-
公开(公告)号:US08417962B2
公开(公告)日:2013-04-09
申请号:US12813955
申请日:2010-06-11
申请人: Mark F. Novak , Robert Karl Spiger , Stefan Thom , David J. Linsley , Scott A. Field , Anil Francis Thomas
发明人: Mark F. Novak , Robert Karl Spiger , Stefan Thom , David J. Linsley , Scott A. Field , Anil Francis Thomas
CPC分类号: G06F21/575
摘要: Booting a computing device includes executing one or more firmware components followed by a boot loader component. A protection component for the computing device, such as an anti-malware program, is identified and executed as an initial component after executing the boot loader component. One or more boot components are also executed, these one or more boot components including only boot components that have been approved by the protection component. A list of boot components that have been previously approved by the protection component can also be maintained in a tamper-proof manner.
-
公开(公告)号:US20110307711A1
公开(公告)日:2011-12-15
申请号:US12813955
申请日:2010-06-11
申请人: Mark F. Novak , Robert Karl Spiger , Stefan Thom , David J. Linsley , Scott A. Field , Anil Francis Thomas
发明人: Mark F. Novak , Robert Karl Spiger , Stefan Thom , David J. Linsley , Scott A. Field , Anil Francis Thomas
IPC分类号: G06F21/00 , G06F12/14 , G06F15/177
CPC分类号: G06F21/575
摘要: Booting a computing device includes executing one or more firmware components followed by a boot loader component. A protection component for the computing device, such as an anti-malware program, is identified and executed as an initial component after executing the boot loader component. One or more boot components are also executed, these one or more boot components including only boot components that have been approved by the protection component. A list of boot components that have been previously approved by the protection component can also be maintained in a tamper-proof manner.
摘要翻译: 启动计算设备包括执行一个或多个固件组件,后跟引导加载程序组件。 在执行引导加载程序组件之后,识别并执行诸如反恶意软件程序之类的计算设备的保护组件作为初始组件。 还执行一个或多个引导组件,这些一个或多个引导组件仅包括被保护组件批准的引导组件。 先前已被保护组件批准的引导组件列表也可以以防篡改的方式进行维护。
-
公开(公告)号:US08789159B2
公开(公告)日:2014-07-22
申请号:US12029168
申请日:2008-02-11
申请人: S. Franklin Williams , Kiran Akella Venkata , David C. LeBlanc , Juraj Gottweis , Gareth A. Howell , Scott A. Field , Ramesh Chinta
发明人: S. Franklin Williams , Kiran Akella Venkata , David C. LeBlanc , Juraj Gottweis , Gareth A. Howell , Scott A. Field , Ramesh Chinta
CPC分类号: G06F21/53
摘要: Systems and methods for creating a secure process on a web server can include creating an application manager process, and creating an application host process, the application host process being created under control of the application manager process. Example methods can also include restricting attributes of the application host process, and assigning a unique logon identifier to the application host process so that the application host process can only communicate with the application manager process.
摘要翻译: 用于在Web服务器上创建安全进程的系统和方法可以包括创建应用程序管理器进程以及创建应用程序主机进程,该应用程序主机进程是在应用程序管理器进程的控制下创建的。 示例方法还可以包括限制应用程序主机进程的属性,以及向应用程序主机进程分配唯一的登录标识符,以便应用程序主机进程只能与应用程序管理器进程通信。
-
公开(公告)号:US07996682B2
公开(公告)日:2011-08-09
申请号:US11251946
申请日:2005-10-17
IPC分类号: G06F21/00
CPC分类号: G06F21/57
摘要: Techniques are described herein for securely prompting a user to confirm sensitive operations, input sensitive information or the like. The techniques include receiving or intercepting calls from applications to prompting routines. When a call to a prompting routine is received or intercepted a hint may be provided to the user to switch to a secure desktop. When the user switches from the user desktop to the secure desktop the particular prompt is displayed. The input to the prompt is received on the secure desktop and verified to have been provided by the user. The user input or a representation of the input is then returned to the application running on the user desktop. Using these techniques, interception of prompting messages by malware does not result in sensitive information being revealed. Furthermore, spoofing of new messages by malware does not lead to the dismissal of critical prompting.
