Mapping encrypted and decrypted data via key management system
    1.
    发明授权
    Mapping encrypted and decrypted data via key management system 有权
    通过密钥管理系统映射加密和解密的数据

    公开(公告)号:US09251382B2

    公开(公告)日:2016-02-02

    申请号:US11961015

    申请日:2007-12-20

    CPC分类号: G06F21/80

    摘要: A data processing system having a host computer including a key manager, a control unit connected to the host computer, a data storage unit (such as a tape drive) controlled by the control unit, and data storage medium for storing data thereon to be written to or read from by the data storage unit. The key manager stores a data structure having at least one record having a volume serial number, as start location, a length entry, and a key for encrypting and decrypting data on the data storage medium. A data storage medium (such as data tape) is mounted on the data storage unit, and a volume recorded on the tape is retrieved. The control unit retrieves the data structure from the key manager and matches the volume serial number recorded in the retrieved data structure with the volume serial number retrieved from the data storage medium. It they match, the control unit passes to the data storage unit, commands to turn on or turn off encryption dependent upon the location where data is written by the data storage unit onto the data storage medium, or to turn on or turn off decryption dependent upon the location where data is read by the data storage unit from the data storage medium.

    摘要翻译: 一种具有主计算机的数据处理系统,包括密钥管理器,连接到主计算机的控制单元,由控制单元控制的数据存储单元(例如磁带驱动器)以及用于存储要写入的数据的数据存储介质 由数据存储单元读取或读取。 密钥管理器存储具有至少一个具有卷序列号的记录的数据结构,作为开始位置,长度条目和用于在数据存储介质上加密和解密数据的密钥。 数据存储介质(例如数据磁带)安装在数据存储单元上,并记录在磁带上的卷。 控制单元从密钥管理器检索数据结构,并将记录在检索的数据结构中的卷序列号与从数据存储介质检索的卷序列号进行匹配。 它们匹配,控制单元传递到数据存储单元,根据数据存储单元将数据写入数据存储介质的位置来打开或关闭加密的命令,或者打开或关闭解密依赖 在数据存储单元从数据存储介质读取数据的位置。

    Assigning unique identification numbers to new user accounts and groups in a computing environment with multiple registries
    2.
    发明授权
    Assigning unique identification numbers to new user accounts and groups in a computing environment with multiple registries 失效
    在具有多个注册表的计算环境中为新用户帐户和组分配唯一的标识号

    公开(公告)号:US07668831B2

    公开(公告)日:2010-02-23

    申请号:US11260796

    申请日:2005-10-27

    IPC分类号: G06F7/00

    摘要: A method, system, and program storage device for creating a new user account or user group with a unique identification number in a computing environment having multiple user registries is provided. In response to receiving a command to create a new user account or user group, an operating system of a clustered computing environment automatically checks multiple registries configured for the operating system to determine whether a candidate identification number for the new user account or user group has been assigned already to one or more existing user accounts or groups, respectively. The operating system automatically assigns the candidate identification number to the new user account or user group created in a target user registry if the checking indicates that the candidate identification number has not been assigned already to any of the existing user accounts or user groups, respectively.

    摘要翻译: 提供了一种用于在具有多个用户注册表的计算环境中创建具有唯一标识号的新用户帐户或用户组的方法,系统和程序存储设备。 响应于接收到创建新用户帐户或用户组的命令,集群计算环境的操作系统自动检查为操作系统配置的多个注册表,以确定新用户帐户或用户组的候选标识号是否已被 分配给一个或多个现有的用户帐户或组。 如果检查指示候选标识号码尚未分配给任何现有用户帐户或用户组,操作系统将自动将候选标识号分配给在目标用户注册表中创建的新用户帐户或用户组。

    METHOD AND APPARATUS FOR PROCESSING REMOTE SHELL COMMANDS
    3.
    发明申请
    METHOD AND APPARATUS FOR PROCESSING REMOTE SHELL COMMANDS 审中-公开
    用于处理远程命令的方法和装置

    公开(公告)号:US20070282964A1

    公开(公告)日:2007-12-06

    申请号:US11422361

    申请日:2006-06-06

    IPC分类号: G06F15/16

    CPC分类号: G06F9/547 G06F2209/549

    摘要: Methods and apparatus for processing of a distributed remote shell command are disclosed. In some embodiments, a target host receives from a client a remote shell command specifying an operation to be performed by an operating system at the target host. The target host performs the specified operation and formulates a response that has a first part containing target host identification data for the target host and a second part showing a result of performance of the specified operation. The target host issues the response to the client.

