Packet filtering in a NIC to control antidote loading
    101.
    发明授权
    Packet filtering in a NIC to control antidote loading 有权
    在NIC中进行包过滤以控制解毒剂加载

    公开(公告)号:US07752659B2

    公开(公告)日:2010-07-06

    申请号:US11057795

    申请日:2005-02-14

    IPC分类号: G06F17/00

    CPC分类号: H04L63/145

    摘要: A method and system is described for selectively downloading antidotes onto a client computer. The client computer is connected via a network interface card (NIC) to a network that contains an anti-virus server. The NIC is initially logically isolated from the client computer, thus permitting the NIC to autonomously examine packets to and from the client computer and the network. The NIC selectively accepts packets only from trusted Internet Protocol (IP) addresses that conform to a security format such as Internet Protocol Security (IPSec).

    摘要翻译: 描述了用于有选择地将解毒剂下载到客户端计算机上的方法和系统。 客户端计算机通过网络接口卡(NIC)连接到包含防病毒服务器的网络。 NIC最初在逻辑上与客户端计算机隔离,从而允许NIC自主地检查到客户端计算机和网络的数据包。 NIC选择性地仅接收来自符合诸如因特网协议安全(IPSec)之类的安全格式的受信任的因特网协议(IP)地址的分组。

    SLATE COMPUTER WITH TACTILE HOME KEYS

    公开(公告)号:US20100090963A1

    公开(公告)日:2010-04-15

    申请号:US12248208

    申请日:2008-10-09

    IPC分类号: G06F3/041

    摘要: Fingertip-sized discrete areas are provided on a slate computer and have different tactile characteristics than the remainder of the surface on which they are disposed. The discrete areas are arranged to mimic home keys of a keyboard and each discrete area corresponds to a respective home key. In this way, a user is given tactile feedback of when fingers are properly placed in the home position, with home key finger placement triggering the presentation of a full keyboard on screen. Other embodiments do not use tactilely distinct keys, with simultaneous placement of two or more fingers on the computer triggering display of the virtual keyboard.

    摘要翻译: 指尖大小的离散区域设置在平板计算机上,并且具有与其所在的表面的其余部分不同的触觉特性。 离散区域被布置为模拟键盘的主键,并且每个离散区域对应于相应的归属键。 以这种方式,给用户提供当手指正确地放置在原始位置时的触觉反馈,家用键指放置触发屏幕上的全键盘的呈现。 其他实施例不使用触觉不同的键,同时在计算机上同时放置两个或更多个手指触发虚拟键盘的显示。

    Blocking Computer System Ports on Per User Basis
    104.
    发明申请
    Blocking Computer System Ports on Per User Basis 有权
    阻止每个用户基础的计算机系统端口

    公开(公告)号:US20100083366A1

    公开(公告)日:2010-04-01

    申请号:US12243762

    申请日:2008-10-01

    IPC分类号: G06F9/00 G06F21/00

    CPC分类号: G06F21/6218

    摘要: An approach is provided that receives a user identifier from a user of the information handling system. The user identifier can include a username as well as a user authentication code, such as a password. Hardware settings that correspond to the user identifier are retrieved from a nonvolatile memory. Hardware devices, such as ports (e.g., USB controller), network interfaces, storage devices, and boot sequences, are configured using the retrieved hardware settings. After the hardware devices have been configured to correspond to the identified user, an operating system is booted.

    摘要翻译: 提供一种从信息处理系统的用户接收用户标识符的方法。 用户标识符可以包括用户名以及诸如密码的用户认证码。 从非易失性存储器检索对应于用户标识符的硬件设置。 使用检索的硬件设置来配置诸如端口(例如,USB控制器),网络接口,存储设备和引导顺序的硬件设备。 在将硬件设备配置为对应于所识别的用户之后,引导操作系统。

    Virtual USB communications port
    105.
    发明授权
    Virtual USB communications port 有权
    虚拟USB通信端口

    公开(公告)号:US07675937B2

    公开(公告)日:2010-03-09

    申请号:US12061899

    申请日:2008-04-03

    IPC分类号: H04J3/22

    CPC分类号: G06F13/24

    摘要: A method and system for accessing a remote real communication port (“COM port”) from a server blade in a server blade chassis by creating a virtual COM port in the server blade. A basic input/output system (BIOS) controller monitors an internal COM port in the server blade for communication traffic. Upon detecting the communication traffic, the BIOS controller reroutes the traffic to a virtual USB COM port created by the BIOS controller chipset. The virtual USB COM port directs the communication traffic to an internal universal serial bus (USB) device in the server blade. The USB device then forwards the traffic to an Ethernet media access controller (MAC) input/output (I/O) on a sideband channel to a remote system, which passes the communication traffic to a real COM port in the remote system.

