Abstract:
An improvement to a graphics controller to prevent the contents of selected portions of the frame buffer from being read by devices external to the graphics controller. The invention defines one or more viewable rectangles in the frame buffer as a protected write-only area. Any attempt to read data from the protected area of the frame buffer triggers a security violation which can delete or destroy the contents of that area to prevent it from being read. The controller can also operate in a bypass mode in which the security functions are bypassed so the graphics controller operates in a conventional manner. A security violation may return the controller to the bypass mode. The invention can prevent protected data, such as copyrighted data downloaded over the Internet, from being copied from the frame buffer and use in an unauthorized manner.
Abstract:
An approach for providing Subscriber Identity Module (SIM) capabilities in an open platform without the need for a discrete, physical SIM device. For one aspect, a computing system provides for secure provisioning of SIM data and algorithms, for example, protected storage of SIM secret data objects, and protected execution of SIM algorithms that provide for Authentication, Authorization and Accounting (AAA) capabilities currently associated with discrete hardware SIM devices.
Abstract:
An approach for providing Subscriber Identity Module (SIM) capabilities in an open platform without the need for a discrete, physical SIM device. For one aspect, a computing system provides for secure provisioning of SIM data and algorithms, for example, protected storage of SIM secret data objects, and protected execution of SIM algorithms that provide for Authentication, Authorization and Accounting (AAA) capabilities currently associated with discrete hardware SIM devices.
Abstract:
For one embodiment of the present invention, a protected storage device of a computer system includes a password stored therein. Instructions may be included on the computer system to authenticate the user. Once authenticated, the password may be transferred to a hard drive where it may be used to unlock the drive. Subsequent to unlocking the drive, an operating system may be loaded. For one embodiment of the present invention, the drive may be relocked by reducing the voltage supplied to the drive in accordance with a power management policy. The drive may be again unlocked by re-authenticating the user and transferring the password from protected storage to the drive.