Attested content protection
    21.
    发明授权
    Attested content protection 有权
    受理内容保护

    公开(公告)号:US08387152B2

    公开(公告)日:2013-02-26

    申请号:US12163426

    申请日:2008-06-27

    CPC分类号: G06F21/57 G06F21/10

    摘要: Computer systems and environments implemented herein permit a local machine increased participation in authorizing access to protected content. An operating system attests to a computing environment at a corresponding computer system. If the computing environment is one permitted to access protected content, the operating system is permitted to regulate further (e.g., application) access to protected content in accordance with a procreation policy. As such, authorization decisions are partially distributed, easing the resource burden on a content protection server. Accordingly, this computing environment can facilitate more robust and efficient authorization decisions when access to protected content is requested.

    摘要翻译: 本文实现的计算机系统和环境允许本地机器增加对授权访问受保护内容的参与。 操作系统在相应的计算机系统上证明计算环境。 如果计算环境是允许访问受保护内容的计算环境,则允许操作系统根据生殖策略进一步(例如,应用)调整对受保护内容的访问。 因此,授权决定部分分配,减轻了内容保护服务器的资源负担。 因此,当请求对受保护内容的访问时,该计算环境可以促进更强大和有效的授权决定。

    Accessing a USB host controller security extension using a HCD proxy
    22.
    发明授权
    Accessing a USB host controller security extension using a HCD proxy 有权
    使用HCD代理访问USB主机控制器安全扩展

    公开(公告)号:US07886353B2

    公开(公告)日:2011-02-08

    申请号:US11090547

    申请日:2005-03-25

    IPC分类号: G06F9/00 G06F15/16

    摘要: Systems and methods for enabling trusted software to monitor and control USB traffic associated with a security extension of a host controller and devices in a USB topology is disclosed. A host controller proxy receives USB-related data from a host controller driver, determines whether the data is of a security interest, and if so, sends the data to a driver for a security extension executing in the trusted execution environment. Likewise, after software executing in the trusted execution environment evaluates and appropriately addresses data sent by the HCD proxy or data retrieved from a hardware security extension, the HCD proxy receives data from the trusted execution environment for further dissemination.

    摘要翻译: 公开了用于使可信软件监视和控制与主机控制器和USB拓扑中的设备的安全扩展相关联的USB流量的系统和方法。 主机控制器代理从主机控制器驱动器接收USB相关数据,确定数据是否具有安全关注,如果是,则将数据发送到驱动程序,以在可信执行环境中执行安全扩展。 类似地,在可信执行环境中执行软件后,对HCD代理发送的数据进行评估并适当地处理从硬件安全扩展检索的数据,HCD代理从可信执行环境接收数据以进一步传播。

    Using a USB host controller security extension for controlling changes in and auditing USB topology
    23.
    发明授权
    Using a USB host controller security extension for controlling changes in and auditing USB topology 失效
    使用USB主机控制器安全扩展来控制USB拓扑的更改和审核

    公开(公告)号:US07761618B2

    公开(公告)日:2010-07-20

    申请号:US11090582

    申请日:2005-03-25

    IPC分类号: G06F5/00 G06F12/14

    摘要: Protecting computer systems from attacks that attempt to change USB topology and for ensuring that the system's information regarding USB topology is accurate is disclosed. A software model is defined that, together with secure USB hardware, provides an ability to define policies using which USB traffic can be properly monitored and controlled. The implemented policy provides control over USB commands through a combination of software evaluation and hardware programming. Legitimate commands are evaluated and “allowed” to be sent to a USB device by a host controller. Illegitimate commands are evaluated and blocked. Additionally, the USB topology is audited to verify that the system's topology map matches the actual USB topology.

