記メモリ内に保存されているモニタリングプログラムまたは評価プログラムのうちの少なくとも1つを実行するために、前記クロックおよび前記データ入力/出力回路に結合されているプログラム実行環境とを含み、 前記第1のブートデバイスは、いつ前記コンピュータが基準に準拠して機能しているかを判断することを特徴とするコンピュータ。
- 2前記その他のブートデバイスは、オペレーティングシステムブートデバイスを含み、前記オペレーティングシステムブートデバイスは、前記通常モードに関連付けられていることを特徴とする請求項1に記載のコンピュータ。
- 3前記コンピュータが前記基準に準拠して機能していない場合に起動される前記代替モードに関連付けられている拘束プログラムコードをさらに含むことを特徴とする請求項1に記載のコンピュータ。
- 4前記代替モードのオペレーションは、前記オペレーティングシステムブートデバイスを停止することを含むことを特徴とする請求項3に記載のコンピュータ。
- 5前記代替モードのオペレーションは、前記コンピュータの機能を減らすこと、または前記基準に準拠して機能することに対応する警告を送信することのうちの少なくとも1つを含むことを特徴とする請求項3に記載のコンピュータ。
- 6前記第1のブートデバイスは、前記コンピュータが電源を入れられたときに初期化され、前記第1のブートデバイスは、前記コンピュータのオペレーション中に実行サイクルを保証されることを特徴とする請求項1に記載のコンピュータ。
- 7前記代替モードは、前記基準に準拠した状態へ戻すためのユーザインターフェースをさらに含むことを特徴とする請求項1に記載のコンピュータ。
- 8前記第1のブートデバイスは、前記入力/出力回路を介してポリシーを受け取り、前記ポリシーは、準拠度合いを判定するための前記基準に相当することを特徴とする請求項1に記載のコンピュータ。
- 9前記第1のブートデバイスは、前記ポリシーを認証することを特徴とする請求項8に記載のコンピュータ。
- 10前記基準への準拠度合いに対応するスコアを計算する際に評価データが使用され、前記スコアがしきい値に達した場合に前記代替モードが発動されることを特徴とする請求項1に記載のコンピュータ。
- 11前記評価データは、オペレーティングシステムのハートビート、指定されたファイルの確認、システムクロックの確認、現在のオペレーティングモード、前記メモリへの書き込み頻度、または最後のプロビジョニングサイクルからの経過時間のうちの少なくとも1つを含むことを特徴とする請求項10に記載のコンピュータ。
- 12前記第1のブートデバイスは、暗号化サービスをさらに含むことを特徴とする請求項1に記載のコンピュータ。
- 13コンピュータ上でポリシーへの準拠度合いをモニタするためのスーパーバイザであって、 安全なメモリと、 単調に増加する時間の測定値を提供するクロックと、 入力/出力回路と、 前記コンピュータのオペレーティングシステムをホストするために使用されるプロセッサとは別個の処理機能であって、前記安全なメモリ、前記クロック、および前記入力/出力回路に結合され、前記安全なメモリおよび前記クロックからの情報を考慮して、前記入力/出力回路を介して受け取られた前記ポリシーへの準拠度合いに対応するデータを評価するための処理機能とを含むことを特徴とするスーパーバイザ。
- 14前記コンピュータが前記ポリシーに準拠していない場合に前記コンピュータのオペレーションを妨げるための、前記処理機能に応答する強制回路をさらに含むことを特徴とする請求項13に記載のスーパーバイザ。
- 15前記ポリシーは、前記コンピュータの有効なハードウェア構成に相当し、前記強制回路は、ハードウェアの機能を前記有効なハードウェア構成に制限することを特徴とする請求項14に記載のスーパーバイザ。
- 16コンピュータ上でポリシーに準拠していない状態を判定する方法であって、 前記ポリシーに準拠していない状態を、前記コンピュータ上で評価できる少なくとも1つの基準に関連付けるステップと、 オペレーティングシステムを起動する前にスーパーバイザをインスタンス化するステップと、 前記スーパーバイザにおいて、前記コンピュータ上の前記少なくとも1つの基準に対応するデータをモニタするステップと、 前記データを評価することによって、いつ前記コンピュータが準拠していない状態にあるかを判定するステップとを含むことを特徴とする方法。
- 17前記少なくとも1つの基準に対応する前記データに基づくスコアがしきい値に達した場合に、前記コンピュータに拘束を課すステップをさらに含み、それによって前記拘束を課す前記ステップは、前記オペレーティングシステムの少なくとも一部を停止するステップをさらに含むことを特徴とする請求項16に記載の方法。
- 18前記少なくとも1つの基準は、コンピューティングセッションの持続時間、プロビジョニングパケットの購入の間における時間、またはプロビジョニングパケットの購入の合計と比較した前記コンピュータのオペレーションの合計時間のうちの少なくとも1つを含むことを特徴とする請求項16に記載の方法。
- 19前記少なくとも1つの基準に対応する前記データは、オペレーティングシステムのハートビート、指定されたファイルの確認、システムクロックの確認、現在のオペレーティングモード、前記メモリへの書き込み頻度、または最後のプロビジョニングサイクルからの経過時間のうちの少なくとも1つを含むことを特徴とする請求項16に記載の方法。
- 20前記オペレーティングシステムから自立したプログラム実行環境を前記スーパーバイザに提供するステップをさらに含むことを特徴とする請求項16に記載の方法。
Independent claims20
52 paragraphs, as filed
The present invention generally relates to computer systems, and more specifically to systems and methods of monitoring computers of the type that pay for each use.
