Special pc mode entered upon detection of undesired state.
Abstract
A system and method for monitoring a computer, particularly a pay-per-use computer, usesan isolated computing environment or supervisor. The isolated computing environmentboots prior to any boot device associated with an operating system, runs concurrentlywith the operating system and monitors and measures the computer in operation.Once the isolated computing environment determines the computer is not in compliancewith the required policies, the isolated computing environment may either imposean impediment to use such as slowing clock speed or completely disable the operatingsystem. The user may have to return the computer to a service provider to restoreit from the offending condition and reset the computer to an operational state.

Term
Term ended
Expired 12 November 2025, 0.9 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
11 claims: 4 independent, 7 dependent
- 1CLAIMS REIVINDICACIONES 1, - A computer adapted for operation in a normal mode and an alternate mode that includes:1,- Una computadora adaptada para operación en un modo normal y un modo alterno que comprende: 5 a memory;5 una memoria;a processor coupled to memory;un procesador acoplado a la memoria;a first startup device that takes precedence over any other startup device, the first startup device remains active concurrently with any other startup device, the first startup device comprises: un primer dispositivo de inicio que tiene precedencia en cualquier otro dispositivo de inicio, el primer dispositivo de inicio permanece activo concurrentemente con cualquier otro dispositivo de 10 Inicio, el primer dispositivo de inicio comprende: a memory for storing data in a tamper-resistant form, the data comprises at least one of configuration data, cryptographic data, status data, executable program data;una memoria para almacenar datos en una forma resistente a falsificación, los datos comprenden al menos uno de datos de configuración, datos criptográficos, datos de estado, datos de programa ejecutable;15 un circuito que proporciona lecturas de tiempo monótonamente en aumento;fifteen a circuit that provides monotonically increasing time readings;a data input / output circuit;un circuito de entrada/salida de datos;a program execution environment, coupled to the clock and the data input / output circuit, for executing at least one of a verification program or a measurement program stored in memory;un ambiente de ejecución de programa, acoplado al reloj y al circuito de entrada/salida de datos, para ejecutar al menos uno de un 20 programa de verificación o un programa de medida almacenado en la memoria;en donde el primer dispositivo de inicio determina cuando la computadora está operando en cumplimiento con un criterio. where the first boot device determines when the computer is operating in compliance with a criteria.
- 55 processing ability to obstruct the operation of the computer when the computer is not in accordance with the policy. 5 capacidad de procesamiento para obstruir la operación de la computadora cuando la computadora no está de acuerdo con la política. . 15.- El supervisor de acuerdo con la reivindicación 14, en donde la política corresponde a una configuración de hardware válida . 15.- The supervisor according to claim 14, wherein the policy corresponds to a valid hardware configuration
- 610 of the computer and the imposing circuit limits the hardware functions to the valid hardware configuration. 16.- A method to determine the non-compliance of a policy in a computer that includes:10 de la computadora y el circuito de imposición limita las funciones de hardware a la configuración de hardware válida. 16.- Un método para determinar el no cumplimiento de una política en una computadora que comprende: asociar el no cumplimiento de la política con al menos un associate non-compliance with the policy with at least one
- 715 criterio medible en la computadora;fifteen computer measurable criteria;iniciar un supervisor antes de activar un sistema operativo;. start a supervisor before activating an operating system;. verificar datos, en el supervisor, que corresponden al menos a un criterio en la computadora;y determinar cuando la computadora está en un estado de no 20 cumplimiento al evaluar los datos. verify data, in the supervisor, that correspond to at least one criterion in the computer;and determine when the computer is in a non-compliant state by evaluating the data.
Independent claims4
70 paragraphs in 5 sections, as filed
(54) Title: SPECIAL PC MODE INTRODUCED AFTER THE DETECTION OF AN UNWANTED STATE.
(54) Title: SPECIAL PC MODE ENTERED UPON DETECTION OF UNDESIRED STATE.
(57) Summary
A system and method for verifying a computer, particularly a pay-as-you-go computer, uses an isolated or supervisory computing environment. The isolated computing environment starts before any boot device associated with an operating system, runs concurrently with the operating system, and verifies and measures the operating computer. Once the isolated computing environment determines that the computer is not in compliance with the required policies, the isolated computing environment can either impose a usage impediment such as reducing the clock speed or completely disabling the operating system. The user may have to return the computer to a service provider to restore it from the offending condition and restore the computer to an operational state.
