Reducing the boot time of a TCPA based computing system when the Core Root of Trust Measurement is embedded in the boot block code
    91.
    发明申请
    Reducing the boot time of a TCPA based computing system when the Core Root of Trust Measurement is embedded in the boot block code 失效
    当信任测度核心嵌入在引导块代码中时,减少基于TCPA的计算系统的启动时间

    公开(公告)号:US20050108564A1

    公开(公告)日:2005-05-19

    申请号:US10712237

    申请日:2003-11-13

    IPC分类号: G06F12/14 G06F21/00 H04L9/00

    CPC分类号: G06F21/572 G06F21/575

    摘要: A method, computer program product and system for reducing the boot time of a TCPA based computing system. A flash memory in the TCPA based computing system may include a register comprising bits configured to indicate whether the segments of the flash memory have been updated. The flash memory may further include a table configured to store measurements of the segments of the flash memory. The flash memory may further include a boot block code that includes a Core Root of Trust for Measurement (CRTM). The CRTM may read the bits in the register to determine if any of the segments of the flash memory have been updated. The CRTM may further obtain the measurement values in the table for those segments that store the POST BIOS code that have not been updated thereby saving time from measuring the POST BIOS code and consequently reducing the boot time.

    摘要翻译: 一种用于减少基于TCPA的计算系统的启动时间的方法,计算机程序产品和系统。 基于TCPA的计算系统中的闪速存储器可以包括寄存器,其包括被配置为指示闪速存储器的段是否已被更新的位。 闪存可以进一步包括被配置为存储闪存的片段的测量的表。 闪速存储器还可以包括引导块代码,其包括用于测量的信任核心根(CRTM)。 CRTM可以读取寄存器中的位,以确定闪存中的任何段是否已更新。 CRTM可以进一步获得存储POST BIOS代码的那些片段的表中的测量值,从而节省了测量POST BIOS代码的时间,从而减少了引导时间。

    Personal computer ROM scan startup protection
    92.
    发明授权
    Personal computer ROM scan startup protection 失效
    个人电脑ROM扫描启动保护

    公开(公告)号:US6098171A

    公开(公告)日:2000-08-01

    申请号:US52733

    申请日:1998-03-31

    摘要: Provides management tools for a System Owner to assure that a personal computer system is secured against access by an unauthorized user by foreclosing the possibility of circumventing a system's security protection during an adapter ROM scan. If security function, such as that for C2 functionality, is enabled, prior to the adapter ROM Scan for the system, the POST code detects whether or not disabling of the keyboard during adapter ROM Scan is enabled. If enabled, the keyboard is disabled or locked prior to adapter ROM Scan. On some systems, the security function may not be used and, the system does not consider password protection for the adapter utilities. If however, the security functionality of the system is enabled, the POST code will continue to enable the password protection for the adapter ROM Scan. Once the input device, e.g., keyboard, is disabled the adapter ROM scan will begin. Upon completion of the adapter ROM scan, the input device will be enabled and progress will continue through POST.

    摘要翻译: 为系统所有者提供管理工具,以确保个人计算机系统受到未经授权的用户的访问,以防止在适配器ROM扫描过程中避免系统的安全保护。 如果启用安全功能(例如C2功能),则在系统的适配器ROM扫描之前,POST代码将检测是否启用了适配器ROM扫描期间禁用键盘。 如果启用,键盘在适配器ROM扫描之前被禁用或锁定。 在某些系统上,可能不使用安全功能,并且系统不会考虑为适配器实用程序提供密码保护。 然而,如果启用了系统的安全功能,POST代码将继续为适配器ROM扫描启用密码保护。 一旦输入设备(例如键盘)被禁用,则适配器ROM扫描将开始。 完成适配器ROM扫描后,将启用输入设备,并通过POST继续进行。

    System and method to update firmware on a hybrid drive
    93.
    发明授权
    System and method to update firmware on a hybrid drive 有权
    用于更新混合驱动器上的固件的系统和方法

    公开(公告)号:US09354857B2

    公开(公告)日:2016-05-31

    申请号:US12051301

    申请日:2008-03-19

    IPC分类号: G06F21/00 G06F9/445 G06F3/06

    摘要: A system, method, and program product is provided that updates the firmware on a hybrid drive by reserving a memory area within the hybrid disk drive's nonvolatile memory buffer. The firmware update is then stored in the reserved memory area. The next time the platters of the hybrid disk drive spin up, the firmware update that is stored in the reserved memory area is identified. The identified update is then written to a firmware memory of a firmware that controls the operation of the hybrid drive. In one embodiment, the update is written to the firmware memory by flashing the firmware's memory. After the firmware is updated, the hybrid drive is reset. Resetting of the hybrid drive includes executing the updated firmware.

