Measuring Platform Components With A Single Trusted Platform Module
    83.
    发明申请
    Measuring Platform Components With A Single Trusted Platform Module 有权
    使用单个可信平台模块测量平台组件

    公开(公告)号:US20140068275A1

    公开(公告)日:2014-03-06

    申请号:US13602449

    申请日:2012-09-04

    IPC分类号: G06F21/72

    摘要: In accordance with some embodiments, a single trusted platform module per platform may be used to handle conventional trusted platform tasks as well as those that would arise prior to the existence of a primary trusted platform module in conventional systems. Thus one single trusted platform module may handle measurements of all aspects of the platform including the baseboard management controller. In some embodiments, a management engine image is validated using a read only memory embedded in a chipset such as a platform controller hub, as the root of trust. Before the baseboard management controller (BMC) is allowed to boot, it must validate the integrity of its flash memory. But the BMC image may be stored in a memory coupled to a platform controller hub (PCH) in a way that it can be validated by the PCH.

    摘要翻译: 根据一些实施例,可以使用每个平台的单个可信平台模块来处理常规可信任平台任务以及在传统系统中存在主要可信平台模块之前出现的那些任务。 因此,单个可信平台模块可以处理包括基板管理控制器的平台的所有方面的测量。 在一些实施例中,使用嵌入在诸如平台控制器集线器的芯片组中的只读存储器作为信任根来验证管理引擎映像。 在允许引导基板管理控制器(BMC)之前,必须验证其闪存的完整性。 但是,BMC图像可以存储在耦合到平台控制器集线器(PCH)的存储器中,其可以由PCH验证。

    Content protection in non-volatile storage devices
    84.
    发明授权
    Content protection in non-volatile storage devices 有权
    非易失性存储设备中的内容保护

    公开(公告)号:US07434068B2

    公开(公告)日:2008-10-07

    申请号:US10055572

    申请日:2001-10-19

    IPC分类号: G06F21/02 H04L9/28

    CPC分类号: G06F21/575 G06F21/64

    摘要: Content stored in a non-volatile storage device is protected from unauthorized modification and/or access. The device is configured as one or more regions, where one or more of the regions implements one or more content protection schemes. The current version of the contents stored in a region is compared to a previously stored valid version to determine if the current version has been modified without authorization. A region may be protected by use of an integrity metric (e.g., checksum, bit mask, and/or cyclic redundancy check value). The methodology may be implemented during the start up sequence of a computer system to protect the basic I/O system (BIOS) from unauthorized modification.

    摘要翻译: 存储在非易失性存储设备中的内容受到保护,免受未经授权的修改和/或访问。 该设备被配置为一个或多个区域,其中一个或多个区域实现一个或多个内容保护方案。 将存储在区域中的内容的当前版本与先前存储的有效版本进行比较,以确定当前版本是否未经授权进行修改。 可以通过使用完整性度量(例如,校验和,位掩码和/或循环冗余校验值)来保护区域。 该方法可以在计算机系统的启动顺序期间实现,以保护基本I / O系统(BIOS)免受未经授权的修改。

    Methods and apparatus to update a basic input/output system (BIOS)
    85.
    发明授权
    Methods and apparatus to update a basic input/output system (BIOS) 有权
    更新基本输入/输出系统(BIOS)的方法和装置

    公开(公告)号:US07188238B2

    公开(公告)日:2007-03-06

    申请号:US10442486

    申请日:2003-05-21

    IPC分类号: G06F15/177 G06F9/455

    CPC分类号: G06F9/4401 G06F8/65

    摘要: Methods and apparatus to update a basic input/output system (BIOS) are described herein. In an example method, a processor determines a storing characteristic associated with a BIOS component stored in a non-volatile memory, and determines an operating characteristic associated with the BIOS component. Based on the storing characteristic and the operating characteristic associated with the BIOS component, the processor determines boundaries of the BIOS component within the non-volatile memory.