The operating system is a key fundamental element in the development of computing systems. Over the decades since personal computing became widespread, operating systems have become significantly more complex. It is extremely difficult to develop a computer operating system that is backward compatible with a significant number of computer applications, yet secure enough to guarantee a high level of tamper resistance. However, new business models for computing that pay for each use (pay-per-use) or pay only for what you use (pay-as-you-go) have been tampered with. It is necessary that the resistance to resistance is guaranteed to a high level.
This application is a partial continuation of U.S. Patent Application No. 11 / 022,493 filed on December 22, 2004, which U.S. Patent Application No. 11 / 02,493 is Dec. 8, 2004. A partial continuation of U.S. Patent Application No. 11 / 006,837 filed on the same day, which U.S. Patent Application No. 11 / 006,837 was filed on November 15, 2004. 10 / 989,122 This is a partial continuation application of the specification.
<p> An object of the present invention is to provide a system and a method for monitoring a computer of a type that pays a fee each time it is used or a type that pays only a fee for use.</p>
<p> Computers that are adapted for use in a pay-as-you-go business model use a supervisor or separate computing environment to provide computer performance, as well as a set of usage policies. You can monitor and evaluate your compliance with. A separate computing environment can have secure memory, secure processing capabilities, and encryption capabilities. A separate computing environment boots before any other boot device to establish a secure computing base before introducing insecure computing features, such as the operating system, into the computer. Can be done.</p><p> According to one aspect of the disclosure, a segregated computing environment can request data, receive data, or search for information with and from a computer. The isolated computing environment can use the data obtained to create a score that represents the degree of policy compliance established by, for example, a service provider. This score can be increased as it is confirmed to be in compliance with the policy, and it can be decreased as it is found to be non-compliant. If the score reaches the threshold level or falls below the threshold level, sanctioned mode (sanctioned) mode) can be activated. Constrained mode, or alternative operating mode, can include a brief warning to the user, limit the capabilities of the computer to make it useless, or completely occlude the operating system or some other key component. You can also stop it and thereby disable the computer. Once disabled, the computer may request service from a service provider or other authorized party to identify and correct non-compliance, and the user will pay a service fee or fine. Can include. The segregated computing environment can send notification data to users and service technicians to help determine the current state of the computer and the corrective action to be taken to restore the computer. Similarly, in non-constrained modes, isolated computing environments can export data for monitoring and diagnostics.</p>
The text below provides a detailed description of many different embodiments, but the legal scope of this description is said to be defined by the wording of the claims attached herein. Please understand the point. This detailed description should be construed as merely exemplary and does not describe all possible embodiments. It seems unrealistic, if not impossible, to explain all possible embodiments. Many alternative embodiments can be implemented using current technology that will remain within the claims or technology developed after the filing date of this patent.
In addition, terms are clearly defined in the present specification by using the sentence "when used in the present specification, the term" "is defined as meaning ..." or a similar sentence. Unless otherwise stated, there is no intention to limit the meaning of the term beyond its candid meaning, that is, its usual meaning, either explicitly or implicitly, and such term is not contained herein in any way. It should be understood that it should not be construed as being limited to the scope of any statement made in that section (excluding terms in the scope of patent claims). As long as any of the terms in the claims attached to this specification is referred to herein in a manner consistent with a single meaning, it is exclusively the reader. It is done for the purpose of clarifying so as not to confuse the above, and it is not intended to limit the terms in the scope of such claims to their single meaning by suggestion or the like. Finally, unless the elements of the claims are defined by describing the word "means" and function without mentioning any structure, the scope of the elements of any claims , 35 It is not intended to be construed in accordance with the application of USC Section 112, paragraph 6.
Many of the features of the invention, and many of the principles of the invention, are best implemented with or within ICs (integrated circuits) such as software programs, software instructions, and application-specific ICs. Those skilled in the art will, in some cases, be disclosed herein, despite the great effort and many design options evoked by, for example, available time, current technology, and economic considerations. It is expected that such software instructions and programs as well as ICs could be easily created with minimal effort, guided by these concepts and principles. Therefore, for the sake of brevity and to minimize any risk that obscures the principles and concepts according to the invention, the principles and concepts of the preferred embodiments will be discussed further when discussing such software and ICs. We will limit ourselves to the essential elements of.
