IP Library Granted Patent US 12,688,303
Granted Patent B2
US 12,688,303 · App. 18/643,527 · Granted Jul 21, 2026

Processor environment agnostic information handling system firmware forensic vulnerability acceleration operation

Inventors: Shekar Babu Suryanarayana (Bangalore, IN); Karunakar Poosapalli (Telangana, IN); Siddhartha Bose (Jabalpur, IN)
Assignee: Dell Products L.P.
G06F21/577G06F21/572
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,688,303
App. No.
18/643,527
Granted
Jul 21, 2026
Kind
B2
Abstract

A firmware management operation. The firmware management operation includes extracting a firmware image from an information handling system, the firmware image comprising a plurality of firmware regions; retrieving a known good firmware image, the known good firmware image comprising a plurality of known good firmware regions; and, performing a processor environment agnostic information handling system forensic vulnerability acceleration operation, the processor environment agnostic information handling system forensic vulnerability acceleration operation identifying potentially vulnerable firmware regions of the firmware image from the information handling system.

Claims (52)

1 . A computer-implementable method for performing a firmware management operation, comprising:

identifying a processor environment installed on an information handling system from a plurality of processor environments, each of the plurality of processing environments implementing a respective processor architecture;

extracting a firmware image from the information handling system, the firmware image comprising a plurality of firmware regions, the plurality of firmware regions including a processor reference code firmware region, a memory training firmware region, an open source firmware region, a firmware volume firmware region, a firmware files system firmware region, a non-volatile memory firmware region, an embedded controller firmware region and a management engine firmware region;

retrieving a known good firmware image, the known good firmware image comprising a plurality of known good firmware regions; and,

performing a processor environment agnostic information handling system forensic vulnerability acceleration operation, the processor environment agnostic information handling system forensic vulnerability acceleration operation being implemented to function with any of the plurality of processor environments, the processor environment agnostic information handling system forensic vulnerability acceleration operation identifying vulnerable firmware regions for the information handling system from the plurality of firmware regions, the processor environment agnostic information handling system forensic vulnerability acceleration operation being implemented to identify, remediate, or a combination thereof, firmware security vulnerabilities, firmware runtime security vulnerabilities, or a combination thereof, the processor environment agnostic information handling system forensic vulnerability acceleration operation identifying potentially vulnerable firmware regions of the firmware image from the information handling system.

2 . The method of claim 1 , wherein:

the processor environment agnostic information handling system forensic vulnerability acceleration operation provides a digital forensic vulnerability protocol, the digital forensic vulnerability protocol dynamically learning firmware vulnerabilities, runtime vulnerabilities, or a combination thereof.

3 . The method of claim 2 , wherein:

the digital forensic vulnerability protocol defines a set of rules for formatting and processing data associated with performance of the processor environment agnostic information handling system firmware forensic vulnerability acceleration operation.

4 . The method of claim 1 , wherein:

the processor environment agnostic information handling system forensic vulnerability acceleration operation implements a digital forensic vulnerability acceleration algorithm, the digital forensic vulnerability acceleration analysis algorithm comprising a set of commands to perform an operation associated with performance of the processor environment agnostic information handling system firmware forensic vulnerability acceleration operation.

5 . The method of claim 4 , wherein:

the digital forensic vulnerability acceleration algorithm is implemented at different stages of firmware execution.

6 . The method of claim 1 , wherein:

the plurality of firmware regions include a processor reference code firmware region, a memory training firmware region, an open source firmware region, a firmware volume (FV) firmware region, a firmware file system (FFS) firmware region, a non-volatile (NV) memory store firmware region, an embedded controller firmware region, a management engine firmware region, or a combination thereof.

7 . A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

identifying a processor environment installed on an information handling system from a plurality of processor environments, each of the plurality of processing environments implementing a respective processor architecture;

extracting a firmware image from the information handling system, the firmware image comprising a plurality of firmware regions, the plurality of firmware regions including a processor reference code firmware region, a memory training firmware region, an open source firmware region, a firmware volume firmware region, a firmware files system firmware region, a non-volatile memory firmware region, an embedded controller firmware region and a management engine firmware region;

retrieving a known good firmware image, the known good firmware image comprising a plurality of known good firmware regions; and,

performing a processor environment agnostic information handling system forensic vulnerability acceleration operation, the processor environment agnostic information handling system forensic vulnerability acceleration operation being implemented to function with any of the plurality of processor environments, the processor environment agnostic information handling system forensic vulnerability acceleration operation identifying vulnerable firmware regions for the information handling system from the plurality of firmware regions, the processor environment agnostic information handling system forensic vulnerability acceleration operation being implemented to identify, remediate, or a combination thereof, firmware security vulnerabilities, firmware runtime security vulnerabilities, or a combination thereof, the processor environment agnostic information handling system forensic vulnerability acceleration operation identifying potentially vulnerable firmware regions of the firmware image from the information handling system.

