Isolated computing environment anchored into cpu and motherboard
Abstract
By adding a separate computing environment to a standard computer, the computer adapts to the type of operation that pays for use. A separate computing environment can include reliable non-volatile memory, a digital signature verification function, a clock or timer, and a logic circuit for triggering execution of a verification program in response to the clock or timer. A physical mechanism, an encryption mechanism, or both can protect the isolated computing environment from tampering. The verification program can evaluate or monitor for non-compliance of the computer and enforce restraints if non-compliance of the computer is detected.
Term
Term ended
Projected expiry passed 12 November 2025, 0.9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
20 claims: 5 independent, 15 dependent
- 1分離コンピューティング環境内でプログラムコードを実行するように適合されているコンピュータであって、 プログラムコードを実行する分離コンピューティング環境と、 前記プログラムコードのみがアクセスすることができ、その他の実行環境によって実行される第2のプログラムコードはアクセスすることができない安全なメモリと、 前記プロセッサを前記安全なメモリから実行させる論理回路と、 論理回路に結合されており、イベントの時間を計るタイマであって、前記プログラムコードが、前記タイマからの信号に応じて呼び出されるタイマと を備えたことを特徴とするコンピュータ。
- 2前記その他の実行環境は、オペレーティングシステム、BIOS構造、およびカーネルのうちの1つを備えたことを特徴とする請求項1に記載のコンピュータ。
- 3前記プログラムコードは、前記コンピュータの状態をモニタすることを特徴とする請求項1に記載のコンピュータ。
- 4前記コンピュータは、プロセッサをさらに含み、前記コンピュータの前記状態は、オペレーティングシステムによって使用されるリソースの状態、アプリケーションプログラムの状態、BIOS拡張の状態、および前記プロセッサの状態のうちの1つであることを特徴とする請求項3に記載のコンピュータ。
- 5前記プロセッサは、前記分離コンピューティング環境を備えたことを特徴とする請求項3に記載のコンピュータ。
- 6前記プログラムコードは、前記コンピュータの前記状態に関連するポリシーを強制することを特徴とする請求項3に記載のコンピュータ。
- 7前記コンピュータの前記状態に関連する前記ポリシーは、前記コンピュータの処理速度を落とすこと、前記コンピュータの機能的なオペレーションを減らすこと、ランダムアクセスメモリへのアクセスを制限すること、インストラクションセットアーキテクチャを制限すること、および前記コンピュータをリセットすることのうちの1つを備えたことを特徴とする請求項6に記載のコンピュータ。
- 8マザーボードをさらに含み、 前記分離コンピューティング環境は、前記マザーボード上に配置され、 前記分離コンピューティング環境は、前記安全なメモリおよび前記タイマを備えたことを特徴とする請求項1に記載のコンピュータ。
- 9コンピュータ内で使用する分離コンピューティング環境であって、 無許可の実行環境によるアクセスから安全であるメモリと、 前記メモリ内に保存され、前記コンピュータの状況を評価するようにコード化されているプログラムであって、前記状況は、前記コンピュータのオペレーションの所定の望ましい状態に相当するプログラムと、 前記プログラムの実行を引き起こすための論理回路と、 インターバルの時間を計るタイマであって、前記間隔に対応して前記プログラムを実行するように前記論理回路をトリガーするタイマと を備えたことを特徴とする分離コンピューティング環境。
- 10前記メモリへのアクセスは、許可された実行環境の暗号による識別子を必要とすることを特徴とする請求項9に記載の分離コンピューティング環境。
- 11前記分離コンピューティング環境は、前記コンピュータ内に取り外せないように配置されていることを特徴とする請求項9に記載の分離コンピューティング環境。
- 12メモリレンジのハッシュ値を判定するための電子署名確認回路をさらに備えたことを特徴とする請求項9に記載の分離コンピューティング環境。
- 13前記プログラムを変更するメッセージの電子署名を検証する電子署名確認回路をさらに備えたことを特徴とする請求項9に記載の分離コンピューティング環境。
- 14前記コンピュータによって実行されるアプリケーションプログラムの電子署名を検証する電子署名確認回路をさらに備えたことを特徴とする請求項9に記載の分離コンピューティング環境。
- 15前記分離コンピューティング環境によって受け取られるデータの電子署名を検証する電子署名確認回路をさらに備えたことを特徴とする請求項9に記載の分離コンピューティング環境。
- 16前記分離コンピューティング環境は、オペレーティングシステムおよびアプリケーションプログラムのうちの1つによって使用されるコンピューテーションリソースにアクセスすることができることを特徴とする請求項9に記載の分離コンピューティング環境。
- 17使用するたびに支払うタイプのオペレーションに適合したコンピュータを製造する方法であって、 コンピュータにマザーボードを提供するステップと、 分離コンピューティング環境を前記マザーボード上に配置するステップであって、前記分離コンピューティング環境は、 安全なメモリと、 インターバルの時間を計るタイマと、 前記安全なメモリ内に格納されているコードの実行を引き起こす論理回路と、を含むステップと、 前記分離コンピューティング環境を改ざんから保護するステップと、 プログラムコードを前記安全なメモリ内に配置するステップであって、前記プログラムコードは、実行されると、前記コンピュータの状態を判定し、前記コンピュータの前記状態が所定の条件を満たしている場合にポリシーを強制するステップと を備えることを特徴とする方法。
- 18前記分離コンピューティング環境を前記マザーボード上に配置するステップは、 前記分離コンピューティング環境をプロセッサ内に配置するステップと、 前記プロセッサを前記マザーボード上に配置するステップと をさらに備えることを特徴とする請求項17に記載の方法。
- 19前記分離コンピューティング環境を前記マザーボード上に配置するステップは、 前記分離コンピューティング環境を前記マザーボード上に配置するステップと、 破壊性を有するコーティングを使用して、前記分離コンピューティング環境を前記マザーボードに固定するステップと をさらに備えることを特徴とする請求項17に記載の方法。
- 20前記コンピュータの状態を変更するステップであって、前記コンピュータの前記状態は、無許可の周辺機器を取り付けること、無許可のコードを実行すること、および有効期限を過ぎても前記コンピュータを機能させることのうちの1つを含むステップと、 前記分離コンピューティング環境が、前記コンピュータの前記状態に対応する前記ポリシーを強制していることをテストするステップと をさらに備えることを特徴とする請求項17に記載の方法。
Independent claims20
39 paragraphs, as filed
The present invention relates to a separate computing environment.
The pay-as-you-go or pay-per-use business model is used in many areas of commerce, from mobile phones to commercial Laundromat. Has been done. In developing pay-as-you-go businesses, providers, such as mobile phone providers, use less hardware (mobile phones) than the market in exchange for expressing their attitude that subscribers will stay on their network. It is offered at a cost. In this particular example, the customer receives the mobile phone with little or no payment in exchange for signing a contract to become a subscriber over a predetermined period of time. Over the term of the contract, the service provider recovers the cost of the hardware by imposing a charge on the consumer using the mobile phone.