FIG. 1 shows a computing device in the form of computer 110. The components of the computer 110 can include, but are not limited to, a processor 120, a system memory 130, and a system bus 121 that connects various system components, including system memory, to the processor 120. The system bus 121 can be any of a plurality of types of bus structures, including a memory bus or memory controller, a peripheral bus, and a local bus that uses any of the various bus architectures. For example, such architectures are known as ISA (Industry Standard Architecture) bus, MCA (Micro Channel Architecture) bus, EISA (Enhanced ISA) bus, VESA (Video Electronics Standards Association) local bus, and PCI. Includes, but is not limited to, (Peripheral component Interconnect) buses.
Computer 110 typically includes various computer readable media. The computer-readable medium can be any medium available that can be accessed by the computer 110, including both volatile and non-volatile media, as well as removable and non-removable media. For example, computer readable media can include, but are not limited to, computer storage media and communication media. Computer storage media are volatile and non-volatile media implemented in any method or technique for storing information such as computer-readable instructions, data structures, program modules, and other data, as well as removable media and. Includes non-removable media. Computer storage media include RAM, ROM, EEPROM, flash memory, or other memory technology, CD-ROM, DVD (digital versatile). disk), or other optical disk storage device, magnetic cassette, magnetic tape, magnetic disk storage device, or other magnetic storage device, or any other device that can be used to store desired information and is accessible by computer 110. Including, but not limited to. The communication medium usually embodies computer-readable instructions, data structures, program modules, or other data in the modulated data signal, such as a carrier wave or other transmission mechanism, and includes any information transmission medium. The term "modulated data signal" means a signal having one or more of its characteristics set or modified in such a way that information is encoded within the signal. For example, the communication medium includes, but is not limited to, a wired medium such as a wired network or a direct wired connection, and a wireless medium such as a sound wave medium, a radio frequency medium, an infrared medium, or another wireless medium. Further, any combination of the above is included in the range of computer-readable media.
System memory 130 includes computer storage media in the form of volatile and / or non-volatile memory such as ROM (read only memory) 131 and RAM (random access memory) 132. The BIOS (basic input / output system) 133 includes a basic routine that assists in transmitting information between elements in the computer 110 at the time of booting, and is usually stored in the ROM 131. RAM 132 typically includes data modules and / or program modules that are readily accessible to processing device 120 and / or are currently being operated by processing device 120. FIG. 1 shows, but is not limited to, an operating system 134, an application program 135, other program modules 136, and program data 137 as examples.
Computer 110 may also include other removable / non-removable, volatile / non-volatile computer storage media. FIG. 1 shows reading and writing between a hard disk drive 141 that reads and writes to and from a non-removable non-volatile magnetic medium and a removable non-volatile magnetic disk 152 for illustration purposes only. The optical disk drive 155 that reads and writes between the magnetic disk drive 151 and the removable non-volatile optical disk 156 such as a CD-ROM or other optical storage medium is shown. Other removable / non-removable, volatile / non-volatile computer storage media that can be used in typical operating environments include magnetic tape cassettes, flash memory cards, digital versatile discs, digital videotapes, solid state RAM, and solids. There are state ROMs, etc., but they are not limited to these. The hard disk drive 141 is typically connected to system bus 121 via a non-removable memory interface such as interface 140, and the magnetic disk drive 151 and optical disk drive 155 are typically systemized by a removable memory interface such as interface 150. It is connected to bus 121.
The drives described above and their associated computer storage media, shown in FIG. 1, provide storage for computer-readable instructions, data structures, program modules, and other data for the computer 110. For example, in FIG. 1, hard disk drive 141 is shown as storing operating system 144, application program 145, other program modules 146, and program data 147. Note that these components may be the same as or different from the operating system 134, the application program 135, the other program modules 136, and the program data 137. Here, the operating system 144, the application program 145, the other program modules 146, and the program data 147 are assigned different numbers to indicate that they are at least different copies. The user can enter commands and information into the computer 110 via an input device such as a keyboard 162 or a pointing device 161 usually called a mouse, trackball, or touchpad. Other input devices (not shown) can include microphones, joysticks, gamepads, satellite broadcast receiving antennas, scanners, and the like. These and other input devices are often connected to the processor 120 via a user input interface 160 that is coupled to the system bus, but are parallel ports, game ports, and USB (universal serial). It can also be connected by other interface structures such as bus) and bus structures. The monitor 191 and other types of display devices are also connected to the system bus 121 via an interface such as the video interface 190. In addition to the monitor, the computer can also include other peripheral output devices such as speakers 197 and printer 196, which can be connected via the peripheral output interface 195.
Computer 110 can function within a networked environment using a logical connection to one or more remote computers, such as remote computer 180. The remote computer 180 can be a personal computer, server, router, network PC, peer device, or other common network node, and although only memory storage 181 is shown in Figure 1, it is usually a computer. Includes many or all of the above elements related to 110. The logical connections shown in Figure 1 include LAN (local area network) 171 and WAN (wide area network) 173, but can also include other networks. Such networking environments are common in offices, enterprise-scale computer networks, intranets, and the Internet.
