System and method to enable platform personality migration
    1.
    发明申请
    System and method to enable platform personality migration 有权
    系统和方法,实现平台人格迁移

    公开(公告)号:US20060074952A1

    公开(公告)日:2006-04-06

    申请号:US10951277

    申请日:2004-09-27

    IPC分类号: G06F17/30

    CPC分类号: G06F9/4451 Y10S707/99943

    摘要: An embodiment of the present invention relates generally to computer configuration and, more specifically, to a system and method to seamlessly determine the component configurations of a series of heterogeneous platforms and enable their respective component configurations to be intelligently migrated from one platform to another. In some embodiments, the invention involves generating configuration binaries for a plurality of target platforms. The configuration binaries are used with tools to create configuration directives for the target machines. In at least one embodiment, the configuration directives are sent to the target platforms in a scripting language. In some embodiments, the scripts are automatically generated by a tool using the configuration binaries for various platforms and policy guidance to determine which settings should be set on or off. Other embodiments are described and claimed.

    摘要翻译: 本发明的实施例一般涉及计算机配置,更具体地,涉及无缝地确定一系列异构平台的组件配置并且使得它们各自的组件配置能够从一个平台被智能迁移到另一个平台的系统和方法。 在一些实施例中,本发明涉及为多个目标平台生成配置二进制文件。 配置二进制文件与工具一起使用,以创建目标计算机的配置指令。 在至少一个实施例中,配置指令以脚本语言发送到目标平台。 在一些实施例中,脚本由工具自动生成,使用各种平台的配置二进制文件和策略指导来确定哪些设置应被设置为开或关。 描述和要求保护其他实施例。

    System and method to secure boot both UEFI and legacy option ROM's with common policy engine
    2.
    发明授权
    System and method to secure boot both UEFI and legacy option ROM's with common policy engine 有权
    使用通用策略引擎来安全地启动UEFI和传统选项ROM的系统和方法

    公开(公告)号:US08694761B2

    公开(公告)日:2014-04-08

    申请号:US12347834

    申请日:2008-12-31

    IPC分类号: G06F9/00

    CPC分类号: G06F21/575

    摘要: In some embodiments, the invention involves using a policy engine during boot, in the driver execution environment (DXE) phases to authenticate that drivers and executable images to be loaded are authenticated. Images to be authenticated include the operating system (OS) loader. The policy engine utilizes a certificate database to hold valid certificates for third party images, according to platform policy. Images that are not authenticated are not loaded at boot time. Other embodiments are described and claimed.

    摘要翻译: 在一些实施例中,本发明涉及在引导期间在驱动程序执行环境(DXE)阶段中使用策略引擎来认证要加载的驱动程序和可执行映像被认证。 要认证的图像包括操作系统(OS)加载程序。 根据平台策略,策略引擎使用证书数据库来保存第三方映像的有效证书。 未通过身份验证的图像在引导时未加载。 描述和要求保护其他实施例。

    SYSTEM AND METHOD TO SECURE BOOT BOTH UEFI AND LEGACY OPTION ROM'S WITH COMMON POLICY ENGINE
    3.
    发明申请
    SYSTEM AND METHOD TO SECURE BOOT BOTH UEFI AND LEGACY OPTION ROM'S WITH COMMON POLICY ENGINE 有权
    使用普通政策引擎安全起见的系统和方法

    公开(公告)号:US20100169633A1

    公开(公告)日:2010-07-01

    申请号:US12347834

    申请日:2008-12-31

    IPC分类号: G06F9/00 G06F12/14

    CPC分类号: G06F21/575

    摘要: In some embodiments, the invention involves using a policy engine during boot, in the driver execution environment (DXE) phases to authenticate that drivers and executable images to be loaded are authenticated. Images to be authenticated include the operating system (OS) loader. The policy engine utilizes a certificate database to hold valid certificates for third party images, according to platform policy. Images that are not authenticated are not loaded at boot time. Other embodiments are described and claimed.