The pay-as-you-go business model presupposes the concept that the hardware provided is of little, no value, or useless when the service provider disconnects. For example, if the above subscribers stop paying their invoices, the service provider will invalidate their account and then turn on the mobile phone as the service provider will not allow communication to that mobile phone. You can, but you will not be able to send or receive calls. A disabled phone has no "salvage" value. That's because the phone doesn't work anywhere else and the components aren't worth the market price. Once the account is up to date, the service provider will re-authorize the use of the device to make calls.
<p> This model works well when service providers and other financially-risk entities have tight control over their use of hardware. This model does not work well if the hardware is practically useful outside the control of the service provider (for example, in the case of a computer, whether or not the computer is connected to the service provider's network). Can be useful). In addition, the open and extensible nature of most computer hardware, such as personal computers and personal digital assistants, allows and facilitates modifications to both hardware and software, a business model of the type that pays on a case-by-case basis or similar. Maintaining the level of control required by the business model becomes even more difficult. Therefore, monitor, correct, and prevent unauthorized configurations of your computer, including compromised or unauthorized operating systems and software that may allow your computer to go beyond the control of your service provider. And there is a need to remove it.</p>
<p> According to one aspect of the disclosure, an isolated computing environment provides a secure storage of programs and information used to monitor and enforce policies related to computer configuration and operation. can do. A separate computing environment can have secure memory for storing or validating verification and enforcement programs, encryption keys, and other data that requires restricted access. .. A separate computing environment may further have a clock or timer and a logic circuit for activating the confirmation program in response to the clock or timer. If the state of the computer is determined to be non-compliant with the terms and conditions required under a business contract or other business contract that pays for each use, the enforcement program is in a non-compliant state of the computer. You can initiate a sanction to correct or urge the user to correct.</p><p> A method of assembling a computer that uses a separate computing environment can include the step of disposing the separate computing environment directly or indirectly on the motherboard of the computer, and also removing the separate computing environment from the computer. Can include steps to attach to the motherboard in a way that causes irreparable damage to the computer. Separate computing environments can also be tested as part of the assembly process.</p>
Although the text that follows provides a detailed description of many different embodiments, it is understood that the legal scope of this description is defined by the wording of the claims attached to this disclosure. I want to. This detailed description should be construed as merely exemplary and does not describe all possible embodiments. This is because it seems impractical, if not impossible, to explain all possible embodiments. Many alternative embodiments can be implemented using current technology that will continue to fall within the claims or technology developed after the filing date of the patent specification.
