Bios method for securing and protecting end point with ownership information
Disclosed systems and methods for securing an information handling system monitor for certain predetermined events, and, upon detecting any one of the predetermined events, requesting ownership data indicative of the authorized or recognized owner. In some embodiments, the ownership data is conveyed via a digital certificate establishing a trusted relationship between the owner and the information handling system. The digital certificate cryptographically associates a manifest of the system's key components and a device identifier such as a service tag. The predetermined requests and events may include, as non-limiting examples, requests to wipe, clear, or sanitize a persistent storage resource, request to change an encryption key, chassis intrusion events, requests to modify an OS image of a platform, requests to modify a security parameter, requests to modify or restore a factory setting of a configuration parameter, incorrect password events exceeding a predetermined threshold, and SPI probe detection events.
1 . A method for managing an information handling system, the method comprising:
responsive to detecting any of a group of suspicious events, requesting ownership information indicative of an owner of an information handling system;
responsive to receiving the ownership data, prompting a user of the information handling system to verify owner information; and′
prohibiting execution of any of a group of irreparable operations until the user successfully verifies the owner information;
wherein the information handling system includes an embedded controller (EC) to support one or more system management functions selected from: thermal management, power monitoring, and battery management and wherein requesting the ownership information comprises requesting the ownership information from-the EC.
2 . The method of claim 1 , wherein the ownership information comprises an encrypted ownership voucher and wherein requesting the ownership data includes verifying the ownership voucher via a trusted connection with an original equipment manufacturer (OEM) database.
3 . The method of claim 1 , wherein the group of suspicious events includes user requests initiated in a pre-operating system (OS) environment.
4 . The method of claim 3 , wherein the group of suspicious events includes user requests initiated from a basic input/output (BIOS) setup interface.
5 . The method of claim 1 , wherein the group of suspicious events includes an event selected from:
a chassis intrusion event;
incorrect password events exceeding a predetermined threshold; and
a serial peripheral interface (SPI) probe detection event.
6 . The method of claim 1 , wherein the ownership information comprises a digital certificate establishing a trusted relationship between the owner and the information handling system platform.
7 . The method of claim 1 , wherein the group of irreparable operations include a request to wipe, clear, or sanitize a persistent storage resource.
8 . A method for preserving an information handling system platform, the method comprising:
responsive to detecting any of a group of suspicious events, requesting ownership data indicative of an owner for the information handling system;
responsive to receiving the ownership data, prompting a user of the information handling system platform to verify the owner data; and′
prohibiting execution of any of a group of irreparable operations until the user successfully verifies the owner data;
responsive to not receiving the owner information, performing backend verification operations including:
establishing BIOS connectivity enabling network access in a pre-OS environment;
communicating the suspicious event and a device identifier associated with the information handling system platform to an OEM backend platform;
responsive to locating and retrieving owner information associated with the device identifier, communicating a request prompting the owner to authenticate; and
responsive to not locating owner information associated with the device identifier, prompting the user to register.
9 . The method of claim 8 , further comprising:
returning a response from the backend platform; and
processing the response to take an action selected from:
proceeding with the irreparable operation;
prohibiting the irreparable operation;
prompting the user to register the information handling system with the OEM; and
prompting the user to retry.
10 . An information handling system, comprising:
a central processing unit (CPU);
an embedded controller (EC) to support one or more system management functions selected from: thermal management, power monitoring, and battery management, coupled to the CPU; and
computer readable storage including processor executable instructions that, when executed by a processor, cause the system to perform operations including:
responsive to detecting any of a group of suspicious events, requesting ownership information indicative of an owner for the information handling system platform;
responsive to receiving the ownership information:
prompting a user of the information handling system platform to verify owner information; and
prohibiting execution of any of a group of irreparable operations until the user successfully verifies the owner information;
responsive to not receiving the owner information, performing backend verification operations including:
establishing BIOS connectivity enabling network access in a pre-OS environment;
communicating the event and a device identifier associated with the information handling system to an OEM backend platform;
responsive to locating and retrieving owner information associated with the device identifier, communicating a request prompting the owner to authenticate; and
responsive to not locating owner information associated with the device identifier, prompting the user to register.
11 . The information handling system of claim 10 , wherein requesting the ownership information comprises requesting the ownership information from EC.
12 . The information handling system of claim 10 , wherein the ownership information comprises an encrypted ownership voucher and wherein requesting the ownership data includes verifying the ownership voucher with via a trusted connection with an original equipment manufacturer (OEM) database.
13 . The information handling system of claim 10 , wherein the plurality of predetermined events includes user requests initiated in a pre-operating system (OS) environment.
14 . The information handling system of claim 13 , wherein the group of suspicious events include user requests initiated from a basic input/output system (BIOS) setup interface.
15 . The information handling system of claim 10 , wherein the group of group of suspicious includes an event selected from:
a chassis intrusion event;
incorrect password events exceeding a predetermined threshold; and
a serial peripheral interface (SPI) probe detection event.
16 . The information handling system of claim 10 , wherein the ownership information comprises a digital certificate establishing a trusted relationship between the owner and the information handling system.
17 . The information handling system of claim 10 , further comprising:
returning a response from the backend platform; and
processing the response to take an action selected from:
proceeding with the irreparable operation;
prohibiting the irreparable operation;
prompting the user to register the information handling system platform with the OEM; and
prompting the user to retry.
18 . The information handling system of claim 10 , wherein the group of irreparable operations include a request to wipe, clear, or sanitize a persistent storage resource.