8 . The system of claim 7 , wherein:

the processor environment agnostic information handling system forensic vulnerability acceleration operation provides a digital forensic vulnerability protocol, the digital forensic vulnerability protocol dynamically learning firmware vulnerabilities, runtime vulnerabilities, or a combination thereof.

9 . The system of claim 8 , wherein:

the digital forensic vulnerability protocol defines a set of rules for formatting and processing data associated with performance of the processor environment agnostic information handling system firmware forensic vulnerability acceleration operation.

10 . The system of claim 7 , wherein:

the processor environment agnostic information handling system forensic vulnerability acceleration operation implements a digital forensic vulnerability acceleration algorithm, the digital forensic vulnerability acceleration analysis algorithm comprising a set of commands to perform an operation associated with performance of the processor environment agnostic information handling system firmware forensic vulnerability acceleration operation.

11 . The system of claim 10 , wherein:

the digital forensic vulnerability acceleration algorithm is implemented at different stages of firmware execution.

12 . The system of claim 7 , wherein:

the plurality of firmware regions include a processor reference code firmware region, a memory training firmware region, an open source firmware region, a firmware volume (FV) firmware region, a firmware file system (FFS) firmware region, a non-volatile (NV) memory store firmware region, an embedded controller firmware region, a management engine firmware region, or a combination thereof.

13 . A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

identifying a processor environment installed on an information handling system from a plurality of processor environments, each of the plurality of processing environments implementing a respective processor architecture;

extracting a firmware image from the information handling system, the firmware image comprising a plurality of firmware regions, the plurality of firmware regions including a processor reference code firmware region, a memory training firmware region, an open source firmware region, a firmware volume firmware region, a firmware files system firmware region, a non-volatile memory firmware region, an embedded controller firmware region and a management engine firmware region;

retrieving a known good firmware image, the known good firmware image comprising a plurality of known good firmware regions; and,

performing a processor environment agnostic information handling system forensic vulnerability acceleration operation, the processor environment agnostic information handling system forensic vulnerability acceleration operation being implemented to function with any of the plurality of processor environments, the processor environment agnostic information handling system forensic vulnerability acceleration operation identifying vulnerable firmware regions for the information handling system from the plurality of firmware regions, the processor environment agnostic information handling system forensic vulnerability acceleration operation being implemented to identify, remediate, or a combination thereof, firmware security vulnerabilities, firmware runtime security vulnerabilities, or a combination thereof, the processor environment agnostic information handling system forensic vulnerability acceleration operation identifying potentially vulnerable firmware regions of the firmware image from the information handling system.

14 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the processor environment agnostic information handling system forensic vulnerability acceleration operation provides a digital forensic vulnerability protocol, the digital forensic vulnerability protocol dynamically learning firmware vulnerabilities, runtime vulnerabilities, or a combination thereof.

15 . The non-transitory, computer-readable storage medium of claim 14 , wherein:

the digital forensic vulnerability protocol defines a set of rules for formatting and processing data associated with performance of the processor environment agnostic information handling system firmware forensic vulnerability acceleration operation.

16 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the processor environment agnostic information handling system forensic vulnerability acceleration operation implements a digital forensic vulnerability acceleration algorithm.

17 . The non-transitory, computer-readable storage medium of claim 16 , wherein:

the digital forensic vulnerability acceleration algorithm is implemented at different stages of firmware execution.

18 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the plurality of firmware regions include a processor reference code firmware region, a memory training firmware region, an open source firmware region, a firmware volume (FV) firmware region, a firmware file system (FFS) firmware region, a non-volatile (NV) memory store firmware region, an embedded controller firmware region, a management engine firmware region, or a combination thereof.

19 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.