BIOS PROTECTION IN A PERSONAL COMPUTER SYSTEM

    公开(公告)号:NZ234712A

    公开(公告)日:1993-04-28

    申请号:NZ23471290

    申请日:1990-07-30

    Applicant: IBM

    Abstract: An apparatus and method for protecting BIOS stored on a direct access storage device (62) into a personal computer system (10). The personal computer system (JO) comprises a system processor (26), a system planar (24), a random access main memory (32), a read only memory (36), a protection means and at least one direct access storage device (62). The read only memory (36) includes a first portion of BIOS and data representing the type of system processor (26) and system planar (24) I/O configuration. The first portion of BIOS initializes the system (10) and the direct access storage device (62), and resets the protection means in order to read in a master boot record into the random access memory (32) from a protectable partition on the direct access storage device (62). The master boot record includes a data segment and an executable code segment. The data segment includes data representing system hardware and a system configuration which is supported by the master boot record. The first BIOS portion confirms the master boot record is compatible with the system hardware by verifying that the data from the data segment of the master boot record agrees with the system processor (26), system planar (24), and planar (24) I/O configuration. If the master boot record is compatible with the system hardware, the first BIOS portion vectors the system processor (26) to execute the executable code segment of the master boot record. The executable code segment confirms that the system configuration has not changed and loads in the remaining BIOS portion from the same protectable partition on the direct access storage device (62) into random access memory (32). The executable code segment then verifies the authenticity of the remaining BIOS portion and vectors the system processor (26) to begin executing the BIOS now in random access memory. BIOS, executing in random access memory (32), then activates the protection means to prevent further access to the protectable partition. BIOS boots up the operating system to begin operation of the personal computer system.

    53.
    发明专利
    未知

    公开(公告)号:DE3808167A1

    公开(公告)日:1988-10-13

    申请号:DE3808167

    申请日:1988-03-11

    Applicant: IBM

    Abstract: A computer system and method for operating a computer system capable of running in mutually incompatible real and protected addressing modes, in which programs written for one mode can be run in the other mode without modification. The BIOS assembles two different common data areas for the two modes, each inclusive of device block pointers, function transfer table pointers, data pointers, and function pointers. The common data area for the real mode is assembled first. To assemble the pointers for the protected mode common data area, the offset values from the real mode area are copied directly, and then selector values are inserted whose physical addresses correspond to the segments of the corresponding pointers in the real mode area. The selector values are derived from a segment descriptor table.

    56.
    发明专利
    未知

    公开(公告)号:AT335232T

    公开(公告)日:2006-08-15

    申请号:AT02754800

    申请日:2002-06-29

    Applicant: IBM

    Abstract: Disclosed is a method and hard disk configuration for accommodating different sizes of applications during an automatic re-provisioning of an appliance server. The disk drive of the appliance server is partitioned with a system partition, a network operating system (NOS) partition, a float partition, and an images partition. The float partition is utilized to provide additional space to the NOS partition and the images partition, when required. A re-provisioning utility is provided, which initiates both a create image utility and an apply image utility, whereby an image file of a current application and associated operating system is created and a stored image file of a second application is installed on the appliance server. When the apply image utility is initiated, the NOS partition is dynamically extended into the float partition server if the second application requires more space than is provided in the NOS partition. Similarly, when an image file is stored in the images partition and the image file requires more space than is available in the images partition, the images partition is dynamically extended into the float partition.

    Protection method and apparatus for computer system

    公开(公告)号:SG44409A1

    公开(公告)日:1997-12-19

    申请号:SG1996000216

    申请日:1990-07-04

    Applicant: IBM

    Abstract: An apparatus and method for protecting BIOS stored on a direct access storage device (62) into a personal computer system (10). The personal computer system (JO) comprises a system processor (26), a system planar (24), a random access main memory (32), a read only memory (36), a protection means and at least one direct access storage device (62). The read only memory (36) includes a first portion of BIOS and data representing the type of system processor (26) and system planar (24) I/O configuration. The first portion of BIOS initializes the system (10) and the direct access storage device (62), and resets the protection means in order to read in a master boot record into the random access memory (32) from a protectable partition on the direct access storage device (62). The master boot record includes a data segment and an executable code segment. The data segment includes data representing system hardware and a system configuration which is supported by the master boot record. The first BIOS portion confirms the master boot record is compatible with the system hardware by verifying that the data from the data segment of the master boot record agrees with the system processor (26), system planar (24), and planar (24) I/O configuration. If the master boot record is compatible with the system hardware, the first BIOS portion vectors the system processor (26) to execute the executable code segment of the master boot record. The executable code segment confirms that the system configuration has not changed and loads in the remaining BIOS portion from the same protectable partition on the direct access storage device (62) into random access memory (32). The executable code segment then verifies the authenticity of the remaining BIOS portion and vectors the system processor (26) to begin executing the BIOS now in random access memory. BIOS, executing in random access memory (32), then activates the protection means to prevent further access to the protectable partition. BIOS boots up the operating system to begin operation of the personal computer system.

