METHOD, APPARATUS, SYSTEM, AND MACHINE READABLE STORAGE MEDIUM FOR PROVIDING SOFTWARE SECURITY
    1.
    发明申请
    METHOD, APPARATUS, SYSTEM, AND MACHINE READABLE STORAGE MEDIUM FOR PROVIDING SOFTWARE SECURITY 有权
    方法,设备,系统和机器可读存储介质提供软件安全

    公开(公告)号:US20140250293A1

    公开(公告)日:2014-09-04

    申请号:US13976504

    申请日:2013-02-25

    IPC分类号: G06F9/44

    摘要: Technologies are provided in example embodiments for determining that a module is to be loaded, the module being associated with module code, determining that the module is a frozen module, the frozen module being associated with frozen module code, determining that a module fingerprint of the module fails to correspond with a frozen module fingerprint of the frozen module, and causing loading of the frozen module code instead of the module code.

    摘要翻译: 在示例实施例中提供技术,用于确定要加载模块,模块与模块代码相关联,确定模块是冻结模块,冻结模块与冻结的模块代码相关联,确定模块的模块指纹 模块不能对应于冻结模块的冻结模块指纹,并导致加载冻结模块代码而不是模块代码。

    System and method to secure boot both UEFI and legacy option ROM's with common policy engine
    2.
    发明授权
    System and method to secure boot both UEFI and legacy option ROM's with common policy engine 有权
    使用通用策略引擎来安全地启动UEFI和传统选项ROM的系统和方法

    公开(公告)号:US08694761B2

    公开(公告)日:2014-04-08

    申请号:US12347834

    申请日:2008-12-31

    IPC分类号: G06F9/00

    CPC分类号: G06F21/575

    摘要: In some embodiments, the invention involves using a policy engine during boot, in the driver execution environment (DXE) phases to authenticate that drivers and executable images to be loaded are authenticated. Images to be authenticated include the operating system (OS) loader. The policy engine utilizes a certificate database to hold valid certificates for third party images, according to platform policy. Images that are not authenticated are not loaded at boot time. Other embodiments are described and claimed.

    摘要翻译: 在一些实施例中,本发明涉及在引导期间在驱动程序执行环境(DXE)阶段中使用策略引擎来认证要加载的驱动程序和可执行映像被认证。 要认证的图像包括操作系统(OS)加载程序。 根据平台策略,策略引擎使用证书数据库来保存第三方映像的有效证书。 未通过身份验证的图像在引导时未加载。 描述和要求保护其他实施例。

    SYSTEM AND METHOD TO SECURE BOOT BOTH UEFI AND LEGACY OPTION ROM'S WITH COMMON POLICY ENGINE
    3.
    发明申请
    SYSTEM AND METHOD TO SECURE BOOT BOTH UEFI AND LEGACY OPTION ROM'S WITH COMMON POLICY ENGINE 有权
    使用普通政策引擎安全起见的系统和方法

    公开(公告)号:US20100169633A1

    公开(公告)日:2010-07-01

    申请号:US12347834

    申请日:2008-12-31

    IPC分类号: G06F9/00 G06F12/14

    CPC分类号: G06F21/575

    摘要: In some embodiments, the invention involves using a policy engine during boot, in the driver execution environment (DXE) phases to authenticate that drivers and executable images to be loaded are authenticated. Images to be authenticated include the operating system (OS) loader. The policy engine utilizes a certificate database to hold valid certificates for third party images, according to platform policy. Images that are not authenticated are not loaded at boot time. Other embodiments are described and claimed.

    摘要翻译: 在一些实施例中,本发明涉及在引导期间在驱动程序执行环境(DXE)阶段中使用策略引擎来认证要加载的驱动程序和可执行映像被认证。 要认证的图像包括操作系统(OS)加载程序。 根据平台策略,策略引擎使用证书数据库来保存第三方映像的有效证书。 未通过身份验证的图像在引导时未加载。 描述和要求保护其他实施例。

    SYSTEMS AND METHODS FOR ACCOUNT RECOVERY USING A PLATFORM ATTESTATION CREDENTIAL
    4.
    发明申请
    SYSTEMS AND METHODS FOR ACCOUNT RECOVERY USING A PLATFORM ATTESTATION CREDENTIAL 有权
    使用平台进行帐号恢复的系统和方法

    公开(公告)号:US20140282969A1

    公开(公告)日:2014-09-18

    申请号:US13995238

    申请日:2013-03-13

    IPC分类号: H04L29/06

    摘要: Described herein is technology for restoring access to a user account. In particular, systems and methods for account recovery using a platform attestation credential are described. In some embodiments, the platform attestation credential is generated by an authentication device in a pre boot environment. A first copy of the platform attestation credential may be bound by an account management system to a user account. Access to the user account may subsequently be restored using a second copy of the platform attestation credential.

