Computer hosting multiple secure execution environments
A plurality of secure execution environments may be used to bind individual components and a computer to that computer or to blind computers to a given system. The secure execution environment may be operable to evaluate characteristics of the computer, such as memory usage, clock validity, and pay-per-use or subscription purchased data, to determine compliance to an operating policy. Each of the secure execution environments may exchange information regarding its own evaluation of compliance to the operating policy. When one or more secure execution environments determines noncompliance or when communication between secure execution environments cannot be established a sanction may be imposed, limiting functionality or disabling the computer.
1 . A computer adapted for use including limited function operating modes comprising:
a processor;
a first secure execution environment communicatively coupled to the processor and operable to monitor and enforce compliance with an operating policy; and
a second secure execution environment communicatively coupled to the first secure execution environment and operable to monitor and enforce compliance with the operating policy and communicatively coupled to the first secure execution environment, wherein the second secure execution environment develops an assessment of compliance with the operating policy and sends a signal including the assessment to the first secure execution environment.
2 . The computer of claim 1 , wherein the signal further comprises a value corresponding to a metering value associated with one of a subscription status and a pay-per-use status.
3 . The computer of claim 1 , wherein the first secure execution environment maintains a stored value representing a usage availability.
4 . The computer of claim 1 , wherein the first secure execution environment receives the signal from the second secure execution environment and imposes a sanction on the computer when the signal indicates non-compliance with the policy.
5 . The computer of claim 1 , wherein the first secure execution environment receives the signal from the second secure execution environment and does not impose a sanction on the computer when the signal indicates non-compliance with the policy when the first secure execution environment determines compliance with the policy.
6 . The computer of claim 1 , wherein the first secure execution environment measures an interval between signals from the second secure execution environment and imposes a sanction on the computer when the interval exceeds a limit.
7 . The computer of claim 1 , wherein the first secure execution environment cryptographically verifies the signal from the second secure execution environment and imposes a sanction on the computer when the signal fails the verification.
8 . The computer of claim 1 , wherein the second secure execution environment imposes a sanction on the computer when the second secure execution environment determines non-compliance with the policy and a cryptographically verifiable veto message is not received from the first secure execution environment.
9 . The computer of claim 1 , further comprising an additional plurality of secure execution environments.
10 . The computer of claim 9 , wherein a majority vote of all secure execution environments determines when to sanction the computer.
11 . The computer of claim 10 , wherein the first secure execution environment receives a policy update to exclude one of the plurality of secure execution environments from the majority vote.
12 . The computer of claim 9 , further comprising a plurality of functional components wherein at least one of the first, second and additional plurality of secure execution environments are hosted in at least one of the plurality of functional components of the computer.
13 . The computer of claim 12 , wherein the first, second and additional plurality of secure execution environments are communicatively coupled using their respective host functional component's data connection.
14 . The computer of claim 12 , wherein the first, second and additional plurality of secure execution environments are communicatively coupled over a dedicated data connection.
15 . A method of monitoring and enforcing compliance to an operating policy on a computer using a plurality of secure execution environments comprising:
establishing cryptographically secured communication among the plurality of secure execution environments;
monitoring compliance to a respective operating policy at each of the plurality of secure execution environments;
determining when the computer is not in compliance at least one of the respective operating policies; and
imposing a sanction on the computer when the computer is not in compliance with at least one of the respective operating policies.
16 . The method of claim 15 , wherein determining when the computer is not in compliance with the operating policy comprises receiving a vote from at least one of the plurality of secure execution environments and determining that the computer is not in compliance when a vote indicating non-compliance is received according to one of a single secure execution environment, a majority of secure execution environments, and a consensus of secure execution environments.
17 . The method of claim 15 , wherein determining when the computer is not in compliance with the operating policy comprises receiving a vote from each of the plurality of secure execution environments and determining that the computer is not in compliance when the vote from each of the plurality of secure execution environments is weighted and the total weighted vote exceeds a threshold.
18 . The method of claim 15 , further comprising designating one of the secure execution environments as a master and the remainder as slaves, wherein the master can override a determination of non-compliance made by one or more of the slaves.
19 . A method of binding a set of computer components to a system comprising:
installing in each of the set of computer components a secure execution environment;
cataloging the secure execution environment of each of the computer components in each of the secure execution environments;
periodically determining that each of the cataloged secure execution environments of each of the respective computer components is present;
imposing a sanction when a secure execution environment determines that one or more of the other cataloged secure execution environments is not present.
20 . The method of claim 19 , wherein each of the computer components is in a separate, networked computer and the system is a collection of computers.