Inactivity monitor for trusted personal computer system
    21.
    发明授权
    Inactivity monitor for trusted personal computer system 失效
    可信个人计算机系统的不活动监视器

    公开(公告)号:US5555373A

    公开(公告)日:1996-09-10

    申请号:US383884

    申请日:1995-02-06

    IPC分类号: G06F11/00 G06F11/34 G06F21/00

    摘要: A personal computer system is described, having security features enabling control over access to data retained in such a system. The system has a normally closed enclosure, at least one erasable memory element for selective activation to active and inactive states and for receiving and storing a privileged access password when in the active state, an option switch operatively connected with the erasable memory element for setting the erasable memory element to the active and inactive states, a tamper detection switch operatively connected with the erasable memory element for detecting opening of the enclosure, and a system processor operatively connected with the erasable memory element for controlling access to at least certain levels of data stored within the system by distinguishing between entry and non-entry of any stored privileged access password and between detection and non-detection of opening of the enclosure by the tamper detection switch. In addition, an inactivity monitor is provided for measuring the time period between successive uses of the system and for determining whether or not the measured time period exceeds a specified inactivity period. A utility is provided for rendering the monitor enabled. When the enabled monitor determines that the measured time exceeds the specified time, power-up of the system is prevented until the privileged access password (or a power-on password) is successfully entered into the system by a user.

    摘要翻译: 描述了个人计算机系统,其具有能够控制对这种系统中保留的数据的访问的安全特征。 该系统具有常闭壳体,至少一个可擦除存储元件,用于选择性地激活到主动和非活动状态,并且在处于活动状态时接收和存储特权访问密码;可选择开关,其可操作地与可擦除存储元件连接,用于设置 可擦除存储器元件到有源和非活动状态,篡改检测开关可操作地与可擦除存储器元件连接以检测外壳的打开;以及系统处理器,其与可擦除存储器元件可操作地连接,用于控制访问存储的至少一定数量的数据 通过区分任何存储的特权访问密码的入口和非入口以及由篡改检测开关检测和不检测外壳的打开之间的系统内。 此外,提供了一种不活动监视器,用于测量系统的连续使用之间的时间段,并且用于确定测量的时间段是否超过指定的不活动期。 提供一个实用程序来使监视器启用。 当启用的监视器确定测量时间超过指定的时间时,系统的上电将被阻止,直到用户成功地将特权访问密码(或开机密码)输入系统为止。

    Personal computer having operating system definition file for
configuring computer system
    22.
    发明授权
    Personal computer having operating system definition file for configuring computer system 失效
    具有用于配置计算机系统的操作系统定义文件的个人计算机

    公开(公告)号:US5504904A

    公开(公告)日:1996-04-02

    申请号:US200790

    申请日:1994-02-23

    CPC分类号: G06F9/4411

    摘要: An operating system definition file (ODF) is provided for each operating system stored in a computer system. Each ODF contains a list of keywords that define the operating environment for the particular operating system. During setup, a set configuration program reads each ODF and produces a master record that specifies an ordering of non-system memory regions across all of the operating systems that coexist in the computer system, allowing non-system memory allocations to be made to regions that meet all operating system needs. A merge matrix is used to merge records from the ODFs into a common array allowing the records to be searched to find optimum non-system memory allocations. A memory address space topology table is also built by the set configuration program for use by the operating system during initialization and during allocation of memory.

    摘要翻译: 为存储在计算机系统中的每个操作系统提供操作系统定义文件(ODF)。 每个ODF包含定义特定操作系统的操作环境的关键字列表。 在安装期间,设置的配置程序读取每个ODF并产生主记录,该主记录指定在计算机系统中共存的所有操作系统之间的非系统存储器区域的顺序,允许非系统存储器分配到 满足所有操作系统的需求。 合并矩阵用于将来自ODF的记录合并为公共数组,允许搜索记录以找到最佳的非系统内存分配。 存储器地址空间拓扑表也由设置的配置程序构建,供操作系统在初始化期间和分配存储器期间使用。

    Boot read-only memory (ROM) configuration optimization
    24.
    发明授权
    Boot read-only memory (ROM) configuration optimization 失效
    引导只读存储器(ROM)配置优化

    公开(公告)号:US07496708B2

    公开(公告)日:2009-02-24

    申请号:US11458477

    申请日:2006-07-19

    IPC分类号: G06F12/00

    摘要: Embodiments of the invention address deficiencies of the art in respect to boot ROM handling and provide a method, system and computer program product for optimized boot ROM handling for I/O devices. In one embodiment of the invention, a ROM scan area optimization method can be provided. The method can include pre-processing multiple boot ROM images to determine memory space requirements in the ROM scan area for all of the boot ROM images. The method further can include partitioning the ROM scan area into multiple, different static portions and at least one dynamic paged portion. Finally, the method can include generating an optimal arrangement of the boot ROM images defining placement of some of the boot ROM images in corresponding ones of the static portions, and others of the boot ROM images in the dynamic paged portion.