摘要翻译: 这里描述了用于安全地提示用户确认敏感操作,输入敏感信息等的技术。 这些技术包括接收或拦截来自应用程序的呼叫以提示例程。 当接收或拦截对提示例程的调用时,可以向用户提供切换到安全桌面的提示。 当用户从用户桌面切换到安全桌面时,会显示特定的提示。 在安全桌面上接收到提示的输入,并验证其已由用户提供。 用户输入或输入的表示然后返回到在用户桌面上运行的应用程序。 使用这些技术,通过恶意软件拦截提示消息不会导致敏感信息被显示。 此外,恶意软件欺骗新消息不会导致关键提示被解雇。
-
公开(公告)号:US07757281B2
公开(公告)日:2010-07-13
申请号:US11450597
申请日:2006-06-09
申请人: Scott A. Field , Liqiang Zhu , Peter T. Brundrett , Paul J. Leach
发明人: Scott A. Field , Liqiang Zhu , Peter T. Brundrett , Paul J. Leach
IPC分类号: G06F7/04
CPC分类号: H04L63/102
摘要: Remote administrative privileges in a distributed system are disabled by default. To administer a remote system, express action is taken to elevate a user status to obtain remote administrative privileges. When local and remote systems communicate, information pertaining to the status of the logged on user is included in the communications. If the user wishes to legitimately administer a remote system, the user provides an explicit request. The request is processed. If the user is configured as an administrator of the remote system and the request contains an indication that the user's administrative status has been elevated, an authorization token is generated. The authorization token is utilized by the remote system to allow the user to administer the remote system.
摘要翻译: 默认情况下,分布式系统中的远程管理权限将被禁用。 要管理远程系统,请采取行动来提升用户状态以获得远程管理权限。 当本地和远程系统进行通信时,通信中包含与登录用户状态有关的信息。 如果用户希望合法地管理远程系统,则用户提供明确的请求。 请求被处理。 如果用户配置为远程系统的管理员,并且该请求包含用户的管理状态提升的指示,则会生成授权令牌。 远程系统利用授权令牌允许用户管理远程系统。
-
公开(公告)号:US20090205034A1
公开(公告)日:2009-08-13
申请号:US12029168
申请日:2008-02-11
申请人: S. Franklin Williams , Kiran Akella Venkata , David C. LeBlanc , Juraj Gottweis , Gareth A. Howell , Scott A. Field , Ramesh Chinta
发明人: S. Franklin Williams , Kiran Akella Venkata , David C. LeBlanc , Juraj Gottweis , Gareth A. Howell , Scott A. Field , Ramesh Chinta
IPC分类号: H04L9/32
CPC分类号: G06F21/53
摘要: Systems and methods for creating a secure process on a web server can include creating an application manager process, and creating an application host process, the application host process being created under control of the application manager process. Example methods can also include restricting attributes of the application host process, and assigning a unique logon identifier to the application host process so that the application host process can only communicate with the application manager process.
摘要翻译: 用于在Web服务器上创建安全进程的系统和方法可以包括创建应用程序管理器进程以及创建应用程序主机进程,该应用程序主机进程是在应用程序管理器进程的控制下创建的。 示例方法还可以包括限制应用程序主机进程的属性,以及向应用程序主机进程分配唯一的登录标识符,以便应用程序主机进程只能与应用程序管理器进程通信。
-
公开(公告)号:US20080235179A1
公开(公告)日:2008-09-25
申请号:US11688037
申请日:2007-03-19
IPC分类号: G06F17/30
CPC分类号: G06F17/3089 , Y10S707/99932
摘要: Systems, methods, and computer-readable media for identifying executable scenario solutions relevant to a user query and returning such executable scenario solutions as search results in response to the user query are provided. Upon receiving a user query, a plurality of results is returned, each result being representative of a series of steps which may be implemented to address a particular issue relevant to the received user query. Often, a series of steps or scenario includes a number of sub-scenarios, each of which is to be executed sequentially to achieve the desired result. Accordingly, upon selection of a particular search result, the user may be guided through a series of sub-scenario result options until an item having direct association to a series of steps is selected. Once selected, the executable scenario solution is presented to the user for execution.
