1460935172-b4f9cae6-3c7a-41b9-a8c1-c912ec775e06

1. A method of estimating demographic information associated with a user of a mobile device while preserving privacy of the user based at least in part on a location estimate of the mobile device of the user, the method comprising:
(a) receiving an estimated geographical location of the mobile device of the user;
(b) receiving a time at which the mobile device was at the estimated geographical location;
(c) providing a set of substitute identifiers for a corresponding set of at least one geographical area;
(d) assigning one of the set of substitute identifiers for a geographical area corresponding to the estimated geographical location of the mobile device;
(e) assigning a substitute identifier for the time at which the mobile device was at the estimated geographical location;
(f) retrieving, from a non-transitory computer readable medium, demographic information corresponding to the substitute identifier for the geographical area and the substitute identifier for the time; and
(g) forming a device demographic profile based on the demographic information corresponding to the substitute identifier for the geographical area and the substitute identifier for the time,
wherein the demographic profile stores statistics of the mobile device that serve as demographic information for the user of the mobile device.
2. The method of claim 1, further comprising (h) estimating the received geographical location associated with the mobile device of the user.
3. The method of claim 1, further comprising (h) recording the device demographic profile in a device demographic profile log.
4. The method of claim 3, further comprising (i) estimating demographic information associated with at least one geographical area of the set of geographical areas based on demographic information recorded in the device demographic profile log, wherein the device demographic profile log contains a plurality of device demographic profiles.
5. The method of claim 1, further comprising (h) sending the estimated demographic information associated with the user of the mobile device to the mobile device.
6. The method of claim 1, wherein the substitute identifier for the geographical area corresponding to the geographical location of the mobile device that is assigned identifies a particular set of demographic information.
7. The method of claim 1, wherein the substitute identifier for the geographical area corresponding to the geographical location of the mobile device that is assigned is reduced in specificity relative to the estimated geographical location of the mobile device.
8. The method of claim 1, wherein the substitute identifier for the time at which the mobile device was at the estimated geographic location is a measure of time that is reduced in specificity relative to the time that was received.
9. The method of claim 8, wherein the substitute identifier for the time at which the mobile device was at the estimated geographic location is at least one of (A) a representation of time lacking date information, (B) a time range, and (C) an hour of a week designation.
10. The method of claim 1, wherein the estimating demographic information associated with the user of the mobile device is performed on a separate computer system from a computer system performing any one or more of steps (a) through (e).
11. The method of claim 10, wherein the separate computer system, relative to the computer system performing any one or more of steps (a) through (e), is as least one of (A) maintained in a separate network, (B) maintained in a separate building, and (C) maintained by a separate operational entity.
12. An computing system configured to estimate demographic information associated with a user of a mobile device while preserving privacy of the user based at least in part on a location estimate of the mobile device of the user, the method comprising:
a location server configured to determine an estimated geographical location of the mobile device of the user; and
a demographic server including:
a device demographics profile logging module configured to receive a time at which the mobile device was at the estimated geographical location, assign a substitute identifier for a geographical area corresponding to the estimated geographical location of the mobile device, and assign a substitute identifier for the time at which the mobile device was at the estimated geographical location,
a location demographics profile retrieval module configured to retrieve demographic information corresponding to the substitute identifier for the geographical area and the substitute identifier for the time, and
a location demographics profile engine configured to form a device demographic profile based on demographic information corresponding to the substitute identifier for the geographical area and the substitute identifier for the time,

wherein the demographic profile stores statistics of the mobile device that serve as demographic information for the user of the mobile device.
13. The computing system of claim 12, wherein the demographic server further comprises a storage device storing a device demographic profile log in which the device demographic profile associated with the user of the mobile device is recorded.
14. The computing system of claim 12, wherein the location demographics profile engine is further configured to adjust the demographic information corresponding to the substitute identifier for the geographical area and the substitute identifier for the time based on device demographic profiles associated with users of a plurality of mobile devices that visited the geographical area.
15. The computing system of claim 12, wherein the location demographics profile engine is further configured to send the device demographic profile to the mobile device.
16. The computing system of claim 12, wherein the substitute identifier for the geographical area corresponding to the geographical location of the mobile device is reduced in specificity relative to the estimated geographical location of the mobile device.
17. The computing system of claim 12, wherein the substitute identifier for the time at which the mobile device was at the estimated geographic location is a measure of time that is reduced in specificity relative to the time that was received.