In addition, terms are clearly defined in the present specification using the sentence "when used in the present specification, the term" "is defined as meaning ..." or a similar sentence. Unless otherwise stated, there is no intention to limit the meaning of the term beyond its candid or ordinary meaning, either explicitly or implicitly, and such term is in the present patent specification. It should be understood that it should not be construed as being limited to the scope of any statement made in any paragraph (excluding the terms of the claim). As long as any of the terms in the claims attached to the Patent Specification is referred to in the Patent Specification in a manner consistent with a single meaning, it is exclusively the specification. It is intended to be clear so as not to confuse the reader of the book, and is not intended to limit the terms of such claims to their single meaning, such as by implied. .. Finally, the scope of any claim element is 35. It is not intended to be construed in accordance with the application of USC Section 112, paragraph 6.
Many of the features of the invention, and many of the principles of the invention, are best implemented with or in software programs, software instructions, and ICs (integrated circuits) such as application-specific ICs. Those skilled in the art will, in some cases, be disclosed herein, despite the great effort and many design options evoked by, for example, available time, current technology, and economic considerations. It is expected that such software instructions and programs as well as ICs could be easily created with minimal effort, guided by these concepts and principles. Therefore, for the sake of brevity and to minimize any risk that obscures the principles and concepts according to the invention, the principles and concepts of preferred embodiments when further discussing such software and ICs. We will limit ourselves to the essential elements of.
Many prior art high-value computers, personal digital assistants, organizers, etc. pay for pre-pay business models and uses without additional security. It cannot be suitable for use in a type of (pay-for-use) business model. As mentioned above, such a device can have a great deal of functionality apart from the functionality that requires a service provider. For example, a personal computer can be disconnected from the Internet services provided and can nevertheless be useful for applications such as document processing, spreadsheets, etc. This "untethered" when a service provider, such as an Internet service provider or other business entity, takes on the cost of a personal computer in anticipation of future fees. value) creates opportunities for fraudulent applications and theft. A prepaid type of business model in which users prepaid to use a subsidized high value computing system environment is an example of the risk of such fraud and theft.
FIG. 1 shows a computing device in the form of computer 110. The components of the computer 110 can include, but are not limited to, a processor 120, a system memory 130, and a system bus 121 that connects various system components, including system memory, to the processor 120. The system bus 121 can be any of a plurality of types of bus structures, including a memory bus or memory controller, a peripheral bus, and a local bus that uses any of the various bus architectures. For example, such architectures are known as ISA (Industry Standard Architecture) bus, MCA (Micro Channel Architecture) bus, EISA (Enhanced ISA) bus, VESA (Video Electronics Standards Association) local bus, and PCI. Includes, but is not limited to, (Peripheral Component Interconnect) buses.
Computer 110 typically includes various computer-readable recording media. The computer-readable recording medium can be any recording medium accessible by the computer 110, including both volatile and non-volatile recording media, as well as both removable and non-removable recording media. .. For example, computer-readable recording media can include, but are not limited to, computer storage media and communication media. Computer storage media are volatile and non-volatile recording media implemented in any method or technique for storing information such as computer-readable instructions, data structures, program modules, and other data, as well as removable recording media. And includes non-removable recording media. Computer storage media include RAM, ROM, EEPROM, flash memory, or other memory technologies, CD-ROMs, DVDs (digital versatile). disk), or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage, or other magnetic storage devices, or any other recording that can be used to store desired information and is accessible by computer 110. Including, but not limited to, media. The communication medium usually embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and includes any information transmission medium. The term "modulated data signal" means a signal having one or more of its characteristics set or modified in such a way as to encode the information in the signal. For example, communication media include, but are not limited to, wired media such as wired networks and direct wired connections, and wireless media such as sound waves, radio frequencies (RF), infrared rays, and other wireless media. Further, any combination of the above is included in the range of the computer-readable recording medium.
System memory 130 includes computer storage media in the form of volatile and / or non-volatile memory such as ROM 131 and RAM 132. The BIOS (basic input / output system) 133 includes a basic routine that assists in transmitting information between elements in the computer 110 during booting and is usually stored in the ROM 131. The RAM 132 typically includes a data module and / or a program module that is readily accessible to the processor 120 and / or is currently being operated by the processor 120. FIG. 1 shows, but is not limited to, an operating system 134, an application program 135, other program modules 136, and program data 137 as examples.
