Firmware updates from an external channel
    1.
    发明授权
    Firmware updates from an external channel 有权
    来自外部通道的固件更新

    公开(公告)号:US09565207B1

    公开(公告)日:2017-02-07

    申请号:US12554690

    申请日:2009-09-04

    摘要: When providing a user with native access to at least a portion of device hardware, the user can be prevented from modifying firmware and other configuration information by controlling the mechanisms used to update that information. In some embodiments, an asymmetric keying approach can be used to encrypt or sign the firmware. In other cases access can be controlled by enabling firmware updates only through a channel or port that is not exposed to the customer, or by mapping only those portions of the hardware that are to be accessible to the user. In other embodiments, the user can be prevented from modifying firmware by only provisioning the user on a machine after an initial mutability period wherein firmware can be modified, such that the user never has access to a device when firmware can be updated. Combinations and variations of the above also can be used.

    摘要翻译: 当向用户提供对至少一部分设备硬件的本地访问时,可以通过控制用于更新该信息的机制来阻止用户修改固件和其他配置信息。 在一些实施例中,可以使用非对称密钥方法来加密或签名固件。 在其他情况下,只能通过不暴露给客户的通道或端口启用固件更新,或仅映射用户可访问的硬件部分来控制访问。 在其他实施例中,可以通过在可修改固件的初始可变性周期之后仅在机器上提供用户来防止用户修改固件,使得当固件可以被更新时,用户永远不能访问设备。 上述的组合和变化也可​​以使用。

    Techniques for resource location and migration across data centers
    3.
    发明授权
    Techniques for resource location and migration across data centers 有权
    数据中心资源定位和迁移技术

    公开(公告)号:US09367257B2

    公开(公告)日:2016-06-14

    申请号:US12209008

    申请日:2008-09-11

    IPC分类号: G06F17/30 G06F3/06

    摘要: An exemplary system includes a front-end component to receive requests for resources in a data center and configured to associate each request with identifying information, to locate one or more resources for each request and to store, in a log file, the identifying information and information about the location of the one or more resources; one or more distributed computation and storage components to acquire log file information and configured to analyze log information to decide if one or more resources associated with one or more requests should be migrated to a data center in a different geographical location; and a location service component to receive decisions made by the one or more distributed computation and storage components and configured to inform the front-end component when a decision causes one or more resources to be migrated to a data center in a different geographical location to thereby allow the front-end component to re-direct future requests for the one or more migrated resources to the data center in the different geographical location. Various other devices, systems and methods are also described.

    摘要翻译: 示例性系统包括前端组件,用于接收对数据中心中的资源的请求,并且被配置为将每个请求与标识信息相关联,以便为每个请求定位一个或多个资源,并在日志文件中存储识别信息和 关于一个或多个资源的位置的信息; 一个或多个分布式计算和存储组件,用于获取日志文件信息并被配置为分析日志信息以确定与一个或多个请求相关联的一个或多个资源是否应迁移到不同地理位置的数据中心; 以及位置服务组件,用于接收由所述一个或多个分布式计算和存储组件做出的决定,并且被配置为当决策导致一个或多个资源迁移到不同地理位置中的数据中心时通知前端组件,从而 允许前端组件将一个或多个已迁移资源的未来请求重新定向到不同地理位置的数据中心。 还描述了各种其它装置,系统和方法。

    Secured firmware updates
    4.
    发明授权
    Secured firmware updates 有权
    安全固件更新

    公开(公告)号:US09148413B1

    公开(公告)日:2015-09-29

    申请号:US13539069

    申请日:2012-06-29

    IPC分类号: H04L29/06 G06F21/00

    摘要: When providing a user with native access to at least a portion of device hardware, the user can be prevented from modifying firmware and other configuration information by controlling the mechanisms used to update that information. In some embodiments, an asymmetric keying approach can be used to encrypt or sign the firmware. In other cases access can be controlled by enabling firmware updates only through a channel or port that is not exposed to the customer, or by mapping only those portions of the hardware that are to be accessible to the user. In other embodiments, the user can be prevented from modifying firmware by only provisioning the user on a machine after an initial mutability period wherein firmware can be modified, such that the user never has access to a device when firmware can be updated. Combinations and variations of the above also can be used.

    摘要翻译: 当向用户提供对至少一部分设备硬件的本地访问时,可以通过控制用于更新该信息的机制来阻止用户修改固件和其他配置信息。 在一些实施例中,可以使用非对称密钥方法来加密或签名固件。 在其他情况下,只能通过不暴露给客户的通道或端口启用固件更新,或仅映射用户可访问的硬件部分来控制访问。 在其他实施例中,可以通过在可修改固件的初始可变性周期之后仅在机器上提供用户来防止用户修改固件,使得当固件可以被更新时,用户永远不能访问设备。 上述的组合和变化也可​​以使用。

    Monitoring and analysis of operating states in a computing environment
    5.
    发明授权
    Monitoring and analysis of operating states in a computing environment 有权
    在计算环境中监视和分析运行状态