(57) Abstract
A system and method for monitoring a Computer, particularly a pay-per-use Computer, uses an isolated computing environment or supervisor. The isolated computing environmentboots prior to any boot device associated with an operating system, runs concurrentlywith the operating system and monitors and measures the Computer in operation.Once the isolated computing environment determines the Computer is not in compliancewith the required policies, the isolated computing environment may either imposean impediment to use such as slowing dock speed or completely disable the operatingsystem. The user may have to return the Computer to a Service provider to restoreit from the offending condition and reset the Computer to an operational State.
SPECIAL PC MODE INTRODUCED AFTER THE DETECTION OF AN UNWANTED STATE
This application is a continuation in part of US Patent Application No. 11 / 022,493, filed December 22, 2004 which is a continuation in part of US Patent Application No. 11 / 006,837, filed on December 8, 2004, which is a continuation in part of US Patent Application No. 10 / 989,122, filed November 15, 2004.
BACKGROUND
Operating systems are a key building block in the development of computer systems. For several decades now that personal computing has become pervasive operating systems, they have increased substantially in complexity. The development of a computer operating system that is backward compatible with a substantial number of computer applications, but is still secure enough to achieve a high level of counterfeit resistance assurance that is extremely challenging. However, new business models for pay-as-you-go or pay-per-time computing require a high level of counterfeit resistance assurance.
BRIEF DESCRIPTION OF THE INVENTION
A computer adapted for use in a pay-as-you-go business model may use a monitor or isolated computing environment 5 to verify and measure the performance of the computer, as well as compliance with a set of usage policies. The isolated computing environment can have secure memory, secure processing capability, and cryptographic capability. The isolated computing environment can be started before other boot devices to establish a secure computing base before the introduction of non-secure computing capabilities to the computer, such as the operating system.
Based on one aspect of the description, the isolated computing environment can request data, receive data, or poll information from the computer. The isolated computing environment can use the acquired data to develop a brand for compliance with established policy, for example, by a service provider. The mark may increase when compliance with policies is confirmed and the mark may decrease by 20 when non-compliance is determined. The mark must reach or fall below a threshold level, a sanctioned mode can be invoked. Sanctioned mode, or alternate operating mode, can involve simple prevention to a user, it can limit a function of the computer to make the computer less useful, or it can stop the operating system or some other key component entirely, thereby disabling Computer. When disabled, the computer may require service by a service provider or other authorized party for determination and correction of conditions that do not agree, and may include user reimbursement service fees or penalties. The isolated computing environment can send notification data to a user or service technician to help determine the. current state of the computer and corrective actions to take to restore the computer. Similarly, even in an unsanctioned mode, the isolated computing environment can export data for verification or diagnosis. .
BRIEF DESCRIPTION OF THE DRAWINGS
Figure 1 is a simplified and representative block diagram of a computer;
Figure 2 is a block diagram of a simplified and isolated computing environment;
Figure 3 is an illustrative, simplified block diagram illustrating one embodiment of a supervisor;
Figure 4 is an illustrative simplified block diagram illustrating another embodiment of a supervisor;
Figure 5 is a flow chart illustrating a method for establishing and measuring compliance with a policy on a computer.
DETAILED DESCRIPTION OF VARIOUS MODALITIES
Although the following text mentions only a detailed description of numerous different embodiments, it should be understood that the legal scope of the description is defined by the words of the claims mentioned at the end of this description. The detailed description should not be construed as illustrative only and does not describe every possible embodiment as describing every possible embodiment would be impractical, if not impossible. Numerous alternative modalities must be implemented, using either current technology or technology developed after the filing date of this patent, which would still fall within the scope of the claims.
It should also be understood that, unless a term is expressly defined in this patent that uses the sentence "As Used Here, the Term" is defined herein to mean ... "or a similar sentence, there is no intent. to limit the meaning of that term, either expressly or by implication, beyond its ordinary meaning or plan, and such term should not be construed to limit in scope on the basis of anything. statement made in any section of this patent (other than the language of the claims). To the extent that any term mentioned in the claims at the end of this patent is referred to in this patent in a manner consistent with an individual meaning, it is done for the sake of clarity only so as not to confuse the reader, and it is not intended that such Claims term is limited, by implication or otherwise, to that individual meaning. Finally, unless a claim item is defined by mentioning the word 5 "means" and a function without mention of any structure, it is not intended that the scope of any claim item be interpreted based on the application of 35 USC § 112 , sixth paragraph.
Most of the inventive functionality and many of the 10 inventive principles are best implemented with or in software programs or Instructions and Integrated Circuits (ICs) such as application specific ICs. It is expected that one skilled in the art, regardless of possibly significant effort and many design choices motivated, for example, by available time, current technology, and economic considerations, when guided by the concepts and principles described herein will be able to easily of generating such software and program instructions and ICs with minimal experimentation. Therefore, in the interest of brevity and minimization of any risk of obscuring the principles and concepts in accordance with the present invention, further discussion of such software and ICs, if any, will be limited to the essentials regarding the principles. and concepts of preferred modalities.