When used in a LAN networking environment, the computer 110 is connected to the LAN 171 via a network interface or adapter 170. When used in a WAN networking environment, the computer 110 typically includes a modem 172 and other means for establishing communication over the WAN 173, such as the Internet. Modem 172 can be internal or external and can be connected to system bus 121 via user input interface 160 or other suitable mechanism. In a networked environment, the program modules shown associated with computer 110, or parts thereof, can be stored in remote memory storage. FIG. 1 shows the remote application program 185 as being on the memory device 181 as an example, but is not limited to this form.
Communication connections 170, 172 allow this device to communicate with other devices. Communication connections 170 and 172 are examples of communication media. The communication medium usually embodies computer-readable instructions, data structures, program modules, or other data in the modulated data signal, such as a carrier wave or other transmission mechanism, and includes any information transmission medium. A "modulated data signal" can be a signal having one or more of its characteristics set or modified in such a way that the information is encoded within the signal. For example, communication media include, but are not limited to, wired media such as wired networks and direct wired connections, and wireless media such as sonic media, RF media, infrared media, and other wireless media. Computer-readable media include both storage media and communication media.
The Separation Computing Environment 125 can be used to implement supervisors, Trustworthy Computing Bases, or other secure environments, and is established for monitoring, evaluating, and / or using Computer 110. Can be used to bind if the policy is not complied with. Those policies can reflect the terms of the agreement between the user of computer 110 and the service provider who has an interest in computer 110. The isolated computing environment 125 will be described in more detail below with reference to FIG.
The isolated computing environment 125 can be instantiated in multiple ways. When implemented by one or more separate components, the isolated computing environment 125 can be located on the motherboard of the computer (not shown). Ideally, removing the isolated computing environment 125, or removing its lid, would cause permanent damage to the motherboard and / or peripheral components, making the computer 110 inoperable.
Another instantiation of the isolated computing environment 125 can be as shown in FIG. 1, where the isolated computing environment 125 is embedded within the processing device 120. Such placement within the processing equipment can provide the advantages of better access to the processing equipment's registers, the ability to monitor data sequences, and increased resistance to physical attacks.
The isolated computing environment 125 can be implemented in software if there is an authenticated boot process. This is because the boot process can guarantee a run cycle and an authenticated operating environment. In such cases, the isolated computing environment 125 can eliminate the need for a separate processor and can be run from the main processor 120. A hardware implementation of the isolated computing environment 125 can be recommended if authenticated boot is not available.
Use the LPM (license provisioning module) (see Figures 3 and 4) to evaluate and authorize the use of your computer in configurations where you pay for each use or only for what you use. Can be incorporated. When implemented in software, this LPM can be stored in non-volatile memory 146 and executed from memory 136. LPM, when implemented in software, can be vulnerable to attack. One purpose of the supervisor (see Figures 3 and 4) and / or the isolated computing environment 125 is to ensure the integrity of the LPM and act as a watchdog for the LPM to help correct its functionality. Can be fulfilled.
In an alternative embodiment, the isolated computing environment 125 can play the role of LPM with respect to the effective hardware configuration of the computer. That is, a separately booted isolated computing environment 125 can have configuration data that allows the computer to operate according to less authorized functionality than potentially available. For example, a computer may be able to work with 512MB (megabyte) of RAM (random access memory), but a valid configuration specifies 256 megabytes of RAM. The isolated computing environment 125 can limit the functions of the computer to 256MB of system memory. Similar limits apply to processor clock rate, available cache memory, number of processor 120 cores available, graphics card capabilities, hard drive capacity, networking option, or internal bus driver. (internal bus It can be forced with respect to driver). From an implementation point of view, there is little or no difference between imposing limits based on monitored activity or enforcing limits based on given settings and licenses.
A simplified typical isolated computing environment is described with reference to Figure 2. This separate computing environment can be the separate computing environment 125 described above, or can be similar to the separate computing environment 125. The isolated computing environment 125 can include both volatile and non-volatile memory 202, data I / O circuits 204, and a timer or clock 206. For example, timer 206 can be used to perform the clock function by counting the actual time interval.
The separate computing environment 125 may further include a digital signature verification circuit 208. The random number generator 210 can be part of the digital signature confirmation circuit 208 if one-way confirmation of the external entity, eg, confirmation of a server (not shown), is required. Digital signature techniques are well known, and hashing, signature matching, symmetric and asymmetric algorithms, and their respective keys are not discussed in detail herein.
The blocks of the separate computing environment 125 can be connected by the bus 212. Bus 212 may be separate from system / processor bus 214 used for external access. A separate bus configuration can increase security by restricting access to the data passed by bus 212. Bus 212 takes security precautions, such as balanced data lines, to make power attacks on the encryption key 218 stored in memory 202 more difficult. Can be incorporated.
Processor 216 can be used to execute the program. As mentioned above, if attested boot is not available, including processor 216 provides guaranteed computing capabilities and isolation from operating system 134 in a separate computing environment 125. Can be provided.
