TECHNOLOGIES FOR SECURE OFFLINE ACTIVATION OF HARDWARE FEATURES
    1.
    发明申请
    TECHNOLOGIES FOR SECURE OFFLINE ACTIVATION OF HARDWARE FEATURES 审中-公开
    硬件特性的离线激活技术

    公开(公告)号:US20150381368A1

    公开(公告)日:2015-12-31

    申请号:US14318278

    申请日:2014-06-27

    IPC分类号: H04L9/32 G06Q30/04 G06F9/44

    摘要: Technologies for secure offline activation of hardware features include a target computing device having a platform controller hub (PCH) including a converged security and manageability engine (CSME) and a number of in-field programmable fuses (IFPs). During assembly of the target computing device by an original equipment manufacturer (OEM), the CSME is provided a list of hardware features to be activated. The CSME configures the IFPs to enable the requested features, generates a digital receipt including the activated features and a unique device ID, and signs the receipt using a unique device key. Signed receipts may be periodically submitted to a vendor computing device, which verifies the signed receipts, extracts the active feature list, and bills the OEM for activated features of the PCHs. The vendor computing device may bill the OEM a maximum price for PCHs for which there is no associated signed receipt. Other embodiments are described and claimed.

    摘要翻译: 用于硬件特征的安全离线激活的技术包括具有包括融合安全性和可管理性引擎(CSME)的平台控制器集线器(PCH)以及多个现场可编程保险丝(IFP))的目标计算设备。 在由原始设备制造商(OEM)组装目标计算设备的过程中,CSME提供要激活的硬件功能的列表。 CSME配置IFP以启用所请求的功能,生成包含激活的功能和唯一设备ID的数字收据,并使用唯一的设备密钥对收据进行签名。 签署的收据可以定期地提交给供应商计算设备,该设备验证签署的收据,提取活动的特征列表,并为OEM的PCH的激活特征收费。 供应商计算设备可以向OEM收取没有相关签名收据的PCH的最高价格。 描述和要求保护其他实施例。

    Method for SMI arbitration timeliness in a cooperative SMI/driver use mechanism
    4.
    发明授权
    Method for SMI arbitration timeliness in a cooperative SMI/driver use mechanism 失效
    合作SMI /驾驶员使用机制中SMI仲裁及时性的方法

    公开(公告)号:US06981081B2

    公开(公告)日:2005-12-27

    申请号:US10325776

    申请日:2002-12-19

    CPC分类号: G06F13/378

    摘要: A Bus Driver implements an arbitration mechanism to allow both the system management interrupt (SMI) and the Bus Driver to cooperatively use a Bus host controller hardware. This mechanism employs a hardware-based semaphore (status bit) to allow either the SMI or the driver to claim ownership of the Bus host controller for an arbitrary period of time. While either the SMI or the driver may own the status bit, the other party must poll the bit until ownership is achieved. For the SMI, this involves scheduling a periodic SMI interrupt. The driver performs self arbitration of claiming the status bit to provide the periodic SMI interrupt the opportunity to claim the bit. The mechanism allows the SMI access to the Bus host controller in a “timely” manner, while minimizing impact to driver access to the Bus host controller, which could impact driver Bus transaction throughput.

    摘要翻译: 总线驱动器实现仲裁机制,允许系统管理中断(SMI)和总线驱动程序协同使用总线主机控制器硬件。 该机制采用基于硬件的信号量(状态位)来允许SMI或驱动程序在任意一段时间内声明对总线主机控制器的所有权。 虽然SMI或驱动程序可能拥有状态位,但是对方必须轮询该位,直到实现所有权。 对于SMI,这涉及调度周期性SMI中断。 驱动程序执行声称状态位的自我仲裁,以使周期性SMI中断有机会声明该位。 该机制允许SMI以“及时”的方式访问总线主机控制器,同时最小化对驱动程序访问总线主机控制器的影响,这可能会影响驱动器总线事务吞吐量。

