Apparatus, system, and method for selecting a waking process
    5.
    发明授权
    Apparatus, system, and method for selecting a waking process 有权
    用于选择醒来过程的设备,系统和方法

    公开(公告)号:US07673161B2

    公开(公告)日:2010-03-02

    申请号:US11277730

    申请日:2006-03-28

    CPC分类号: G06F9/4418

    摘要: An apparatus, system, and method are disclosed for selecting a waking process. An input module receives a specified input during the off state of a data processing device. In addition, the input module stores the input in the storage module. The storage module may be integrated within the input module. The input module activates the data processing device in response to the input. A wake module retrieves the input from the storage module. In addition, the wake module determines a process that corresponds to the input. The wake module wakes the data processing device using the process.

    摘要翻译: 公开了一种用于选择一个清醒过程的装置,系统和方法。 输入模块在数据处理装置的关闭状态期间接收指定的输入。 此外,输入模块将输入存储在存储模块中。 存储模块可以集成在输入模块内。 输入模块响应输入激活数据处理设备。 唤醒模块从存储模块检索输入。 此外,唤醒模块确定与输入对应的进程。 唤醒模块使用该过程唤醒数据处理设备。

    System and method to update device driver or firmware using a hypervisor environment without system shutdown
    6.
    发明授权
    System and method to update device driver or firmware using a hypervisor environment without system shutdown 有权
    使用虚拟机管理程序环境更新设备驱动程序或固件而无需系统关闭的系统和方法

    公开(公告)号:US08201161B2

    公开(公告)日:2012-06-12

    申请号:US11970038

    申请日:2008-01-07

    IPC分类号: G06F9/445

    CPC分类号: G06F9/45537 G06F9/4411

    摘要: A system, method, and program product is provided that has a virtualized environment provided by a hypervisor. In the virtualized environment, one or more guest operating systems operate simultaneously with a privileged operating system. One of the guest operating systems identifies a device software update, such as a device driver or firmware update, corresponding to a hardware device that is attached to the computer system. The hypervisor is used to notify the privileged operating system of the device software update. When the privileged operating system is notified of the update, the privileged operating system uses one or more techniques to deny the guest operating systems access to the device. The privileged operating system then updates the device software update. After the device software update has been applied, the privileged operating system resumes access between the guest operating systems and the hardware device.

    摘要翻译: 提供了具有由管理程序提供的虚拟化环境的系统,方法和程序产品。 在虚拟化环境中,一个或多个客户机操作系统与特权操作系统同时操作。 其中一个客户操作系统识别对应于连接到计算机系统的硬件设备的设备软件更新,例如设备驱动程序或固件更新。 管理程序用于通知特权操作系统的设备软件更新。 当特权操作系统被通知更新时,特权操作系统使用一种或多种技术来拒绝来宾操作系统对设备的访问。 特权操作系统然后更新设备软件更新。 在应用设备软件更新之后,特权操作系统在客户操作系统和硬件设备之间恢复访问。

    System and Method to Update Device Driver or Firmware Using a Hypervisor Environment Without System Shutdown
    7.
    发明申请
    System and Method to Update Device Driver or Firmware Using a Hypervisor Environment Without System Shutdown 有权
    使用虚拟机管理程序环境更新设备驱动程序或固件的系统和方法,无需系统关闭

    公开(公告)号:US20090178033A1

    公开(公告)日:2009-07-09

    申请号:US11970038

    申请日:2008-01-07

    IPC分类号: G06F9/445 G06F21/00

    CPC分类号: G06F9/45537 G06F9/4411

    摘要: A system, method, and program product is provided that has a virtualized environment provided by a hypervisor. In the virtualized environment, one or more guest operating systems operate simultaneously with a privileged operating system. One of the guest operating systems identifies a device software update, such as a device driver or firmware update, corresponding to a hardware device that is attached to the computer system. The hypervisor is used to notify the privileged operating system of the device software update. When the privileged operating system is notified of the update, the privileged operating system uses one or more techniques to deny the guest operating systems access to the device. The privileged operating system then updates the device software update. After the device software update has been applied, the privileged operating system resumes access between the guest operating systems and the hardware device.