摘要翻译: 提供了用于识别与用户查询相关的可执行场景解决方案的系统,方法和计算机可读介质,并且响应于用户查询返回这些可执行场景解决方案作为搜索结果。 在接收到用户查询时,返回多个结果,每个结果代表可以被实现以处理与所接收的用户查询相关的特定问题的一系列步骤。 通常,一系列步骤或场景包括若干子场景,每个子场景将被顺序执行以实现期望的结果。 因此,在选择特定的搜索结果之后,可以引导用户通过一系列子场景结果选项直到选择与一系列步骤有直接关联的项目。 一旦选择,可执行的场景解决方案被呈现给用户执行。
-
公开(公告)号:US20080235170A1
公开(公告)日:2008-09-25
申请号:US11688023
申请日:2007-03-19
IPC分类号: G06F15/18
CPC分类号: G06Q30/02
摘要: Mechanisms for directing advertising in search result presentation and/or scenario solution execution based upon a user's locality are provided. Locality refers to a collection of metadata created based upon scenario solutions executed by a user and/or enablers acquired by a user during scenario solution execution. For instance, embodiments of the present invention provide a mechanism by which scenario solutions or enablers related to commonly executed scenario solutions or enablers stored in association with the user's locality can be advertised to the user in conjunction with presentation of scenario solution-related search results. Additionally, embodiments of the present invention provide a mechanism by which more highly rated scenario solutions and/or enablers than those associated with the user's locality may be advertised during presentation of an executed scenario solution.
摘要翻译: 提供了基于用户的位置来指导广告在搜索结果呈现和/或场景解决方案执行中的机制。 局部性是指在场景解决方案执行期间,基于由用户执行的场景解决方案创建的元数据集和/或用户获取的使能器。 例如,本发明的实施例提供了一种机制,通过该机制可以与呈现场景解决方案相关的搜索结果一起向用户通告与通常执行的场景解决方案相关的场景解决方案或使能者与用户的地点相关联地存储。 此外,本发明的实施例提供了一种机制,通过该机制,在呈现执行的场景解决方案期间可以通告与用户的位置相关联的更高度评价的场景解决方案和/或使能者。
-
公开(公告)号:US20080120690A1
公开(公告)日:2008-05-22
申请号:US11601155
申请日:2006-11-17
IPC分类号: G06F21/00
CPC分类号: G06F21/57 , G06F2221/2149
摘要: If a service detects that a state of a computer system deviates from an acceptable state, the computer system can be prevented from accessing network resources or locations, except for those network resources or locations that would bring the state into compliance. Monitored states can include whether applications or the operating system have been properly purchased, whether they have been properly updated, and whether they are being properly used given the environment of their usage. Network restrictions can be implemented through a parental control mechanism, a domain name service mechanism, or other like mechanisms, and can include redirection to appropriate network resources or locations.
摘要翻译: 如果服务检测到计算机系统的状态偏离可接受状态,则可以防止计算机系统访问网络资源或位置,除了将使状态符合的那些网络资源或位置。 受监视的状态可以包括应用程序或操作系统是否已正确购买,是否已正确更新,以及是否在使用环境中正确使用它们。 网络限制可以通过家长控制机制,域名服务机制或其他类似的机制实现,并且可以包括重定向到适当的网络资源或位置。
-
公开(公告)号:US07376968B2
公开(公告)日:2008-05-20
申请号:US10718153
申请日:2003-11-20
申请人: Andrew J. Ritz , David B. Cross , Duncan Bryce , James A. Schwartz, Jr. , Jianrong Gu , Scott A. Field
发明人: Andrew J. Ritz , David B. Cross , Duncan Bryce , James A. Schwartz, Jr. , Jianrong Gu , Scott A. Field
CPC分类号: G06F21/575 , G06F21/6209 , G06F2221/2107
摘要: A system and method for facilitating BIOS integrated encryption is provided. An interface is defined between the operating system and the BIOS. The operating system employs this interface to provide BIOS code information to facilitate decryption of data that is encrypted on the system. In the pre-operating system boot phase, the BIOS employs the decryption information provided from this interface in order to decrypt the data. The decrypted information can be employed to facilitate secure rebooting of a computer system from hibernate mode and/or secure access to device(s).
摘要翻译: 提供了一种用于促进BIOS集成加密的系统和方法。 在操作系统和BIOS之间定义一个接口。 操作系统采用该接口提供BIOS代码信息,以便于在系统上加密的数据的解密。 在操作前系统启动阶段,BIOS使用从该接口提供的解密信息来解密数据。 解密的信息可用于促进计算机系统从休眠模式的安全重新启动和/或安全地访问设备。
-
-
-
-
-
-
-
-
-