    摘要翻译: 本文描述了更新基本输入/输出系统(BIOS)的方法和装置。 在示例性方法中,处理器确定与存储在非易失性存储器中的BIOS组件相关联的存储特性,并且确定与BIOS组件相关联的操作特性。 基于与BIOS组件相关联的存储特性和操作特性,处理器确定非易失性存储器内BIOS组件的边界。

    Identifying an operating system associated with a boot path
    86.
    发明申请
    Identifying an operating system associated with a boot path 审中-公开
    识别与引导路径相关联的操作系统

    公开(公告)号:US20060288197A1

    公开(公告)日:2006-12-21

    申请号:US11154320

    申请日:2005-06-16

    IPC分类号: G06F15/177

    CPC分类号: G06F9/441

    摘要: Various characteristics of a hard drive may be analyzed in order to determine the nature of an operating system stored thereon. For example, an operating system indicator and/or a boot record may be identified which may enable operating system identification. Alternatively, checksums may be used to disambiguate the stored operating system. Other disk characteristics may be utilized to enable a determination of operating system and operating system version. This information may be provided to the user in a graphical user interface indicating the correspondence between operating systems and drives, or a desired operating system, once identified, may be automatically used without analyzing all drives.

    摘要翻译: 可以分析硬盘驱动器的各种特性以便确定存储在其上的操作系统的性质。 例如,可以识别可以实现操作系统识别的操作系统指示符和/或引导记录。 或者,可以使用校验和来消除存储的操作系统的歧义。 可以使用其他磁盘特性来确定操作系统和操作系统版本。 可以在指示操作系统和驱动器之间的对应关系的图形用户界面中向用户提供该信息,或者一旦识别出所需的操作系统,则可以在不分析所有驱动器的情况下自动使用该信息。

    Data security
    87.
    发明申请
    Data security 有权
    数据安全

    公开(公告)号:US20050081048A1

    公开(公告)日:2005-04-14

    申请号:US10686410

    申请日:2003-10-14

    IPC分类号: G06F3/06 G06F21/00 G06F12/14

    摘要: In one embodiment, a method is provided that may include encrypting, based least in part upon at least one key, one or more respective portions of input data to generate one or more respective portions of output data to be stored in one or more locations in storage. The method of this embodiment also may include generating, based at least in part upon the one or more respective portions of the output data, check data to be stored in the storage, and/or selecting the one or more locations in the storage so as to permit the one or more respective portions of the output data to be distributed among two or more storage devices comprised in the storage. Many modifications, variations, and alternatives are possible without departing from this embodiment.

    摘要翻译: 在一个实施例中,提供了一种方法,其可以包括至少部分地基于至少一个密钥加密输入数据的一个或多个相应部分,以生成要存储在一个或多个位置中的输出数据的一个或多个相应部分 存储。 该实施例的方法还可以包括至少部分地基于输出数据的一个或多个相应部分生成要存储在存储器中的检查数据和/或选择存储器中的一个或多个位置,以便 以允许输出数据的一个或多个相应部分在包括在存储器中的两个或更多个存储设备之间分配。 在不脱离本实施例的情况下,可以进行许多修改,变型和替换。

    Performing Redundant Memory Hopping
    89.
    发明申请
    Performing Redundant Memory Hopping 有权
    执行冗余内存跳转

    公开(公告)号:US20130031322A1

    公开(公告)日:2013-01-31

    申请号:US13647154

    申请日:2012-10-08

    IPC分类号: G06F12/16

    摘要: In one embodiment, the present invention includes a method for receiving an indication of a loss of redundancy with respect to a pair of mirrored memory regions of a partially redundant memory system, determining new mirrored memory regions, and dynamically migrating information stored in the original mirrored memory regions to the new mirrored memory regions. Other embodiments are described and claimed.

    摘要翻译: 在一个实施例中,本发明包括一种用于接收相对于部分冗余存储器系统的一对镜像存储器区域的冗余丢失的指示的方法,确定新的镜像存储器区域以及动态迁移存储在原始镜像中的信息 内存区域到新的镜像内存区域。 描述和要求保护其他实施例。

    Performing Redundant Memory Hopping
    90.
    发明申请
    Performing Redundant Memory Hopping 有权
    执行冗余内存跳转

    公开(公告)号:US20120079316A1

    公开(公告)日:2012-03-29

    申请号:US13307547

    申请日:2011-11-30

    IPC分类号: G06F11/20

    摘要: In one embodiment, the present invention includes a method for receiving an indication of a loss of redundancy with respect to a pair of mirrored memory regions of a partially redundant memory system, determining new mirrored memory regions, and dynamically migrating information stored in the original mirrored memory regions to the new mirrored memory regions. Other embodiments are described and claimed.

    摘要翻译: 在一个实施例中,本发明包括一种用于接收相对于部分冗余存储器系统的一对镜像存储器区域的冗余丢失的指示的方法,确定新的镜像存储器区域以及动态迁移存储在原始镜像中的信息 内存区域到新的镜像内存区域。 描述和要求保护其他实施例。