Method for secure device discovery and introduction
    4.
    发明授权
    Method for secure device discovery and introduction 有权
    安全设备发现和介绍的方法

    公开(公告)号:US08001584B2

    公开(公告)日:2011-08-16

    申请号:US11241589

    申请日:2005-09-30

    IPC分类号: H04L9/32

    摘要: A first message is transmitted over a communication channel to initiate a transaction. The first message contains a random number and a public key of a device. Continuing the transaction, a second message is received. The second message also contains a random number and a public key of a second device. At least one message is received that contains a proof-of-possession of the device's password, along with a credential that is encrypted with a credential key.

    摘要翻译: 通过通信信道发送第一消息以发起交易。 第一个消息包含一个设备的随机数和公钥。 继续交易,收到第二条消息。 第二个消息还包含第二个设备的随机数和公钥。 接收到至少一个包含设备密码证明的消息,以及使用证书密钥加密的证书。

    Method and apparatus for secured embedded device communication
    5.
    发明授权
    Method and apparatus for secured embedded device communication 有权
    用于安全嵌入式设备通信的方法和装置

    公开(公告)号:US08949598B2

    公开(公告)日:2015-02-03

    申请号:US13334643

    申请日:2011-12-22

    IPC分类号: H04L29/04 H04L9/32 H04L29/06

    摘要: In a computing device that includes a host operating system and a management engine separate from the host operating system, if the primary operating system is not operating, a management engine may obtain from a credential server via a first network connection logon information for a secured network and the management engine connects to the secure network through a secured connection using the logon information. If the operating system is operating the operating system provides the logon information to the management engine. Certificate verification may be performed by a remote server on behalf of the management engine. Other embodiments are disclosed and claimed.

    摘要翻译: 在包括与主机操作系统分离的主机操作系统和管理引擎的计算设备中,如果主操作系统不工作,则管理引擎可以经由用于安全网络的第一网络连接登录信息从证书服务器获得 并且管理引擎通过使用登录信息的安全连接连接到安全网络。 如果操作系统正在操作,操作系统会向管理引擎提供登录信息。 证书验证可以由远程服务器代表管理引擎执行。 公开和要求保护其他实施例。

    SANDBOXING FOR MULTI-TENANCY
    6.
    发明申请
    SANDBOXING FOR MULTI-TENANCY 审中-公开
    多伦多沙发

    公开(公告)号:US20130160115A1

    公开(公告)日:2013-06-20

    申请号:US13330682

    申请日:2011-12-20

    IPC分类号: G06F11/00

    摘要: Systems and methods according to various embodiments disclose a worker process manager adapted to spawn one or more worker processes on a server and to load an application on each of the worker processes. The worker process manager is adapted to isolate the one or more worker processes from each other and to control resource usage by the worker processes. A resource manager is adapted to detect applications that overuse system resources. The worker process manager is adapted to isolate worker processes and to control resource usage using one or more of the following techniques: least-privilege execution, messaging isolation, credentials isolation, data isolation, network isolation, fair share resource usage, and managed runtime security. Heuristic algorithms are used to detect applications that frequently overuse system resources that are unchargeable and that cause system unresponsiveness.

    摘要翻译: 根据各种实施例的系统和方法公开了适于在服务器上产生一个或多个工作进程并且在每个工作进程上加载应用程序的工作进程管理器。 工作进程管理器适于将一个或多个工作进程彼此隔离并且控制工作进程的资源使用。 资源管理器适用于检测过度使用系统资源的应用程序。 工作进程管理器适用于使用以下一种或多种技术来隔离工作进程并控制资源使用:最小权限执行,消息传递隔离,凭据隔离,数据隔离,网络隔离,公平共享资源使用以及受管理的运行时安全性 。 启发式算法用于检测经常过度使用不可充电的系统资源并导致系统无响应的应用程序。

    Method and apparatus for secured embedded device communication
    7.
    发明授权
    Method and apparatus for secured embedded device communication 有权
    用于安全嵌入式设备通信的方法和装置

    公开(公告)号:US08091123B2

    公开(公告)日:2012-01-03

    申请号:US12059354

    申请日:2008-03-31

    IPC分类号: G06F17/00 G06F17/30

    摘要: In a computing device that includes a host operating system and a management engine separate from the host operating system, if the primary operating system is not operating, a management engine may obtain from a credential server via a first network connection logon information for a secured network and the management engine connects to the secure network through a secured connection using the logon information. If the operating system is operating the operating system provides the logon information to the management engine. Certificate verification may be performed by a remote server on behalf of the management engine. Other embodiments are disclosed and claimed.

    摘要翻译: 在包括与主机操作系统分离的主机操作系统和管理引擎的计算设备中,如果主操作系统不工作,则管理引擎可以经由用于安全网络的第一网络连接登录信息从证书服务器获得 并且管理引擎通过使用登录信息的安全连接连接到安全网络。 如果操作系统正在操作,操作系统会向管理引擎提供登录信息。 证书验证可以由远程服务器代表管理引擎执行。 公开和要求保护其他实施例。

    Multi-tenant, high-density container service for hosting stateful and stateless middleware components
    9.
    发明授权
    Multi-tenant, high-density container service for hosting stateful and stateless middleware components 有权
    多租户,高密度容器服务,用于托管状态和无状态的中间件组件

    公开(公告)号:US08468548B2

    公开(公告)日:2013-06-18

    申请号:US12972411

    申请日:2010-12-17

    IPC分类号: G06F13/00

    CPC分类号: G06F9/5061

    摘要: A container service is capable of hosting large numbers of middleware components for multiple tenants. A central container manager controls a plurality of compute nodes. The central container manager receives middleware components from external devices or services and assigns the components to containers on one or more designated compute nodes. Each compute node has a container management agent and one or more containers. The container management agents activate and manage the appropriate number of containers to run the assigned middleware components. The container management agent assigns each container on its compute node a limited set of privileges to control access to shared resources. The central container manager and each node's container management agent monitor container load levels and dynamically adjust the placement of the middleware components to maintain balanced operation. The compute nodes are grouped into clusters based upon the type of middleware components hosted on each compute node.

    摘要翻译: 容器服务能够为多个租户托管大量的中间件组件。 中央容器管理器控制多个计算节点。 中央容器管理器从外部设备或服务器接收中间件组件,并将组件分配给一个或多个指定的计算节点上的容器。 每个计算节点都有一个容器管理代理和一个或多个容器。 容器管理代理激活并管理适当数量的容器以运行分配的中间件组件。 容器管理代理在其计算节点上分配有限的一组权限以控制对共享资源的访问。 中央集装箱管理员和每个节点的集装箱管理代理监控集装箱装载水平,动态调整中间件组件的位置,保持平衡运行。 基于每个计算节点上托管的中间件组件的类型,将计算节点分组为集群。