System and method to seamlessly enable enhanced management and scripting of a computer system and its add-in devices
    1.
    发明申请
    System and method to seamlessly enable enhanced management and scripting of a computer system and its add-in devices 有权
    系统和方法无缝地实现计算机系统及其附加设备的增强的管理和脚本编制

    公开(公告)号:US20050144428A1

    公开(公告)日:2005-06-30

    申请号:US10746579

    申请日:2003-12-24

    IPC分类号: G06F9/44 G06F9/445 G06F15/177

    摘要: An embodiment of the present invention is a system and method relating to seamlessly enable enhanced management and scripting of a computer system and its add-in devices. In at least one embodiment, the present invention enables a system administrator or integrator to script a common configuration for multiple devices and then automatically configure the devices using the script. The language construct and central data repository for configuration settings are extended to comprehend a scripting language. A script is read by a script engine during either pre-boot or runtime. The script engine searches a keyword database on the central data repository to determine requested configuration settings. A data offset is corresponding to a specific op-code is used to determine where configuration settings are located, for modification.

    摘要翻译: 本发明的一个实施例是一种与无缝地实现计算机系统及其附加装置的增强的管理和脚本化有关的系统和方法。 在至少一个实施例中,本发明使得系统管理员或集成商可以为多个设备编写通用配置,然后使用脚本自动配置设备。 用于配置设置的语言结构和中央数据存储库被扩展以理解脚本语言。 脚本在预引导或运行期间由脚本引擎读取。 脚本引擎搜索中央数据存储库中的关键字数据库以确定所请求的配置设置。 数据偏移对应于用于确定配置设置位置的特定操作码,以供修改。

    System and method to enable platform personality migration
    3.
    发明申请
    System and method to enable platform personality migration 有权
    系统和方法,实现平台人格迁移

    公开(公告)号:US20060074952A1

    公开(公告)日:2006-04-06

    申请号:US10951277

    申请日:2004-09-27

    IPC分类号: G06F17/30

    CPC分类号: G06F9/4451 Y10S707/99943

    摘要: An embodiment of the present invention relates generally to computer configuration and, more specifically, to a system and method to seamlessly determine the component configurations of a series of heterogeneous platforms and enable their respective component configurations to be intelligently migrated from one platform to another. In some embodiments, the invention involves generating configuration binaries for a plurality of target platforms. The configuration binaries are used with tools to create configuration directives for the target machines. In at least one embodiment, the configuration directives are sent to the target platforms in a scripting language. In some embodiments, the scripts are automatically generated by a tool using the configuration binaries for various platforms and policy guidance to determine which settings should be set on or off. Other embodiments are described and claimed.

    摘要翻译: 本发明的实施例一般涉及计算机配置,更具体地,涉及无缝地确定一系列异构平台的组件配置并且使得它们各自的组件配置能够从一个平台被智能迁移到另一个平台的系统和方法。 在一些实施例中,本发明涉及为多个目标平台生成配置二进制文件。 配置二进制文件与工具一起使用,以创建目标计算机的配置指令。 在至少一个实施例中,配置指令以脚本语言发送到目标平台。 在一些实施例中,脚本由工具自动生成,使用各种平台的配置二进制文件和策略指导来确定哪些设置应被设置为开或关。 描述和要求保护其他实施例。

    System and method to secure boot both UEFI and legacy option ROM's with common policy engine
    4.
    发明授权
    System and method to secure boot both UEFI and legacy option ROM's with common policy engine 有权
    使用通用策略引擎来安全地启动UEFI和传统选项ROM的系统和方法

    公开(公告)号:US08694761B2

    公开(公告)日:2014-04-08

    申请号:US12347834

    申请日:2008-12-31

    IPC分类号: G06F9/00

    CPC分类号: G06F21/575

    摘要: In some embodiments, the invention involves using a policy engine during boot, in the driver execution environment (DXE) phases to authenticate that drivers and executable images to be loaded are authenticated. Images to be authenticated include the operating system (OS) loader. The policy engine utilizes a certificate database to hold valid certificates for third party images, according to platform policy. Images that are not authenticated are not loaded at boot time. Other embodiments are described and claimed.

