Method and apparatus for providing centralized user authorization to allow secure sign-on to a computer system
    61.
    发明授权
    Method and apparatus for providing centralized user authorization to allow secure sign-on to a computer system 有权
    用于提供集中式用户授权以允许安全地登录到计算机系统的方法和装置

    公开(公告)号:US07765407B2

    公开(公告)日:2010-07-27

    申请号:US11612092

    申请日:2006-12-18

    IPC分类号: G06F21/00

    CPC分类号: G06F21/575

    摘要: A method for providing centralized user authorization to allow secure sign-on to a computer system is disclosed. In response to a user attempting to boot up a computer system, a message is sent to a trusted server by a hypervisor within the computer to request a new hard drive password for the computer system. If the user is not authorized to access the computer system, a packet is sent by the trusted server to instruct the hypervisor to stop any boot process on the computer system. If the user is authorized to access the computer system, a packet containing a partial hard drive password is sent by the trusted server to the computer system. The packet is then encrypted with a system public key by the computer system to yield the partial hard drive password. The computer system subsequently combines the partial hard drive password with a user password to generate a new complete hard drive password to continue with the boot process.

    摘要翻译: 公开了一种用于提供集中式用户授权以允许对计算机系统进行安全登录的方法。 响应于尝试启动计算机系统的用户,由计算机内的虚拟机管理程序向可信服务器发送消息,以请求计算机系统的新的硬盘驱动器密码。 如果用户没有权限访问计算机系统,则可信服务器发送一个数据包,以指示管理程序停止计算机系统上的任何引导过程。 如果用户被授权访问计算机系统,则包含部分硬盘驱动器密码的分组由可信服务器发送到计算机系统。 然后,计算机系统使用系统公钥对数据包进行加密,以产生部分硬盘驱动器密码。 计算机系统随后将部分硬盘驱动器密码与用户密码相结合,以生成新的完整硬盘驱动器密码,以继续引导过程。

    LOCAL VERIFICATION OF TRUSTED DISPLAY BASED ON REMOTE SERVER VERIFICATION
    63.
    发明申请
    LOCAL VERIFICATION OF TRUSTED DISPLAY BASED ON REMOTE SERVER VERIFICATION 有权
    基于远程服务器验证的TRUSTED显示器的本地验证

    公开(公告)号:US20090089875A1

    公开(公告)日:2009-04-02

    申请号:US11865048

    申请日:2007-09-30

    IPC分类号: H04L9/32

    CPC分类号: G06F21/57 H04L63/12

    摘要: In a system with a main memory, a network adapter, and a display, a transaction security module in communication with the network adapter. The transaction security module acts to: establish a secure identification item with an entity which positively identifies the entity; accept an application OS of the entity; and initiate a guest OS with the entity; the network adapter acting to connect with the entity subsequent to initiation of a guest OS; and the display acting to display the secure identification item subsequent to connection with the entity.

    摘要翻译: 在具有主存储器,网络适配器和显示器的系统中,与网络适配器通信的事务安全模块。 交易安全模块用于:建立一个安全的识别项目,该实体确实标识该实体; 接受实体的应用程序OS; 并与实体发起客户操作系统; 所述网络适配器在发起客户操作系统之后与所述实体进行连接; 以及显示器,用于在与所述实体连接之后显示所述安全识别项目。

    Method and Apparatus for Using Non-Addressable Memories of a Computer System
    65.
    发明申请
    Method and Apparatus for Using Non-Addressable Memories of a Computer System 审中-公开
    使用计算机系统不可寻址记忆的方法和装置

    公开(公告)号:US20080162805A1

    公开(公告)日:2008-07-03

    申请号:US11619293

    申请日:2007-01-03

    IPC分类号: G06F12/08

    摘要: A method for using non-addressable memory of a computer system is disclosed. Any system memory above an addressable memory limit of a computer system (i.e., non-addressable memory) is initially converted to a disk cache by a hypervisor. In response to a read request, the hypervisor intercepts the read request, and then sends the data for the read request from the disk cache to a read requestor if the data for the read request is available in the disk cache. In response to a write request, the hypervisor intercepts the write request, and then writes the data for the write request to the disk cache and updating corresponding disk cache tables.

    摘要翻译: 公开了一种使用计算机系统的不可寻址存储器的方法。 高于计算机系统的可寻址存储器限制(即,不可寻址存储器)的任何系统存储器最初由管理程序转换为磁盘高速缓存。 响应于读取请求,管理程序拦截读取请求,然后将读取请求的数据从磁盘缓存发送到读取请求者,如果读取请求的数据在磁盘缓存中可用。 响应于写请求,管理程序拦截写请求,然后将写请求的数据写入磁盘缓存并更新对应的磁盘缓存表。

    Method and apparatus for managing user time on a rental computer
    66.
    发明申请
    Method and apparatus for managing user time on a rental computer 有权
    用于在租用计算机上管理用户时间的方法和装置

    公开(公告)号:US20070244708A1

    公开(公告)日:2007-10-18

    申请号:US11403752

    申请日:2006-04-13

    IPC分类号: G06Q10/00 G06Q30/00

    摘要: Hacking a rental computer to use it beyond purchased rental time is prevented by plugging a time card with internal counter into a DIMM socket of the motherboard and encrypting the register locations of the time card with the private key of the motherboard to bind the time card to the motherboard. Thus, if the time card is not detected at boot or if it is removed during operation the computer is disabled. The counter counts down the rented time period as it receives clocking signals, and at the elapse of the purchased period disables the computer.

    摘要翻译: 将出租计算机用于超出购买的租赁时间的情况下,可以通过将带有内部计数器的时间卡插入主板的DIMM插槽,并用主板的私钥将时间卡的注册位置加密,将时间卡绑定到 主板。 因此,如果在启动时未检测到时间卡,或者在操作期间删除了时间卡,则计算机被禁用。 计数器会收到租用的时间段,因为它收到时钟信号,并且在购买的时间段过去禁用计算机。

    Apparatus, system, and method for buffering write data in response to motion
    70.
    发明申请
    Apparatus, system, and method for buffering write data in response to motion 有权
    用于响应于运动缓冲写入数据的装置,系统和方法

    公开(公告)号:US20070113286A1

    公开(公告)日:2007-05-17

    申请号:US11273360

    申请日:2005-11-14

    IPC分类号: H04N7/16 G06F12/14

    摘要: An apparatus, system, and method are disclosed for buffering write data. A motion sensor module senses the motion of a motion-sensitive storage device. A direction module writes data to a buffer if the motion exceeds a threshold motion. The direction module further writes the data to the motion-sensitive storage device if the motion does not exceed the threshold motion. In one embodiment, a write module writes the data from the buffer to the motion-sensitive storage device when the motion does not exceed the threshold motion.

    摘要翻译: 公开了用于缓冲​​写入数据的装置,系统和方法。 运动传感器模块感测运动敏感存储设备的运动。 如果运动超过阈值运动,方向模块将数据写入缓冲区。 如果运动没有超过阈值运动,方向模块还将数据写入运动敏感存储设备。 在一个实施例中,当运动不超过阈值运动时,写入模块将数据从缓冲器写入运动敏感存储设备。