Updating firmware securely over a network
    2.
    发明授权
    Updating firmware securely over a network 有权
    通过网络安全地更新固件

    公开(公告)号:US07770003B2

    公开(公告)日:2010-08-03

    申请号:US11024583

    申请日:2004-12-29

    IPC分类号: G06F9/00

    CPC分类号: H04L63/0428 H04L63/0478

    摘要: A method according to one embodiment may include: receiving a first encrypted signal at a server of a computing network, the first encrypted signal comprising firmware encrypted by a first encryption algorithm having a first complexity level; sending a second encrypted signal over the computing network to at least one managed client in response to the first encrypted signal, the second encrypted signal comprising the firmware encrypted by a second encryption algorithm having a second complexity level, wherein said first complexity level is greater than said second complexity level; and updating existing firmware of the at least one managed client in response to receipt of the second signal at the at least one managed client. Of course, many alternatives, variations, and modifications are possible without departing from this embodiment.

    摘要翻译: 根据一个实施例的方法可以包括:在计算网络的服务器处接收第一加密信号,所述第一加密信号包括由具有第一复杂度级别的第一加密算法加密的固件; 响应于所述第一加密信号,通过所述计算网络向所述至少一个被管理客户端发送第二加密信号,所述第二加密信号包括由具有第二复杂度级别的第二加密算法加密的固件,其中所述第一复杂度级别大于 说第二复杂度水平; 以及响应于所述至少一个被管理的客户端上的所述第二信号的接收,更新所述至少一个受管客户端的现有固件。 当然,在不偏离本实施例的情况下,可以进行许多替代,变化和修改。

    Operating system independent agent
    3.
    发明申请
    Operating system independent agent 审中-公开
    操作系统独立代理

    公开(公告)号:US20100223625A1

    公开(公告)日:2010-09-02

    申请号:US12660338

    申请日:2010-02-24

    IPC分类号: G06F15/16 G06F15/163

    摘要: Described is a computing platform comprising a host processing system to host an operating system, a communication adapter to transmit data to or and receive data from a data transmission medium, and a non-volatile storage. The computing platform may also comprise an agent executable independently of the operating system to enable read-only or read/write access to at least a portion of the non-volatile storage.

    摘要翻译: 描述了一种计算平台,包括主机操作系统的主机处理系统,用于向数据传输介质发送数据或从数据传输介质接收数据的通信适配器以及非易失性存储器。 计算平台还可以包括可独立于操作系统执行的代理,以实现对非易失性存储器的至少一部分的只读或读/写访问。

    Methods, apparatuses, and systems for the dynamic evaluation and delegation of network access control
    4.
    发明授权
    Methods, apparatuses, and systems for the dynamic evaluation and delegation of network access control 有权
    用于动态评估和授权网络访问控制的方法,设备和系统

    公开(公告)号:US08752132B2

    公开(公告)日:2014-06-10

    申请号:US12901349

    申请日:2010-10-08

    IPC分类号: H04L29/06

    摘要: Embodiments of the inventions are generally directed to methods, apparatuses, and systems for the dynamic evaluation and delegation of network access control. In an embodiment, a platform includes a switch to control a network connection and an endpoint enforcement engine coupled with the switch. The endpoint enforcement engine may be capable of dynamically switching among a number of network access control modes responsive to an instruction received from the network connection.

    摘要翻译: 本发明的实施例一般涉及用于动态评估和授权网络访问控制的方法,装置和系统。 在一个实施例中,平台包括用于控制网络连接的开关和与开关耦合的端点执行引擎。 端点执行引擎可以响应于从网络连接接收的指令而能够在多个网络访问控制模式之间动态切换。

    METHODS, APPARATUSES, AND SYSTEMS FOR THE DYNAMIC EVALUATION AND DELEGATION OF NETWORK ACCESS CONTROL
    5.
    发明申请
    METHODS, APPARATUSES, AND SYSTEMS FOR THE DYNAMIC EVALUATION AND DELEGATION OF NETWORK ACCESS CONTROL 有权
    动态评估和网络访问控制代码的方法,设备和系统

    公开(公告)号:US20130276052A1

    公开(公告)日:2013-10-17

    申请号:US12901349

    申请日:2010-10-08

    IPC分类号: H04L29/06

    摘要: Embodiments of the inventions are generally directed to methods, apparatuses, and systems for the dynamic evaluation and delegation of network access control. In an embodiment, a platform includes a switch to control a network connection and an endpoint enforcement engine coupled with the switch. The endpoint enforcement engine may be capable of dynamically switching among a number of network access control modes responsive to an instruction received from the network connection.