The memory 202 can store data 220 in addition to storing the encryption key 216, which can be used for operational information such as the current score related to compliance. , Can include system information such as specific contract information. The evaluation data 222 can be associated with the monitoring program 224. This monitor program 224, which will be described in more detail later, is simply used to capture evaluations, receive information about the current operation of computer 110, and measure compliance scores. If the compliance score falls below a predetermined threshold, restraint program 226 can be invoked. Restraint program 226 can trigger both software and hardware mechanisms to weaken or disable computer 110.
FIG. 3 illustrates an exemplary embodiment of a computer 110, with computing-related hardware and software components that pay for each use or only for what they use. Shows the relationship with. The operating system 134 of FIG. 1 can support the LPM 302 and the operating system service 304 associated with the type of operation that pays only for what it uses. Operating system service 304 can include secure time, secure store, and encryption / decryption. In this embodiment, the elements of the isolated computing environment 125 are configured as supervisor 306. Supervisor 306 has a secure memory 308, a secure clock 310, and a cryptographic key. store) 312 can be included. Make unique hardware identifier 314 available to Supervisor 306 for use in processing provisioning packets and in identifying computer 110 to external entities. be able to.
The secure memory 308 can be a separate memory area that can only be accessed by the isolated computing environment 125 and / or after cryptographic authentication. The reliable clock 310 can provide a tamper-resistant time base, which provides a monotonically increasing amount of time over the life of the computer. Reliable clock 310 is for interval timing or calendar Can be used as a base). The encryption keystore 312 can provide a storage area for the encryption key. The keystore 312 can be essentially write-only memory and can also include cryptographic algorithms so that the calculations are performed within the keystore and only the results are provided. Once the key is written and verified, it cannot be read from the keystore 312.
Supervisor 306, and its underlying isolated computing environment 125, can function independently of operating system 134. For security reasons, Supervisor 306 can boot before any other boot device when the computer 110 is turned on or restarted. Booting independently of the operating system helps ensure that Supervisor 306 and the isolated computing environment 125 are not spoofed by another boot device or run out of CPU time.
Communication between Supervisor 306 and Operating System Service 304 can be achieved over logical communication link 316 and can be supported over physical communication bus 214. LPM302 can communicate with Supervisor 306, as indicated by logical link 318. Link 318 supports the request from Supervisor 306 to LPM 302 for audit data. In addition, the LPM 302 can send a periodic heartbeat to Supervisor 306 as a continuous audit of system compliance. Supervisor 306 can completely disable operating system 134 if a non-compliant situation is found, so the constraint mode user interface for use while computer 110 is in constraint mode. You can have enough power and hardware access to present the 320.
Audit / heartbeat data can be sent over logical link 318 and can contain data needed to validate software components, especially LPM302. Supervisor 316 can be programmed to wait for heartbeat data at regular intervals. Heartbeat data can include validation information such as digital signatures of binary executable code, including sequence numbers and other methods to prevent replay attacks. For example, a regular heartbeat from LPM302 is evidence that the LPM is still in operation, and if its signature is confirmed, that the LPM is a legitimate version of the unmodified code. Can function as. If the supervisor fails to verify the authenticity of the heartbeat, or if the heartbeat does not arrive within a given time period, the heartbeat can be rejected and the compliance score can be reduced. Policy rule (policy) Some rules) do not allow you to penalize heartbeat messages that arrive more often than necessary, while a single heartbeat failure cannot be sufficient to trigger a restraint.
Supervisor 306 is different from known hypervisors or monitors. A monitor exists between the operating system and the associated hardware and can coordinate resource sharing and CPU time slicing. Because monitors are so closely tied to operating systems, it is difficult to abstract them for different operating systems, or even for operating system versions. In contrast, Supervisor 306, in one embodiment, does not attempt to manage or coordinate the use of system resources during normal operation. Supervisor 306, in its simplest form, receives a policy, authenticates the policy, monitors whether it complies with it, and binds it if it does not comply with it. This policy can be a data structure passed by the operating system that corresponds to a given limit, such as hours of use or months of use in the calendar.
Supervisor 306 is independent of the operating system and other boot devices, so it can be used to enforce policies for virtually any operating system or operating environment. This independence from the underlying platform is facilitated by, in one embodiment, the supervisor being guaranteed access to compute cycles, secure memory, and time standards.
Figure 4 shows an operating system associated with a computer of the type that pays for each use, such as computer 110. shows an alternative embodiment of the arm and hardware components. As in the case of FIG. 3, the operating system 134 includes the LPM 302 and the underlying operating system service 304. The smaller supervisor 309 can also be based on a hardware-separated computing environment 125 of the system via bus 330, rather than providing and maintaining secure resources for the system as in the embodiment of Figure 3. You can only monitor the secure resource 307. The secure resource 307 can have a secure memory 308, a trusted clock 310, an encryption keystore 312, and a hardware identifier 314. Various operating system calling Individual service requests to entities) can be made via the logical connections indicated by data paths 322, 324, 326. An audit / heartbeat logical connection 318 can be maintained between Supervisor 309 and LPM 302. In this configuration, the hardware identifier 314 is made available to the LPM 302 over the logical connection 328, especially for identifying provisioning packets and for use in generating heartbeat signals. Can be done.