Computer 110 may also include other removable / non-removable, volatile / non-volatile computer storage media. FIG. 1 shows reading and writing between a hard disk drive 141 that reads and writes to and from a non-removable non-volatile magnetic recording medium and a removable non-volatile magnetic disk 152 for illustration purposes only. The optical disk drive 151 for reading and writing between the magnetic disk drive 151 and the removable non-volatile optical disk 156 such as a CD-ROM or other optical recording medium is shown. Other removable / non-removable, volatile / non-volatile computer storage media that can be used in typical operating environments include magnetic tape cassettes, flash memory cards, digital versatile disks, digital videotapes, solid-state RAM, and solid-state. There are ROMs, etc., but they are not limited to these. The hard disk drive 141 is typically connected to the system bus 121 via a non-removable memory interface such as interface 140, and the magnetic disk drive 151 and optical disk drive 155 are typically connected to the system bus via a removable memory interface such as interface 150. It is connected to 121.
The above-mentioned drives and their associated computer storage media, shown in FIG. 1, provide storage for computer-readable instructions, data structures, program modules, and other data for the computer 110. For example, in FIG. 1, the hard disk drive 141 is shown to store an operating system 144, an application program 145, other program modules 146, and program data 147. Note that these components may be the same as or different from the operating system 134, the application program 135, the other program modules 136, and the program data 137. Here, different numbers are assigned to indicate that the operating system 144, the application program 145, the other program modules 146, and the program data 147 are at least different copies. The user can enter commands and information into the computer 110 via an input device such as a keyboard 162 or a pointing device 161 usually called a mouse, trackball, or touchpad. Other input devices (not shown) can include microphones, joysticks, gamepads, satellite receiving antennas, scanners, and the like. These and other input devices are often connected to the processor 120 via a user input interface 160 coupled to the system bus, but other interface structures and bus structures such as parallel ports, game ports, USB, etc. You can also connect with. The monitor 191 and other types of display devices are also connected to the system bus 121 via an interface such as the video interface 190. In addition to the monitor, the computer should include other peripheral output devices such as speakers 197 and printer 196.
Computer 110 can function within a networked environment using a logical connection to one or more remote computers, such as remote computer 180. The remote computer 180 can be a personal computer, server, router, network PC, peer device, or other common network node, and although only memory storage device 181 is shown in Figure 1, it is usually a computer. Includes many or all of the above elements related to 110. The logical connections shown in Figure 1 include LAN171 and WAN173, but other networks can also be included. Such networking environments are common in offices, enterprise-scale computer networks, intranets, and the Internet.
When used in a LAN networking environment, the computer 110 is connected to the LAN 171 via a network interface or adapter 170. When used in a WAN networking environment, the computer 110 typically includes a modem 172 and other means for establishing communication over the WAN 173, such as the Internet. Modem 172 can be internal or external and can be connected to system bus 121 via user input interface 160 or other suitable mechanism. In a networked environment, the program modules shown associated with computer 110, or parts thereof, can be stored in remote memory storage devices. FIG. 1 shows, as an example, the remote application program 185 resident on the memory device 181 but is not limited to this form.
Communication connections 170, 172 allow this device to communicate with other devices. Communication connections 170 and 172 are examples of communication media. The communication medium usually embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and includes any information transmission medium. The term "modulated data signal", who like to encode the signal in the information may be a signal that has one or more of its characteristics set or changed in method. For example, communication media include, but are not limited to, wired media such as wired networks and direct wired connections, and wireless media such as sound waves, RF, infrared rays, and other wireless media. Computer-readable recording media include both storage media and communication media.
The isolated computing environment 125 (discussed in more detail in relation to Figure 2) can store and execute programs and data. The isolated computing environment 125 can be deployed and configured to enforce the terms of the agreement between the user of computer 110 and the service provider who has an interest in computer 110.
The isolated computing environment 125 can be instantiated in multiple ways. When implemented by one or more separate components, the isolated computing environment 125 can be located on the motherboard of the computer (not shown). Motherboards are any circuit interconnect and component mounting base suitable for a given application. Technology), and can range from glass fiber materials to molded epoxy resins, mylars, ceramics, and so on. The isolated computing environment 125 can be coated with epoxy or embedded under an interconnect layer or component when placed on or within the motherboard. Coating or embedding the isolated computing environment 125 can be the isolated computing environment 125 itself, the power and ground connections associated with the isolated computing environment 125, or the data and address connections to the isolated computing environment 125. Can play a role in making it more difficult to remove or tamper with. Ideally, removing the isolated computing environment 125, or removing its lid, would cause permanent damage to the motherboard and / or peripheral components, making the computer 110 inoperable.
Another instantiation of the isolated computing environment 125 can be as shown in FIG. 1, where the isolated computing environment 125 is embedded within the processing device 120. Such placement within the processing equipment can provide the advantages of better access to the processing equipment's registers, the ability to monitor data sequences, and increased resistance to physical attacks.
Refer to Figure 2 to discuss and explain a typical simplified isolated computing environment. This separate computing environment can be the separate computing environment 125 introduced above, or can be similar to the separate computing environment 125. The isolated computing environment 125 can include a memory 202, a logic circuit 204, and a clock or timer 206, for example the timer 206 may be used to perform the clock by counting the actual time interval. it can. Memory 202 can include both volatile and non-volatile memory.
