首页> 外国专利> Security policy enforcement based on dynamic security context updates

Security policy enforcement based on dynamic security context updates

机译:基于动态安全上下文更新的安全策略强制执行

摘要

An information handling system (IHS) includes a memory having a BIOS, at least one sensor that generates security related data for the IHS, a controller, and one or more I/O drivers. The memory, at least one sensor and controller operate within a secure environment of the IHS; the I/O driver(s) operate outside of the secure environment. The controller includes a security policy management engine, which is executable during runtime of the IHS to continuously monitor security related data generated by the at least one sensor, determine whether the security related data violates at least one security policy rule specified for the IHS, and provide a notification of security policy violation to the BIOS, if the security related data violates at least one security policy rule. The I/O driver(s) include a security enforcement engine, which is executable to receive the notification of security policy violation from the BIOS, and perform at least one security measure in response thereto.
机译:信息处理系统(IHS)包括具有BIOS的存储器,至少一个传感器,用于为IHS,控制器和一个或多个I / O驱动器生成安全相关数据。存储器,至少一个传感器和控制器在IHS的安全环境中运行; I / O驱动程序在安全环境之外运行。控制器包括安全策略管理引擎,其在IHS的运行时可执行,以连续监视由至少一个传感器生成的安全相关数据,确定安全相关数据是否违反了为IHS指定的至少一个安全策略规则,以及如果安全相关数据违反了至少一个安全策略规则,则提供对BIOS的安全策略违规的通知。 I / O驱动器包括安全强制引擎,该引擎是可执行的,用于从BIOS接收安全策略违规的通知,并执行至少一个安全措施响应于此。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号