Methods and apparatus for implementing context-dependent file security
    1.
    发明申请
    Methods and apparatus for implementing context-dependent file security 审中-公开
    用于实现上下文相关文件安全的方法和装置

    公开(公告)号:US20070006321A1

    公开(公告)日:2007-01-04

    申请号:US11173111

    申请日:2005-07-01

    IPC分类号: H04L9/32

    CPC分类号: G06F21/6218 G06F2221/2141

    摘要: The present invention concerns methods and apparatus for implementing context-dependent security for files and other computer system resources. In particular, methods and apparatus of the present invention implement context-based permissions that are used in context-dependent file security. In examples of the present invention, the context-based permissions may allow access to a file only when an attempt to access the file is made at a certain time of day, or from an authorized computer system, or from a computer having a certain application program installed. In general terms, the context-based permissions may specify time, location and application information that either alone or in combination may be used to restrict access to a file.

    摘要翻译: 本发明涉及用于为文件和其他计算机系统资源实现上下文相关安全性的方法和装置。 特别地,本发明的方法和装置实现了在上下文相关文件安全性中使用的基于上下文的权限。 在本发明的示例中,基于上下文的许可只允许在一天中的特定时间或从授权的计算机系统或具有特定应用的计算机进行访问文件时访问文件 程序安装。 一般而言,基于上下文的权限可以指定时间,位置和应用程序信息,这些信息可以单独使用或组合使用来限制对文件的访问。

    Secure hardware personalization service
    2.
    发明申请
    Secure hardware personalization service 有权
    安全硬件个性化服务

    公开(公告)号:US20060156406A1

    公开(公告)日:2006-07-13

    申请号:US11035337

    申请日:2005-01-13

    IPC分类号: G06F12/14

    摘要: Methods and devices for securely providing personalities to reconfigurable hardware. Reconfigurable hardware is provided with one or more domains. At least one domain serves as a gatekeeper domain and another domain serves as a task domain. A service provider provides an authentication and security personality to the gatekeeper domain. The hardware is shipped to the user. A user then accesses the service provider via a network connection and downloads a task personality into the task domain, but only if the personality in the gatekeeper domain allows the download to take place. Once the task personality completes a task, the user may download another task personality into the task domain, if permitted by the personality loaded in the gatekeeper domain. The domains and personalities are managed and made available by the service provider.

    摘要翻译: 用于安全地为可重构硬件提供个性的方法和设备。 可重配置硬件提供有一个或多个域。 至少一个域用作网守域,另一个域用作任务域。 服务提供商向网守域提供认证和安全个性。 硬件发送给用户。 用户然后通过网络连接访问服务提供商,并将任务个性下载到任务域中,但是仅当网守域中的个性允许下载发生时。 一旦任务个性完成任务,用户可以将其他任务个性下载到任务域中,如果被加载在网闸域中的个性允许的话。 域和个性由服务提供商管理和提供。

    Methods and apparatus for patching software in accordance with instituted patching policies
    3.
    发明申请
    Methods and apparatus for patching software in accordance with instituted patching policies 审中-公开
    根据制定的修补策略修补软件的方法和装置

    公开(公告)号:US20070169089A1

    公开(公告)日:2007-07-19

    申请号:US11333064

    申请日:2006-01-17

    IPC分类号: G06F9/44

    CPC分类号: G06F9/4484

    摘要: The present invention concerns methods and apparatus for controlling software patching activity in, for example, computer systems. Methods and apparatus of the present invention may implement a software shell and institute a patching policy to control patching activities. When implemented, the software shell acts as a barrier which permits patching of the underlying software only when the patching activity would be in accordance with the instituted patching policy. Various patching policies can be instituted in embodiments of the present invention. For example, patching may be done when convenient; or just before when the software requiring the patch is needed; or patching may be blocked to prevent unwanted software characteristics and/or behavior. In other circumstances, patching may be delayed until confidence has been established in a new patch so as to avoid disrupting a computer system that is already functioning in an acceptable manner. In still further circumstances, a particular software action may be blocked so as to avoid the necessity of having to patch software, particularly when the action may interrupt the orderly function of a computer system.

    摘要翻译: 本发明涉及用于控制例如计算机系统中的软件补丁活动的方法和装置。 本发明的方法和装置可以实现软件外壳并且制定修补策略来控制修补活动。 当实施时,软件shell作为屏障,只有当修补活动符合建立的修补策略时,才能修补底层软件。 可以在本发明的实施例中提出各种修补策略。 例如,可以在方便时进行修补; 或者在需要补丁需要的软件之前; 或者修补可能被阻止,以防止不必要的软件特性和/或行为。 在其他情况下,修补可能会延迟,直到在新补丁中建立置信度,以避免中断已经以可接受的方式运作的计算机系统。 在另外的情况下,可能会阻止特定的软件动作,以避免必须对软件进行补丁,特别是当该动作可能中断计算机系统的有序功能时。

    Methods and apparatus for categorizing computer system states for use in identifying individual computer systems to receive state-dependent maintenance
    4.
    发明申请
    Methods and apparatus for categorizing computer system states for use in identifying individual computer systems to receive state-dependent maintenance 审中-公开
    用于分类计算机系统状态以用于识别各个计算机系统以接收依赖于状态的维护的方法和装置

    公开(公告)号:US20060271923A1

    公开(公告)日:2006-11-30

    申请号:US11138871

    申请日:2005-05-25

    IPC分类号: G06F9/44

    CPC分类号: G06F8/60

    摘要: The present invention concerns methods and apparatus that categorize states of computer systems selected to receive state-dependent maintenance activities as a prelude to the performance of those maintenance activities. In methods and apparatus of the present invention, it is determined, for example, that a certain version of an application program operating in computer systems having a specific operating system will be updated. A signature corresponding to the combination of the application program and operating system is incorporated in a software agent. The software agent is designed to poll computer systems in order to identify targets drawn from a population of computer systems that have states corresponding to the signature incorporated in the software agent. All computer systems having states that correspond to the signature then have the state-dependent computer maintenance activity performed on them.