    摘要翻译: 一种通过在服务器刀片服务器中创建虚拟COM端口从服务器刀片服务器机箱中的服务器刀片访问远程实际通信端口(“COM端口”)的方法和系统。 基本的输入/输出系统(BIOS)控制器监视服务器刀片中的内部COM端口以实现通信流量。 在检测到通信流量时,BIOS控制器将流量重新路由到由BIOS控制器芯片组创建的虚拟USB COM端口。 虚拟USB COM端口将通信流量引导到服务器刀片中的内部通用串行总线(USB)设备。 然后,USB设备将流量转发到边带通道上的以太网媒体访问控制器(MAC)输入/输出(I / O)到远程系统,远程系统将通信流量传递到远程系统中的真实COM端口。

    System and Method for Securely Updating Firmware Devices by Using a Hypervisor
    107.
    发明申请
    System and Method for Securely Updating Firmware Devices by Using a Hypervisor 审中-公开
    使用管理程序安全更新固件设备的系统和方法

    公开(公告)号:US20080244553A1

    公开(公告)日:2008-10-02

    申请号:US11692283

    申请日:2007-03-28

    IPC分类号: G06F9/44

    CPC分类号: G06F21/572

    摘要: A system, method, and program product is provided that receives and processes a firmware update at a computer system. The computer system is executing a hypervisor and one or more guest operating systems, and the firmware update corresponds to a hardware device accessible by the computer system. The hardware device is a type that is programmed using an updateable firmware. The hypervisor operating in the computer system processes the received firmware update by first inhibiting use of the device by each of the guest operating systems. After the guest operating systems have been inhibited from using the device, the firmware in the device is upgraded by the hypervisor using the received firmware update. After the firmware has been upgraded, each of the guest operating systems is allowed use of the device.

    摘要翻译: 提供了一种在计算机系统接收和处理固件更新的系统,方法和程序产品。 计算机系统正在执行管理程序和一个或多个客户操作系统,并且固件更新对应于计算机系统可访问的硬件设备。 硬件设备是使用可更新固件编程的类型。 在计算机系统中操作的管理程序通过首先禁止每个客户操作系统使用该设备来处理所接收的固件更新。 在客户机操作系统被禁止使用设备之后,设备中的固件由管理程序使用接收到的固件更新进行升级。 在升级固件之后,允许每个客户机操作系统使用该设备。

    Polled automatic virus fix
    108.
    发明授权
    Polled automatic virus fix 有权
    轮询自动病毒修复

    公开(公告)号:US07353428B2

    公开(公告)日:2008-04-01

    申请号:US10848796

    申请日:2004-05-19

    IPC分类号: G06F11/00

    CPC分类号: G06F8/65 G06F21/57

    摘要: A client computer is connected via a network to an anti-virus server and polls the server for indication that an anti-virus needs to be immediately downloaded from the anti-virus server. The client computer disengages from the network, and re-establishes a link with only the trusted anti-virus server. The anti-virus fix is installed, the client computer re-booted, and the client computer is then allowed to reconnect to the full network. If the client's primary operating system (OS) is infected, a secondary OS in the client computer performs the anti-virus download and execution. The disengagement from the network is performed by applying a filter in a network interface card (NIC) driver by the primary OS, the secondary OS, a service processor (SP), or by a virtual machine manager (VMM), depending on which is available at the client computer.

    摘要翻译: 客户端计算机通过网络连接到防病毒服务器,并轮询服务器以指示需要从防病毒服务器立即下载防病毒。 客户端计算机与网络脱离联系,并重新建立与唯一可信任的防病毒服务器的链接。 安装了防病毒修复程序,客户端计算机重新启动,然后允许客户端计算机重新连接到完整的网络。 如果客户端的主操作系统(OS)被感染,客户端计算机中的辅助操作系统将执行防病毒下载和执行。 通过由主OS,辅助OS,服务处理器(SP)或虚拟机管理器(VMM)在网络接口卡(NIC)驱动器中应用过滤器来执行从网络的脱离,这取决于哪个是 在客户端计算机上可用。

    Method and system for configuring an operating system in a computer system
    110.
    发明授权
    Method and system for configuring an operating system in a computer system 有权
    在计算机系统中配置操作系统的方法和系统

    公开(公告)号:US07257701B2

    公开(公告)日:2007-08-14

    申请号:US09990003

    申请日:2001-11-21

    IPC分类号: G06F15/00

    摘要: A method and system for configuring an operating system in a computer system including language selection during bootup rather than at manufacture. A first aspect of the method and system comprises providing a plurality of operating system images in the computer system, each of the plurality of operating system images being based upon a particular language, selecting one of the plurality of operating system images based on the language supported by the computer system and loading the selected operating system image into the computer system. A second aspect of the method and system comprises providing a language-independent operating system image in the computer system, determining a language supported by the computer system, loading the language-independent operating system image into the computer system, and associating the language supported by the computer system with the language-independent operating system image.

    摘要翻译: 一种用于在计算机系统中配置操作系统的方法和系统,包括在启动期间而不是制造期间的语言选择。 所述方法和系统的第一方面包括在所述计算机系统中提供多个操作系统图像,所述多个操作系统图像中的每一个基于特定语言,基于所支持的语言来选择所述多个操作系统图像中的一个 通过计算机系统将所选择的操作系统映像加载到计算机系统中。 该方法和系统的第二方面包括在计算机系统中提供与语言无关的操作系统图像,确定由计算机系统支持的语言,将与语言无关的操作系统映像加载到计算机系统中,以及将由 计算机系统具有与语言无关的操作系统映像。