Figure 1 illustrates a computing device in the form of a computer 110. The components of the computer 110 may include, but are not limited to, a processing unit.
120, a system memory 130, and a system common conductor 121 that couples various system components including the system memory to the processing unit 120. The system common conductor 121 can be any of several types of common conductor structures including a memory common conductor or memory controller, a peripheral common conductor, and a local common conductor using any of a variety of common conductor architectures. By way of example, and not limitation, such architectures include common conductor of
Industrial Standard Architecture (ISA), Micro Channel Architecture (MCA) common conductor, Enhanced ISA common conductor (EISA), Video Electronic Standards Association (VESA) local common conductor, and Peripheral Component Interconnect common conductor ( PCI) also known as a common mezzanine driver.
Computer 110 typically includes a variety of computer-readable media. Computer-readable media can be any available media that can be accessed by computer 110 and includes both volatile 20 and non-volatile media, removable and non-removable media. By way of example, and not limitation, computer-readable media may comprise computer storage media and communication media. Computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, FLASH memory or other memory technology, CD-ROM, digital versatile discs (DVD) or other optical disc storage, magnetic cassettes, magnetic tape , magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and that can be accessed by the computer 110. Communication media typically represents computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism and includes any means of information delivery. The term "modulated data signal" means a signal that has one or more of its characteristics set or changed in such a way as to encode information in the signal. By way of example, and not limitation, communication media includes wired media such as a wired network or direct wired connection, and wireless media such as acoustic, radio frequency, infrared, or other wireless media. Combinations of any of the above must also be included within the scope of computer-readable media.
System memory 130 includes computer storage media in the form of volatile and / or non-volatile memory such as read-only memory (ROM) 131 and random access memory (RAM) 132. A basic input / output system 133 (BIOS), which contains the basic routines that help transfer information between items within computer 110, such as 5 during startup, is typically stored in ROM 131. RAM 132 typically contains data and / or program modules that are immediately accessible to and / or currently operated by processing unit 120. By way of example, and not limitation, Figure 1 illustrates operating system 134, programs 10 application 135, other program modules 136, and program data 137.
Computer 110 may also include other volatile / non-volatile removable / non-removable computer storage media. By way of example only, Figure 1 illustrates a hard disk drive 141 that reads from or writes to non-volatile, non-removable magnetic media 15, a magnetic disk drive 151 that reads from or writes to a non-volatile, removable magnetic disk 152, and an optical disc drive 155 that reads from or writes to a removable, non-volatile optical disc 156 such as a CD ROM or other optical media. Other removable / non-removable, volatile / non-volatile computer storage media that may be used in the illustrative operating environment include, but are not limited to, magnetic tape cassettes, flash memory cards, digital versatile disks, digital video tape. , Solid state RAM, solid state ROM, and the like. Hard disk drive 141 typically connects to common system conductor 121 through a non-removable memory interface such as interface 140, and magnetic-disc drive 151 and optical disc drive 155 which typically connect to conductor. system common 121 through a removable memory inferry, such as interface 5 150.
The drives and their associated computer storage media discussed above and illustrated in Figure 1 provide storage of computer-readable instructions, data structures, program modules, and other data for the computer 110. In Figure 1, for example, hard disk drive 141 is illustrated as storing operating system 144, application programs 145, other program modules 146, and program data 147. It is noted that these components may be the same or different from operating system 134, application programs 135, other program modules 136, and program data 137. Operating system 144, application programs 145, other program modules 146, and Program data 147 are given different numbers here to illustrate that they are at least different copies. A user can enter commands and information into computer 20 through input devices such as a keyboard 162 and pointing device 161, commonly referred to as a mouse, trackball, or touch pad. Other input devices (not shown) may include a microphone, joystick, game pad, satellite dish, scanner, or
..
Similar. These and other input devices are frequently connected to the processing unit 120 through a user input interface 160 that is coupled to the system common conductor, but can be connected through another interface and common conductor structures, such as such as a parallel port, game port, or universal serial common driver (USB). A monitor 191 or other type of display device is also connected to the common system conductor 121 through an interface, such as a video interface 190. In addition to the monitor, computers 10 may also include other peripheral output devices such as speakers 197 and printer 196, which can be connected via a peripheral output interface 195.
Computer 110 can operate in a network environment that uses logical connections to one or more remote computers, such as remote computer 180. Remote computer 180 can be a personal computer, server, router, network PC, peer device, or other common network node, and typically includes many or all of the items described above relative to computer 110, although only Illustrates a memory storage device 181 in Figure 1. The logical connections illustrated in Figure 1 include a local area network (LAN) 171 and a wide area network (WAN) 173, but also include other networks. Such network environments are commonly located in offices, on computer networks spread over 25 companies, intranets, and the Internet.
