HOME IMAGE CONTENT SECURELY ISOLATED FROM CORPORATE IT
    122.
    发明申请
    HOME IMAGE CONTENT SECURELY ISOLATED FROM CORPORATE IT 有权
    家庭图像内容安全从企业分离

    公开(公告)号:US20110088082A1

    公开(公告)日:2011-04-14

    申请号:US12578462

    申请日:2009-10-13

    CPC classification number: G06F21/575 G06F21/53

    Abstract: An exemplary apparatus includes one or more processors, volatile memory, a storage drive and circuitry configured to establish a network connection and to attempt to send credentials via an established network connection. Such an apparatus further includes circuitry configured, responsive to authentication failure after an attempt to send credentials, to release an implemented security policy and load an operating system stored on the storage drive, and, responsive to an attempt to send credentials, to maintain an implemented security policy and to use an operating system exposed via an established network connection and associated with the sent credentials Such an apparatus optionally includes circuitry configured to implement a security policy that isolates at least a portion of a local storage drive. Various other apparatuses, systems, methods, etc., are also disclosed.

    Abstract translation: 示例性设备包括一个或多个处理器,易失性存储器,存储驱动器和被配置为建立网络连接并且尝试经由建立的网络连接发送凭证的电路。 这样的装置还包括:在尝试发送凭证之后,响应于认证失败,释放所实施的安全策略并加载存储在存储驱动器上的操作系统,以及响应于尝试发送凭证来维护实现的电路 安全策略,并且使用通过建立的网络连接公开并与所发送的证书相关联的操作系统。这种装置可选地包括被配置为实现隔离本地存储驱动器的至少一部分的安全策略的电路。 还公开了各种其它装置,系统,方法等。

    Techniques for preventing damage to a portable device
    123.
    发明授权
    Techniques for preventing damage to a portable device 有权
    防止对便携式设备造成损坏的技术

    公开(公告)号:US07782201B2

    公开(公告)日:2010-08-24

    申请号:US12028556

    申请日:2008-02-08

    CPC classification number: H04M1/72527 H04M2250/12

    Abstract: A technique for preventing damage to a portable device includes detecting movement of a portable device and determining whether a port of the portable device is attached to an external device. When the external device is attached to the port, a notification is provided to a user of the portable device that the external device requires detachment from the portable device (e.g., assuming that the notification is not masked).

    Abstract translation: 用于防止对便携式设备的损坏的技术包括检测便携式设备的移动并确定便携式设备的端口是否附接到外部设备。 当外部设备附接到端口时,向便携式设备的用户提供通知,外部设备需要从便携式设备拆卸(例如,假设通知未被屏蔽)。

    APPARATUS, SYSTEM, AND METHOD FOR IMPROVING USER BOOT VIA A STORAGE AREA NETWORK
    125.
    发明申请
    APPARATUS, SYSTEM, AND METHOD FOR IMPROVING USER BOOT VIA A STORAGE AREA NETWORK 有权
    用于通过存储区域网络改进用户引导的装置,系统和方法

    公开(公告)号:US20100191946A1

    公开(公告)日:2010-07-29

    申请号:US12361529

    申请日:2009-01-28

    CPC classification number: H04L67/1097 G06F3/06 G06F9/4416 G06F9/445 G06F17/30

    Abstract: An apparatus, system, and method are disclosed for remotely booting a client from a storage area network (“SAN”). A connection module enables a client, such as a diskless client, to connect to two or more storage area networks (“SANs”), the SANs belonging to a group of redundant SANs, each SAN in the group redundantly storing at least a portion of substantially identical operating system data for the client. The boot module enables the client to remotely boot an operating system from the two or more redundant SANs. The boot module makes at least one read request to each of the two or more connected SANs, each read request configured to retrieve a disparate portion of the operating system data for loading the operating system onto the client. The boot module loads the operating system onto the client using a combination of data retrieved from the two or more connected SANs.

    Abstract translation: 公开了用于从存储区域网络(“SAN”)远程引导客户端的装置,系统和方法。 连接模块使诸如无盘客户端之类的客户端能够连接到两个或多个存储区域网络(“SAN”),属于一组冗余SAN的SAN,该组中的每个SAN冗余地存储至少一部分 基本上相同的操作系统数据为客户端。 引导模块使客户端能够从两个或多个冗余SAN远程引导操作系统。 引导模块对两个或多个连接的SAN中的每一个进行至少一个读取请求,每个读取请求被配置为检索用于将操作系统加载到客户端上的操作系统数据的不同部分。 引导模块使用从两个或多个连接的SAN检索的数据的组合将操作系统加载到客户端上。

    Method and apparatus for providing centralized user authorization to allow secure sign-on to a computer system
    126.
    发明授权
    Method and apparatus for providing centralized user authorization to allow secure sign-on to a computer system 有权
    用于提供集中式用户授权以允许安全地登录到计算机系统的方法和装置

    公开(公告)号:US07765407B2

    公开(公告)日:2010-07-27

    申请号:US11612092

    申请日:2006-12-18

    CPC classification number: G06F21/575

    Abstract: A method for providing centralized user authorization to allow secure sign-on to a computer system is disclosed. In response to a user attempting to boot up a computer system, a message is sent to a trusted server by a hypervisor within the computer to request a new hard drive password for the computer system. If the user is not authorized to access the computer system, a packet is sent by the trusted server to instruct the hypervisor to stop any boot process on the computer system. If the user is authorized to access the computer system, a packet containing a partial hard drive password is sent by the trusted server to the computer system. The packet is then encrypted with a system public key by the computer system to yield the partial hard drive password. The computer system subsequently combines the partial hard drive password with a user password to generate a new complete hard drive password to continue with the boot process.