    摘要翻译: 本发明涉及将被选择接收状态依赖的维护活动的计算机系统的状态分类为执行那些维护活动的前奏的方法和装置。 在本发明的方法和装置中,例如,确定在具有特定操作系统的计算机系统中操作的某个版本的应用程序将被更新。 与应用程序和操作系统的组合相对应的签名被并入软件代理。 软件代理被设计为轮询计算机系统,以便识别从具有与包含在软件代理中的签名相对应的状态的计算机系统群体绘制的目标。 具有对应于签名的状态的所有计算机系统具有对它们执行的与状态相关的计算机维护活动。

    Methods and apparatus for implementing an integrated user interface for managing multiple virtual machines operative in a computing system
    5.
    发明申请
    Methods and apparatus for implementing an integrated user interface for managing multiple virtual machines operative in a computing system 失效
    用于实现用于管理在计算系统中操作的多个虚拟机的集成用户界面的方法和装置

    公开(公告)号:US20060265711A1

    公开(公告)日:2006-11-23

    申请号:US11134750

    申请日:2005-05-20

    IPC分类号: G06F9/455

    CPC分类号: G06F9/451 G06F9/45533

    摘要: The present invention concerns methods and apparatus for managing multiple virtual machines simultaneously operative in a computing environment. The methods and apparatus of the present invention provide an integrated work environment—for example, a desktop—which incorporates graphical and control elements from multiple virtual machines. In embodiments of the present invention, application programs and resources available in multiple virtual machines can be accessed from a single desktop. Methods and apparatus of the present invention provide visual cues for associating control elements and resources with particular virtual machines. In embodiments of the present invention, multiple virtual machines operative in a computing environment can comprise a plurality of collaborative virtual machines, or a private virtual machine and one or more collaborative virtual machines.

    摘要翻译: 本发明涉及用于管理在计算环境中同时操作的多个虚拟机的方法和装置。 本发明的方法和装置提供了集成的工作环境,例如桌面,它集成了来自多个虚拟机的图形和控制元素。 在本发明的实施例中,可以从单个桌面访问多个虚拟机中可用的应用程序和资源。 本发明的方法和装置提供用于将控制元素和资源与特定虚拟机相关联的视觉提示。 在本发明的实施例中,在计算环境中操作的多个虚拟机可以包括多个协作虚拟机,或私有虚拟机和一个或多个协作虚拟机。

    Virtual protection service
    7.
    发明申请
    Virtual protection service 审中-公开
    虚拟保护服务

    公开(公告)号:US20060155671A1

    公开(公告)日:2006-07-13

    申请号:US11035349

    申请日:2005-01-13

    IPC分类号: G06F7/00

    CPC分类号: H04L63/145 G06F21/56

    摘要: A method of transferring an image of a system or disk to a computer dedicated to performing a resource-intensive task, such as virus scanning, disk defragmentation or similar service. Once the dedicated computer has performed the task, the resulting image is compared to the current image of the client system or disk to produce an updated image. The client system or disk is then updated with the updated image.

    摘要翻译: 将系统或磁盘的图像传送到专用于执行资源密集型任务(例如病毒扫描,磁盘碎片整理或类似服务)的计算机的方法。 一旦专用计算机执行了任务,将所得到的图像与客户端系统或磁盘的当前图像进行比较,以产生更新的图像。 客户端系统或磁盘随后使用更新后的图像进行更新。

    Virtual device hub
    10.
    发明申请
    Virtual device hub 审中-公开
    虚拟设备中心

    公开(公告)号:US20060107269A1

    公开(公告)日:2006-05-18

    申请号:US10991766

    申请日:2004-11-17

    IPC分类号: G06F9/46

    CPC分类号: G06F9/5077

    摘要: A virtual device hub, into which local devices are plugged, enables those devices to be virtualized locally and with a remote virtual machine. Those devices then appear as available to the remote application, and can be used, for example, to print a report being processed on the remote host to a printer located at the user's physical location. The user's virtual device hub is a small computer device with network capability that is able to access the remote virtual machine. When the user runs an application, the application is actually being run in the remote virtual machine.

    摘要翻译: 本地设备插入的虚拟设备集线器使这些设备能够在本地虚拟化并使用远程虚拟机进行虚拟化。 然后这些设备对于远程应用程序可用,并且可以用于例如将在远程主机上正在处理的报告打印到位于用户的物理位置的打印机。 用户的虚拟设备集线器是具有网络功能的小型计算机设备,能够访问远程虚拟机。 当用户运行应用程序时,应用程序实际上正在远程虚拟机中运行。