    摘要翻译: 公开了用于处理分布式远程shell命令的方法和装置。 在一些实施例中,目标主机从客户端接收指定由目标主机上的操作系统执行的操作的远程shell命令。 目标主机执行指定的操作,并且制定响应,该响应具有包含目标主机的目标主机标识数据的第一部分,以及示出指定操作的执行结果的第二部分。 目标主机向客户端发出响应。

    Pre-generation of generic session keys for use in communicating within communications environments
    6.
    发明授权
    Pre-generation of generic session keys for use in communicating within communications environments 有权
    通用会话密钥的预生成用于通信环境中的通信

    公开(公告)号:US07885412B2

    公开(公告)日:2011-02-08

    申请号:US11239252

    申请日:2005-09-29

    IPC分类号: H04L9/08 H04L9/14 H04L9/30

    CPC分类号: H04L9/0825 H04L9/083

    摘要: Generic session keys are pre-generated and stored in a pool of session keys for later use in communicating within a communications environment. The session keys that are stored in the pool are pre-encrypted with the private key of the entity storing those keys. To communicate between entities, a pre-encrypted session key is extracted from the pool and then further encrypted with the destination entity's public key to ensure data integrity and data confidentiality. The encrypted key is then forwarded to the destination entity and used during communications between the two entities.

    摘要翻译: 通用会话密钥是预先生成的,并存储在一个会话密钥池中,供以后用于通信环境中的通信。 存储在池中的会话密钥使用存储这些密钥的实体的私钥进行预加密。 为了在实体之间通信,从池中提取预加密的会话密钥,然后使用目的实体的公钥进一步加密,以确保数据完整性和数据机密性。 然后将加密的密钥转发到目的地实体,并在两个实体之间的通信期间使用。

    Plural/alternate files registry creation and management
    7.
    发明授权
    Plural/alternate files registry creation and management 失效
    多个/备用文件注册表创建和管理

    公开(公告)号:US07873674B2

    公开(公告)日:2011-01-18

    申请号:US11334209

    申请日:2006-01-18

    IPC分类号: G06F7/00 G06F17/30

    CPC分类号: G06F21/604 Y10S707/966

    摘要: Disclosed are a method of and system for managing plural files registries, for use with a computer operating system having a user/group management operation. The method comprises the steps of creating a plurality of files registries, and providing an administrator with access to each of said plurality of files registries independent of all of the others of said plurality of file registries. Preferably, this is done by inserting, for each of said plurality of files registries, a respective one instruction into the user/group management operation specifying a base directory path to said each of said plurality of files registries.

    摘要翻译: 公开了一种用于管理多个文件注册表的方法和系统,用于具有用户/组管理操作的计算机操作系统。 该方法包括以下步骤:创建多个文件注册表,并且向管理员提供独立于所述多个文件注册表中的所有其他文件的所有多个文件注册表中的每一个的访问。 优选地,这通过将针对每个所述多个文件注册表插入到指定到所述多个文件注册表中的每一个的基本目录路径的用户/组管理操作中的相应一个指令来完成。

    Method and Apparatus For Mapping Encrypted and Decrypted Data Via Key Management System
    10.
    发明申请
    Method and Apparatus For Mapping Encrypted and Decrypted Data Via Key Management System 有权
    通过密钥管理系统映射加密和解密数据的方法和装置

    公开(公告)号:US20090164513A1

    公开(公告)日:2009-06-25

    申请号:US11961015

    申请日:2007-12-20

    IPC分类号: G06F17/30

    CPC分类号: G06F21/80

    摘要: A data processing system having a host computer including a key manager, a control unit connected to the host computer, a data storage unit (such as a tape drive) controlled by the control unit, and data storage medium for storing data thereon to be written to or read from by the data storage unit. The key manager stores a data structure having at least one record having a volume serial number, as start location, a length entry, and a key for encrypting and decrypting data on the data storage medium. A data storage medium (such as data tape) is mounted on the data storage unit, and a volume recorded on the tape is retrieved. The control unit retrieves the data structure from the key manager and matches the volume serial number recorded in the retrieved data structure with the volume serial number retrieved from the data storage medium. It they match, the control unit passes to the data storage unit, commands to turn on or turn off encryption dependent upon the location where data is written by the data storage unit onto the data storage medium, or to turn on or turn off decryption dependent upon the location where data is read by the data storage unit from the data storage medium.

    摘要翻译: 一种具有主计算机的数据处理系统,包括密钥管理器,连接到主计算机的控制单元,由控制单元控制的数据存储单元(例如磁带驱动器)以及用于存储要写入的数据的数据存储介质 由数据存储单元读取或读取。 密钥管理器存储具有至少一个具有卷序列号的记录的数据结构,作为开始位置,长度条目和用于在数据存储介质上加密和解密数据的密钥。 数据存储介质(例如数据磁带)安装在数据存储单元上,并记录在磁带上的卷。 控制单元从密钥管理器检索数据结构,并将记录在检索的数据结构中的卷序列号与从数据存储介质检索的卷序列号进行匹配。 它们匹配,控制单元传递到数据存储单元,根据数据存储单元将数据写入数据存储介质的位置来打开或关闭加密的命令,或者打开或关闭解密依赖 在数据存储单元从数据存储介质读取数据的位置。