    Wakeup circuit for computer system that enables codec controller to generate system interrupt in response to detection of a wake event by a codec
    6.
    发明授权
    Wakeup circuit for computer system that enables codec controller to generate system interrupt in response to detection of a wake event by a codec 有权
    用于计算机系统的唤醒电路,使得编解码器控制器能够响应于由编解码器检测到唤醒事件而产生系统中断

    公开(公告)号:US06564330B1

    公开(公告)日:2003-05-13

    申请号:US09472096

    申请日:1999-12-23

    IPC分类号: G06F126

    CPC分类号: G06F1/24

    摘要: A wake up circuit for a computer system with a codec controller. The circuit provides a wakeup signal to the computer system when a codec detects an event that requires the system to become active. This signal is provided whether the communications link between the codecs and their controller is active or inactive. When the link is inactive, as indicated by the absence of a bit clock, a data signal on any of the codec input lines triggers the controller to send a power activation signal to the system and to initiate an activation of the codec link. If the link is already active, the general purpose input status change bit is transmitted to the controller, which writes it into a register that is used to trigger a power activation signal to the system. An enable input permits the wakeup signal to be enabled or disabled under program control. The wakeup signal can be used to trigger a system management interrupt or other interrupt suitable for initiating a system resume function.

    摘要翻译: 用于具有编解码器控制器的计算机系统的唤醒电路。 当编解码器检测到需要系统激活的事件时,该电路向计算机系统提供唤醒信号。 提供该信号是否编解码器与其控制器之间的通信链路是活动的还是非活动的。 当链路处于非活动状态时,如没有位时钟所示,任何编解码器输入线上的数据信号触发控制器向系统发送电源激活信号并启动编解码器链路的激活。 如果链路已经处于活动状态,则通用输入状态改变位被发送到控制器,控制器将其写入用于触发系统功率激活信号的寄存器。 启用输入允许在程序控制下启用或禁用唤醒信号。 唤醒信号可用于触发适用于启动系统恢复功能的系统管理中断或其他中断。

    Methods and apparatus for mixing encrypted data with unencrypted data
    7.
    发明授权
    Methods and apparatus for mixing encrypted data with unencrypted data 有权
    将加密数据与未加密数据进行混合的方法和装置

    公开(公告)号:US08098817B2

    公开(公告)日:2012-01-17

    申请号:US10745424

    申请日:2003-12-22

    IPC分类号: H04K1/04

    摘要: Methods and apparatus for mixing encrypted data with unencrypted data are disclosed. A disclosed system receives data from a first media source, such as DVD-Audio content, and encrypts the data from the first media source using a key stream to form an encrypted data stream. The disclosed system may separate the encrypted data stream into a plurality of encrypted data streams and may combine the plurality of encrypted data streams with an unencrypted data stream associated with a second media source to form a mixed data stream. The mixed data stream is formed without decrypting the plurality of encrypted data streams and is transmitted to hardware or a hardware driver.

    摘要翻译: 公开了加密数据与未加密数据混合的方法和装置。 所公开的系统从诸如DVD音频内容的第一媒体源接收数据,并且使用密钥流来加密来自第一媒体源的数据以形成加密的数据流。 所公开的系统可以将加密的数据流分离成多个加密数据流,并且可以将多个加密数据流与与第二媒体源相关联的未加密数据流组合以形成混合数据流。 形成混合数据流,而不对多个加密数据流进行解密,并将其传输到硬件或硬件驱动器。

    Extensible Pre-Boot Authentication
    8.
    发明申请
    Extensible Pre-Boot Authentication 有权
    可扩展的预引导认证

    公开(公告)号:US20110138166A1

    公开(公告)日:2011-06-09

    申请号:US12974244

    申请日:2010-12-21

    IPC分类号: G06F9/24

    CPC分类号: G06F21/575

    摘要: In one embodiment, the present invention includes a method for obtaining a pre-boot authentication (PBA) image from a non-volatile storage that is configured with full disk encryption (FDE), and storing the PBA image in a memory. Then a callback protocol can be performed between a loader executing on an engine of a chipset and an integrity checker of a third party that provided the PBA image to confirm integrity of the PBA image, the PBA image is executed if the integrity is confirmed, and otherwise it is deleted. Other embodiments are described and claimed.