    摘要翻译: 在一些实施例中,本发明涉及在引导期间在驱动程序执行环境(DXE)阶段中使用策略引擎来认证要加载的驱动程序和可执行映像被认证。 要认证的图像包括操作系统(OS)加载程序。 根据平台策略,策略引擎使用证书数据库来保存第三方映像的有效证书。 未通过身份验证的图像在引导时未加载。 描述和要求保护其他实施例。

    SYSTEM AND METHOD TO SECURE BOOT BOTH UEFI AND LEGACY OPTION ROM'S WITH COMMON POLICY ENGINE
    5.
    发明申请
    SYSTEM AND METHOD TO SECURE BOOT BOTH UEFI AND LEGACY OPTION ROM'S WITH COMMON POLICY ENGINE 有权
    使用普通政策引擎安全起见的系统和方法

    公开(公告)号:US20100169633A1

    公开(公告)日:2010-07-01

    申请号:US12347834

    申请日:2008-12-31

    IPC分类号: G06F9/00 G06F12/14

    CPC分类号: G06F21/575

    摘要: In some embodiments, the invention involves using a policy engine during boot, in the driver execution environment (DXE) phases to authenticate that drivers and executable images to be loaded are authenticated. Images to be authenticated include the operating system (OS) loader. The policy engine utilizes a certificate database to hold valid certificates for third party images, according to platform policy. Images that are not authenticated are not loaded at boot time. Other embodiments are described and claimed.

    摘要翻译: 在一些实施例中,本发明涉及在引导期间在驱动程序执行环境(DXE)阶段中使用策略引擎来认证要加载的驱动程序和可执行映像被认证。 要认证的图像包括操作系统(OS)加载程序。 根据平台策略,策略引擎使用证书数据库来保存第三方映像的有效证书。 未通过身份验证的图像在引导时未加载。 描述和要求保护其他实施例。

    Method of testing system memory
    6.
    发明授权
    Method of testing system memory 失效
    系统内存测试方法

    公开(公告)号:US5835704A

    公开(公告)日:1998-11-10

    申请号:US744625

    申请日:1996-11-06

    申请人: Yan Li Mahesh Natu

    发明人: Yan Li Mahesh Natu

    摘要: A method of testing at least a selected portion of system memory for a microprocessor system is disclosed, the microprocessor system having burst mode capability to transfer data values between the microprocessor and the system memory via a system bus. The method includes the steps of: writing at least a selected portion of system memory with a predetermined test pattern using the burst mode capability of the microprocessor system; reading back values from the at least a selected portion of system memory using the burst mode capability of the microprocessor system; and comparing the values read from the at least a selected portion of system memory with the predetermined test pattern written.

    摘要翻译: 公开了一种用于测试微处理器系统的至少一部分系统存储器的方法,该微处理器系统具有突发模式能力,以经由系统总线在微处理器和系统存储器之间传送数据值。 该方法包括以下步骤:使用微处理器系统的突发模式能力,用预定的测试模式写入系统存储器的至少一部分; 使用微处理器系统的突发模式能力从系统存储器的至少一个选定部分读回值; 以及将从系统存储器的至少一个选定部分读取的值与所写入的预定测试图案进行比较。

    Method, apparatus, and system for manageability and secure routing and endpoint access
    7.
    发明申请
    Method, apparatus, and system for manageability and secure routing and endpoint access 有权
    用于可管理性和安全路由和端点访问的方法,设备和系统

    公开(公告)号:US20120047309A1

    公开(公告)日:2012-02-23

    申请号:US12806643

    申请日:2010-08-18

    IPC分类号: G06F13/36

    摘要: A solution is presented to securing endpoints without the need for a separate bus or communication path. The solution allows for controlling access to endpoints by utilizing a management protocol by overlapping with existing interconnect communication paths in a packet format and utilizing a PCI address BDF (Bus number, Device number, and Function number) for verification.

    摘要翻译: 提供了解决方案来保护端点,而不需要单独的总线或通信路径。 该解决方案允许通过利用管理协议控制对端点的访问,通过与分组格式的现有互连通信路径重叠并利用PCI地址BDF(总线号码,设备号码和功能号码)进行验证。

    FIRMWARE INTEGRITY VERIFICATION
    8.
    发明申请
    FIRMWARE INTEGRITY VERIFICATION 审中-公开
    固件完整性验证

    公开(公告)号:US20090172639A1

    公开(公告)日:2009-07-02

    申请号:US11965295

    申请日:2007-12-27

    IPC分类号: G06F9/44

    CPC分类号: G06F21/57

    摘要: In some embodiments, the integrity of firmware stored in a non-volatile memory is verified prior to initiation of a firmware reset vector. Other embodiments are described and claimed.

    摘要翻译: 在一些实施例中,在启动固件复位向量之前验证存储在非易失性存储器中的固件的完整性。 描述和要求保护其他实施例。