FIRMWARE INTEGRITY VERIFICATION
    11.
    发明申请
    FIRMWARE INTEGRITY VERIFICATION 审中-公开
    固件完整性验证

    公开(公告)号:US20090172639A1

    公开(公告)日:2009-07-02

    申请号:US11965295

    申请日:2007-12-27

    IPC分类号: G06F9/44

    CPC分类号: G06F21/57

    摘要: In some embodiments, the integrity of firmware stored in a non-volatile memory is verified prior to initiation of a firmware reset vector. Other embodiments are described and claimed.

    摘要翻译: 在一些实施例中,在启动固件复位向量之前验证存储在非易失性存储器中的固件的完整性。 描述和要求保护其他实施例。

    System and method to seamlessly enable enhanced management and scripting of a computer system and its add-in devices
    14.
    发明申请
    System and method to seamlessly enable enhanced management and scripting of a computer system and its add-in devices 有权
    系统和方法无缝地实现计算机系统及其附加设备的增强的管理和脚本编制

    公开(公告)号:US20050144428A1

    公开(公告)日:2005-06-30

    申请号:US10746579

    申请日:2003-12-24

    IPC分类号: G06F9/44 G06F9/445 G06F15/177

    摘要: An embodiment of the present invention is a system and method relating to seamlessly enable enhanced management and scripting of a computer system and its add-in devices. In at least one embodiment, the present invention enables a system administrator or integrator to script a common configuration for multiple devices and then automatically configure the devices using the script. The language construct and central data repository for configuration settings are extended to comprehend a scripting language. A script is read by a script engine during either pre-boot or runtime. The script engine searches a keyword database on the central data repository to determine requested configuration settings. A data offset is corresponding to a specific op-code is used to determine where configuration settings are located, for modification.

    摘要翻译: 本发明的一个实施例是一种与无缝地实现计算机系统及其附加装置的增强的管理和脚本化有关的系统和方法。 在至少一个实施例中,本发明使得系统管理员或集成商可以为多个设备编写通用配置,然后使用脚本自动配置设备。 用于配置设置的语言结构和中央数据存储库被扩展以理解脚本语言。 脚本在预引导或运行期间由脚本引擎读取。 脚本引擎搜索中央数据存储库中的关键字数据库以确定所请求的配置设置。 数据偏移对应于用于确定配置设置位置的特定操作码,以供修改。

    Method, Apparatus, and System for Manageability and Secure Routing and Endpoint Access
    15.
    发明申请
    Method, Apparatus, and System for Manageability and Secure Routing and Endpoint Access 有权
    用于可管理性和安全路由和端点访问的方法,设备和系统

    公开(公告)号:US20150096051A1

    公开(公告)日:2015-04-02

    申请号:US14565833

    申请日:2014-12-10

    IPC分类号: G06F21/85

    摘要: A solution is presented to securing endpoints without the need for a separate bus or communication path. The solution allows for controlling access to endpoints by utilizing a management protocol by overlapping with existing interconnect communication paths in a packet format and utilizing a PCI address BDF (Bus number, Device number, and Function number) for verification.

    摘要翻译: 提供了解决方案来保护端点,而不需要单独的总线或通信路径。 该解决方案允许通过利用管理协议控制对端点的访问,通过与分组格式的现有互连通信路径重叠并利用PCI地址BDF(总线号码,设备号码和功能号码)进行验证。

    Apparatus and method for secure boot environment
    16.
    发明授权
    Apparatus and method for secure boot environment 有权
    安全引导环境的装置和方法

    公开(公告)号:US07984286B2

    公开(公告)日:2011-07-19

    申请号:US12215071

    申请日:2008-06-25

    IPC分类号: G06F15/177 H04L9/32

    CPC分类号: G06F21/575

    摘要: In some embodiments, a processor-based system may include at least one processor, at least one memory coupled to the at least one processor, a boot block stored at a first memory location, a capsule update stored at a second memory location, a startup authenticated code module to ensure the integrity of the boot block upon a restart of the processor-based system, code which is executable by the processor-based system to cause the processor-based system to validate the boot block with the startup authenticated code module upon the restart of the processor-based system, and, if the boot block is successfully validated, to validate the capsule update for the processor-based system with the startup authenticated code module. Other embodiments are disclosed and claimed.