In operation, both configurations shown in Figures 3 and 4 can function similarly with respect to creating compliance scores. The compliance score can be the accumulation of weighted values determined by evaluation and observation. Rating 222, performed by monitoring process 224 (Figure 2), can be used to evaluate and classify various events in their simplest form: good or bad. Each good event results in an increase in compliance score, while each bad event results in a decrease in compliance score. Criteria can be established so that one event is not sufficient to ensure that the compliance score reaches the minimum threshold and is subject to constraints.
Supervisors 306 and 309 of the embodiments of FIGS. 3 and 4 can both evaluate the frequency and quality of the heartbeat signal. If a good heartbeat is received on time, the compliance score can be increased. Supervisor 306 in FIG. 3 can have full access to key data used during measurements and evaluations. For example, the compliance score can be increased if Monitor 224 determines that the operating system is measuring usage. Monitor 224 can also determine the aggregation of time spent against the purchase of additional time. The compliance score can also be increased if the estimated purchase matches the estimated use. Other evaluations can also be captured, such as checking for a specified file, such as the LPM302 or boot file (not shown), or checking the system clock.
However, if the heartbeat fails or does not arrive on time, the compliance score can be reduced. The compliance score can also be reduced if the operating system remains unmeasured for a given period of time. The compliance score can also be reduced if the operating system enters and exits the measurement state too frequently, suggesting that the measurement circuit may have been tampered with.
Supervisor 309 of the embodiment of FIG. 4 can have less access to direct measurement data and operating system state. Such a configuration can further depend on other factors such as heartbeat monitoring and the frequency of safe storage changes as an indication that the measurement data has been updated.
The compliance score in any embodiment can be increased or decreased as various "good" and "bad" ratings are determined, starting from the first value. When the compliance score drops sufficiently, the first threshold can be reached to trigger the action. In one embodiment, the first threshold can be the only threshold and constraints can be imposed immediately. In another embodiment, the first threshold can trigger a warning to the user that a tampering concern has arisen and that appropriate action may be required. In yet another embodiment, the first threshold can trigger limited constraints, such as limiting the resolution of the display or slowing down the processor. If the compliance score continues to decline, it may reach a threshold at which dramatic constraints can be invoked, such as disabling the operating system. At this point, it may be necessary to bring the computer 110 to a service center in order to recover it. If the operating system is disabled, the restraint mode user interface 320 can be invoked for recovery services.
To illustrate using an exemplary embodiment, computer 110 can be given an initial compliance score of 80. After a successful series of heartbeats, time-of-use purchases, and given measurements, the compliance score can be increased up to 100 (in other embodiments, the compliance score cap cannot be used). However, at this point the user attempts to disable the measurement mechanism by overwriting the LPM302. Destination memory The evaluation of LPM302 fails because the hash of range) does not match the expected hash. The heartbeat signal stops, and the predetermined measurement also stops. This is because alternative LPMs are not programmed to support those features. If each evaluation fails in succession, the compliance score can drop to, for example, 70. When the compliance score reaches 70, the user will be warned that the system appears to have been tampered with and that it will shut down without taking corrective action. The user ignores this warning and the compliance score drops to 55. Supervisor 306 can then take action to shut down the computer 110 by invoking the restraint program 226 and, for example, stopping the processing device 120. The restraint mode user interface 320 can then pop up a message informing the user that the computer has been disabled and that it must be brought to the service center to recover.
At the service center, the technician can use the restraint mode user interface 320 to determine that the alternate LPM was not compliant and restore the compliant LPM 302. The service technician can trigger Supervisor 306 to restart the Monitor 224 program if desired and manually reset the compliance score if desired. In this example, it is clear that someone has tampered with the computer, so fines and service fees can be imposed on the user to prevent them from tampering with the system in the future.
FIG. 5 describes a method for determining a non-compliance state on a computer. Policies that establish rules of operation and standards of use for Computer 110 can be established by service providers and other stakeholders who have a financial interest in Computer 110. Once the policy is established, in 402 it is possible to create an evaluable criterion for determining compliance with the policy. This criterion may include assessment of known memory range hashing, etc., and / or monitoring of status and activity on the computer 110, such as re-providing usage credits on the computer 110. it can. This evaluation and monitoring criterion can be programmed within a supervisor, such as Supervisor 306, and the supervisor can be incorporated onto the isolated computing environment 125.
You can start Supervisor 306 on a 404 before booting any other system element, including operating system 134, that is, before booting. I've mentioned the reasons for booting first, but in a nutshell, doing so helps to ensure a clean operating environment known to Supervisor 306. For example, the first compliance score can be established for operations that follow established policies when first launched during manufacturing or installation. In one embodiment, Supervisor 306 has a program execution environment that is independent of Operating System 134 in order to further isolate Supervisor 306 from attacks made against Operating System 134 and related components.