    Abstract translation: 公开了一种用于提供集中式用户授权以允许对计算机系统进行安全登录的方法。 响应于尝试启动计算机系统的用户,由计算机内的虚拟机管理程序向可信服务器发送消息,以请求计算机系统的新的硬盘驱动器密码。 如果用户没有权限访问计算机系统,则可信服务器发送一个数据包,以指示管理程序停止计算机系统上的任何引导过程。 如果用户被授权访问计算机系统,则包含部分硬盘驱动器密码的分组由可信服务器发送到计算机系统。 然后,计算机系统使用系统公钥对数据包进行加密,以产生部分硬盘驱动器密码。 计算机系统随后将部分硬盘驱动器密码与用户密码相结合,以生成新的完整硬盘驱动器密码,以继续引导过程。

    Techniques for Booting a Stateless Client
    127.
    发明申请
    Techniques for Booting a Stateless Client 有权
    引导无状态客户端的技术

    公开(公告)号:US20100058042A1

    公开(公告)日:2010-03-04

    申请号:US12200401

    申请日:2008-08-28

    CPC classification number: G06F9/4416 G06F9/45533

    Abstract: A technique for booting a stateless client includes booting a virtual machine (VM) monitor on the client. The VM monitor is stored in a non-volatile memory area of a memory subsystem (of the client) and a first portion of an operating system (which does not include any state information for the operating system) is stored in the non-volatile memory area of the client. Booting of the operating system for the client is initiated and a remote storage (that stores a second portion of the operating system that includes state information for the operating system) is accessed via a communication link. Booting of the operating system for the client is completed using the second portion of the operating system.

    Abstract translation: 用于引导无状态客户端的技术包括在客户机上引导虚拟机(VM)监视器。 VM监视器存储在客户端的存储器子系统的非易失性存储器区域中,并且操作系统的第一部分(其不包括用于操作系统的任何状态信息)存储在非易失性存储器中 客户区域。 启动用于客户端的操作系统的启动,并且经由通信链路访问远程存储(存储操作系统的第二部分,其包括操作系统的状态信息)。 使用操作系统的第二部分完成客户端操作系统的引导。

    APPARATUS, SYSTEM, AND METHOD FOR MANAGING NETWORK BANDWIDTH
    128.
    发明申请
    APPARATUS, SYSTEM, AND METHOD FOR MANAGING NETWORK BANDWIDTH 有权
    用于管理网络带宽的装置,系统和方法

    公开(公告)号:US20090245111A1

    公开(公告)日:2009-10-01

    申请号:US12059872

    申请日:2008-03-31

    Abstract: An apparatus, system, and method are disclosed for managing network bandwidth. A monitor module monitors traffic of a plurality of peer computers over a Transmission Control Protocol/Internet Protocol (TCP/IP) network. A detection module detects traffic exceeding a traffic threshold for the network. A delay module delays issuing each TCP/IP acknowledge signal for a specified delay interval in response to detecting the traffic exceeding the traffic threshold.

    Abstract translation: 公开了一种用于管理网络带宽的装置,系统和方法。 监视器模块通过传输控制协议/因特网协议(TCP / IP)网络监视多个对等计算机的业务。 检测模块检测超过网络流量阈值的流量。 响应于检测到超过流量阈值的流量,延迟模块延迟以指定的延迟间隔发布每个TCP / IP确认信号。

    System and Method for Securely Updating Firmware Devices by Using a Hypervisor
    130.
    发明申请
    System and Method for Securely Updating Firmware Devices by Using a Hypervisor 审中-公开
    使用管理程序安全更新固件设备的系统和方法

    公开(公告)号:US20080244553A1

    公开(公告)日:2008-10-02

    申请号:US11692283

    申请日:2007-03-28

    CPC classification number: G06F21/572

    Abstract: A system, method, and program product is provided that receives and processes a firmware update at a computer system. The computer system is executing a hypervisor and one or more guest operating systems, and the firmware update corresponds to a hardware device accessible by the computer system. The hardware device is a type that is programmed using an updateable firmware. The hypervisor operating in the computer system processes the received firmware update by first inhibiting use of the device by each of the guest operating systems. After the guest operating systems have been inhibited from using the device, the firmware in the device is upgraded by the hypervisor using the received firmware update. After the firmware has been upgraded, each of the guest operating systems is allowed use of the device.

    Abstract translation: 提供了一种在计算机系统接收和处理固件更新的系统,方法和程序产品。 计算机系统正在执行管理程序和一个或多个客户操作系统,并且固件更新对应于计算机系统可访问的硬件设备。 硬件设备是使用可更新固件编程的类型。 在计算机系统中操作的管理程序通过首先禁止每个客户操作系统使用该设备来处理所接收的固件更新。 在客户机操作系统被禁止使用设备之后,设备中的固件由管理程序使用接收到的固件更新进行升级。 在升级固件之后,允许每个客户机操作系统使用该设备。

Patent Agency Ranking