Method and apparatus for secure remote system management
    1.
    发明授权
    Method and apparatus for secure remote system management 失效
    用于安全远程系统管理的方法和装置

    公开(公告)号:US07024695B1

    公开(公告)日:2006-04-04

    申请号:US09476737

    申请日:1999-12-30

    Abstract: To prevent unauthorized access to hardware management information in an out-of-band mode, i.e., when the operating system of the hardware is not executing, a method and apparatus employ an authentication protocol. Upon receiving a request for hardware component information in a service processor that is disposed in a hardware component, which request is received as an open session request and which request passes external to an operating system controlling the hardware component, the service processor transmits a challenge string to the requesting client application. In response to a challenge response received from the requesting client application, the service processor compares the challenge response to an expected response to the challenge. The expected challenge response is calculated by the service processor. Based on the result of the comparison, the service processor transmits an authentication response to the requesting client application indicating success or failure of the authentication process. On the client side, in response to a challenge string from the service processor, the requesting client application transmits to the service processor a challenge response, which includes an sequence number that increments with every new message from the requesting client application. The challenge response also includes a hash number calculated by the requesting client application, which hash number is a function of the challenge string, session identification number, sequence number and/or a password. Each new packet including data and/or commands from the client application includes a similarly calculated hash number.

    Abstract translation: 为了防止在带外模式(即,硬件的操作系统未执行)下的硬件管理信息的未经授权的访问,方法和装置采用认证协议。 在接收到在硬件组件中设置的服务处理器中的硬件组件信息的请求时,该请求作为开放会话请求被接收,并且哪个请求在控制硬件组件的操作系统外部通过,服务处理器发送挑战串 到请求的客户端应用程序。 响应于从请求客户端应用程序接收到的挑战响应,服务处理器将挑战响应与对挑战的期望响应进行比较。 预期的挑战响应由服务处理器计算。 基于比较的结果,服务处理器向请求客户端应用发送认证响应,指示认证过程的成败。 在客户端,响应于来自服务处理器的挑战串,请求客户端应用程序向服务处理器发送挑战响应,该响应响应包括随请求的客户端应用程序的每个新消息递增的序列号。 挑战响应还包括由请求客户端应用计算的哈希号,该哈希号是挑战串,会话识别号,序列号和/或密码的函数。 包括来自客户端应用程序的数据和/或命令的每个新分组包括类似地计算的散列数。

    SECURE AND EFFICIENT MICROCODE(UCODE) HOT-UPGRADE FOR BARE METAL CLOUD

    公开(公告)号:US20210096848A1

    公开(公告)日:2021-04-01

    申请号:US17120072

    申请日:2020-12-11

    Abstract: A microcode (uCode) hot-upgrade method for bare metal cloud deployment and associated apparatus. Under the uCode hot-upgrade method, a uCode path is received at an out-of-band controller (e.g., baseboard management controller (BMC)) and buffered in a memory buffer in the out-of-band controller. The out-of-band controller exposes the memory buffer as a Memory-Mapped Input-Output (MMIO) range to a host CPU. A uCode upgrade interrupt service is triggered to upgrade uCode for one or more CPUs in a bare-metal cloud platform during runtime of a tenant host operating system (OS) using an out-of-bound process. This innovation enables cloud service providers to deploy uCode hot-patches to bare metal servers for live-patch without touching the tenant operating system environment.

    EVENT-TRIGGERED STORAGE OF DATA TO NON-VOLATILE MEMORY
    8.
    发明申请
    EVENT-TRIGGERED STORAGE OF DATA TO NON-VOLATILE MEMORY 审中-公开
    事件触发数据存储到非易失性存储器

    公开(公告)号:US20150089287A1

    公开(公告)日:2015-03-26

    申请号:US14127548

    申请日:2013-09-23

    Abstract: An event management resource monitors a processor environment. In response to detecting occurrence of a trigger event in the processor environment, the event management resource initiates a transfer of processor cache data from volatile storage in the processor environment to non-volatile memory. The event management resource can be configured to produce status information associated with the transfer of cache data to a respective non-volatile memory resource. The event management resource stores the status information in a non-volatile storage resource for later retrieval. Accordingly, status information associated with the event causing the transfer is available for analysis on subsequent power up or reboot of a respective computer system.

    Abstract translation: 事件管理资源监视处理器环境。 响应于在处理器环境中检测到触发事件的发生,事件管理资源启动处理器高速缓存数据从处理器环境中的易失性存储器传送到非易失性存储器。 可以将事件管理资源配置为产生与缓存数据传送相关联的状态信息到相应的非易失性存储器资源。 事件管理资源将状态信息存储在非易失性存储资源中,供以后检索。 因此,与导致传送的事件相关联的状态信息可用于在随后的相应计算机系统的加电或重新启动时进行分析。

    MEMORY ALLOCATION FOR VIRTUAL MACHINES USING MEMORY MAP
    9.
    发明申请
    MEMORY ALLOCATION FOR VIRTUAL MACHINES USING MEMORY MAP 有权
    使用存储器映射的虚拟机的内存分配

    公开(公告)号:US20140181576A1

    公开(公告)日:2014-06-26

    申请号:US13722499

    申请日:2012-12-20

    Abstract: Apparatuses and methods associated with memory allocations for virtual machines are disclosed. In embodiments, an apparatus may include a processor; a plurality of memory modules; and a memory controller configured to provide a layout of the memory modules. The apparatus may further include a VMM configured to be operated by the processor to manage execution of a VM by the processor including selective allocation of the memory modules to the VM using the layout of the memory modules provided to the VMM by the memory controller. Other embodiments may be described and claimed.

    Abstract translation: 公开了与虚拟机的存储器分配相关联的装置和方法。 在实施例中,装置可以包括处理器; 多个存储器模块; 以及存储器控制器,被配置为提供所述存储器模块的布局。 该设备可以进一步包括被配置为由处理器操作以管理由处理器执行VM的VMM,包括使用由存储器控制器提供给VMM的存储器模块的布局来将存储器模块选择性地分配给VM。 可以描述和要求保护其他实施例。

Patent Agency Ranking