When used in a LAN environment, computer 110 connects to LAN 171 through a network interface or adapter 170. When used in a WAN environment, computer 110 typically includes a 172 or other modem. means 5 for establishing communications on the WAN 173, such as the Internet. Modem 172, which may be internal or external, may be connected to system common conductor 121 through user input interface 160, or other appropriate mechanism. In a network environment, the illustrated program modules relating to the computer 110, 10, or portions thereof, may be stored in the remote memory storage device. By way of example, and not limitation, Figure 1 illustrates remote application programs 185 as resident in memory device 181.
Communications connections 1 70, 172 allow the device to communicate with another device. Communications connections 170, 172 are an example of communication media. The communication media typically represents computer-readable instructions, data structures, program modules, or other data in the modulated data signal such as a carrier wave or other transport mechanism and includes any information delivery medium. A "modulated data signal" can be a signal that has one or more of its characteristics set or changed in such a way as to encode information in the signal. By way of example and not limitation, communication media includes wired media such as direct wired or wired network connection, and wireless media such as acoustic media, infrared RF, and other wireless media. Computer-readable media can include both storage media and communication media.
An isolated computing environment 125 can be used to implement a supervisor, a trusted computing base, or other secure environment, and can be used to verify, measure, and / or sanction the computer 110 when established policies for use are not followed. Policies may reflect the terms of an agreement between a user of computer 110 and a service provider with an interest in computer 110. The isolated computing environment 125 is discussed in more detail with respect to Figure 2, below.
The isolated computing environment 125 can be started in more than one way. When implemented by one or more separate components, the isolated computing environment 125 can be arranged on the motherboard (not illustrated) of the computer. Ideally, removal or uncovering of the isolated computing environment 125 causes permanent damage to the motherboard and / or surrounding components and renders the computer 110 inoperable.
Another installation of the isolated computing environment 125 can be as illustrated in Figure 1, where the isolated computing environment 125 is incorporated in the processing unit 120. By being thus arranged in the processing unit it can offer 25 improvement advantages to data stream verification and processing unit logs as well as improved resistance to physical attacks.
When there is a certified startup procedure, the isolated computing environment 125 can be implemented in the software because the startup procedure can guarantee the execution cycles and a certified operating environment. In such a case, the isolated computing environment 125 may not require a separate processor but can be run from the main processing unit 120. When a certified boot is not available, a hardware implementation of the isolated computing environment 10 may be recommended.
The License Provision Module, or LPM (see Figures 3 and 4), can be incorporated to measure and authorize the use of the computer in a pay-as-you-go or pay-per-time configuration. The LPM, when implemented in software, can be stored in non-volatile memory 146 and run from memory 136. When the LPM is implemented in software, it can be vulnerable to attack. A purpose of the supervisor (see Figures 3 and 4) and / or the isolated computing environment 125 may be to act as a gatekeeper in the LPM to help ensure its integrity and proper function.
In an alternate mode, the isolated computing environment 125 can take over the role of LPM with respect to valid hardware configuration of the computer. That is, the separately started isolated computing environment 125 may have configuration data that allows the operation of the computer according to its licensed capacity, the licensed capacity being less than the. potentially available. For example, the computer may be able to run with 512 megabytes (MB) of * random access memory (RM), but the valid configuration specifies 5..256 megabytes of RAM. The isolated computing environment
125 You can limit the function of the computer to 256 MB of system memory. Similar restrictions may be imposed with respect to processor clock speed, available cache memory, number of 120 processor core available, 10 graphics card functions, hard drive capacity, network options, or internal common driver drivers. From an implementation perspective, there is little or no difference between imposing a limitation based on verified activity or imposing a limitation based on a predetermined license configuration.
Referring to Figure 2, a simplified and representative isolated computing environment is discussed and described. The isolated computing environment may be or is similar to the isolated computing environment 125 previously introduced. The computing environment 125 may include a memory 202, both volatile and non-volatile, a data input / output circuit 204, and a clock timer 206. For example, a stopwatch 206 can be used to implement the clock function to the point of real time intervals.
The isolated computing environment 125 may further include a digital signature verification circuit 208. When a one-way verification is required from an external entity, for example, a server verification (not illustrated), a random number generator 210 may be a part of the digital signature verification circuit 208. Digital signature technology is well known and not. 5 Verification, signature verification, symmetric and asymmetric algorithms and their respective keys are discussed in detail here.