    摘要翻译: 在一个实施例中,本发明包括一种从配置有全盘加密(FDE)的非易失性存储器获得预引导认证(PBA)图像并将PBA图像存储在存储器中的方法。 然后,可以在执行在芯片组的引擎上的加载器和提供PBA图像以确认PBA图像的完整性的第三方的完整性检查器之间执行回调协议,如果确认完整性则执行PBA图像;以及 否则删除。 描述和要求保护其他实施例。

    Real-time processing of a synchronous or isochronous data stream in the presence of gaps in the data stream due to queue underflow or overflow
    9.
    发明授权
    Real-time processing of a synchronous or isochronous data stream in the presence of gaps in the data stream due to queue underflow or overflow 失效
    在存在由于队列下溢或溢出引起的数据流中的间隙的同步或等时数据流的实时处理

    公开(公告)号:US06631429B2

    公开(公告)日:2003-10-07

    申请号:US09471942

    申请日:1999-12-23

    IPC分类号: G06F1300

    CPC分类号: H04L12/64 H04L25/05

    摘要: In one embodiment of the present invention, an output device sends a spurious data sample in place of a first data sample to be sent from a queue if the queue is in a state of underflow during which the first data sample is not available to be sent. The buffer is to store data samples for an isochronous data transmission. Circuitry skips the first data sample when the first data sample becomes available in the queue so that synchronization for subsequent data samples sent from the queue is preserved. In another embodiment of the present invention, an input device advances an input buffer pointer to point to a next location in a memory in response to receiving a data sample at a queue during a state of overflow. The input buffer pointer indicates a location in the memory to which a next data sample is to be sent from the queue. The queue stores data samples for an isochronous data transmission. By advancing the input buffer pointer, synchronization for subsequent data samples is preserved.

    摘要翻译: 在本发明的一个实施例中,如果队列处于下溢状态,则第一数据样本不可用于发送,则输出设备发送伪数据样本代替要从队列发送的第一数据样本 。 缓冲区用于存储用于同步数据传输的数据样本。 当第一个数据样本在队列中可用时,电路会跳过第一个数据样本,以便保留从队列发送的后续数据样本的同步。 在本发明的另一实施例中,响应于在溢出状态期间在队列处接收到数据样本,输入装置使输入缓冲器指针前进到指向存储器中的下一个位置。 输入缓冲区指针指示要从队列发送下一个数据样本的存储器中的位置。 队列存储用于等时数据传输的数据样本。 通过前进输入缓冲区指针,保留后续数据样本的同步。

    Methods and apparatus for mixing encrypted data with unencrypted data
    10.
    发明授权
    Methods and apparatus for mixing encrypted data with unencrypted data 有权
    将加密数据与未加密数据进行混合的方法和装置

    公开(公告)号:US08538018B2

    公开(公告)日:2013-09-17

    申请号:US13342288

    申请日:2012-01-03

    IPC分类号: H04N7/167

    摘要: Methods and apparatus for mixing encrypted data with unencrypted data are disclosed. A disclosed system receives data from a first media source, such as DVD-Audio content, and encrypts the data from the first media source using a key stream to form an encrypted data stream. The disclosed system may separate the encrypted data stream into a plurality of encrypted data streams and may combine the plurality of encrypted data streams with an unencrypted data stream associated with a second media source to form a mixed data stream. The mixed data stream is formed without decrypting the plurality of encrypted data streams and is transmitted to hardware or a hardware driver.

    摘要翻译: 公开了加密数据与未加密数据混合的方法和装置。 所公开的系统从诸如DVD音频内容的第一媒体源接收数据,并且使用密钥流来加密来自第一媒体源的数据以形成加密的数据流。 所公开的系统可以将加密的数据流分离成多个加密数据流,并且可以将多个加密数据流与与第二媒体源相关联的未加密数据流组合以形成混合数据流。 形成混合数据流,而不对多个加密数据流进行解密,并将其传输到硬件或硬件驱动器。