    摘要翻译: 本发明的实施例一般涉及用于动态评估和授权网络访问控制的方法,装置和系统。 在一个实施例中,平台包括用于控制网络连接的开关和与开关耦合的端点执行引擎。 端点执行引擎可以响应于从网络连接接收的指令而能够在多个网络访问控制模式之间动态切换。

    Controlling access to multiple isolated memories in an isolated execution environment
    8.
    发明授权
    Controlling access to multiple isolated memories in an isolated execution environment 有权
    在独立的执行环境中控制对多个隔离存储器的访问

    公开(公告)号:US06678825B1

    公开(公告)日:2004-01-13

    申请号:US09618738

    申请日:2000-07-18

    IPC分类号: G06F1760

    摘要: The present invention provides a method, apparatus, and system for controlling memory accesses to multiple isolated memory areas in an isolated execution environment. A page manager is used to distribute a plurality of pages to a plurality of different areas of a memory, respectively. The memory is divided into non-isolated areas and isolated areas. The page manager is located in an isolated area of memory. Further, a memory ownership page table describes each page of memory and is also located in an isolated area of memory. The page manager assigns an isolated attribute to a page if the page is distributed to an isolated area of memory. On the other hand, the page manager assigns a non-isolated attribute to a page if the page is distributed to a non-isolated area of memory. The memory ownership page table records the attribute for each page. In one embodiment, a processor having a normal execution mode and an isolated execution mode generates an access transaction. The access transaction is configured using a configuration storage that contains configuration settings related to a page and access information. An access checking circuit coupled to the configuration storage checks the access transaction using at least one of the configuration settings and the access information and generates an access grant signal if the access transaction is valid.

    摘要翻译: 本发明提供一种用于控制对隔离执行环境中的多个隔离存储器区域的存储器访问的方法,装置和系统。 页面管理器用于分别将多个页面分发到存储器的多个不同区域。 记忆分为非隔离区和隔离区。 页面管理器位于隔离区内。 此外,存储器所有权页表描述了存储器的每一页,并且还位于存储器的隔离区域中。 页面管理器将一个隔离的属性分配给页面,如果该页面被分发到一个隔离的内存区域。 另一方面,如果页面被分发到存储器的非隔离区域,则页面管理器将非隔离属性分配给页面。 内存所有权页表记录每个页面的属性。 在一个实施例中,具有正常执行模式和隔离执行模式的处理器生成访问事务。 访问事务使用包含与页面和访问信息相关的配置设置的配置存储进行配置。 耦合到配置存储器的访问检查电路使用配置设置和访问信息中的至少一个来检查访问事务,并且如果访问事务有效则生成访问许可信号。

    Digital signature purpose encoding
    9.
    发明授权
    Digital signature purpose encoding 失效
    数字签名用途编码

    公开(公告)号:US6023509A

    公开(公告)日:2000-02-08

    申请号:US720444

    申请日:1996-09-30

    摘要: A method and apparatus for encoding a purpose into a digital signature, where purpose and digital signature bound into an extended digital signature. The extended digital signature capability binds a purpose description identifying the purpose for the digital signature so that when affixed to a digital signature, the digital signature cannot be employed for improper purposes. A hash function is used to generate a hash value from the purpose description. The hash value is used in a digital signature function to bind the purpose to a digital signature. The extended digital signature can be verified for validity by comparing it to a hash value. In an electronic transaction, the extended digital signature can allow a purpose to be bound with the digital signature so that improper or unauthorized transactions are detected and disallowed.

    摘要翻译: 一种用于将目的编码为数字签名的方法和装置,其中目的和数字签名绑定到扩展数字签名中。 扩展的数字签名能力绑定了识别数字签名的目的的目的描述,使得当附加到数字签名时,数字签名不能用于不正当的目的。 哈希函数用于从目的描述生成哈希值。 哈希值用于数字签名功能以将目的绑定到数字签名。 通过将扩展的数字签名与散列值进行比较,可以验证扩展的数字签名的有效性。 在电子交易中,扩展的数字签名可以允许将目的与数字签名绑定,从而检测和不允许不正当或未经授权的交易。