The blocks of the isolated computing environment 125 may be coupled by a common conductor 210. The common conductor 210 may be separated from a common system or processing unit conductor 214 used for external access. Separate common conductors can improve security by limiting access to data passed by common conductor 210. Common conductor 210 may incorporate security precautions such as balanced data lines to make power attacks on cryptographic keys 216 stored in memory 202 more difficult.
A processor 216 may be available for program execution. As discussed above, when certified boot is not available, processor 216 can be included to provide the isolated computing environment 125 with guaranteed computing capacity 20 and separation from operating system 134.
Memory 202 may, in addition to storing pictographic keys 216, store data 220 that may include operational information, such as a current mark associated with compliance, or system information, such as specific contractual information. Measurement data 222 can be associated. -16 with a verification program 224. Verification program 224 is discussed in more detail below, but briefly, it is used to take measurements, receive information about the current operation of computer 110, and determine a compliance mark. The sanction program 226 may be invoked when a compliance flag is below a predetermined threshold. The sanction program 226 may be capable of activating both software and hardware mechanisms to knock out or disable the computer 110.
Figure 3 illustrates an illustrative embodiment of a computer 110, showing the related hardware and software components associated with the pay-per-use or pay-per-time computation. The operating system 134 of Figure 1 can support the LPM 302 and operating system services 304 associated with the pay-per-view operation. The operating system services 304 may include time-safe, secure storage, and cryptic encoding / decoding. In this mode, the elements of the isolated computing environment 125 are configured as a supervisor 306. The supervisor 306 can include a secure memory 308, a secure clock 310, and a cryptographic key storage 312. A unique hardware identifier 314 may be available to supervisor 306 for use in processing provisioning package and when identifying computer 110 to an external entity.
Secure memory 308 can be a separate memory area accessible only by isolated computing environment 125, and / or only after cryptographic verification. The secure watch 310 can provide a counterfeit resistant time base that provides monotonously increased for the life of the computer. The secure watch 310 can be used for interval time recording or as a calendar basis. Cryptographic key storage 312 can provide storage for cryptographic keys. The key store 312 may be essentially a write-only memory and include cryptographic algorithms such as calculations that are performed within the key store and only results are provided. Keys may not be read from key store 312 once they are written and verified.
The supervisor 306, and its fundamental isolated computing environment 125, can be operated independently of the operating system 134. For security reasons, the supervisor 306 may start before any other startup device when the computer 110 is powered on or reset. Independent startup of the operating system helps to ensure that the supervisor 306 and the isolated computing environment 125 are not fooled or suffered from CPU time by another startup device.
Communication between supervisor 306 and operating system services 304 may be on logical communication link 316, and may be supported with physical communication common 25 214. LPM 302 may be on
18.
communication with supervisor 306 as shown by logical link 318. Link 318 supports requests from supervisor .306 to LPM 302 for the listening area. Additionally, the LPM 302 can send a periodic heartbeat to supervisor 306 as an audition in the course of system compliance. Because supervisor 306 can completely disable operating system 134 when a non-compliant situation is discovered, supervisor 306 may have enough power and hardware access to present a sanctioned mode user interface 320 for use while computer 110 is in sanctioned mode.
The add / beat data may be sent on logical link 318 and may include data required to validate a software component, particularly the LPM 302. Supervisor 316 may be programmed to wait for the beat data at a regular interval.
The heartbeat data can include validation information such as a digital signature or its binary executable code, which includes a sequence number or other method to prevent a response attack. The regular heartbeat, for example, of the LPM 302 can serve as evidence that the LPM is still running and when the signature is verified, that it is the correct version of the unmodified code. The supervisor must fail to validate the authenticity of the heartbeat, or if the heartbeat does not arrive within a prescribed period, the heartbeat may fail and may be reduced to the compliance mark. Heartbeat messages that arrive more frequently than required may not be penalized, while an individual failed heartbeat may not be sufficient to invoke a penalty depending on the policy rules.
Supervisor 306 is different from a known hypervisor or monitor. A monitor can already be between the operating system and the related hardware to negotiate the resource share or CPU time cut. Because a monitor is closely tied to the operating system, it is difficult to summarize a monitor to a variety of operating systems, or even operating system versions. In contrast, the 306 monitor, in one mode, does not attempt to handle or negotiate system resource usage during normal operation. In its simplest form, the supervisor 306 receives a policy, verifies the policy, verifies compliance, and sanctions non-compliance with the policy. -The policy can be a data structure that passes from the operating system that corresponds to the predetermined limits, for example, hours of use or months of calendar of use.
Because the supervisor 306 is independent of the operating system, or on another boot device, the supervisor 306 can be used to enforce policies for virtually any operating system or operating environment. This independence from the base platform is, in a way, facilitated by the supervisor's guaranteed access to the count cycles, secure memory, and time base.