Once Supervisor 306 is booted, other boot devices, such as operating system 134 and any other early boot device, can be booted on the 406. When computer 110 is operating, supervisor 306 can initiate monitoring and evaluation at 408 according to the criteria created at block 402. Each finding in monitoring and evaluation can be used to adjust the compliance score.
The criteria used in block 408 are clock confirmation, duration of a single computing session, amount of time measured while provisioned packets are being served, or computer in total number of provisioned packets provided. Can include comparisons during the total time of operations of.
Measurement and evaluation data that can be used to evaluate various criteria are operating system heartbeats, confirmation of specified files, confirmation of system clock, current operating mode, frequency of writes to memory, or last provisioning. It can be the elapsed time from the provisioning cycle. For example, clock confirmation can include a comparison of a reliable clock time of 310 with a soft clock under the control of the operating system, followed by the last time the provisioning packet was served. The analysis can continue.
Each time the results of each evaluation or monitoring are determined, the compliance score at 410 can be compared to a given threshold. If the score exceeds the threshold, the "no" branch from block 410 can return to block 408, where further evaluation can be incorporated. If the compliance score falls below the threshold, further testing is performed in 412 to proceed to the "yes" branch from block 410 and determine if the score indicates a warning or constraint. Is appropriate. If the warning is appropriate, you can proceed from block 412 to the branch labeled Warning and the warning will be displayed at 416. And at block 408, execution can continue.
If it is determined in block 412 that the constraint is appropriate, the constraint can be branched from block 412 to block 414 and the constraint can be imposed in block 414. A set of constraints can be made available, including reducing the resolution and color depth of the display, slowing down the processor, and, depending on the policy, the operating system can be shut down. Or you can shut down other major systems or devices that effectively disable the computer 110.
Although the text described above provides a detailed description of many different embodiments of the invention, the scope of the invention is defined by the wording of the claims attached herein. I want you to understand. This detailed description should be construed as merely exemplary and does not describe all possible embodiments of the invention. This is because it seems impractical, if not impossible, to explain all possible embodiments. Many alternative embodiments can be implemented using current techniques that will continue to fall within the claims that define the invention or techniques developed after the filing date of the patent application.
Therefore, many modifications and variations can be made in the techniques and structures described and illustrated herein without departing from the spirit and scope of the invention. Therefore, it should be understood that the methods and devices described herein are exemplary only and do not limit the scope of the invention.
<figref num="1">It is a simplified typical block diagram showing a computer.</figref><figref num="2">It is a block diagram which shows the simplified separated computing environment.</figref><figref num="3">FIG. 6 is a simplified exemplary block diagram showing an embodiment of a supervisor.</figref><figref num="4">FIG. 6 is a simplified exemplary block diagram showing another embodiment of the supervisor.</figref><figref num="5">It is a flowchart which shows the method of establishing and evaluating the compliance with a policy on a computer.</figref>
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2000293369A | Cites | Japan | Search report |
| US2003046026A1 | Cites | United States of America | Examiner |
| US2004003288A1 | Cites | United States of America | Examiner |
| JPH0736559A | Cites | Japan | Examiner |
117 members in 12 offices
Priority claims24
| Document | Office | Kind | Date |
|---|---|---|---|
| 10989122 | United States of America | – | |
| 98912204 | United States of America | A | |
| 98912204 | United States of America | A | |
| 11006837 | United States of America | – | |
| 683704 | United States of America | A | |
| 683704 | United States of America | A | |
| 11022493 | United States of America | – | |
| 2249304 | United States of America | A | |
| 2249304 | United States of America | A | |
| 11152214 | United States of America | – | |
| 15221405 | United States of America | A | |
| 15221405 | United States of America | A | |
| 2005040940 | United States of America | W | |
| 2005040940 | United States of America | W | |
| 2004006837 | – | – | – |
| 2004022493 | – | – | – |
| 2004989122 | – | – | – |
| 2005152214 | – | – | – |
| 2005040940 | – | – | – |
| US20040006837 | – | – | – |
| US20040022493 | – | – | – |
| US20040989122 | – | – | – |
| US20050152214 | – | – | – |
| WO2005US40940 | – | – | – |
Members117
| Document | Office | Kind | |