    摘要翻译: 提供了一种系统,方法和程序产品,其通过在混合磁盘驱动器的非易失性存储器缓冲器内预留存储器区域来更新混合驱动器上的固件。 然后将固件更新存储在保留的存储器区域中。 混合磁盘驱动器的下一次盘旋时,识别存储在保留存储器区域中的固件更新。 然后将所识别的更新写入控制混合驱动器的操作的固件的固件存储器。 在一个实施例中,通过闪烁固件的存储器将更新写入固件存储器。 固件更新后,混合驱动器将被复位。 混合驱动器的复位包括执行更新的固件。

    Method and apparatus for updating firmware on a storage device
    95.
    发明授权
    Method and apparatus for updating firmware on a storage device 有权
    用于更新存储设备上的固件的方法和装置

    公开(公告)号:US09063816B2

    公开(公告)日:2015-06-23

    申请号:US12701148

    申请日:2010-02-05

    IPC分类号: G06F9/44 G06F9/445 G06F11/14

    CPC分类号: G06F8/65 G06F11/1433

    摘要: A method, apparatus, and system are disclosed for updating firmware on a storage device. The apparatus includes a detection module and an update module. The detection module detects, during a boot sequence, an indicator of an available update of firmware controlling a storage device. The available update is stored on non-volatile storage media of the storage device. The update module updates the storage device with the available update in response to the detection module detecting the indicator of the available update.

    摘要翻译: 公开了一种用于更新存储设备上的固件的方法,装置和系统。 该装置包括检测模块和更新模块。 检测模块在引导顺序期间检测控制存储设备的固件的可用更新的指示符。 可用的更新存储在存储设备的非易失性存储介质上。 响应于检测模块检测到可用更新的指示符,更新模块用可用更新来更新存储设备。

    Method and apparatus for sharing an integrity security module in a dual-environment computing device
    96.
    发明授权
    Method and apparatus for sharing an integrity security module in a dual-environment computing device 有权
    在双环境计算设备中共享完整性安全模块的方法和装置

    公开(公告)号:US08943329B2

    公开(公告)日:2015-01-27

    申请号:US12748787

    申请日:2010-03-29

    IPC分类号: G06F21/00 G06F9/52 G06F21/57

    CPC分类号: G06F9/52 G06F21/575

    摘要: A method and apparatus are disclosed for sharing an integrity security module in a dual-environment computing device. The apparatus include an integrity security module, one or more processors, a detection module and a regeneration module. The one or more processors may have access to the integrity security module and may operate in two distinct operating environments of a dual-environment computing device. The detection module may detect, during an initialization sequence, a power state transition of an operating environment of the dual-environment computing device. The regeneration module may regenerate one or more integrity values from a stored integrity metric log in response to detecting the power state transition of the operating environment of the dual-environment computing device.

    摘要翻译: 公开了用于在双环境计算设备中共享完整性安全模块的方法和装置。 该装置包括完整性安全模块,一个或多个处理器,检测模块和再生模块。 一个或多个处理器可以访问完整性安全模块,并且可以在双环境计算设备的两个不同的操作环境中操作。 检测模块可以在初始化序列期间检测双环境计算设备的操作环境的功率状态转换。 响应于检测双环境计算设备的操作环境的功率状态转换,再生模块可以从存储的完整性度量日志重新生成一个或多个完整性值。

    APPARATUS AND METHOD FOR GESTURE INPUT IN A DYNAMICALLY ZONED ENVIRONMENT
    97.
    发明申请
    APPARATUS AND METHOD FOR GESTURE INPUT IN A DYNAMICALLY ZONED ENVIRONMENT 有权
    动态区域输入的装置和方法

    公开(公告)号:US20120169618A1

    公开(公告)日:2012-07-05

    申请号:US12984487

    申请日:2011-01-04

    IPC分类号: G06F3/041

    摘要: An apparatus and method are disclosed for dynamically zoning a touch screen environment. The apparatus includes an identification module detecting a number of users around a perimeter of a display, a zoning module generating, via a processor, a plurality of user zones in response to the number of users detected, and a positioning module orienting a gesture zone, within each of the plurality of user zones, in relation to a corresponding user. The method includes detecting a number of users around a perimeter of a display, generating, via a processor, a plurality of user zones in response to the number of users detected, and orienting a gesture zone, within each of the plurality of user zones, in relation to a corresponding user.