    摘要翻译: 在一些实施例中,基于处理器的系统可以包括至少一个处理器,耦合到至少一个处理器的至少一个存储器,存储在第一存储器位置的引导块,存储在第二存储器位置的封装更新,启动 认证代码模块,以确保在基于处理器的系统重新启动时引导块的完整性,该代码可由基于处理器的系统执行,以使基于处理器的系统使用启动认证代码模块来验证引导块 重新启动基于处理器的系统,并且如果启动块被成功验证,则使用启动认证代码模块验证基于处理器的系统的胶囊更新。 公开和要求保护其他实施例。

    Apparatus and method for secure boot environment
    17.
    发明申请
    Apparatus and method for secure boot environment 有权
    安全引导环境的装置和方法

    公开(公告)号:US20090327684A1

    公开(公告)日:2009-12-31

    申请号:US12215071

    申请日:2008-06-25

    IPC分类号: G06F9/00

    CPC分类号: G06F21/575

    摘要: In some embodiments, a processor-based system may include at least one processor, at least one memory coupled to the at least one processor, a boot block stored at a first memory location, a capsule update stored at a second memory location, a startup authenticated code module to ensure the integrity of the boot block upon a restart of the processor-based system, code which is executable by the processor-based system to cause the processor-based system to validate the boot block with the startup authenticated code module upon the restart of the processor-based system, and, if the boot block is successfully validated, to validate the capsule update for the processor-based system with the startup authenticated code module. Other embodiments are disclosed and claimed.

    摘要翻译: 在一些实施例中,基于处理器的系统可以包括至少一个处理器,耦合到至少一个处理器的至少一个存储器,存储在第一存储器位置的引导块,存储在第二存储器位置的封装更新,启动 认证代码模块,以确保在基于处理器的系统重新启动时引导块的完整性,该代码可由基于处理器的系统执行,以使基于处理器的系统使用启动认证代码模块来验证引导块 重新启动基于处理器的系统,并且如果启动块被成功验证,则使用启动认证代码模块验证基于处理器的系统的胶囊更新。 公开和要求保护其他实施例。

    System and method to enable platform personality migration
    20.
    发明申请
    System and method to enable platform personality migration 有权
    系统和方法,实现平台人格迁移

    公开(公告)号:US20060074952A1

    公开(公告)日:2006-04-06

    申请号:US10951277

    申请日:2004-09-27

    IPC分类号: G06F17/30

    CPC分类号: G06F9/4451 Y10S707/99943

    摘要: An embodiment of the present invention relates generally to computer configuration and, more specifically, to a system and method to seamlessly determine the component configurations of a series of heterogeneous platforms and enable their respective component configurations to be intelligently migrated from one platform to another. In some embodiments, the invention involves generating configuration binaries for a plurality of target platforms. The configuration binaries are used with tools to create configuration directives for the target machines. In at least one embodiment, the configuration directives are sent to the target platforms in a scripting language. In some embodiments, the scripts are automatically generated by a tool using the configuration binaries for various platforms and policy guidance to determine which settings should be set on or off. Other embodiments are described and claimed.

    摘要翻译: 本发明的实施例一般涉及计算机配置,更具体地,涉及无缝地确定一系列异构平台的组件配置并且使得它们各自的组件配置能够从一个平台被智能迁移到另一个平台的系统和方法。 在一些实施例中,本发明涉及为多个目标平台生成配置二进制文件。 配置二进制文件与工具一起使用,以创建目标计算机的配置指令。 在至少一个实施例中,配置指令以脚本语言发送到目标平台。 在一些实施例中,脚本由工具自动生成,使用各种平台的配置二进制文件和策略指导来确定哪些设置应被设置为开或关。 描述和要求保护其他实施例。