    摘要翻译: 本发明的实施例解决了关于引导ROM处理的本领域的缺陷,并提供了用于I / O设备的优化引导ROM处理的方法,系统和计算机程序产品。 在本发明的一个实施例中,可以提供ROM扫描区域优化方法。 该方法可以包括预处理多个引导ROM映像,以确定所有引导ROM映像的ROM扫描区域中的存储器空间要求。 该方法还可以包括将ROM扫描区域划分成多个不同静态部分和至少一个动态分页部分。 最后,该方法可以包括生成引导ROM图像的最优布置,其将一些引导ROM图像的定位放置在动态分页部分中的静态部分和其他引导ROM图像中的相应静态部分中。

    System and method for installing personal computer software
    25.
    发明授权
    System and method for installing personal computer software 有权
    用于安装个人计算机软件的系统和方法

    公开(公告)号:US07143067B1

    公开(公告)日:2006-11-28

    申请号:US09248160

    申请日:1999-02-09

    IPC分类号: G06Q99/00 H04K1/00 H04L9/00

    CPC分类号: G06F8/61

    摘要: A system and method for installing a customized set of software on a personal computer, tailored to the requirements of the prospective user and avoiding unnecessary software and attendant license fees. Software (all that may be desired) in unusable form is loaded onto the personal computer then selected software (that which a particular user may require and/or desire) is converted (decompressed and/or decrypted) to produce usable versions of the selected software while the other software may be erased, if desired, to free up space in storage. The selection of software is done on the user's function (department and/or mission) and may be supplemented by a user selection from a menu, based on a selection utility.

    摘要翻译: 一种用于在个人计算机上安装定制的软件集的系统和方法,其根据潜在用户的要求并避免不必要的软件和附带的许可费用。 软件(所有可能需要的)以不可用的形式被加载到个人计算机上,然后选择的软件(特定用户可能需要和/或期望的)被转换(解压缩和/或解密)以产生所选软件的可用版本 而如果需要,其他软件可能被擦除,以释放存储空间。 软件的选择是根据用户的功能(部门和/或任务)完成的,并且可以根据选择实用程序从菜单中的用户选择来补充。

    Secure switching for downloading network boots
    26.
    发明授权
    Secure switching for downloading network boots 失效
    安全切换下载网络引导

    公开(公告)号:US07130995B2

    公开(公告)日:2006-10-31

    申请号:US10674838

    申请日:2003-09-30

    IPC分类号: G06F15/177 G06F9/24 G06F9/00

    摘要: A method and system for managing a secure network boot of a secondary server (server blade). The server blade sends a request, via an Ethernet switch, for a boot program to multiple Dynamic Host Configuration Protocol (DHCP) servers. One of the DHCP servers responds with an address of at least one Pre-boot Execution Environment (PXE) server that can upload a boot program to the server blade. Only if the responding DHCP server is on a list of known trusted DHCP servers will the Ethernet switch allow the server blade to receive the response from the responding DHCP server, thus allowing the download of a boot program from a PXE server.

    摘要翻译: 用于管理辅助服务器(服务器刀片)的安全网络引导的方法和系统。 服务器刀片通过以太网交换机向多个动态主机配置协议(DHCP)服务器发送启动程序的请求。 其中一个DHCP服务器响应至少一个预引导执行环境(PXE)服务器的地址,该服务器可以将引导程序上传到服务器刀片。 只有响应的DHCP服务器在已知的可信DHCP服务器的列表上,以太网交换机才允许服务器刀片接收来自响应的DHCP服务器的响应,从而允许从PXE服务器下载引导程序。

    Wireless proximity containment security
    27.
    发明授权
    Wireless proximity containment security 失效
    无线接近遏制安全

    公开(公告)号:US5712973A

    公开(公告)日:1998-01-27

    申请号:US650205

    申请日:1996-05-20

    IPC分类号: G06F21/00 H04L9/00

    CPC分类号: G06F21/35

    摘要: A personal computer system has security features enabling control over access to data retained in such system. The system cooperates with a transmitter of radiation having a predefined characteristic. A radiation detector within the system detects such radiation and produces an alarm signal when detection fails or is lost. The alarm signal is retained and triggers security logic cooperating with power-on-sequence logic to prevent the system from becoming operative. It is preferred to also provide an erasable memory element that when switched to an active state stores a privileged-access password. Logic is provided to cooperate with such element and override the security logic when the correct password is input to the system. As an added security feature the transmitter may be deactivated if an intrusion is detected at the site to shut down all systems responding to the radiation in the security zone.