The separate computing environment 125 may further include a digital signature verification circuit 208. The random number generator 210 can be part of the digital signature confirmation circuit 208 if one-way confirmation of the external entity, eg, confirmation of a server (not shown), is required. Digital signature techniques are well known, and hashing, signature verification, symmetric and asymmetric algorithms, and their respective keys are not discussed in detail herein.
The blocks of the separate computing environment 125 can be connected by the bus 212. Bus 212 may be separate from system / processor bus 214 used for external access. Separate buses can increase security by restricting access to the data passed by bus 212. Bus 212 incorporates security precautions, such as balanced data lines, to make power attacks on encryption key 216 stored in memory 202 more difficult. be able to.
Memory 202 can include non-volatile memory, which in addition stores at least one verification program 218 and at least one enforcement program, in addition to storing the encryption key 216. ) 220 can be stored. These programs will be discussed in more detail below. Other data 222, such as a hash code and / or other digital signature information associated with a known BIOS code, or an application program, can be stored in memory 202. Other examples of data 222 that can be stored in memory 202 are compliance data about the current state of computer 110 and proof for confirmation of downloaded updates to verifier 218 or coercion 220. It can be written information. The non-volatile memory in memory 202 can also enable a reliable and secure boot process separate from the operating system 144.
The verification program 218 and the coercion program 220 are illustrated as being stored within the isolation computing environment 125, but externally, eg, memory 202, with a digital signature or hash of the program stored within the isolation computing environment 125. It can also be stored in data section 216 of. When monitoring or evaluating an application program, the isolated computing environment 125 can verify the hash or digital signature of the application program before or during execution. The programs 218, 220 and data stored in memory 202 are part of the security associated with the success of the pay-as-you-go business model and the pay-as-you-go business model, so their data. It may be important to protect against unauthorized access and tampering. Unauthorized access to memory 202 can be restricted using logic circuit 204, digital signature verification circuit 208, or a combination of both. Access to memory can be limited to known program code, that is, the process of executing program code trusted by the isolated computing environment 125. This program code can be confirmation program 218 or coercion program 220. However, other programs can be granted access to memory 202. For example, an application that supports the management of credits and balances related to usage can use the memory of the isolated computing environment 125. If repairs or maintenance are required, access to memory 202 can be granted to supported service processes on networked devices that have a valid certificate to perform the repairs.
The separate computing environment 125 can have a plurality of functions. One function of the isolated computing environment 125 is to protect itself from unauthorized updates and tampering. Programs and data stored within the Separation Computing Environment 125 can also be injected at the time of manufacture, or downloaded if correctly signed with a signature authenticated by the Separation Computing Environment 125 itself. You can also. Another feature monitors and / or evaluates the state of computer 110 to determine if intrusions or other unauthorized changes are in progress or have occurred in the state of computer 110. be able to. Another aspect of monitoring and evaluation is to provide resources and support legitimate changes in the state of computer 110 with respect to features related to hosting secure features such as event dispatchers and balance managers. Can be done. The third function can be to check the current BIOS code, as well as to check for updates and enhancements to the BIOS code. Another feature of the isolated computing environment 125 can be that both reliable clocks or timers provide a source of time for measuring programs and expiration dates. The clock or timer can also prevent the isolated computing environment 125 from being granted access to the computer 110 on a daily basis and becoming "starve" in the CPU cycle. Another feature may be to enforce restraints if a non-compliant condition is determined within the computer 110.
Memory 202 can be protected to protect against unauthorized updates and tampering. To achieve this, only certain programs can access the memory 202, for example, an update routine authenticated by a digital signature under the control of the secure operating mode of the computer 110. Any program run by another execution environment, such as the operating system or kernel, can make memory 202 inaccessible. The kernel normally runs when computer 110 is booting. For example, Intel® x86 processors can work in several modes, or in the rings of execution. Rings 0-2 are occupied by the kernel and ring 3 is occupied by the "user mode" process. The third mode, SMM (system management) mode) is occupied by the BIOS. Programs that have access to secure memory 202 are outside the scope of the kernel, but can be run in SMM because the BIOS needs to be protected.
For the security of the isolated computing environment 125, devices other than the isolated computing environment 125 may simply not be able to address the dedicated physical memory of the memory 202 of the isolated computing environment 125. This is a separate computing environment for any of the data related to the operation of memory 202 in the separate computing environment 125, including programs 218, 220, key 216, and state / operational data 222. It's just one way to make it accessible and changeable. The digital signature verification circuit 208 can be used to verify all requested changes to memory 202 that occur externally, i.e. through the operating system 144. By verifying the digital signature using the internally stored key, trust can be established for untrusted sources, that is, data received by operating system 144.