    摘要翻译: 公开了保护计算机系统免受试图改变USB拓扑并确保系统有关USB拓扑的信息准确的攻击。 定义了一种软件模型,它与安全USB硬件一起提供了一种定义可以正确监控和控制哪个USB流量的策略的能力。 实施的策略通过软件评估和硬件编程的组合来提供对USB命令的控制。 评估合法的命令,并通过主机控制器将“允许”命令发送到USB设备。 非法命令被评估和阻止。 另外,USB拓扑被审计,以验证系统的拓扑图匹配实际的USB拓扑。

    ATTESTED CONTENT PROTECTION
    24.
    发明申请
    ATTESTED CONTENT PROTECTION 有权
    强制内容保护

    公开(公告)号:US20090327705A1

    公开(公告)日:2009-12-31

    申请号:US12163426

    申请日:2008-06-27

    IPC分类号: H04L9/32 G06F21/24 H04L9/08

    CPC分类号: G06F21/57 G06F21/10

    摘要: The present invention extends to methods, systems, and computer program products for protecting content. Embodiments of the invention permit a local machine increased participation in authorizing access to protected content. An operating system attests to a computing environment at a corresponding computer system. If the computing environment is one permitted to access protected content, the operating system is permitted to regulate further (e.g., application) access to protected content in accordance with a procreation policy. As such, authorization decisions are partially distributed, easing the resource burden on a content protection server. Accordingly, embodiments of the invention can facilitate more robust and efficient authorization decisions when access to protected content is requested.

    摘要翻译: 本发明扩展到用于保护内容的方法,系统和计算机程序产品。 本发明的实施例允许本地机器增加对授权对受保护内容的访问的参与。 操作系统在相应的计算机系统上证明计算环境。 如果计算环境是允许访问受保护内容的计算环境,则允许操作系统根据生殖策略进一步(例如,应用)调整对受保护内容的访问。 因此,授权决定部分分配,减轻了内容保护服务器的资源负担。 因此,当请求访问受保护内容时,本发明的实施例可以促进更强大和有效的授权决定。

    System and method for performing secure device communications in a
peer-to-peer bus architecture
    25.
    发明授权
    System and method for performing secure device communications in a peer-to-peer bus architecture 失效
    用于在对等总线架构中执行安全设备通信的系统和方法

    公开(公告)号:US6061794A

    公开(公告)日:2000-05-09

    申请号:US940551

    申请日:1997-09-30

    IPC分类号: G06F1/00 G06F21/00 G06F12/14

    摘要: A system and method for performing secure peer-to-peer device communications on an I/O bus, such as a PCI bus, a Fiber Channel bus, an IEEE, 1394 bus or a Universal Serial Bus. The system includes a plurality of intelligent I/O devices, such as intelligent storage devices and/or controllers, communications devices, video devices and audio devices. The I/O devices perform peer-to-peer message and data transfers, thereby bypassing the operating system running on the computer's CPU. The intelligent I/O devices encrypt messages and data before transmitting them on the I/O bus and conversely decrypt the messages and data upon reception. The encryption provides secrecy and/or authentication of the sender. The devices use keys or passwords to encrypt/decrypt the data. The keys are stored in non-volatile memory in the devices and are distributed to the devices by the system BIOS at initialization time. The devices perform access authorization validation using rule sets also distributed by the BIOS at initialization time. The rule sets specify which I/O operations are valid for a peer I/O device to request of a respective I/O device based, preferably, upon the device class/subclasses of the requesting device. In another embodiment, one of the intelligent I/O devices may be a communications device which serves as a firewall for the I/O bus. In this embodiment, the rule set further includes identification information of the remote machines/devices.

    摘要翻译: 用于在诸如PCI总线,光纤通道总线,IEEE,1394总线或通用串行总线的I / O总线上执行安全的对等设备通信的系统和方法。 该系统包括多个智能I / O设备,诸如智能存储设备和/或控制器,通信设备,视频设备和音频设备。 I / O设备执行对等消息和数据传输,从而绕过计算机CPU上运行的操作系统。 智能I / O设备在I / O总线上传输消息和数据之前加密消息和数据,并在接收时反向解密消息和数据。 加密提供发送者的保密和/或认证。 设备使用密钥或密码来加密/解密数据。 密钥存储在设备的非易失性存储器中,并在初始化时由系统BIOS分发给设备。 这些设备使用在BIOS初始化时分配的规则集执行访问授权验证。 规则集指定哪个I / O操作对于对等I / O设备有效,以优选地基于请求设备的设备类/子类来请求相应的I / O设备。 在另一个实施例中,智能I / O设备中的一个可以是用作I / O总线的防火墙的通信设备。 在该实施例中,规则集还包括远程机器/设备的识别信息。