    摘要翻译: 个人计算机系统具有安全特征,使得能够控制对这种系统中保留的数据的访问。 该系统与具有预定特征的辐射发射器协作。 系统内的辐射探测器检测到这种辐射,并在检测失败或丢失时产生报警信号。 报警信号被保留,并触发安全逻辑与电源顺序逻辑配合,以防止系统变得可操作。 优选地还提供一种可擦除存储元件,当切换到活动状态时存储特权访问密码。 当提供正确的密码输入到系统时,逻辑被提供以与这样的元件配合并且覆盖安全逻辑。 作为增加的安全特征,如果在现场检测到入侵以关闭响应于安全区域中的辐射的所有系统,则发射机可以被去激活。

    Securing trusted personal computer system against unauthorized movement
    28.
    发明授权
    Securing trusted personal computer system against unauthorized movement 失效
    保证信任的个人计算机系统免受未经授权的移动

    公开(公告)号:US5574786A

    公开(公告)日:1996-11-12

    申请号:US383828

    申请日:1995-02-06

    CPC分类号: G06F21/86 G06F21/88

    摘要: A personal computer system is described, having security features enabling control over access to data retained in such a system. The system has a normally closed enclosure, at least one erasable memory element for selective activation to active and inactive states and for receiving and storing a privileged access password when in the active state, an option switch operatively connected with the erasable memory element for setting the erasable memory element to the active and inactive states, a tamper detection switch operatively connected with the erasable memory element for detecting opening of the enclosure, and a system processor operatively connected with the erasable memory element for controlling access to at least certain levels of data stored within the system by distinguishing between entry and non-entry of any stored privileged access password. In addition, switch means are provided for monitoring unauthorized movement of the system together with means for rendering the movement monitoring switch enabled or disabled. When the movement monitoring switch detects movement of the system while the switch is enabled and when the tamper detection switch detects opening of the enclosure, power-up of the system is prevented until the privileged access password (or a power-on password) is successfully entered into the system by a user.

    摘要翻译: 描述了个人计算机系统,其具有能够控制对这种系统中保留的数据的访问的安全特征。 该系统具有常闭壳体,至少一个可擦除存储器元件,用于选择性激活到主动和非活动状态,并且在处于活动状态时接收和存储特权访问密码;可选择开关,其可操作地与可擦除存储元件连接,用于设置 可擦除存储器元件到有源和非活动状态,篡改检测开关可操作地与可擦除存储器元件连接以检测外壳的打开;以及系统处理器,其与可擦除存储器元件可操作地连接,用于控制访问存储的至少一定数量的数据 通过区分任何存储的特权访问密码的入口和不输入,在系统内。 此外,提供开关装置,用于监视系统的未授权移动以及启用或禁用运动监视开关的装置。 当运动监视开关检测到开关启用时系统的移动,并且当篡改检测开关检测到机箱的打开时,系统的上电将被阻止,直到特权访问密码(或开机密码)成功 由用户输入系统。

    Method and apparatus for selectively reclaiming a portion of RAM in a
personal computer system
    29.
    发明授权
    Method and apparatus for selectively reclaiming a portion of RAM in a personal computer system 失效
    用于选择性地回收个人计算机系统中的RAM的一部分的方法和装置

    公开(公告)号:US5187792A

    公开(公告)日:1993-02-16

    申请号:US521050

    申请日:1990-05-09

    摘要: An apparatus and method for reclaiming a portion of random access memory in a personal computer system. The personal computer system comprises a system processor, a memory controller, a random access main memory, a read only memory, and at least one direct access storage device. The read only memory includes operating system microcode. The memory controller regulates communications between main memory and the system processor. In response to signals from the system processor, the memory controller can either execute the microcode out of the read only memory and recover main memory previously used to store the microcode, or disable read only memory, copy the microcode to main memory and execute the microcode out of main memory.

    摘要翻译: 一种用于在个人计算机系统中回收随机存取存储器的一部分的装置和方法。 个人计算机系统包括系统处理器,存储器控制器,随机存取主存储器,只读存储器和至少一个直接存取存储设备。 只读存储器包括操作系统微码。 存储器控制器调节主存储器与系统处理器之间的通信。 响应于来自系统处理器的信号,存储器控制器可以从只读存储器中执行微代码并恢复先前用于存储微代码的主存储器,或者禁用只读存储器,将微代码复制到主存储器并执行微代码 超出主要记忆。