    摘要翻译: 提供了具有由管理程序提供的虚拟化环境的系统,方法和程序产品。 在虚拟化环境中,一个或多个客户机操作系统与特权操作系统同时操作。 其中一个客户操作系统识别对应于连接到计算机系统的硬件设备的设备软件更新,例如设备驱动程序或固件更新。 管理程序用于通知特权操作系统的设备软件更新。 当特权操作系统被通知更新时,特权操作系统使用一种或多种技术来拒绝来宾操作系统对设备的访问。 特权操作系统然后更新设备软件更新。 在应用设备软件更新之后,特权操作系统在客户操作系统和硬件设备之间恢复访问。

    Data processing system and method for password protecting a boot device
    8.
    发明授权
    Data processing system and method for password protecting a boot device 有权
    用于密码保护引导设备的数据处理系统和方法

    公开(公告)号:US07814532B2

    公开(公告)日:2010-10-12

    申请号:US09847085

    申请日:2001-05-02

    CPC分类号: G06F21/575

    摘要: A data processing system and method of password protecting the boot of a data processing system are disclosed. According to the method, in response to an attempt to boot the data processing system utilizing a boot device, the boot device is interrogated for a password. If the boot device supplies password information corresponding to that of a trusted boot device, the data processing system boots utilizing the boot device. If, however, the boot device does not supply password information corresponding to that of a trusted boot device, booting from the boot device is inhibited. In a preferred embodiment, the password information comprises a unique combination of the boot device's manufacturer-supplied model and serial numbers.

    摘要翻译: 公开了一种密码保护数据处理系统引导的数据处理系统和方法。 根据该方法,响应于利用引导设备引导数据处理系统的尝试,引导设备被询问密码。 如果引导设备提供与可信引导设备的密码信息相对应的密码信息,则数据处理系统使用引导设备引导。 但是,如果引导设备不提供与受信任引导设备相对应的密码信息,则禁止从引导设备引导。 在优选实施例中,密码信息包括引导设备的制造商提供的模型和序列号的唯一组合。

    Method and system for tracking a secure boot in a trusted computing environment
    9.
    发明授权
    Method and system for tracking a secure boot in a trusted computing environment 有权
    用于在可信计算环境中跟踪安全引导的方法和系统

    公开(公告)号:US07191464B2

    公开(公告)日:2007-03-13

    申请号:US09978381

    申请日:2001-10-16

    IPC分类号: H04L9/32 G06F15/177

    CPC分类号: G06F21/575

    摘要: A method, system and computer readable medium containing programming instructions for tracking a secure boot in a computer system having a plurality of devices is disclosed. The method, system and computer readable medium include providing an embedded security system (ESS) in the computer system, wherein the ESS includes at least one boot platform configuration register (PCR) and a shadow PCR for each of the at least one boot PCRs, initiating a platform reset to boot the computer system via BIOS, and, for a device booted, generating a measurement value for the device and extending that value to one of the at least one boot PCRs and its corresponding shadow PCR. The system, method and computer readable medium of the present invention also includes comparing the measurement values of the boot PCRs to their corresponding shadow PCRs, whereby the computer system is trusted if the measurement values match.

    摘要翻译: 公开了一种包含用于在具有多个设备的计算机系统中跟踪安全引导的编程指令的方法,系统和计算机可读介质。 所述方法,系统和计算机可读介质包括在所述计算机系统中提供嵌入式安全系统(ESS),其中所述ESS包括用于所述至少一个启动PCR中的每一个的至少一个引导平台配置寄存器(PCR)和阴影PCR, 启动平台重置以通过BIOS引导计算机系统,并且对于引导的设备,生成所述设备的测量值并将该值扩展到所述至少一个启动PCR中的一个及其相应的阴影PCR。 本发明的系统,方法和计算机可读介质还包括将引导PCR的测量值与其相应的阴影PCR进行比较,从而如果测量值匹配,则计算机系统被信任。

    Secure method for system attribute modification
    10.
    发明授权
    Secure method for system attribute modification 有权
    系统属性修改的安全方法

    公开(公告)号:US07174465B2

    公开(公告)日:2007-02-06

    申请号:US10180160

    申请日:2002-06-26

    IPC分类号: H04L9/32 H04L9/00

    CPC分类号: G06F21/57

    摘要: A method is disclosed for securely updating system attributes of a client computer with a BIOS and includes signing a public key of a secure server with a private key of the BIOS prior to completion of manufacturing of the client computer to create an encrypted public key and embedded private key stored at the server. The method includes receiving at the server a request packet transmitted from the client computer requesting system attribute modification, encrypting the request packet to create an encrypted packet, and transmitting a return packet to client computer comprising the encrypted packet, the server's public key, and server instructions. The client computer decrypts the request packet using the server's public key and compares it to the original request packet, and if identical, executes the server instructions to modify the client computer's boot block to update client computer's system attributes.

    摘要翻译: 公开了一种用于使用BIOS安全地更新客户端计算机的系统属性的方法,并且包括在完成客户端计算机的制造之前用BIOS的私钥对安全服务器的公共密钥进行签名以创建加密的公共密钥并且嵌入 私钥存储在服务器端。 该方法包括在服务器处接收从客户端计算机发送的请求系统属性修改的请求分组,对请求分组进行加密以创建加密的分组,以及向包括加密分组,服务器的公钥和服务器的客户端计算机发送返回分组 说明。 客户端计算机使用服务器的公钥解密请求包,并将其与原始请求包进行比较,如果相同,则执行服务器指令修改客户端计算机的启动块以更新客户端计算机的系统属性。