    摘要翻译: 在一些实施例中,本发明涉及在引导期间在驱动程序执行环境(DXE)阶段中使用策略引擎来认证要加载的驱动程序和可执行映像被认证。 要认证的图像包括操作系统(OS)加载程序。 根据平台策略,策略引擎使用证书数据库来保存第三方映像的有效证书。 未通过身份验证的图像在引导时未加载。 描述和要求保护其他实施例。

    Apparatus and method for secure boot environment
    4.
    发明授权
    Apparatus and method for secure boot environment 有权
    安全引导环境的装置和方法

    公开(公告)号:US07984286B2

    公开(公告)日:2011-07-19

    申请号:US12215071

    申请日:2008-06-25

    IPC分类号: G06F15/177 H04L9/32

    CPC分类号: G06F21/575

    摘要: In some embodiments, a processor-based system may include at least one processor, at least one memory coupled to the at least one processor, a boot block stored at a first memory location, a capsule update stored at a second memory location, a startup authenticated code module to ensure the integrity of the boot block upon a restart of the processor-based system, code which is executable by the processor-based system to cause the processor-based system to validate the boot block with the startup authenticated code module upon the restart of the processor-based system, and, if the boot block is successfully validated, to validate the capsule update for the processor-based system with the startup authenticated code module. Other embodiments are disclosed and claimed.

    摘要翻译: 在一些实施例中,基于处理器的系统可以包括至少一个处理器,耦合到至少一个处理器的至少一个存储器,存储在第一存储器位置的引导块,存储在第二存储器位置的封装更新,启动 认证代码模块,以确保在基于处理器的系统重新启动时引导块的完整性,该代码可由基于处理器的系统执行,以使基于处理器的系统使用启动认证代码模块来验证引导块 重新启动基于处理器的系统,并且如果启动块被成功验证,则使用启动认证代码模块验证基于处理器的系统的胶囊更新。 公开和要求保护其他实施例。

    Apparatus and method for secure boot environment
    5.
    发明申请
    Apparatus and method for secure boot environment 有权
    安全引导环境的装置和方法

    公开(公告)号:US20090327684A1

    公开(公告)日:2009-12-31

    申请号:US12215071

    申请日:2008-06-25

    IPC分类号: G06F9/00

    CPC分类号: G06F21/575

    摘要: In some embodiments, a processor-based system may include at least one processor, at least one memory coupled to the at least one processor, a boot block stored at a first memory location, a capsule update stored at a second memory location, a startup authenticated code module to ensure the integrity of the boot block upon a restart of the processor-based system, code which is executable by the processor-based system to cause the processor-based system to validate the boot block with the startup authenticated code module upon the restart of the processor-based system, and, if the boot block is successfully validated, to validate the capsule update for the processor-based system with the startup authenticated code module. Other embodiments are disclosed and claimed.

    摘要翻译: 在一些实施例中,基于处理器的系统可以包括至少一个处理器,耦合到至少一个处理器的至少一个存储器,存储在第一存储器位置的引导块,存储在第二存储器位置的封装更新,启动 认证代码模块,以确保在基于处理器的系统重新启动时引导块的完整性,该代码可由基于处理器的系统执行,以使基于处理器的系统使用启动认证代码模块来验证引导块 重新启动基于处理器的系统,并且如果启动块被成功验证,则使用启动认证代码模块验证基于处理器的系统的胶囊更新。 公开和要求保护其他实施例。

    Autonomous initialization of non-volatile random access memory in a computer system
    6.
    发明授权
    Autonomous initialization of non-volatile random access memory in a computer system 有权
    计算机系统中非易失性随机存取存储器的自动初始化

    公开(公告)号:US09378133B2

    公开(公告)日:2016-06-28

    申请号:US13997945

    申请日:2011-09-30

    IPC分类号: G06F12/02 G06F9/44

    CPC分类号: G06F12/0246 G06F9/4403

    摘要: A non-volatile random access memory (NVRAM) is used in a computer system to store information that allows the NVRAM to autonomously initialize itself at power-on. The computer system includes a processor, an NVRAM controller coupled to the processor, and an NVRAM that comprises the NVRAM controller. The NVRAM is byte-rewritable and byte-erasable by the processor. The NVRAM stores a memory interface table containing information for the NVRAM controller to autonomously initialize the NVRAM upon power-on of the computer system without interacting with the processor and firmware outside of the NVRAM. The information is provided by the NVRAM controller to the processor to allow the processor to access the NVRAM.