    Linked lists of transfer descriptors scheduled at intervals
    26.
    发明授权
    Linked lists of transfer descriptors scheduled at intervals 有权
    传输描述符的链接列表以间隔安排

    公开(公告)号:US6061687A

    公开(公告)日:2000-05-09

    申请号:US158812

    申请日:1998-09-22

    申请人: David R. Wooten

    发明人: David R. Wooten

    IPC分类号: G06F13/10 G06F13/26 G06F17/00

    摘要: A computer system including a serial bus host controller and host controller driver. The host controller driver providing data structures for the host controller to operate on. The data structures having a linking mechanism for processing lists of descriptors, and alternate buffer configurations for receiving data from the serial bus devices.

    摘要翻译: 一种包括串行总线主机控制器和主机控制器驱动程序的计算机系统。 主机控制器驱动程序提供主机控制器操作的数据结构。 具有用于处理描述符列表的链接机制的数据结构以及用于从串行总线设备接收数据的备用缓冲器配置。

    Method and apparatus for synchronizing a serial bus clock to a serial
bus function clock
    27.
    发明授权
    Method and apparatus for synchronizing a serial bus clock to a serial bus function clock 失效
    将串行总线时钟同步到串行总线功能时钟的方法和装置

    公开(公告)号:US6061411A

    公开(公告)日:2000-05-09

    申请号:US577625

    申请日:1995-12-22

    申请人: David R. Wooten

    发明人: David R. Wooten

    IPC分类号: H04L7/00 H04L25/40 H04L25/36

    CPC分类号: H04J3/0632

    摘要: A method and apparatus of synchronizing a serial bus data rate to a serial bus function data rate to eliminate the build up of overruns or underruns of data. A response is provided to a start of frame packet. The response packet contains a response code for indicating a modification to the serial bus frame counter. Thereby, slight variations in data rates can be eliminated by adjusting the serial bus data rate instead of the serial bus function data rate.

    摘要翻译: 一种将串行总线数据速率同步到串行总线功能数据速率的方法和装置,以消除数据超载或欠载的累积。 对帧分组的开始提供响应。 响应分组包含用于指示对串行总线帧计数器的修改的响应代码。 因此,可以通过调整串行总线数据速率而不是串行总线功能数据速率来消除数据速率的微小变化。

    Arbiter organization for serial bus transfers
    28.
    发明授权
    Arbiter organization for serial bus transfers 失效
    仲裁组织串行总线传输

    公开(公告)号:US5621898A

    公开(公告)日:1997-04-15

    申请号:US346097

    申请日:1994-11-29

    申请人: David R. Wooten

    发明人: David R. Wooten

    CPC分类号: G06F13/362

    摘要: A serial bus host controller arbiter which organizes data transfer events into three categories, periodic data transfers, which are usually isochronous transfers; aperiodic transfers, which usually are asynchronous transfers; and control transfers. The arbiter fundamentally operates on a periodic basis. At the beginning of each period, the arbiter preferably alternates between periodic transfers and control transfers. When all of the periodic transfers have been completed, the arbiter then provides access to the various asynchronous transfers which are scheduled to occur, alternating with any remaining control transfers. The arbiter gives preference to the periodic events, and if any time within the period is available, which is referred to as the free time, control events are interleaved with periodic events until no free time remains or all are completed. Any remaining time in the period is used cycling through the aperiodic transfers. The arbiter of the preferred embodiment keeps a running total of free time during each period to determine if additional control or aperiodic transfers can occur.