    公开(公告)号:US09037922B1

    公开(公告)日:2015-05-19

    申请号:US13461068

    申请日:2012-05-01

    IPC分类号: G06F11/00 G06F11/30

    摘要: A set of techniques is described for monitoring and analyzing crashes and other malfunctions in a multi-tenant computing environment (e.g. cloud computing environment). The computing environment may host many applications that are executed on different computing resource combinations. The combinations may include varying types and versions of hardware or software resources. A monitoring service is deployed to gather statistical data about the failures occurring in the computing environment. The statistical data is then analyzed to identify abnormally high failure patterns. The failure patterns may be associated with particular computing resource combinations being used to execute particular types of applications. Based on these failure patterns, suggestions can be issued to a user to execute the application using a different computing resource combination. Alternatively, the failure patterns may be used to modify or update the various resources in order to correct the potential malfunctions caused by the resource.

    摘要翻译: 描述了一组技术来监视和分析多租户计算环境(例如云​​计算环境)中的崩溃和其他故障。 计算环境可以承载在不同的计算资源组合上执行的许多应用。 组合可以包括硬件或软件资源的不同类型和版本。 部署监控服务来收集有关在计算环境中发生故障的统计数据。 然后分析统计数据以识别异常高的故障模式。 故障模式可以与用于执行特定类型的应用的特定计算资源组合相关联。 基于这些故障模式,可以向用户发出建议,以使用不同的计算资源组合来执行应用。 或者,可以使用故障模式来修改或更新各种资源,以便校正由资源引起的潜在的故障。

    ARCHIVAL DATA STORAGE SYSTEM
    8.
    发明申请
    ARCHIVAL DATA STORAGE SYSTEM 有权
    存档数据存储系统

    公开(公告)号:US20140046908A1

    公开(公告)日:2014-02-13

    申请号:US13570088

    申请日:2012-08-08

    IPC分类号: G06F17/30

    CPC分类号: G06F17/30008 G06F17/30073

    摘要: A cost-effective, durable and scalable archival data storage system is provided herein that allow customers to store, retrieve and delete archival data objects, among other operations. For data storage, in an embodiment, the system stores data in a transient data store and provides a data object identifier may be used by subsequent requests. For data retrieval, in an embodiment, the system creates a job corresponding to the data retrieval and provides a job identifier associated with the created job. Once the job is executed, data retrieved is provided in a transient data store to enable customer download. In various embodiments, jobs associated with storage, retrieval and deletion are scheduled and executed using various optimization techniques such as load balancing, batch processed and partitioning. Data is redundantly encoded and stored in self-describing storage entities increasing reliability while reducing storage costs. Data integrity is ensured by integrity checks along data paths.

    摘要翻译: 本文提供了一种经济高效,可持续和可扩展的存档数据存储系统,允许客户存储,检索和删除存档数据对象以及其他操作。 对于数据存储,在一个实施例中,系统将数据存储在瞬态数据存储器中,并且可以由随后的请求使用提供的数据对象标识符。 对于数据检索,在一个实施例中,系统创建与数据检索相对应的作业,并提供与创建的作业相关联的作业标识符。 执行作业后,在瞬态数据存储中提供检索的数据,以便客户下载。 在各种实施例中,使用诸如负载平衡,批处理和分区之类的各种优化技术调度和执行与存储,检索和删除相关联的作业。 数据被冗余编码并存储在自描述存储实体中,从而提高可靠性,同时降低存储成本。 通过沿着数据路径的完整性检查来确保数据完整性。

    Historical browsing session management
    9.
    发明授权
    Historical browsing session management 有权
    历史浏览会话管理

    公开(公告)号:US08589385B2

    公开(公告)日:2013-11-19

    申请号:US13246803

    申请日:2011-09-27

    IPC分类号: G06F17/30 G06F7/00

    摘要: A remote browsing process is directed to the generation and management of a remote browse session at a network computing provider. A client computing device requests a remote browse session instance at a network computing provider. The network computing and storage provider processes the requested content for display, and provides a processed representation of the requested content to the client computing device for display. The network computing provider further provides a historical content representation corresponding to the requested content to a historical browse storage component for storage. The network computing provider may further provide historical content representations to the historical browse storage component for content directly or indirectly referenced by the requested content. The client computing device may subsequently search for content not previously displayed by the client computing device.

    摘要翻译: 远程浏览过程针对在网络计算提供商处的远程浏览会话的生成和管理。 客户端计算设备在网络计算提供商处请求远程浏览会话实例。 网络计算和存储提供商处理所请求的内容以进行显示,并将所请求的内容的处理表示提供给客户端计算设备进行显示。 网络计算提供者还向历史浏览存储组件提供对应于所请求的内容的历史内容表示以进行存储。 网络计算提供者可以进一步向历史浏览存储组件提供历史内容表示,以供所请求内容直接或间接引用的内容。 客户端计算设备可以随后搜索客户端计算设备之前未显示的内容。