Another way to protect memory 202 could be to create another execution mode, such as Mode Z or Ring-1. Memory 202 can be partitioned according to its function so that some areas of memory 202 can only be accessed by mode Z, while other areas of memory 202 are read-only from ring 0. It becomes. There can be case-specific access to a specified section of memory 202, such as read access from ring 0 to a specific specified range of memory 202. For example, some of the keys 216 can be read-only from ring 0. It is clear that the code associated with the isolated computing environment 125 can have access to all its memory 202, including full read and write access to key 216.
The isolated computing environment 125 can allow access to the memory used by the operating system to monitor and constrain the operating system 144. Because the isolated computing environment 125 is used to monitor and evaluate the operating system 144, access to the isolated computing environment to memory should not use operating system function calls. Otherwise, an intervener's attack on the isolated computing environment 125 may be incorporated. To monitor, evaluate, and constrain the operating system 144, the isolated computing environment 125 can incorporate both a memory watcher and an instruction pointer watcher, which have access to and specified a particular memory location. Monitor the movement of the instruction pointer through the location. Accessing and using the specified memory location may indicate that a non-compliant program is functioning or that an attempt to compromise the security of your computer may be underway.
The isolated computing environment 125 can serve to provide authorized resources or resources of the type that pay for each use, and to host features related to activation. Such resources may include some or all of the above, such as network connections 170, 172, hard disk drives 141, or video interface 190. The Separation Computing Environment 125 can also host a Balance Manager, which maintains accounts for the used and available amount of resources of the type that you pay for each use. The isolated computing environment 125 can be used to provide, activate, and monitor the resources mentioned above, so early in the manufacturing process, perhaps before assembling the computer 110, check the isolated computing environment program, eg. It may be necessary to program or inject Program 218 and Forced Program 220, or other initial operational data 222. If programming is done in the late stage of the isolated computing environment 125, that programming can also be done in a secure environment, or as is known in the field of data security, all. You can also use the transport key to verify the initial programming of. This can be especially important if the programming of the isolated computing environment 125 is performed at the time of sale or after it is owned by the user.
The confirmation program 218 can monitor or evaluate the condition of the computer 110. The state of computer 110 can be used to determine the level at which computer 110 complies with a set of policies or predetermined conditions. Those predetermined conditions can be both positive and negative conditions. That is, a policy or condition may require the presence of certain elements, such as hardware, software, peripherals, etc., or a policy may prohibit the presence of certain other elements. For example, one policy may require the presence of a given version of the system driver, while another policy may prohibit the presence of another boot device. To determine compliance, verification program 218 can use the state of resources used by the operating system, the state of application programs, the BIOS structure, or the BIOS extension (BIOS). The status of extension) can be monitored. In addition, Confirmation Program 218 can monitor compliance with various policies, including usage policies related to the terms and conditions of contracts that pay for each use. In non-compliance, confirmation program 218 can alert the user, for example, by using a pop-up message, or can activate coercion program 220 to initiate binding.
Timer 206 can provide a reliable standard for a pay-as-you-go type of period, including periods such as unlimited use for one month. The timer 206 also acts as a trigger to ensure that the verification program 218 and / or the coercion program 220 of the isolated computing environment 125 receive sufficient processor execution cycles to perform their respective tasks. Can be fulfilled. This trigger function can force the logic circuit 204 to execute the confirmation program 218. The logic circuit 204 can force an interrupt, which causes the processor to execute the confirmation program 218 from the appropriate location.
Corrective if Confirmation Program 218 determines that it is not compliant action) can be started. For example, coercion program 220 can overwrite a non-compliant driver with a driver from a known location. Conversely, if the non-compliant condition cannot be automatically corrected, constraints can be imposed to urge the user to make the system compliant. The constraint can be invoked by the logic circuit 204 that activates the coercion program 220. To perform coercion, the isolated computing environment 125, under the direction of coercion program 220, either disables or otherwise constrains resources under the direct influence or control of computer 110. be able to. Policies can vary depending on the state of the computer and can include reducing the functional operations of the computer, such as slowing down the computer or booting in "safe mode". .. Other constraints include limiting the amount of random access memory available for processing, the instruction set architecture, that is, limiting the processor commands available for execution, slowing access to hard disk 141, and so on. Alternatively, it can include limiting the accessible space on the hard disk drive 141. Further constraints can include limiting the resolution of the display, or even resetting the computer 110 frequently and periodically. The purpose of the constraints is to be able to undo those constraints, more specifically by the user. However, there may be certain policies that require the computer 110 to be disabled to a level that requires qualified service personnel with special equipment to restore service. This may be the case if, despite the warning, it is determined that a hostile attack has been repeatedly attempted over a period of time.