    摘要翻译: 串行总线主机控制器仲裁器,将数据传输事件组织成三类,定时数据传输,通常是同步传输; 非周期性转移,通常是异步传输; 和控制转移。 仲裁员从根本上定期运作。 在每个时期的开始,仲裁者最好在周期性转移和控制转移之间进行交替。 当所有周期性传输已经完成时,仲裁器然后提供对被调度发生的各种异步传输的访问,与任何剩余的控制传输交替。 仲裁者优先考虑周期性事件,并且如果在该周期内的任何时间可用(称为空闲时间),则控制事件与周期性事件交错,直到没有空闲时间或全部完成为止。 该期间的任何剩余时间都是通过非周期性转移使用。 优选实施例的仲裁器在每个周期期间保持运行总共空闲时间以确定是否可以发生额外的控制或非周期性传送。

    Redundancy scheme for a dynamic RAM
    29.
    发明授权
    Redundancy scheme for a dynamic RAM 失效
    动态RAM的冗余方案

    公开(公告)号:US4389715A

    公开(公告)日:1983-06-21

    申请号:US194613

    申请日:1980-10-06

    IPC分类号: G11C29/00 G11C29/04 G11C11/40

    CPC分类号: G11C29/808

    摘要: A redundancy scheme is described for replacing defective main memory cells in a dynamic RAM with spare memory cells. The spare cells are arranged in groups of spare rows and spare columns of memory cells such that a plurality of groups of spare rows and columns of cells are substituted for defective main rows and columns of cells so as to repair relatively large defects which impair adjacent rows and columns of main memory cells. In the preferred embodiment, the RAM includes a plurality of address buffers, each of which receives an incoming row address bit and then an incoming column address bit for sequentially outputting row and column address data. Associated with each buffer is a store for a defective row address, a store for a defective column address, and a comparator. The stores retain defective memory cell addresses which the comparator sequentially compares against the address data sequentially output by the buffer. When the comparator senses a match, a control signal is generated to initiate substitution of spare memory cells for the defective main memory cells.

    摘要翻译: 描述了用于用备用存储器单元替换动态RAM中的有缺陷的主存储器单元的冗余方案。 备用单元被布置成存储器单元的备用行和备用列的组,使得多组备用行和单元列被替换有缺陷的主行和单元列,以便修复相对较大的相邻行的缺陷 和主存储单元的列。 在优选实施例中,RAM包括多个地址缓冲器,每个地址缓冲器接收输入行地址位,然后接收输入列地址位,用于顺序地输出行和列地址数据。 与每个缓冲器相关联的是存储缺陷行地址,存储有缺陷列地址和比较器的存储。 存储器保持缺陷的存储单元地址,比较器顺序地与由缓冲器顺序输出的地址数据进行比较。 当比较器感测到匹配时,产生控制信号以启动用于缺陷主存储器单元的备用存储器单元的替换。

    Methods and Compositions for Increased Yield
    30.
    发明申请
    Methods and Compositions for Increased Yield 审中-公开
    提高产量的方法和组成

    公开(公告)号:US20110010793A1

    公开(公告)日:2011-01-13

    申请号:US12918067

    申请日:2009-02-13

    摘要: The invention overcomes the deficiencies of the art by providing methods for breeding soybean plants containing genomic regions associated with the pubescence alleles, T and Td, associated with increased grain yield. In addition, the invention provides the locus for Td. Moreover, the invention includes germplasm and the use of germplasm containing genomic regions conferring increased yield for introgression into elite germplasm in a breeding program. Moreover, the invention provides methods of purifying soybean breeding lines for such traits as flower color and pubescence color at early stages, such as seed. The invention also provides derivatives, and plant parts of these plants and uses thereof.

    摘要翻译: 本发明克服了本领域的缺陷,提供了与含有与增加的谷物产量相关的柔毛等位基因T和Td相关联的基因组区域的大豆植物育种方法。 此外,本发明提供了Td的基因座。 此外,本发明包括种质和使用含有基因组区域的种质,从而在育种程序中赋予精液种质增加的产量。 此外,本发明提供了在诸如种子之类的早期阶段纯化大豆育种品系的方法,用于诸如花色和柔毛色等性状。 本发明还提供这些植物的衍生物和植物部分及其用途。