Reducing the boot time of a TCPA based computing system when the core root of trust measurement is embedded in the boot block code
    142.
    发明授权
    Reducing the boot time of a TCPA based computing system when the core root of trust measurement is embedded in the boot block code 有权
    当信任测度的核心根源嵌入引导块代码时,减少基于TCPA的计算系统的启动时间

    公开(公告)号:US07962759B2

    公开(公告)日:2011-06-14

    申请号:US12426519

    申请日:2009-04-20

    CPC classification number: G06F21/572 G06F21/575

    Abstract: A computer program product and system for reducing the boot time of a TCPA based computing system. A flash memory in the TCPA based computing system may include a register comprising bits configured to indicate whether the segments of the flash memory have been updated. The flash memory may further include a table configured to store measurements of the segments of the flash memory. The flash memory may further include a boot block code that includes a Core Root of Trust for Measurement (CRTM). The CRTM may read the bits in the register to determine if any of the segments of the flash memory have been updated. The CRTM may further obtain the measurement values in the table for those segments that store the POST BIOS code that have not been updated thereby saving time from measuring the POST BIOS code and consequently reducing the boot time.

    Abstract translation: 一种用于减少基于TCPA的计算系统的引导时间的计算机程序产品和系统。 基于TCPA的计算系统中的闪速存储器可以包括寄存器,其包括被配置为指示闪速存储器的段是否已被更新的位。 闪存可以进一步包括被配置为存储闪存的片段的测量的表。 闪速存储器还可以包括引导块代码,其包括用于测量的信任核心根(CRTM)。 CRTM可以读取寄存器中的位,以确定闪存中的任何段是否已更新。 CRTM可以进一步获得存储POST BIOS代码的那些片段的表中的测量值,从而节省了测量POST BIOS代码的时间,从而减少了引导时间。

    SECURE DATA DISPOSAL FOR DISK DRIVE
    144.
    发明申请
    SECURE DATA DISPOSAL FOR DISK DRIVE 有权
    安全数据处理磁盘驱动器

    公开(公告)号:US20110026157A1

    公开(公告)日:2011-02-03

    申请号:US12902380

    申请日:2010-10-12

    CPC classification number: G11B5/024 G06F21/6245 G06F2221/2143

    Abstract: When a disk sector is written to, a bit for the sector is set indicating that the sector will require secure data disposal (SDD) to be run on it To saw time during end of life disposal, SDD is executed only on sectors whose bits indicate that they have been written to. SDD can be executed on each dirty sector in one operation at end of life or incrementally during use as disk activity permits.

    Abstract translation: 当磁盘扇区被写入时,扇区的位被设置,指示该扇区将需要安全数据处理(SDD)在其上运行。为了在生命周期结束时处理时间,SDD仅在其位指示的扇区 他们已经写了。 在磁盘活动允许的期间,SDD可以在使用结束时的一个操作中的每个脏扇区执行,或者在使用期间逐步执行。

    System and method to avoid disk lube pooling
    145.
    发明授权
    System and method to avoid disk lube pooling 有权
    避免磁盘润滑池的系统和方法

    公开(公告)号:US07817370B2

    公开(公告)日:2010-10-19

    申请号:US11692307

    申请日:2007-03-28

    Abstract: A system and method to avoid disk lube pooling is presented. A track access monitor tracks the number of times that a program accesses a particular track located on a hard drive. When the track access monitor determines that the number of track accesses to a particular track exceed a track access threshold, the track access monitor invokes a sequence of events to scan adjacent tracks in order to uniformly redistribute lubrication over the hard drive. In one embodiment, the track access monitor incrementally performs the adjacent track scanning during hard drive idle periods, such as when the system waits for a password from a user or when the operating system conserves power and idles the hard drive due to lack of activity.