FIG. 3 shows how to assemble a computer 110 with a separate computing environment 125. In addition to other structural elements, a motherboard (not shown) can be provided at reference numeral 302. The motherboard can be a standard board with wiring traces and landing pads for mounting and connecting circuit components, as described above. Boards without parts, motherboards with parts, and motherboards with half parts are readily available on the commercial retail market. At reference numeral 304, the isolated computing environment 125 can be placed on the motherboard. The separate computing environment 125 can be a combination of individual components such as custom integrated circuits, components such as MCM (multi-chip module), or is fully integrated into the chip of the processor 120. It can also be transformed into.
When placed on the motherboard, code 306 can protect the isolated computing environment 125 from tampering. Anti-tampering mechanisms, although known, can include placing in epoxies and other coatings to remove those epoxies and other coatings without damaging or destroying the board and surrounding components. That is difficult. Another tamper-proof mechanism could be to sandwich the isolated computing environment 125 under other components. To prevent key theft, a metal coating can be applied to prevent laser probing. As mentioned above, the isolated computing environment 125 itself can have a separate means for protecting the integrity of its own circuits and content.
Execution code, such as confirmation program code 218 and compulsory program code 220, can be used to initialize the isolated computing environment 125 before or after it is placed on the motherboard at reference numeral 304. The functions of the confirmation program and the compulsory program are described above. In addition, keys and other data such as certificates and known hash codes can be downloaded or injected. Injection is usually done early in the manufacturing process, such as during chip testing. Late downloads may require cryptographic authentication and / or secure channels.
Once assembled, you can test your computer 110. At reference numeral 310, one or more of the states of the computer can be modified to perform functional tests of the isolated computing environment 125. This change can include installing unauthorized peripherals, loading / executing unauthorized code, or configuring computer 110 to function beyond its expiration date. Testing of the isolation computing environment 125 at code 312 is performed by determining that confirmation program 218 is functioning properly to identify non-compliant conditions and that enforcement program 220 imposes appropriate constraints. be able to.
<figref num="1">It is a simplified typical block diagram showing a computer.</figref><figref num="2">It is a block diagram which shows the simplified separated computing environment.</figref><figref num="3">It is a flowchart which shows the method of binding a related device to a computer.</figref>
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2014525637A | Cited by | Japan | Search report |
| JP2014518428A | Cited by | Japan | Examiner |
| JP2014525637A | Cited by | Japan | Examiner |
| JP2001526550A | Cites | Japan | Examiner |
| JP2002182562A | Cites | Japan | Search report |
| JP2003510684A | Cites | Japan | Examiner |
| US2004003288A1 | Cites | United States of America | Examiner |
| JPH0736559A | Cites | Japan | Examiner |
117 members in 12 offices
Priority claims19
| Document | Office | Kind | Date |
|---|---|---|---|
| 10989122 | United States of America | – | |
| 98912204 | United States of America | A | |
| 98912204 | United States of America | A | |
| 11006837 | United States of America | – | |
| 683704 | United States of America | A | |
| 683704 | United States of America | A | |
| 11022493 | United States of America | – | |
| 2249304 | United States of America | A | |
| 2249304 | United States of America | A | |
| 2005040950 | United States of America | W | |
| 2005040950 | United States of America | W | |
| 2004006837 | – | – | – |
| 2004022493 | – | – | – |
| 2004989122 | – | – | – |
| 2005040950 | – | – | – |
| US20040006837 | – | – | – |
| US20040022493 | – | – | – |
| US20040989122 | – | – | – |
| WO2005US40950 | – | – | – |
Members117
| Document | Office | Kind | |
|---|---|---|---|
| US1533449A | United States of America | A | |
| US1958296A | United States of America | A | |
| US4084557A | United States of America | A | |
| CA2526588A1 | Canada | A1 | |
| US2006105739A1 | United States of America | A1 | |
| US2006107306A1 | United States of America | A1 | |
| US2006107328A1 | United States of America | A1 | |
| US2006107329A1 | United States of America | A1 | |
| US2006107335A1 | United States of America | A1 | |
| KR20060054164A | Republic of Korea | A | |
| EP1659530A1 | European Patent Office (EPO) | A1 | |