    摘要翻译: 公开了用于动态地划分触摸屏环境的装置和方法。 该装置包括:识别模块,用于检测围绕显示器周边的多个用户;分区模块,响应于检测到的用户数量,经由处理器生成多个用户区域;以及定位模块,定向姿势区域, 在多个用户区域的每一个内,相对于相应的用户。 该方法包括检测围绕显示器的周边的用户数量,响应于检测到的用户的数量并且在多个用户区域的每一个内定向手势区域,经由处理器生成多个用户区域, 相对于相应的用户。

    Method and Apparatus for Updating Firmware on a Storage Device
    98.
    发明申请
    Method and Apparatus for Updating Firmware on a Storage Device 有权
    用于更新存储设备上的固件的方法和装置

    公开(公告)号:US20110197185A1

    公开(公告)日:2011-08-11

    申请号:US12701148

    申请日:2010-02-05

    CPC分类号: G06F8/65 G06F11/1433

    摘要: A method, apparatus, and system are disclosed for updating firmware on a storage device. The apparatus includes a detection module and an update module. The detection module detects, during a boot sequence, an indicator of an available update of firmware controlling a storage device. The available update is stored on non-volatile storage media of the storage device. The update module updates the storage device with the available update in response to the detection module detecting the indicator of the available update.

    摘要翻译: 公开了一种用于更新存储设备上的固件的方法,装置和系统。 该装置包括检测模块和更新模块。 检测模块在引导顺序期间检测控制存储设备的固件的可用更新的指示符。 可用的更新存储在存储设备的非易失性存储介质上。 响应于检测模块检测到可用更新的指示符,更新模块用可用更新来更新存储设备。

    Computer implemented method, system and computer program product for controlling software entitlement
    99.
    发明授权
    Computer implemented method, system and computer program product for controlling software entitlement 有权
    计算机实现方法,系统和计算机程序产品,用于控制软件授权

    公开(公告)号:US07934214B2

    公开(公告)日:2011-04-26

    申请号:US11394792

    申请日:2006-03-31

    IPC分类号: G06F9/445 H04L29/06

    CPC分类号: G06F8/61

    摘要: Computer implemented method, system and computer program product for controlling software entitlement. A computer implemented method for controlling software entitlement includes receiving a request to install a software item on a designated machine. A determination is made if the designated machine is of a machine type authorized for installation of the software item. If the designated machine is of a machine type authorized for installation of the software item, a determination is made, using stored configuration data, if at least one additional criterion specified for entitlement to install the software item on the designated machine is satisfied using stored configuration data. If the at least one additional criterion specified for entitlement to install the software item on the designated machine is satisfied, installation of the software item on the designated machine is enabled in accordance with the at least one additional criterion.

    摘要翻译: 计算机实现方法,系统和计算机程序产品,用于控制软件授权。 用于控制软件授权的计算机实现的方法包括在指定的机器上接收安装软件项目的请求。 如果指定的机器是被授权安装软件项目的机器类型,则确定。 如果指定的机器是被授权安装软件项目的机器类型,则使用存储的配置数据确定如果使用存储的配置满足在指定机器上安装软件项目的权利所指定的至少一个附加标准 数据。 如果满足指定用于在指定机器上安装软件项目的权利的至少一个附加标准,则根据至少一个附加标准启用软件项目在指定机器上的安装。

    System and method for protecting disk drive password when BIOS causes computer to leave suspend state
    100.
    发明授权
    System and method for protecting disk drive password when BIOS causes computer to leave suspend state 有权
    当BIOS使计算机挂起状态时,保护磁盘驱动器密码的系统和方法

    公开(公告)号:US07814321B2

    公开(公告)日:2010-10-12

    申请号:US11788654

    申请日:2007-04-19

    IPC分类号: H04L9/32

    CPC分类号: G06F21/80

    摘要: To unlock a HDD when a computer is in the suspend state, at both BIOS and the HDD a secret is combined with a password to render a new one-time password. BIOS sends its new one-time password to the HDD which unlocks itself only if a match is found. The new one-time password is then saved as an “old” password for subsequent combination with the secret when coming out of subsequent suspend states. In this way, if a computer is stolen the thief cannot sniff the bus between BIOS and the HDD to obtain a password that is of any use once the computer ever re-enters the suspend state.

    摘要翻译: 要在计算机处于挂起状态时解锁HDD,在BIOS和HDD两者中,将密码与密码相结合以呈现新的一次性密码。 BIOS将其新的一次性密码发送到HDD,只有在找到匹配时才会自动解锁。 然后将新的一次性密码保存为“旧”密码,以便随后从后续挂起状态中与秘密组合。 以这种方式,如果计算机被盗,小偷不能在BIOS和HDD之间嗅探总线,以获得一旦计算机重新进入暂停状态就可以使用的密码。