Remote disablement of a computer system
    1.
    发明授权
    Remote disablement of a computer system 有权
    远程禁用计算机系统

    公开(公告)号:US08702812B2

    公开(公告)日:2014-04-22

    申请号:US12040821

    申请日:2008-02-29

    IPC分类号: G06F21/00

    CPC分类号: G06F21/88 G06F2221/2143

    摘要: Methods and arrangements for ensuring that, when a computer system is stolen or otherwise misplaced, the system is rendered unusable (i.e., locked down). Conventional solutions have required software running on the system to perform the lockdown action, but in accordance with at least one preferred embodiment of the present invention is the linkage of TPM (Trusted Platform Module) and AMT (Active Management Technology) solutions whereby an AMT arrangement can remove secure data or identifiers so that any encrypted data present on the system will become unusable.

    摘要翻译: 确保当计算机系统被盗或以其他方式错位时,系统变得无法使用(即锁定)的方法和装置。 常规解决方案需要在系统上运行的软件来执行锁定动作,但是根据本发明的至少一个优选实施例是TPM(可信平台模块)和AMT(主动管理技术)解决方案的联动,由此AMT布置 可以删除安全数据或标识符,使系统上存在的任何加密数据变得不可用。

    MERGING EXTERNAL NVRAM WITH FULL DISK ENCRYPTION
    3.
    发明申请
    MERGING EXTERNAL NVRAM WITH FULL DISK ENCRYPTION 有权
    合并外部NVRAM与全盘加密

    公开(公告)号:US20090089590A1

    公开(公告)日:2009-04-02

    申请号:US11865049

    申请日:2007-09-30

    IPC分类号: G06F12/14

    CPC分类号: G06F21/80 G06F21/79

    摘要: Methods and arrangements for managing a flash drive, hard disk, or connection between the two, in a manner to ensure that sensitive data is not decrypted at any time when it would be vulnerable. Accordingly, in a first implementation, the data may preferably be encrypted as it first goes into a flash drive and decrypted when it comes out of the flash drive. In another implementation, the flash drive may be logically bound to the hard disk, so that they would both use the same encryption key. In yet another implementation, if a hard disk is moved to another system, then the flash drive may also preferably be simultaneously moved.

    摘要翻译: 用于管理闪存驱动器,硬盘或两者之间的连接的方法和布置,以确保敏感数据在易受攻击的任何时候不被解密。 因此,在第一实现中,数据可以优选地被加密,因为它们首先进入闪存驱动器并且当它从闪存驱动器出来时被解密。 在另一个实现中,闪存驱动器可以逻辑地绑定到硬盘,使得它们都将使用相同的加密密钥。 在又一实施方式中,如果将硬盘移动到另一系统,则闪存驱动器也可以优选地同时移动。

    Merging external NVRAM with full disk encryption
    4.
    发明授权
    Merging external NVRAM with full disk encryption 有权
    将外部NVRAM与全磁盘加密合并

    公开(公告)号:US09323956B2

    公开(公告)日:2016-04-26

    申请号:US11865049

    申请日:2007-09-30

    IPC分类号: G06F12/14 G06F21/80 G06F21/79

    CPC分类号: G06F21/80 G06F21/79

    摘要: Methods and arrangements for managing a flash drive, hard disk, or connection between the two, in a manner to ensure that sensitive data is not decrypted at any time when it would be vulnerable. Accordingly, in a first implementation, the data may preferably be encrypted as it first goes into a flash drive and decrypted when it comes out of the flash drive. In another implementation, the flash drive may be logically bound to the hard disk, so that they would both use the same encryption key. In yet another implementation, if a hard disk is moved to another system, then the flash drive may also preferably be simultaneously moved.