18. A non-transitory computer readable medium having executable instructions stored thereon, the executable instruction when executed by one or more processors of one or more computing systems operable to:
determine an estimated geographical location of a mobile device of a user;
determine a time at which the mobile device was at the estimated geographical location;
assign a substitute identifier for a geographical area corresponding to the estimated geographical location of the mobile device;
assign a substitute identifier for the time at which the mobile device was at the estimated geographical location;
retrieve demographic information corresponding to the substitute identifier for the geographical area and the substitute identifier for the time; and
form a device demographic profile based on the demographic information corresponding to the substitute identifier for the geographical area and the substitute identifier for the time,
wherein the demographic profile stores statistics of the mobile device that serve as demographic information for the user of the mobile device.
19. The non-transitory computer-readable medium of claim 18, wherein the executable instructions when executed are further operable to:
adjust the demographic information corresponding to the substitute identifier for the geographical area and the substitute identifier for the time based on device demographic profiles associated with users of a plurality of mobile devices that visited the geographical area.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A removable peripheral apparatus for enabling a subscription-based computing system comprising:
an execution unit including a processor;
a private memory including an encrypted application;
a computing system interface; and
a cryptographic unit including a secure storage, the secure storage including a number of metering units and a computer-readable medium having computer-executable instructions comprising:
a communication module for routing messages and data from the execution unit through the computing system interface to the computing system;
a decryption module for routing data related to the encrypted application through the cryptographic unit to the execution unit to thereby transform the encrypted application into executable data for use by the computing system; and
a metering module for decrementing the number of metering units during execution of the encrypted application by the computing system.
2. The apparatus of claim 1, wherein the encrypted application is at least one of an operating system, a basic inputoutput system, a software application dependent upon the operating system, and a data file associated with the software application.
3. The apparatus of claim 1, wherein the secure storage includes at least one of firmware, security certificates associated with the encrypted application, encryption keys, and a trusted clock.
4. The apparatus of claim 1, further comprising a public non-volatile memory capable of storing at least one of an unencrypted application, a data file associated with the unencrypted application, and a data file associated with the encrypted application.
5. The apparatus of claim 1, further comprising an indicator, wherein if the metering module decrements the number of metering units to a number below a threshold, the execution unit activates the indicator.
6. The apparatus of claim 1, wherein the computing system interface includes a male type-A USB connector.
7. A system including a secure computing device in communication with a computer, the secure computing device including a protected processor for executing computer executable code, a secure memory for storing metered access time, and computer executable code, a cryptographic core and an inputoutput circuit, the protected processor physically configured to execute computer executable code for:
determining if the metered access time is below a threshold;
communicating an encrypted application from the secure memory to the cryptographic core;
decrypting the encrypted application at the cryptographic core;
communicating the decrypted application to the computer through the inputoutput circuit;
executing the decrypted application on the computer; and
decrementing the metered access time while the decrypted application executes on the computer.
8. The system of claim 7, further comprising activating an indicator light of the secure computing device if the metered access time is below a threshold.
9. The system of claim 7, further comprising a server in communication with the secure computing device and the computer, the server communicating an amount of metered access time to the secure computing device if the amount of metered access time is below a threshold.
10. The system of claim 7, wherein the inputoutput circuit is in communication with a male type-A USB connector.
11. The system of claim 7, wherein the secure memory includes at least one of read-only memory and flash memory.
12. The system of claim 7, wherein the secure computing device includes a smartcard.
13. The system of claim 7, wherein the encrypted application is at least one of an operating system, a basic inputoutput system, a software application dependent upon the operating system, a Softgrid\xae application, and a data file associated with the software application.
14. The system of claim 7, wherein the secure memory includes at least one of firmware, security certificates associated with the encrypted application, encryption keys, and a trusted clock.
15. The system of claim 7, wherein secure computing device comprises a universal serial bus flash device.
16. The system of claim 7, further comprising computer executable code for loading a degraded operating system if the metered access time is below a threshold.
17. A method for enabling a metered computing environment comprising:
determining an amount of access data stored on a secure computing device, the secure computing device including a secure memory including an encrypted application, a cryptographic core, and a computing system interface;
decrypting the encrypted application at the cryptographic core;
executing the decrypted application at a computer through the computing system interface;
decrementing an amount of access data from the secure computing device while the decrypted application is executing at the computer; and
saving the decremented amount of access data to the secure memory.
18. The method of claim 17, further comprising loading a degraded operating system if the amount of access data stored on the secure computing device is below a threshold level.
19. The method of claim 17, further comprising displaying a user interface if the amount of access data stored on the secure computing device is below a threshold level;
communicating an additional amount of access data through the user interface.
20. The method of claim 17, wherein the access data comprises at least one of an amount of time, a number of uses, a number of pages associated with the decrypted application, a number of actions associated with the decrypted application, or a decrypted application file size.