Anti-theft in firmware
    3.
    发明授权

    公开(公告)号:US10762216B2

    公开(公告)日:2020-09-01

    申请号:US15789607

    申请日:2017-10-20

    申请人: INTEL CORPORATION

    摘要: Methods, systems and storage media are disclosed for enhanced system boot processing that authenticates boot code based on biometric information of the user before loading the boot code to system memory. For at least some embodiments, the bio-metric authentication augments authentication of boot code based on a unique platform identifier. The enhanced boot code authentication occurs before loading of the operating system, and may be performed during a Unified Extensible Firmware Interface (UEFI) boot sequence. Other embodiments are described and claimed.

    Media protection policy enforcement for multiple-operating-system environments

    公开(公告)号:US10025934B2

    公开(公告)日:2018-07-17

    申请号:US15665669

    申请日:2017-08-01

    申请人: Intel Corporation

    摘要: Technologies for media protection policy enforcement include a computing device having multiple operating systems and a data storage device partitioned into a number of regions. During execution of each of the operating systems, a policy enforcement module may intercept media access requests and determine whether to allow the media access requests based on platform media access policies. The media access policies may allow requests based on the identity of the executing operating system, the region of the data storage device, or the requested storage operation. Prior to loading a selected operating system, a firmware policy enforcement module may determine a region of the disk storage device to protect from the selected operating system. The firmware policy enforcement module may configure the data storage device to prevent access to that region. The media access policies may be stored in one or more firmware variables. Other embodiments are described and claimed.

    BROADCASTING MANAGEMENT INFORMATION USING FOUNTAIN CODES

    公开(公告)号:US20170185420A1

    公开(公告)日:2017-06-29

    申请号:US15454529

    申请日:2017-03-09

    申请人: Intel Corporation

    摘要: Technologies for broadcasting management information include a management server and a number of client devices. The management server encodes management data such as a certificate revocation list into a number of message fragments using a fountain code encoding algorithm and broadcasts the message fragments continually over a network. Each client device analyzes the network during a boot process to receive the broadcast message fragments. Each client device decodes the message fragments using a fountain code decoding algorithm and determines whether the message is complete. If the message is complete, the client device parses the message to retrieve the management data and may install the management data on the client device. If the message is incomplete, the client device may store the message fragments in nonvolatile storage for processing during future boot events. The client device may perform those operations in a pre-boot firmware environment. Other embodiments are described and claimed.

    Offloading the processing of a network protocol stack
    10.
    发明授权
    Offloading the processing of a network protocol stack 有权
    卸载网络协议栈的处理

    公开(公告)号:US09465623B2

    公开(公告)日:2016-10-11

    申请号:US14478603

    申请日:2014-09-05

    申请人: Intel Corporation

    IPC分类号: G06F9/44 H04L29/08 H04L12/24

    摘要: A computer system is partitioned during a pre-boot phase of the computer system between a first partition and a second partition, wherein the first partition to include a first processing unit and the second partition to include a second processing unit. An Input/Output (I/O) operating system is booted on the first partition. A general purpose operating system is booted on the second partition. Network transactions are issued by the general purpose operating system to be performed by the I/O operating system. The network transactions are performed by the I/O operating system.

    摘要翻译: 计算机系统在计算机系统的预引导阶段在第一分区和第二分区之间进行分区,其中第一分区包括第一处理单元,第二分区包括第二处理单元。 在第一个分区上引导输入/输出(I / O)操作系统。 通用操作系统在第二个分区上启动。 网络事务由通用操作系统由I / O操作系统执行。 网络事务由I / O操作系统执行。