    摘要翻译: 用于管理闪存驱动器,硬盘或两者之间的连接的方法和布置,以确保敏感数据在易受攻击的任何时候不被解密。 因此,在第一实现中,数据可以优选地被加密,因为它们首先进入闪存驱动器并且当它从闪存驱动器出来时被解密。 在另一个实现中,闪存驱动器可以逻辑地绑定到硬盘,使得它们都将使用相同的加密密钥。 在又一实施方式中,如果将硬盘移动到另一系统,则闪存驱动器也可以优选地同时移动。

    Password management outside of a BIOS
    5.
    发明授权
    Password management outside of a BIOS 有权
    BIOS之外的密码管理

    公开(公告)号:US08566600B2

    公开(公告)日:2013-10-22

    申请号:US12040535

    申请日:2008-02-29

    IPC分类号: G06F21/00

    CPC分类号: G06F21/31 G06F21/575

    摘要: In accordance with at least one presently preferred embodiment of the present invention, there is broadly contemplated herein the managing of a POP not solely in the BIOS but at least partly in a more secure location. In accordance with a particularly preferred embodiment of the present invention, this location could be in a NVRAM (non-volatile random access memory) inside a TPM (trusted platform module). Most preferably, this location will contain code that the BIOS preferably will need to access and employ in order to complete the booting of the system.

    摘要翻译: 根据本发明的至少一个目前优选的实施例,这里广泛考虑到不仅在BIOS中管理POP,而且至少部分地在更安全的位置。 根据本发明的特别优选的实施例,该位置可以在TPM(可信平台模块)内的NVRAM(非易失性随机存取存储器)中。 最优选地,该位置将包含BIOS优选地需要访问和应用以便完成系统引导的代码。

    Password Management Outside of a Bios
    7.
    发明申请
    Password Management Outside of a Bios 有权
    一个Bios之外的密码管理

    公开(公告)号:US20090222909A1

    公开(公告)日:2009-09-03

    申请号:US12040535

    申请日:2008-02-29

    IPC分类号: G06F21/00

    CPC分类号: G06F21/31 G06F21/575

    摘要: In accordance with at least one presently preferred embodiment of the present invention, there is broadly contemplated herein the managing of a POP not solely in the BIOS but at least partly in a more secure location. In accordance with a particularly preferred embodiment of the present invention, this location could be in a NVRAM (non-volatile random access memory) inside a TPM (trusted platform module). Most preferably, this location will contain code that the BIOS preferably will need to access and employ in order to complete the booting of the system.

    摘要翻译: 根据本发明的至少一个目前优选的实施例,这里广泛考虑到不仅在BIOS中管理POP,而且至少部分地在更安全的位置。 根据本发明的特别优选的实施例,该位置可以在TPM(可信平台模块)内的NVRAM(非易失性随机存取存储器)中。 最优选地,该位置将包含BIOS优选地需要访问和应用以便完成系统引导的代码。

    Local verification of trusted display based on remote server verification
    8.
    发明授权
    Local verification of trusted display based on remote server verification 有权
    基于远程服务器验证的受信任显示的本地验证

    公开(公告)号:US08205248B2

    公开(公告)日:2012-06-19

    申请号:US11865048

    申请日:2007-09-30

    IPC分类号: G06F7/04 H04L9/32

    CPC分类号: G06F21/57 H04L63/12

    摘要: In a system with a main memory, a network adapter, and a display, a transaction security module in communication with the network adapter. The transaction security module acts to: establish a secure identification item with an entity which positively identifies the entity; accept an application OS of the entity; and initiate a guest OS with the entity; the network adapter acting to connect with the entity subsequent to initiation of a guest OS; and the display acting to display the secure identification item subsequent to connection with the entity.

    摘要翻译: 在具有主存储器,网络适配器和显示器的系统中,与网络适配器通信的事务安全模块。 交易安全模块用于:建立一个安全的识别项目,该实体确实标识该实体; 接受实体的应用程序OS; 并与实体发起客户操作系统; 所述网络适配器在发起客户操作系统之后与所述实体进行连接; 以及显示器,用于在与所述实体连接之后显示所述安全识别项目。