    摘要翻译: 这里描述的是用于恢复对用户帐户的访问的技术。 特别地,描述了使用平台认证证书进行帐户恢复的系统和方法。 在一些实施例中,平台证明凭证由预引导环境中的认证设备生成。 平台认证凭证的第一个副本可能会被帐户管理系统约束到用户帐户。 随后可以使用平台认证凭证的第二副本来恢复对用户帐户的访问。

    Cross validation of data using multiple subsystems
    7.
    发明授权
    Cross validation of data using multiple subsystems 有权
    使用多个子系统交叉验证数据

    公开(公告)号:US08751813B2

    公开(公告)日:2014-06-10

    申请号:US13550583

    申请日:2012-07-16

    IPC分类号: H04L9/32

    摘要: A method and apparatus for cross validation of data using multiple subsystems are described. According to one embodiment of the invention, a computer comprises a first subsystem and a second subsystem; and a memory, the memory comprising a first memory region and a second memory region, the first memory region being associated with the first subsystem and a second memory region being associated with the second subsystem; upon start up of the computer, the first subsystem to validate the second memory region and the second subsystem to validate the first memory region.

    摘要翻译: 描述了使用多个子系统进行数据交叉验证的方法和装置。 根据本发明的一个实施例,计算机包括第一子系统和第二子系统; 以及存储器,所述存储器包括第一存储器区域和第二存储器区域,所述第一存储器区域与所述第一子系统相关联,以及与所述第二子系统相关联的第二存储器区域; 在计算机启动时,第一子系统用于验证第二存储器区域和第二子系统以验证第一存储器区域。

    System and method to provide added security to a platform using locality-based data
    8.
    发明授权
    System and method to provide added security to a platform using locality-based data 有权
    使用基于位置的数据为平台增加安全性的系统和方法

    公开(公告)号:US08561138B2

    公开(公告)日:2013-10-15

    申请号:US12347830

    申请日:2008-12-31

    IPC分类号: G06F21/00

    摘要: In some embodiments, the invention involves protecting a platform using locality-based data and, more specifically, to using the locality-based data to ensure that the platform has not been stolen or subject to unauthorized access. In some embodiments, a second level of security, such as a key fob, badge or other source device having an identifying RFID is used for added security. Other embodiments are described and claimed.

    摘要翻译: 在一些实施例中,本发明涉及使用基于地点的数据来保护平台,更具体地说,涉及使用基于位置的数据来确保平台未被盗或遭受未经授权的访问。 在一些实施例中,使用具有识别RFID的第二级安全性,例如密钥卡,徽章或其他源设备来增加安全性。 描述和要求保护其他实施例。

    METHOD AND APPARATUS FOR QUICK RESUMPTION
    9.
    发明申请
    METHOD AND APPARATUS FOR QUICK RESUMPTION 有权
    快速恢复的方法和装置

    公开(公告)号:US20130151876A1

    公开(公告)日:2013-06-13

    申请号:US13764245

    申请日:2013-02-11

    IPC分类号: G06F1/32

    CPC分类号: G06F1/3234 G06F9/4418

    摘要: When transitioning from sleep mode to active mode, a processing system loads first stage resume content and second stage resume content into a volatile memory of the processing system. The first stage resume content may contain contextual data for a first program that was in use before the processing system transitioned to sleep mode. The second stage resume content may contain contextual data for another program that was in use before the processing system transitioned to sleep mode. The processing system may provide a user interface for the first program before all of the second stage resume content has been loaded into the volatile memory. Other embodiments are described and claimed.

    摘要翻译: 当从睡眠模式转换到活动模式时,处理系统将第一级恢复内容和第二级恢复内容加载到处理系统的易失性存储器中。 第一阶段恢复内容可以包含在处理系统转换到睡眠模式之前正在使用的第一程序的上下文数据。 第二阶段恢复内容可以包含在处理系统转换到睡眠模式之前正在使用的另一程序的上下文数据。 处理系统可以在所有第二阶段恢复内容已经被加载到易失性存储器之前为第一程序提供用户界面。 描述和要求保护其他实施例。

    Method to qualify access to a block storage device via augmentation of the device'S controller and firmware flow
    10.
    发明授权
    Method to qualify access to a block storage device via augmentation of the device'S controller and firmware flow 有权
    通过增加设备的控制器和固件流来限制访问块存储设备的方法

    公开(公告)号:US08161258B2

    公开(公告)日:2012-04-17

    申请号:US13100138

    申请日:2011-05-03

    IPC分类号: G06F12/14

    摘要: A method to qualify access to a block storage device via augmentation of the device's controller and firmware flow. The method employs one or more block exclusion vectors (BEVs) that include attributes specifying allowed access operations for corresponding block address ranges. Logic in accordance with the BEVs is programmed into the controller for the block storage device, such as a disk drive controller for a disk drive. In response to an access request, a block address range corresponding to the storage block(s) requested to be accessed is determined. Based on the BEV entries, a determination is made to whether the determined logical block address range is covered by a corresponding BEV entry. If so, the attributes of the BEV are used to determine whether the access operation is allowed. The method may be used to secure access to firmware stored on a disk drive, thus enabling a system configuration that does not require a conventional firmware storage device.

    摘要翻译: 一种通过增加设备的控制器和固件流来限制访问块存储设备的方法。 该方法采用一个或多个块排除向量(BEV),其包括指定相应块地址范围的允许访问操作的属性。 根据BEV的逻辑被编程到用于块存储设备的控制器中,例如用于磁盘驱动器的磁盘驱动器控制器。 响应于访问请求,确定与请求访问的存储块相对应的块地址范围。 基于BEV条目,确定所确定的逻辑块地址范围是否被相应的BEV条目覆盖。 如果是,则使用BEV的属性来确定是否允许访问操作。 该方法可以用于保护对存储在磁盘驱动器上的固件的访问,从而实现不需要常规固件存储设备的系统配置。