    58.
    发明专利
    未知

    公开(公告)号:DE69027165T2

    公开(公告)日:1996-12-12

    申请号:DE69027165

    申请日:1990-07-04

    Applicant: IBM

    Abstract: An apparatus and method for protecting BIOS stored on a direct access storage device (62) into a personal computer system (10). The personal computer system (JO) comprises a system processor (26), a system planar (24), a random access main memory (32), a read only memory (36), a protection means and at least one direct access storage device (62). The read only memory (36) includes a first portion of BIOS and data representing the type of system processor (26) and system planar (24) I/O configuration. The first portion of BIOS initializes the system (10) and the direct access storage device (62), and resets the protection means in order to read in a master boot record into the random access memory (32) from a protectable partition on the direct access storage device (62). The master boot record includes a data segment and an executable code segment. The data segment includes data representing system hardware and a system configuration which is supported by the master boot record. The first BIOS portion confirms the master boot record is compatible with the system hardware by verifying that the data from the data segment of the master boot record agrees with the system processor (26), system planar (24), and planar (24) I/O configuration. If the master boot record is compatible with the system hardware, the first BIOS portion vectors the system processor (26) to execute the executable code segment of the master boot record. The executable code segment confirms that the system configuration has not changed and loads in the remaining BIOS portion from the same protectable partition on the direct access storage device (62) into random access memory (32). The executable code segment then verifies the authenticity of the remaining BIOS portion and vectors the system processor (26) to begin executing the BIOS now in random access memory. BIOS, executing in random access memory (32), then activates the protection means to prevent further access to the protectable partition. BIOS boots up the operating system to begin operation of the personal computer system.

    59.
    发明专利
    未知

    公开(公告)号:DE69027164T2

    公开(公告)日:1996-12-12

    申请号:DE69027164

    申请日:1990-07-04

    Applicant: IBM

    Abstract: An apparatus and method for decreasing the memory requirements of BIOS in a personal computer system (10) includes storing a first portion of BIOS in memory and a second portion on a direct storage access device. The personal computer system (10) comprises a system processor (26), a random access main memory, a read only memory (36), and at least one direct access storage device (62,66). The read only memory (36) includes the first portion of BIOS and data representing the type of system processor (26) and system planar (24) I/O configuration. The first portion of BIOS only includes routines for initializing the system (10) and the direct access storage device (62,66) to read in a master boot record into the system (10) from the direct access storage device (62,66). The master boot record includes a data segment (122-138) and an executable code segment (120). The data segment (122-138) includes data representing system hardware and a system configuration which is supported by the master boot record. The first BIOS portion confirms the master boot record is compatible with the system hardware by verifying that the data from the data segment (122-138) of the master boot record agrees with the system processor (26), system planar (24), and planar (24) I/O configuration. If the master boot record is compatible with the system hardware, the first BIOS portion vectors the system processor (26) to execute the executable code segment (120) of the master boot record. The executable code segment (120) confirms that the system conf iguration has not changed and loads in the remaining BIOS portion from the direct access storage device (62,66) into random access memory (32) superseding the first BIOS portion. The executable code segment (120) then verifies the authenticity of the remaining BIOS portion and vectors the system processor (26) to begin executing the remaining BIOS now in random access memory (32). The remaining BIOS in main memory includes reusable routines for operating the system (10) in a normal manner.

    TRUSTED PERSONAL COMPUTER SYSTEM WITH IDENTIFICATION

    公开(公告)号:CA2099026C

    公开(公告)日:1996-12-03

    申请号:CA2099026

    申请日:1993-06-23

    Applicant: IBM

    Abstract: This invention relates to personal computer systems and, more particularly, to such a system having security features enabling control over access to data retained in such a system. This invention contemplates protecting a personal computer system which has the capability of becoming a secure system from being placed into that condition by an attack on an unsecured machine. Additionally, in a network environment, it is important to maintain network security that any given particular system be uniquely identified to the network, in order to guard against the substitution of an insecure "alternate" which would open the network to attack through an insecure system. This invention contemplates provision for such identification in a secure manner.

Patent Agency Ranking