    摘要翻译: 在计算机系统中使用非易失性随机存取存储器(NVRAM)来存储允许NVRAM在上电时自动初始化的信息。 计算机系统包括处理器,耦合到处理器的NVRAM控制器和包括NVRAM控制器的NVRAM。 NVRAM是字节可重写的,可由处理器字节擦除。 NVRAM存储包含NVRAM控制器的信息的存储器接口表,用于在计算机系统上电时自动初始化NVRAM,而不与NVRAM之外的处理器和固件交互。 该信息由NVRAM控制器提供给处理器,以允许处理器访问NVRAM。

    AUTONOMOUS INITIALIZATION OF NON-VOLATILE RANDOM ACCESS MEMORY IN A COMPUTER SYSTEM
    7.
    发明申请
    AUTONOMOUS INITIALIZATION OF NON-VOLATILE RANDOM ACCESS MEMORY IN A COMPUTER SYSTEM 有权
    计算机系统中非易失性随机存取存储器的自动初始化

    公开(公告)号:US20130304980A1

    公开(公告)日:2013-11-14

    申请号:US13997945

    申请日:2011-09-30

    IPC分类号: G06F12/02

    CPC分类号: G06F12/0246 G06F9/4403

    摘要: A non-volatile random access memory (NVRAM) is used in a computer system to store information that allows the NVRAM to autonomously initialize itself at power-on. The computer system includes a processor, an NVRAM controller coupled to the processor, and an NVRAM that comprises the NVRAM controller. The NVRAM is byte-rewritable and byte-erasable by the processor. The NVRAM stores a memory interface table containing information for the NVRAM controller to autonomously initialize the NVRAM upon power-on of the computer system without interacting with the processor and firmware outside of the NVRAM. The information is provided by the NVRAM controller to the processor to allow the processor to access the NVRAM.

    摘要翻译: 在计算机系统中使用非易失性随机存取存储器(NVRAM)来存储允许NVRAM在上电时自动初始化的信息。 计算机系统包括处理器,耦合到处理器的NVRAM控制器和包括NVRAM控制器的NVRAM。 NVRAM是字节可重写的,可由处理器字节擦除。 NVRAM存储包含NVRAM控制器的信息的存储器接口表,用于在计算机系统上电时自动初始化NVRAM,而不与NVRAM之外的处理器和固件交互。 该信息由NVRAM控制器提供给处理器,以允许处理器访问NVRAM。

    Live network configuration within a link based computing system
    8.
    发明申请
    Live network configuration within a link based computing system 有权
    基于链路的计算系统中的实时网络配置

    公开(公告)号:US20070118628A1

    公开(公告)日:2007-05-24

    申请号:US11284537

    申请日:2005-11-21

    IPC分类号: G06F15/177

    CPC分类号: H04L41/082

    摘要: A method is described in which, in response to notice of a configuration event yet to happen within a network that is part of a link-based computing system, a component within said link based computing system: a) identifies networking configuration information changes to be made by components within the link-based computing system; and, b) sends instances of program code to each one of the components. Each instance of program code is to be executed by a specific component that it was sent to. Each instance of program code is customized to implement the particular one or more networking configuration information changes to be made at the specific component it was sent to.

    摘要翻译: 描述了一种方法,其中响应于在作为基于链路的计算系统的一部分的网络内尚未发生的配置事件的通知,所述基于链路的计算系统中的组件:a)将网络配置信息变化标识为 由基于链路的计算系统中的组件构成; 和b)将程序代码的实例发送到每个组件。 程序代码的每个实例都要由发送到的特定组件来执行。 程序代码的每个实例被定制以实现要在其发送到的特定组件上进行的特定一个或多个网络配置信息更改。