|---|---|---|---|
| US1533449A | United States of America | A | |
| US1958296A | United States of America | A | |
| US4084557A | United States of America | A | |
| CA2526588A1 | Canada | A1 | |
| US2006105739A1 | United States of America | A1 | |
| US2006107306A1 | United States of America | A1 | |
| US2006107328A1 | United States of America | A1 | |
| US2006107329A1 | United States of America | A1 | |
| US2006107335A1 | United States of America | A1 | |
| KR20060054164A | Republic of Korea | A | |
| EP1659530A1 | European Patent Office (EPO) | A1 | |
| US2006112384A1 | United States of America | A1 | |
| WO2006055420A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055421A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055424A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055425A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055427A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055428A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2005232307A1 | Australia | A1 | |
| CN1783138A | China | A | |
| BRPI0504855A | Brazil | A | |
| JP2006190254A | Japan | A | |
| US2006165005A1 | United States of America | A1 | |
| US2006165227A1 | United States of America | A1 | |
| US2006168664A1 | United States of America | A1 | |
| TW200630885A | Taiwan Province of China | A | |
| TW200631377A | Taiwan Province of China | A | |
| TW200632711A | Taiwan Province of China | A | |
| TW200634584A | Taiwan Province of China | A | |
| US2006227364A1 | United States of America | A1 | |
| WO2006055421A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2006055424A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2006055425A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2007033102A1 | United States of America | A1 | |
| WO2007032974A1 | World Intellectual Property Organization (WIPO) | A1 | |
| RU2005135424A | Russian Federation | A | |
| WO2006055427A3 | World Intellectual Property Organization (WIPO) | A3 | |
| MX2007005655A | Mexico | A | |
| MX2007005657A | Mexico | A | |
| MX2007005660A | Mexico | A | |
| MX2007005662A | Mexico | A | |
| MX2007005656A | Mexico | A | |
| MX2007005659A | Mexico | A | |
| EP1815322A2 | European Patent Office (EPO) | A2 | |
| EP1815327A2 | European Patent Office (EPO) | A2 | |
| EP1815629A2 | European Patent Office (EPO) | A2 | |
| EP1815639A2 | European Patent Office (EPO) | A2 | |
| EP1815640A2 | European Patent Office (EPO) | A2 | |
| EP1815641A2 | European Patent Office (EPO) | A2 | |
| KR20070084257A | Republic of Korea | A | |
| KR20070084258A | Republic of Korea | A | |
| KR20070084259A | Republic of Korea | A | |
| KR20070084260A | Republic of Korea | A | |
| KR20070088633A | Republic of Korea | A | |
| KR20070088634A | Republic of Korea | A | |
| CN101057214A | China | A | |
| CN101057218A | China | A | |
| CN101057435A | China | A | |
| US2007244820A1 | United States of America | A1 | |
| CN101069215A | China | A | |
| EP1815640A4 | European Patent Office (EPO) | A4 | |
| KR20080043831A | Republic of Korea | A | |
| JP2008521089AThis record | Japan | A | |
| JP2008521090A | Japan | A | |
| JP2008521091A | Japan | A | |
| JP2008521092A | Japan | A | |
| JP2008521093A | Japan | A | |
| JP2008521094A | Japan | A | |
| WO2008077051A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006055420A3 | World Intellectual Property Organization (WIPO) | A3 | |
| BRPI0515720A | Brazil | A | |
| EP1952331A1 | European Patent Office (EPO) | A1 | |
| US7421413B2 | United States of America | B2 | |
| CN101263523A | China | A | |
| BRPI0518003A | Brazil | A | |
| CN101292248A | China | A | |
| RU2007117897A | Russian Federation | A | |
| RU2007117899A | Russian Federation | A | |
| RU2007117900A | Russian Federation | A | |
| RU2007117916A | Russian Federation | A | |
| BRPI0518911A2 | Brazil | A2 | |
| BRPI0518912A2 | Brazil | A2 | |
| BRPI0518921A2 | Brazil | A2 | |
| EP1815629A4 | European Patent Office (EPO) | A4 | |
| RU2007122339A | Russian Federation | A | |
| RU2007122344A | Russian Federation | A | |
| WO2008157676A2 | World Intellectual Property Organization (WIPO) | A2 | |
| BRPI0518914A2 | Brazil | A2 | |
| WO2008157676A3 | World Intellectual Property Organization (WIPO) | A3 | |
| JP2009508258A | Japan | A | |
| CN100470467C | China | C | |
| CN101416440A | China | A | |
| WO2006055428A3 | World Intellectual Property Organization (WIPO) | A3 | |
| MX2009005409A | Mexico | A | |
| US7562220B2 | United States of America | B2 | |
| RU2008109229A | Russian Federation | A | |
| CN101558412A | China | A | |
| US7610631B2 | United States of America | B2 | |
| US2010037325A1 | United States of America | A1 | |
| US7669056B2 | United States of America | B2 |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2008521089
- Publication, DOCDB
- 2008521089
- Publication, EPODOC
- JP2008521089
- Application
- 2007541351
- Application, DOCDB
- 2007541351
- Application, EPODOC
- JP20070541351
Titles2
- Japanese
- 望ましくない状態の検知時に入る特別なPCモード
- English
- Special PC mode to enter when undesired condition is detected
Classification
- CPC, 7
- G06F21/575
- H04L9/32
- G06F21/72
- G06F21/74
- G06F21/87
- G06F21/52
- G06F17/00
- IPC, 3
- G06F21 22
- G06F21 20
- G06F1 00
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo