Abstract:
A computer system (and a motherboard for a computer system) is presented which provides a trusted platform by which operations can be performed with an increased level trust and confidence. The basis of trust for the computer system (or motherboard) is established by an encryption coprocessor and by code which interfaces with the encryption coprocessor and establishes root of trust metrics for the platform. The encryption coprocessor is built such that certain critical operations are allowed only if physical presence of an operator has been detected. Physical presence is determined by inference based upon the status of registers in the core chipset (e.g. on the motherboard).
Abstract:
A data processing system and method are described for permitting a server computer system to remotely disable an ability of a client computer system to access a network which couples the client computer system to the server computer system. The server computer system transmits an indication to the client computer system utilizing the network that the ability of the client computer system to access said network be at least temporarily disabled. In response to a receipt of the indication by the client computer system, the ability of the client computer system to access the network is at least temporarily disabled. The client computer system is unable to transmit information utilizing the network while the client computer system is temporarily disabled.
Abstract:
A system and method for autonomic wireless presence ping is presented. An IS administrator wishes to collect capacity requirement information corresponding to a wireless network, such as the number of packets a client sends to and receives from an access point. The IS administrator sends a request to the access point. In turn, the access point sends a control packet to client devices it supports, instructing them to enable an enhanced presence ping bit. Each client enables its enhanced presence ping bit, and collect enhanced status information. Each client device sends the enhanced status information to the access point either when a timer expires, or when the client device receives a ping request from the access point. The access point then forwards the enhanced status information to the IS administrator for analysis.
Abstract:
PROBLEM TO BE SOLVED: To provide a system and method capable of balancing the load among blade servers. SOLUTION: When a first blade server that is servicing a client computer becomes congested, service is transferred to a second blade server potential in a different blade center. In this case, the first blade and client are frozen, and then a pointer to the currently addressed location in a client's virtual storage and an exact memory map in the first blade server that is associated with the client computer are sent to the second blade server along with a client's IP address. These are used to reconstruct the state of the first blade in the second blade, at which time the second blade resumes service to the client. COPYRIGHT: (C)2006,JPO&NCIPI
Abstract:
PROBLEM TO BE SOLVED: To provide a computer system for making it impossible to use an in-circuit emulator(ICE) device in a security environment, and making it possible to use the ICE device in a manufacture environment or a non-security environment. SOLUTION: This processor is integrated with a special S latch which can be set according to a security signal. In one state of the S latch, the processor is set so as to be put in a security mode where only an instruction is performed, and any command from an ICE device is not performed. In the second state of the S latch, the processor is set so as to be put in a non-security state. Security data read by a boot block code stored in a BIOS storage device are written in a non-volatile random access memory(NVRAM). The book block code is made operable so that the security data in the NVRAM can be read, and the S latch is set so as to be put in a proper security state.
Abstract:
A data processing system and method are described for permitting a server computer system to remotely disable an ability of a client computer system to access a network which couples the client computer system to the server computer system. The server computer system transmits an indication to the client computer system utilizing the network that the ability of the client computer system to access said network be at least temporarily disabled. In response to a receipt of the indication by the client computer system, the ability of the client computer system to access the network is at least temporarily disabled. The client computer system is unable to transmit information utilizing the network while the client computer system is temporarily disabled.
Abstract:
A data processing system and method are described for permitting a server computer system to remotely disable an ability of a client computer system t o access a network which couples the client computer system to the server computer system. The server computer system transmits an indication to the client computer system utilizing the network that the ability of the client computer system to access said network be at least temporarily disabled. In response to a receipt of the indication by the client computer system, the ability of the client computer system to access the network is at least temporarily disabled. The client computer system is unable to transmit information utilizing the network while the client computer system is temporarily disabled.
Abstract:
Un metodo y sistema para controlar la adicion de un dispositivo USB a un sistema de computadora anfitrion mediante un detector de enchufe caliente (conexion con la maquina encendida) de equipo fisico que monitorea a los puertos USB. Las lineas de senalizacion diferencial que conectan al dispositivo USB se les da compuerta logica O (OR) en conjunto, de manera tal que senales D+ o D- logicamente altas desde el dispositivo USB senalan a la linea de interrupcion del administracion del sistema (SMI) de la unidad de procesamiento central, UPC (CPU) para iniciar el modo de administracion de sistema (SMM). Al entrar el SMM, se transfiere control de sistema de computadora anfitrion a un BIOS de manejador de interrupciones SMI que reside en el espacio de direccion SMM del sistema de computadora anfitrion. El SMM BIOS, se carga en el espacio de direcciones SMM durante la autocomprobacion de energia (POST) y se asegura antes de inicio del Sistema Operativo SO (OS). El codigo SMM BIOS contiene instrucciones de si el dispositivo USB conectado o no debera hacerse visible al sistema operativo de la computadora. Si el dispositivo no esta autorizado, se desactivan, la lineas D+/D- no se conectan al controlador anfitrion USB, y la senal SMI se libera, permitiendo que la computadora continue su operacion sin que el sistema operativo nunca perciba al dispositivo USB.
Abstract:
A data processing system and method are described for permitting a server computer system to remotely disable an ability of a client computer system to access a network which couples the client computer system to the server computer system. The server computer system transmits an indication to the client computer system utilizing the network that the ability of the client computer system to access said network be at least temporarily disabled. In response to a receipt of the indication by the client computer system, the ability of the client computer system to access the network is at least temporarily disabled. The client computer system is unable to transmit information utilizing the network while the client computer system is temporarily disabled.
Abstract:
A data processing system and method are described for permitting a server computer system to remotely disable an ability of a client computer system to access a network which couples the client computer system to the server computer system. The server computer system transmits an indication to the client computer system utilizing the network that the ability of the client computer system to access said network be at least temporarily disabled. In response to a receipt of the indication by the client computer system, the ability of the client computer system to access the network is at least temporarily disabled. The client computer system is unable to transmit information utilizing the network while the client computer system is temporarily disabled.