Figure 4 illustrates an alternate embodiment of the operating system 25 and associated hardware components by a pay-as-you-go computer, such as computer 110. As in Figure 3, the operating system 130 includes the LPM 302 and the base operating system services. 304. A small supervisor 309, which can also be based on a hardware isolated computing environment 125, 5 can only verify the secure system resources 307 through the common conductor 330, rather than offer and maintain them as in the modality of Figure 3 Secure resources 307 may have secure memory 308, secure clock 310, cryptographic key storage 312, and hardware identifier 314. Individual service requests 10 to the various call entities of the operating system can be made through logical conduits illustrated by data paths 322, 324, 326. The logical connection of audio η / 1 to i do 318 can stay between supervisor 309 and LPM 302. In this configuration, the hardware identifier 314 may be made available to the LPM 302 through the logical connection 328, among other things, to verify provisioning packets and to be used in generating the heartbeat signal.
In operation, both configurations as illustrated in Figures 3 and 4 can operate in a similar way with respect to developing a compliance mark. The compliance mark can be an accumulation of heavy values determined by measurement and observation. The measurements 222 made by the verification process 224 (Figure 2) can be used to evacuate different events and classify them, in the simplest way, whether they are good or bad. The good event results in an improved compliance mark, while each bad event lowers the compliance mark. Criteria can be established so that no single event can be sufficient for the compliance mark to reach a minimum threshold, causing penalties to be imposed.
Supervisors 306, 309 of the Figure 3 and Figure 4 modes can both measure the frequency and quality of heartbeat signals. The compliance mark can be raised when good beats are received at the moment. The supervisor 306 of Figure 3-10 may have full access to key data used in measurement and measurement. For example, the compliance market may also increase when monitor 224 determines that the operating system is using metering. Monitor 224 may also determine a timestamp used against purchases of additional time. When your estimated purchases match your estimated usage, you can also increase your compliance mark. Other measures may be taken, such as checking designated files, for example the LPM 302 or boot files (not illustrated), or checking the system clock.
However, when the heartbeat fails or does not arrive on time, the compliance mark can be lowered. If the operating system persists in an unmetered state for a predetermined amount of time, the compliance flag may be lowered. If the operating system enters and exits the measurement state at a very high rate, perhaps indicating tampering with measurement circuitry, the compliance mark may also be lowered.
Supervisor 306 of the Figure 4 mode may have less access to direct measurement data or operating system status. Such a configuration may be more secure in the verification of the noise or other factors such as the rate of change of assured storage as an indication that the measurement data has been updated.
The compliance mark in a modality can start at an initial value and increase or decrease when several "good" and "bad" measures are determined. When the compliance mark is lowered sufficiently, a first threshold can be reached, which triggers an action. In one embodiment, the first threshold may be the threshold only and an immediate penalty may be imposed. In another embodiment, the first threshold may trigger an advertisement that alerts the user that spoof adults have emerged and that appropriate action needs to be taken. In still another embodiment, the first threshold may trigger a limited penalty, such as limiting a display resolution or reducing processor speed. The compliance mark must continue to lower a threshold that can be reached where a dramatic sanction such as disabling the operating system can be invoked. At that point, computer 110 may need to be taken to a service center for restoration. The sanctioned mode user interface 320 can be activated for restore services when the operating system is disabled.
To illustrate the use of an illustrative modality, a computer 110 may be provided with a start compliance flag of 80. After a series of successful heartbeats, a airtime purchase, and routine issuance, the 5 compliance spans it can be increased to a maximum of 100 (other modalities may not use a maximum compliance mark limit). At that point, however, the user tries to defeat the mechanism by overwriting the LPM 302. An LPM 302 measurement fails because a target memory range check does not match the expected check. Heartbeat signals stop and routine measurement stops because LPM is not programmed to support those functions. With each successive measurement failure the compliance mark may decrease, for example, to 70. When the compliance mark reaches 70, a warning message is presented to the user indicating that the system appears to have been tampered with and will shut down without corrective action. The user ignores the warning and the compliance flag decreases to 55. The supervisor 306 can then activate the session program 226 to take action to shut down the computer 110, eg, 20 by interrupting the processing unit 120. The inferred user of sanctioned mode 320 then a message may immediately appear informing the user that the computer has been disabled and must be taken to a service center for restoration.
At the service center, a technician can use the inferred <sup>24</sup> mode user number 320 to determine that the replacement LPM agrees and restore a compliant LPM 302. The service technician may activate the supervisor 306 to restart the monitor program 224, if required, and may be able to manually reset the plug-in flag, if desired. In this example, as someone clearly computer friendly, a fine or service charge may be imposed on the user to discourage future attempts at tampering with the system.
