IP Library Granted Patent US 11,341,246
Granted Patent B2
US 11,341,246 · App. 16/549,113 · Granted May 24, 2022

Secure firmware update for device with low computing power

Inventors: Santosh Gore (Bangalore, IN); Raveendra Babu Madala (Bangalore, IN); Viswanath Ponnuru (Bangalore, IN); Deepu Syam Sreedhar M (Calicut, IN); Sura Rajashekar Reddy (Andhra Pradesh, IN)
Assignee: Dell Products L.P.
G06F21/572G06F8/65H04L9/3247G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,341,246
App. No.
16/549,113
Filed
Aug 23, 2019
Granted
May 24, 2022
Kind
B2
Art Unit
2199
USPC
717/168
Abstract

An information handling system may include a host system comprising a host system processor, a management controller coupled to the host system processor, and an information handling resource coupled to the host system processor and the management controller, the information handling resource including a firmware. The information handling system may be configured to transfer a firmware update package from the host system to the management controller, wherein the firmware update package includes a cryptographic signature; verify, at the management controller, the cryptographic signature; transfer data indicative of the verification from the management controller to the information handling resource; and in response to receiving the data indicative of the verification from the management controller, install, by the information handling resource, the firmware update package.

Claims (33)

1. An information handling system comprising:

a host system comprising a host system processor;

a management controller coupled to the host system processor; and

an information handling resource coupled to the host system processor and the management controller, the information handling resource including a firmware, an onboard processor, and an onboard memory having a size;

wherein the information handling system is configured to:

transfer a firmware update package from the host system to the management controller, wherein the firmware update package includes a cryptographic signature;

verify, at the management controller, the cryptographic signature, wherein the verification of the cryptographic signature uses a process that requires at least a minimum amount of memory that is greater than the size of the onboard memory of the information handling resource, such that the onboard processor and the onboard memory of the information handling resource are not capable of verifying the cryptographic signature;

transfer data indicative of the verification from the management controller to the information handling resource, wherein the data indicative of the verification comprises a cryptographic token, and wherein the cryptographic token is stored at the information handling resource in storage that is inaccessible to the host system;

transfer the cryptographic token from the management controller to the host system;

transfer the firmware update package and the cryptographic token from the host system to the information handling resource;

compare, by the information handling resource, the cryptographic token received from the management controller and the cryptographic token received from the host system; and

in response to a match between the cryptographic token received from the management controller and the cryptographic token received from the host system, install, by the information handling resource, the firmware update package.

2. The information handling system of claim 1 , wherein the cryptographic signature complies with a cryptographic standard.

3. The information handling system of claim 2 , wherein the cryptographic standard is Federal Information Processing Standards (FIPS) 186-4.

4. A method comprising:

transferring a firmware update package from a host system to a management controller of the host system, wherein the firmware update package includes a cryptographic signature;

the management controller verifying the cryptographic signature;

the management controller transferring data indicative of the verification to an information handling resource, wherein the information handling resource includes an onboard processor and an onboard memory that has a size, and wherein the verification of the cryptographic signature uses a process that requires at least a minimum amount of memory that is greater than the size of the onboard memory of the information handling resource, such that the onboard processor and the onboard memory of the information handling resource are not capable of verifying the signature, wherein the data indicative of the verification comprises a cryptographic token, and wherein the cryptographic token is stored at the information handling resource in storage that is inaccessible to the host system;

transferring the cryptographic token from the management controller to the host system;

transferring the firmware update package and the cryptographic token from the host system to the information handling resource;

comparing, by the information handling resource, the cryptographic token received from the management controller and the cryptographic token received from the host system; and

in response to a match between the cryptographic token received from the management controller and the cryptographic token received from the host system, information handling resource installing the firmware update package.

5. The method of claim 4 , wherein the data indicative of the verification is sent from the management controller to the information handling resource via an Inter-Integrated Circuit (I2C) bus.

6. An article of manufacture comprising a non-transitory, computer-readable medium having computer-executable code thereon that is executable by a processor of an information handling system for:

transferring a firmware update package from a host system of the information handling system to a management controller of the information handling system, wherein the firmware update package includes a cryptographic signature;

the management controller verifying the cryptographic signature;

the management controller transferring data indicative of the verification to an information handling resource, wherein the information handling resource includes an onboard processor and an onboard memory that has a size, and wherein the verification of the cryptographic signature uses a process that requires at least a minimum amount of memory that is greater than the size of the onboard memory of the information handling resource, such that the onboard processor and the onboard memory of the information handling resource are not capable of verifying the signature, wherein the data indicative of the verification comprises a cryptographic token, and wherein the cryptographic token is stored at the information handling resource in storage that is inaccessible to the host system;

transferring the cryptographic token from the management controller to the host system;

transferring the firmware update package and the cryptographic token from the host system to the information handling resource;

comparing, by the information handling resource, the cryptographic token received from the management controller and the cryptographic token received from the host system; and

in response to a match between the cryptographic token received from the management controller and the cryptographic token received from the host system, the information handling resource installing the firmware update package.

7. The article of claim 6 , wherein the cryptographic signature complies with a cryptographic standard.

8. The article of claim 7 , wherein the cryptographic standard is Federal Information Processing Standards (FIPS) 186-4.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (051302/0528) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.); SECUREWORKS CORP.
Reel/Frame 060438/0593 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST AT REEL 051449 FRAME 0728 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
Reel/Frame 058002/0010 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Dec 31, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 051449/0728 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 16, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 051302/0528 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2019
From: GORE, SANTOSH; MADALA, RAVENDRA BABU; PONNURU, VISWANATH; SREEDHAR M, DEEPU SYAM; REDDY, SURA RAJASHEKAR
To: DELL PRODUCTS L.P.
Reel/Frame 050145/0094 →
Continuity (1)
Related Publication 20210056208A1 · Feb 25, 2021