    Abstract translation: 提出了一种避免磁盘润滑池的系统和方法。 轨道访问监视器跟踪程序访问位于硬盘驱动器上的特定轨道的次数。 当轨道访问监视器确定对特定轨道的轨道访问数量超过轨道访问阈值时,轨道访问监视器调用一系列事件来扫描相邻轨道,以便均匀地重新分配硬盘驱动器上的润滑。 在一个实施例中,轨道访问监视器在硬盘驱动器空闲时段期间,例如当系统等待来自用户的密码或当操作系统由于缺乏活动而节省电力和空闲硬盘驱动器时,逐渐执行相邻轨道扫描。

    Apparatus, System, and Method for Accurate Automated Scheduling of Computer Suspend and Resume
    146.
    发明申请
    Apparatus, System, and Method for Accurate Automated Scheduling of Computer Suspend and Resume 有权
    用于计算机挂起和恢复的精确自动调度的装置,系统和方法

    公开(公告)号:US20100217968A1

    公开(公告)日:2010-08-26

    申请号:US12389892

    申请日:2009-02-20

    CPC classification number: G06F9/4418

    Abstract: An apparatus, system, and method are disclosed for suspend-resume scheduling in conjunction with an operation requiring a suspend-resume cycle of a computer 200, including updating, for purposes of system configuration management, a non-volatile memory 506, such as an electrically erasable programmable read-only memory (“EEPROM”) 702. A control module 402 sends 806 a request to update the EEPROM 702. A suspend module 404 suspends 818 an operating system 204. A standby module 406 prepares 904 the computer 200 to enter a standby state, estimates 914 a sufficient amount of time to enter the standby state, places 916 the estimate into an alarm register 608, and then enters 918 the standby state. An update module 308 exits 1004 the standby state in response to an alarm signal 612, receives the request if present 1008, writes 1012 the EEPROM 702 with the updated information, and resumes 1018 the operating system 204.

    Abstract translation: 公开了一种结合需要计算机200的暂停 - 恢复周期的操作的暂停恢复调度的装置,系统和方法,包括为了系统配置管理而更新非易失性存储器506,诸如 电可擦除可编程只读存储器(“EEPROM”)702。控制模块402发送806更新EEPROM 702的请求。挂起模块404将操作系统204挂起818.待机模块406准备904计算机200进入 在待机状态下,估计914足够的时间进入待机状态,将该估计值放置在报警寄存器608中,然后进入待机状态918。 更新模块308响应于报警信号612离开待机状态1004,如果存在则接收请求1008,用更新的信息写入1012,并且恢复操作系统204。

    Packet filtering in a NIC to control antidote loading
    148.
    发明授权
    Packet filtering in a NIC to control antidote loading 有权
    在NIC中进行包过滤以控制解毒剂加载

    公开(公告)号:US07752659B2

    公开(公告)日:2010-07-06

    申请号:US11057795

    申请日:2005-02-14

    CPC classification number: H04L63/145

    Abstract: A method and system is described for selectively downloading antidotes onto a client computer. The client computer is connected via a network interface card (NIC) to a network that contains an anti-virus server. The NIC is initially logically isolated from the client computer, thus permitting the NIC to autonomously examine packets to and from the client computer and the network. The NIC selectively accepts packets only from trusted Internet Protocol (IP) addresses that conform to a security format such as Internet Protocol Security (IPSec).

    Abstract translation: 描述了用于有选择地将解毒剂下载到客户端计算机上的方法和系统。 客户端计算机通过网络接口卡(NIC)连接到包含防病毒服务器的网络。 NIC最初在逻辑上与客户端计算机隔离,从而允许NIC自主地检查到客户端计算机和网络的数据包。 NIC选择性地仅接收来自符合诸如因特网协议安全(IPSec)之类的安全格式的受信任的因特网协议(IP)地址的分组。

    Blocking Computer System Ports on Per User Basis
    150.
    发明申请
    Blocking Computer System Ports on Per User Basis 有权
    阻止每个用户基础的计算机系统端口

    公开(公告)号:US20100083366A1

    公开(公告)日:2010-04-01

    申请号:US12243762

    申请日:2008-10-01

    CPC classification number: G06F21/6218

    Abstract: An approach is provided that receives a user identifier from a user of the information handling system. The user identifier can include a username as well as a user authentication code, such as a password. Hardware settings that correspond to the user identifier are retrieved from a nonvolatile memory. Hardware devices, such as ports (e.g., USB controller), network interfaces, storage devices, and boot sequences, are configured using the retrieved hardware settings. After the hardware devices have been configured to correspond to the identified user, an operating system is booted.

    Abstract translation: 提供一种从信息处理系统的用户接收用户标识符的方法。 用户标识符可以包括用户名以及诸如密码的用户认证码。 从非易失性存储器检索对应于用户标识符的硬件设置。 使用检索的硬件设置来配置诸如端口(例如,USB控制器),网络接口,存储设备和引导顺序的硬件设备。 在将硬件设备配置为对应于所识别的用户之后,引导操作系统。

Patent Agency Ranking