Figure 5 describes and discusses a method to determine non-compliance with a policy on a computer. A policy that establishes operating rules and criteria of use for the computer 110 may be established by a service provider or other party with a financial interest in the computer 110. After the policy is established, measurable criteria for determining compliance and Non-compliance with the policy may develop 402. Criteria may include measures such as verification of known memory ranges and / or verification of conditions and activities in computer 110, such as re-providing usage credits in computer 110. Measurement and verification criteria can be programmed into a supervisor such as supervisor 306, which in turn can be built in an isolated computing environment 125.
The supervisor 306 can be activated 404 before activating, or starting, any other system element that includes an operating system 134. The reasons for the first start are discussed. <sup>25 </sup>previously, but briefly, doing that helps to secure a. Clean operating environment known to supervisor 306. When first activated, for example during manufacturing or at installation time, an initial compliance mark 5 may be set that corresponds to operation in accordance with established policy. In one embodiment, the supervisor 306 has a program execution environment autonomous from the operating system 134, to further isolate the supervisor 306 from attacks made on the operating system 134 and associated components.
After the supervisor 306 starts, it can start 406 other boot devices, such as the operating system 134 and other pre-boot devices. When computer 110 is operational, supervisor 306 can begin to verify and measure 408 in accordance with criteria developed in block 402. Each edit verification find can be used to adjust the compliance mark.
The criteria used in block 408 may include clock check, the duration of an individual computing session, the amount of time measured between where the provisioning packets are provided, or comparisons between the total operating time of the computer in the total number of provision packages provided.
The measurement and measurement data that can be used to evaluate the various criteria may be in the operating system heartbeat, a designated file check, 'check
a system clock, a current operating mode, a frequency of writes to memory, or a time since the last provisioning cycle. For example, a clock check may include a comparison of the secure clock time 310 to a soft clock under the control of the operating system and may be followed by an analysis of the last time the provisioning packets were provided.
As soon as the measurement result upon verification is determined, the compliance mark can be compared 410 to a predetermined threshold. When the mark is above the threshold, the no-branch from block 410 can be taken to block 408 where further action can be taken. When the compliance flag is below the threshold, the yes branch of block 410 can be taken as an additional test performed to determine 412 if the flag indicates a warning or sanction that is appropriate. When a warning is appropriate the branching of the labeled warning can be taken from block 412 and a warning 416 can be displayed. Execution can then continue at block 408.
When it is determined at block 412 that a sanction is appropriate, the sanctioned branch of block 412 can be taken to block 414 where a sanction can be imposed. A scale of penalties may be available, including producing display resolution, color depth, reducing processor, and depending on policy, the operating system may be disabled 25 or another major system or device that substantially disables the computer 110.
Although the above text mentions a detailed description of numerous different embodiments of the invention, it should be understood that the scope of the invention is defined by the words of the 5 claims mentioned at the end of this patent. The detailed description should be construed as illustrative only and does not describe every possible embodiment of the invention since describing every possible embodiment would be impractical, if not impossible. Numerous alternative modalities can be implemented, using either current technology or technology developed after the filing date of this patent, which would even fall within the scope of the claims defining the invention.
Thus, many modifications and variations can be made in the techniques and structures described and illustrated herein without departing from the spirit and scope of the present invention. Accordingly, it should be understood that the methods and apparatus described herein are illustrative only and are not limited to the scope of the invention.