| US2006112384A1 | United States of America | A1 | |
| WO2006055420A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055421A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055424A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055425A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055427A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055428A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2005232307A1 | Australia | A1 | |
| CN1783138A | China | A | |
| BRPI0504855A | Brazil | A | |
| JP2006190254A | Japan | A | |
| US2006165005A1 | United States of America | A1 | |
| US2006165227A1 | United States of America | A1 | |
| US2006168664A1 | United States of America | A1 | |
| TW200630885A | Taiwan Province of China | A | |
| TW200631377A | Taiwan Province of China | A | |
| TW200632711A | Taiwan Province of China | A | |
| TW200634584A | Taiwan Province of China | A | |
| US2006227364A1 | United States of America | A1 | |
| WO2006055421A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2006055424A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2006055425A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2007033102A1 | United States of America | A1 | |
| WO2007032974A1 | World Intellectual Property Organization (WIPO) | A1 | |
| RU2005135424A | Russian Federation | A | |
| WO2006055427A3 | World Intellectual Property Organization (WIPO) | A3 | |
| MX2007005655A | Mexico | A | |
| MX2007005657A | Mexico | A | |
| MX2007005660A | Mexico | A | |
| MX2007005662A | Mexico | A | |
| MX2007005656A | Mexico | A | |
| MX2007005659A | Mexico | A | |
| EP1815322A2 | European Patent Office (EPO) | A2 | |
| EP1815327A2 | European Patent Office (EPO) | A2 | |
| EP1815629A2 | European Patent Office (EPO) | A2 | |
| EP1815639A2 | European Patent Office (EPO) | A2 | |
| EP1815640A2 | European Patent Office (EPO) | A2 | |
| EP1815641A2 | European Patent Office (EPO) | A2 | |
| KR20070084257A | Republic of Korea | A | |
| KR20070084258A | Republic of Korea | A | |
| KR20070084259A | Republic of Korea | A | |
| KR20070084260A | Republic of Korea | A | |
| KR20070088633A | Republic of Korea | A | |
| KR20070088634A | Republic of Korea | A | |
| CN101057214A | China | A | |
| CN101057218A | China | A | |
| CN101057435A | China | A | |
| US2007244820A1 | United States of America | A1 | |
| CN101069215A | China | A | |
| EP1815640A4 | European Patent Office (EPO) | A4 | |
| KR20080043831A | Republic of Korea | A | |
| JP2008521089A | Japan | A | |
| JP2008521090A | Japan | A | |
| JP2008521091A | Japan | A | |
| JP2008521092AThis record | Japan | A | |
| JP2008521093A | Japan | A | |
| JP2008521094A | Japan | A | |
| WO2008077051A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006055420A3 | World Intellectual Property Organization (WIPO) | A3 | |
| BRPI0515720A | Brazil | A | |
| EP1952331A1 | European Patent Office (EPO) | A1 | |
| US7421413B2 | United States of America | B2 | |
| CN101263523A | China | A | |
| BRPI0518003A | Brazil | A | |
| CN101292248A | China | A | |
| RU2007117897A | Russian Federation | A | |
| RU2007117899A | Russian Federation | A | |
| RU2007117900A | Russian Federation | A | |
| RU2007117916A | Russian Federation | A | |
| BRPI0518911A2 | Brazil | A2 | |
| BRPI0518912A2 | Brazil | A2 | |
| BRPI0518921A2 | Brazil | A2 | |
| EP1815629A4 | European Patent Office (EPO) | A4 | |
| RU2007122339A | Russian Federation | A | |
| RU2007122344A | Russian Federation | A | |
| WO2008157676A2 | World Intellectual Property Organization (WIPO) | A2 | |
| BRPI0518914A2 | Brazil | A2 | |
| WO2008157676A3 | World Intellectual Property Organization (WIPO) | A3 | |
| JP2009508258A | Japan | A | |
| CN100470467C | China | C | |
| CN101416440A | China | A | |
| WO2006055428A3 | World Intellectual Property Organization (WIPO) | A3 | |
| MX2009005409A | Mexico | A | |
| US7562220B2 | United States of America | B2 | |
| RU2008109229A | Russian Federation | A | |
| CN101558412A | China | A | |
| US7610631B2 | United States of America | B2 | |
| US2010037325A1 | United States of America | A1 | |
| US7669056B2 | United States of America | B2 |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2008521092
- Publication, DOCDB
- 2008521092
- Publication, EPODOC
- JP2008521092
- Application
- 2007541356
- Application, DOCDB
- 2007541356
- Application, EPODOC
- JP20070541356
Titles2
- Japanese
- CPUおよびマザーボード内に固定された分離コンピューティング環境
- English
- Separate computing environment fixed within the CPU and motherboard
Classification
- CPC, 22
- G06F21/10
- G06F15/76
- G06F21/123
- G06F21/50
- G06F2221/2135
- G06F2221/2137
- G06F2221/2153
- G06Q20/145
- G06Q20/341
- G07F7/082
- G07F7/1008
- G07F7/1016
- G06F21/725
- G06Q20/3552
- H04L63/0823
- H04L9/3247
- H04L2209/12
- H04L2209/56
- H04L67/34
- H04L67/125
- G06F9/00
- G06F1/00
- IPC, 2
- G06F21 22
- G06F21 24
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo