IP Library Granted Patent US 12663999
Granted Patent B2
US 12663999 · App. 18/772,631 · Granted Jun 23, 2026

Secure operating system provisioning system

Inventors: Srinivas Giri Raju Gowda (Fremont, CA); Douglas Lang Farley (Round Rock, TX); Trevor Christian Cockrell (Hutto, TX)
Assignee: Dell Products L.P.
G06F9/4403G06F21/575G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12663999
App. No.
18/772,631
Granted
Jun 23, 2026
Kind
B2
Abstract

A secure operating system provisioning system includes a resource system having resource device(s), an SCP device, and a BIOS coupled to the resource device(s) and the SCP device. The BIOS begins initialization operations, retrieves a first subset of BIOS firmware, enters a first SMM and uses the first subset of BIOS firmware to authenticate the resource device(s) before exiting the first SMM. The BIOS then enters a second SMM in response to an SMI from the SCP device and verifies a runtime image stored in the SCP device, retrieves a second subset of the BIOS firmware from the runtime image, and stores the second subset of the BIOS firmware in the BIOS before exiting the second SMM. The BIOS then uses the second subset of the BIOS firmware to provide an operating system for the resource system to complete the initialization operations.

Claims (66)

1 . A secure operating system provisioning system, comprising:

at least one resource device that is included in the resource system;

a System Control Processor (SCP) device; and

a Basic Input/Output System (BIOS) that is coupled to the at least one resource device and the SCP device and that is configured to:

begin initialization operations for the resource system;

retrieve a first subset of BIOS firmware;

enter a first System Management Mode (SMM);

authenticate, while in the first SMM and using the first subset of BIOS firmware, the at least one resource device;

exit the first SMM;

enter, in response to a System Management Interrupt (SMI) from the SCP device, a second SMM;

verify, while in the second SMM, a runtime image that is stored in the SCP device;

retrieve, while in the second SMM, a second subset of the BIOS firmware from the runtime image;

store, while in the second SMM, the second subset of the BIOS firmware in the BIOS;

exit the second SMM; and

provide, using the second subset of the BIOS firmware, an operating system for the resource system to complete the initialization operations for the resource system.

2 . The system of claim 1 , wherein the BIOS is configured to:

configure, while in the first SMM and using the first subset of BIOS firmware, each of the at least one resource device in an idle mode; and

configure, using the second subset of the BIOS firmware, each of the at least one resource device in a runtime mode.

3 . The system of claim 1 , wherein the first subset of the BIOS firmware is retrieved from the SCP device.

4 . The system of claim 1 , wherein the first subset of the BIOS firmware is retrieved from a physical Serial Peripheral Interface (SPI) storage device that is included in the resource system and that is separate from the SCP device.

5 . The system of claim 1 , wherein the first subset of the BIOS firmware is configured for use by the BIOS to perform initialization operations for the resource system up to a Direct eXecution Environment (DXE).

6 . The system of claim 1 , wherein the operating system is provided by a microvisor.

7 . An Information Handling System (IHS), comprising:

a Basic Input/Output System (BIOS) processing system; and

a BIOS memory system that is coupled to the BIOS processing system and that includes instructions that, when executed by the BIOS processing system, cause the BIOS processing system to provide a BIOS engine that is configured to:

begin initialization operations for a resource system;

retrieve a first subset of BIOS firmware;

enter a first System Management Mode (SMM);

authenticate, while in the first SMM and using the first subset of BIOS firmware, at least one resource device included in the resource system;

exit the first SMM;

enter, in response to a System Management Interrupt (SMI) from an SCP device that is included in the resource system, a second SMM;

verify, while in the second SMM, a runtime image that is stored in the SCP device;

retrieve, while in the second SMM, a second subset of the BIOS firmware from the runtime image;

store, while in the second SMM, the second subset of the BIOS firmware in the memory system;

exit the second SMM; and

provide, using the second subset of the BIOS firmware, an operating system for the resource system to complete the initialization operations for the resource system.

8 . The IHS of claim 7 , wherein the BIOS engine is configured to:

configure, while in the first SMM and using the first subset of BIOS firmware, each of the at least one resource device in an idle mode; and

configure, using the second subset of the BIOS firmware, each of the at least one resource device in a runtime mode.

9 . The IHS of claim 7 , wherein the first subset of the BIOS firmware is retrieved from the SCP device.

10 . The IHS of claim 7 , wherein the first subset of the BIOS firmware is retrieved from a physical Serial Peripheral Interface (SPI) storage device that is included in the resource system and that is separate from the SCP device.

11 . The IHS of claim 7 , wherein the first subset of the BIOS firmware is configured for use by the BIOS to perform initialization operations for the resource system up to a Direct eXecution Environment (DXE).

12 . The IHS of claim 7 , wherein the operating system is provided by a microvisor.

13 . The IHS of claim 7 , wherein the BIOS engine is configured to:

report, prior to entering the second SMM, the at least one resource device to the SCP device.

14 . A method for securely providing an operating system for a computing device, comprising:

beginning, by a Basic Input/Output System (BIOS), initialization operations for a resource system;

retrieving, by the BIOS, a first subset of BIOS firmware;

entering, by the BIOS, a first System Management Mode (SMM);

authenticating, by the BIOS while in the first SMM and using the first subset of BIOS firmware, at least one resource device included in the resource system;

exiting, by the BIOS, the first SMM;

entering, by the BIOS in response to a System Management Interrupt (SMI) from an SCP device that is included in the resource system, a second SMM;

verifying, by the BIOS while in the second SMM, a runtime image that is stored in the SCP device;

retrieving, by the BIOS while in the second SMM, a second subset of the BIOS firmware from the runtime image;

storing, by the BIOS while in the second SMM, the second subset of the BIOS firmware in the memory system;

exiting, by the BIOS, the second SMM; and

providing, by the BIOS using the second subset of the BIOS firmware, an operating system for the resource system to complete the initialization operations for the resource system.

15 . The method of claim 14 , further comprising:

configuring, by the BIOS while in the first SMM and using the first subset of BIOS firmware, each of the at least one resource device in an idle mode; and

configuring, by the BIOS using the second subset of the BIOS firmware, each of the at least one resource device in a runtime mode.

16 . The method of claim 14 , wherein the first subset of the BIOS firmware is retrieved from the SCP device.

17 . The method of claim 14 , wherein the first subset of the BIOS firmware is retrieved from a physical Serial Peripheral Interface (SPI) storage device that is included in the resource system and that is separate from the SCP device.

18 . The method of claim 14 , wherein the first subset of the BIOS firmware is configured for use by the BIOS to perform initialization operations for the resource system up to a Direct eXecution Environment (DXE).

19 . The method of claim 14 , wherein the operating system is provided by a microvisor.

20 . The method of claim 14 , further comprising:

reporting, by the BIOS prior to entering the second SMM, the at least one resource device to the SCP device.