Contents5
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
114 members in 12 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 98912204 | United States of America | A | |
| 683704 | United States of America | A | |
| 2249304 | United States of America | A | |
| 15221405 | United States of America | A | |
| 2005040940 | United States of America | W |
Members114
| Document | Office | Kind | |
|---|---|---|---|
| CA2526588A1 | Canada | A1 | |
| US2006105739A1 | United States of America | A1 | |
| US2006107306A1 | United States of America | A1 | |
| US2006107328A1 | United States of America | A1 | |
| US2006107329A1 | United States of America | A1 | |
| US2006107335A1 | United States of America | A1 | |
| KR20060054164A | Republic of Korea | A | |
| EP1659530A1 | European Patent Office (EPO) | A1 | |
| US2006112384A1 | United States of America | A1 | |
| WO2006055420A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055421A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055424A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055425A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055427A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006055428A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2005232307A1 | Australia | A1 | |
| CN1783138A | China | A | |
| BRPI0504855A | Brazil | A | |
| JP2006190254A | Japan | A | |
| US2006165005A1 | United States of America | A1 | |
| US2006165227A1 | United States of America | A1 | |
| US2006168664A1 | United States of America | A1 | |
| TW200630885A | Taiwan Province of China | A | |
| TW200631377A | Taiwan Province of China | A | |
| TW200632711A | Taiwan Province of China | A | |
| TW200634584A | Taiwan Province of China | A | |
| US2006227364A1 | United States of America | A1 | |
| WO2006055421A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2006055424A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2006055425A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2007033102A1 | United States of America | A1 | |
| WO2007032974A1 | World Intellectual Property Organization (WIPO) | A1 | |
| RU2005135424A | Russian Federation | A | |
| WO2006055427A3 | World Intellectual Property Organization (WIPO) | A3 | |
| MX2007005655AThis record | Mexico | A | |
| MX2007005657A | Mexico | A | |
| MX2007005660A | Mexico | A | |
| MX2007005662A | Mexico | A | |
| MX2007005656A | Mexico | A | |
| MX2007005659A | Mexico | A | |
| EP1815322A2 | European Patent Office (EPO) | A2 | |
| EP1815327A2 | European Patent Office (EPO) | A2 | |
| EP1815629A2 | European Patent Office (EPO) | A2 | |
| EP1815639A2 | European Patent Office (EPO) | A2 | |
| EP1815640A2 | European Patent Office (EPO) | A2 | |
| EP1815641A2 | European Patent Office (EPO) | A2 | |
| KR20070084257A | Republic of Korea | A | |
| KR20070084258A | Republic of Korea | A | |
| KR20070084259A | Republic of Korea | A | |
| KR20070084260A | Republic of Korea | A | |
| KR20070088633A | Republic of Korea | A | |
| KR20070088634A | Republic of Korea | A | |
| CN101057214A | China | A | |
| CN101057218A | China | A | |
| CN101057435A | China | A | |
| US2007244820A1 | United States of America | A1 | |
| CN101069215A | China | A | |
| EP1815640A4 | European Patent Office (EPO) | A4 | |
| KR20080043831A | Republic of Korea | A | |
| JP2008521089A | Japan | A | |
| JP2008521090A | Japan | A | |
| JP2008521091A | Japan | A | |
| JP2008521092A | Japan | A | |
| JP2008521093A | Japan | A | |
| JP2008521094A | Japan | A | |
| WO2008077051A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006055420A3 | World Intellectual Property Organization (WIPO) | A3 | |
| BRPI0515720A | Brazil | A | |
| EP1952331A1 | European Patent Office (EPO) | A1 | |
| US7421413B2 | United States of America | B2 | |
| CN101263523A | China | A | |
| BRPI0518003A | Brazil | A | |
| CN101292248A | China | A | |
| RU2007117897A | Russian Federation | A | |
| RU2007117899A | Russian Federation | A | |
| RU2007117900A | Russian Federation | A | |
| RU2007117916A | Russian Federation | A | |
| BRPI0518911A2 | Brazil | A2 | |
| BRPI0518912A2 | Brazil | A2 | |
| BRPI0518921A2 | Brazil | A2 | |
| EP1815629A4 | European Patent Office (EPO) | A4 | |
| RU2007122339A | Russian Federation | A | |
| RU2007122344A | Russian Federation | A | |
| WO2008157676A2 | World Intellectual Property Organization (WIPO) | A2 | |
| BRPI0518914A2 | Brazil | A2 | |
| WO2008157676A3 | World Intellectual Property Organization (WIPO) | A3 | |
| JP2009508258A | Japan | A | |
| CN100470467C | China | C | |
| CN101416440A | China | A | |
| WO2006055428A3 | World Intellectual Property Organization (WIPO) | A3 | |
| MX2009005409A | Mexico | A | |
| US7562220B2 | United States of America | B2 | |
| RU2008109229A | Russian Federation | A | |
| CN101558412A | China | A | |
| US7610631B2 | United States of America | B2 | |
| US2010037325A1 | United States of America | A1 | |
| US7669056B2 | United States of America | B2 | |
| EP1815639A4 | European Patent Office (EPO) | A4 | |
| CN101292248B | China | B | |
| EP1815322A4 | European Patent Office (EPO) | A4 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Abandonment or withdrawalAbandonedFA | FA |
Numbers
- Application
- 2007005655
Titles2
- English
- SPECIAL PC MODE ENTERED UPON DETECTION OF UNDESIRED STATE.
- Spanish
- MODO DE PC ESPECIAL INTRODUCIDO DESPUES DE LA DETECCION DE UN ESTADO INDESEADO.
Classification
- CPC, 7
- G06F21/575
- H04L9/32
- G06F21/72
- G06F21/74
- G06F21/87
- G06F21/52
- G06F17/00
- IPC, 1
- H04L9 00