Device access control system
    31.
    发明授权

    公开(公告)号:US11829493B2

    公开(公告)日:2023-11-28

    申请号:US17221319

    申请日:2021-04-02

    IPC分类号: G06F21/62

    CPC分类号: G06F21/62

    摘要: A device access control system includes a computing system having a device access controller subsystem coupled to devices and a central processing subsystem. A device access control manager subsystem is coupled to the device access controller subsystem and operates, during initialization operations for the computing system, to identify application(s) that are configured to be provided by the central processing subsystem, and identify a first subset of the devices that satisfy application provisioning requirements for the application(s). The device access control management subsystem then configures the device access controller subsystem to provide the central processing subsystem access to the first subset of the devices in order to allow the central processing subsystem to provide the application(s), and disable access for the central processing subsystem to a second subset of the devices in order to prevent the central processing subsystem from using the second subset of the devices to provide the application(s).

    Distributed key management system
    32.
    发明授权

    公开(公告)号:US11601262B2

    公开(公告)日:2023-03-07

    申请号:US17071268

    申请日:2020-10-15

    IPC分类号: H04L9/08 H04L9/40

    摘要: A distributed key management system includes a first SCP subsystem coupled to second SCP subsystems via a network. The first SCP subsystem establishes secure communication channels with the second SCP subsystems, and a first key management subsystem in the first SCP subsystem retrieves enabling key(s) for communicating via the secure communication channels from a second key management subsystem in one of the second SCP subsystems, and stores the enabling key(s). The first key management subsystem then receives a first enabling key request from the first SCP subsystem and determines whether the first SCP subsystem is trusted. If the first SCP subsystem is trusted, the first key management subsystem provides the first SCP subsystem access to the at least one enabling key. If the first SCP subsystem is not trusted, the first key management subsystem prevents the first SCP subsystem from accessing the at least one enabling key stored.

    WORKLOAD COMPLIANCE GOVERNOR SYSTEM

    公开(公告)号:US20230058909A1

    公开(公告)日:2023-02-23

    申请号:US17975918

    申请日:2022-10-28

    IPC分类号: G06F9/50

    摘要: A workload compliance governor system includes a management system coupled to a computing system. A workload compliance governor subsystem in the computing system receives a workload performance request associated with a workload, exchanges hardware compose communications with the management system to compose hardware components for the workload, and receives back an identification of hardware components. The workload compliance governor subsystem then determines that the identified hardware components satisfy hardware compliance requirements for the workload, and configures the identified hardware components in the computing system based on the software compliance requirements for the workload in order to cause those identified hardware components to provide an operating system and at least one application that operate to perform the workload.

    GRAPH-BASED DATA FLOW CONTROL SYSTEM

    公开(公告)号:US20220327066A1

    公开(公告)日:2022-10-13

    申请号:US17840247

    申请日:2022-06-14

    IPC分类号: G06F13/12 G06F16/901

    摘要: A graph-based data flow control system includes a control plane system coupled to SCP subsystems. The control plane system identifies a workload, and identifies service(s) on the SCP subsystems for manipulating/exchanging data to perform the workload. The control plane system generates a respective SCP-local data flow control graph for each SCP subsystem that defines how their service(s) will manipulate/exchange data within that SCP subsystem, and generates inter-SCP data flow control graph(s) that define how service(s) provided by at least one SCP subsystem will manipulate/exchange data with service(s) provided by at least one other SCP subsystem. The control plane system then transmits each respective SCP-local data flow control graph to each of the SCP subsystems, and the inter-SCP data flow control graph(s) to at least one SCP subsystem, for use by the SCP subsystems in causing their service(s) to manipulate/exchange data to perform the workload.

    Live migration/high availability system

    公开(公告)号:US11327852B1

    公开(公告)日:2022-05-10

    申请号:US17077869

    申请日:2020-10-22

    IPC分类号: G06F11/14 G06F11/20

    摘要: A live migration/high availability system includes a first computing system having a first SCP subsystem coupled to first computing system components and a first hypervisor subsystem that provides a first virtual machine. Each time the first SCP subsystem receives snapshot commands from the hypervisor subsystem, it retrieves respective SCP component state information that was not retrieved in response to a previous snapshot command from each first SCP component included in the first SCP subsystem, and uses the respective SCP component state information to generate a respective SCP subsystem snapshot based on that snapshot command. The first SCP subsystem then transmits the SCP subsystem snapshots to a second SCP subsystem in a second computing system, and the second SCP subsystem uses the SCP subsystem snapshots to allow a second hypervisor subsystem on the second computing system to provide a second virtual machine that operates the same as the first virtual machine.

    DISTRIBUTED KEY MANAGEMENT SYSTEM
    36.
    发明申请

    公开(公告)号:US20220123920A1

    公开(公告)日:2022-04-21

    申请号:US17071268

    申请日:2020-10-15

    IPC分类号: H04L9/08 H04L29/06

    摘要: A distributed key management system includes a first SCP subsystem coupled to second SCP subsystems via a network. The first SCP subsystem establishes secure communication channels with the second SCP subsystems, and a first key management subsystem in the first SCP subsystem retrieves enabling key(s) for communicating via the secure communication channels from a second key management subsystem in one of the second SCP subsystems, and stores the enabling key(s). The first key management subsystem then receives a first enabling key request from the first SCP subsystem and determines whether the first SCP subsystem is trusted. If the first SCP subsystem is trusted, the first key management subsystem provides the first SCP subsystem access to the at least one enabling key. If the first SCP subsystem is not trusted, the first key management subsystem prevents the first SCP subsystem from accessing the at least one enabling key stored.

    System control processor (SCP) cloning system

    公开(公告)号:US11301259B1

    公开(公告)日:2022-04-12

    申请号:US17068923

    申请日:2020-10-13

    IPC分类号: G06F9/44 G06F9/4401 G06F9/445

    摘要: A System Control Processor (SCP) cloning system includes a first computing system coupled to second computing systems via a network. The first computing system includes a first SCP subsystem coupled to a central processing system and first computing system components in the first computing system. The first SCP subsystem receives a first cloning command via the network from a management system and, based on the first cloning command, retrieves respective first SCP component state information from each of a plurality of first SCP components that are included in the first SCP subsystem, uses the respective first SCP component state information to generate a first SCP subsystem image that is configured for installation on an SCP subsystem to configure that SCP subsystem the same as the first SCP subsystem, and transmits the first SCP subsystem image to a second SCP subsystem in each of at least one second computing system.

    COORDINATED INITIALIZATION SYSTEM
    38.
    发明申请

    公开(公告)号:US20220091859A1

    公开(公告)日:2022-03-24

    申请号:US17030632

    申请日:2020-09-24

    IPC分类号: G06F9/445 G06F16/23 G06F13/20

    摘要: A coordinated initialization system includes a computing system with first and second initialization subsystems coupled to a coordinated initialization subsystem. The coordinated initialization subsystem receives first and second initialization progress information associated with respective first and second initialization subsystem operations performed by the respective first and second initialization subsystems. Using a coordinated initialization database that identifies dependences between the first and second initialization operations, the coordinated initialization subsystem determines that the first initialization progress information identifies a first initialization operation that is going to be performed by the first initialization subsystem and that is dependent on a second initialization operation that is identified by the second initialization progress information and that has not yet been performed by the second initialization subsystem and, in response, causes the first initialization subsystem to pause the first initialization subsystem operations until the second initialization operation has been performed.