IP Library Granted Patent US 12693797
Granted Patent B2
US 12693797 · App. 18/921,247 · Granted Jul 28, 2026

Secure one-time programming undo system

Inventors: Gregory Martin Allen (Layton, UT); Jonathan Jay Kellen (Dassel, MN); Austin Patrick Bolen (Austin, TX)
Assignee: Dell Products L.P.
G06F3/0622G06F3/0634G06F3/0673
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12693797
App. No.
18/921,247
Granted
Jul 28, 2026
Kind
B2
Abstract

A secure one-time programming undo system includes a component and a component configuration system. A one-time programming subsystem in the component configuration system provides the component with personality configuration information that configures the component to perform component operations, and performs a one-time programming operation that configures a component engine in the component to deny modification requests to modify the personality configuration information. A one-time programming undo subsystem in the component configuration system performs a one-time programming undo authentication operation, and transmits a one-time programming undo instruction that is associated with the one-time programming undo authentication operation to the component, with the one-time programming undo authentication operation configured to authenticate the one-time programming undo instruction to the component such that the component executes the one-time programming undo instruction that reconfigures the component engine in the component to allow modification requests to modify the personality configuration information.

Claims (64)

1 . A secure one-time programming undo component, comprising:

a component including a component chassis;

a secure memory subsystem housed in the component chassis; and

a component engine that is housed in the component chassis, that is coupled to the secure memory subsystem, and that is configured to:

receive, from a component configuration system, first personality configuration information;

provide the first personality configuration information in the secure memory subsystem to configure the component engine to perform first component operations;

receive, from the component configuration system, a first one-time programming instruction and first one-time programming undo information;

configure, in response to receiving the first one-time programming instruction, the secure memory subsystem to prevent modification to the first personality configuration information;

store the first one-time programming undo information in the secure memory subsystem;

receive, from the component configuration system subsequent to configuring the secure memory subsystem to prevent modification to the first personality configuration information, a one-time programming undo instruction;

authenticate, based on the first one-time programming undo information stored in the secure memory subsystem, the one-time programing undo instruction; and

configure, in response to authenticating the first one-time programming instruction, the secure memory subsystem to allow modification to the first personality configuration information.

2 . The system of claim 1 , wherein the component engine is configured to:

receive, from the component configuration system subsequent to configuring the secure memory subsystem to allow modification to the first personality configuration information, second personality configuration information;

provide the second personality configuration information in the secure memory subsystem in place of the first personality configuration information to configure the component engine to perform second component operations that are different than the first component operations;

receive, from the component configuration system, a second one-time programming instruction and second one-time programming undo information;

configure, in response to receiving the second one-time programming instruction, the secure memory subsystem to prevent modification to the second personality configuration information; and

store the second one-time programming undo information in the secure memory subsystem.

3 . The system of claim 2 , wherein the first component operations include encryption operations that prevent the reading and writing of data without authentication credentials, and wherein the second component operations allow the reading and writing of data without authentication credentials.

4 . The system of claim 1 , wherein the first one-time programming undo information is a first code that is stored in the secure memory subsystem, the one-time programming undo instruction includes a second code, and the one-time programing undo instruction is authenticated based on the second code matching the first code.

5 . The system of claim 1 , wherein the first one-time programming undo information is configured for use in enabling an authenticated communication session, and the one-time programing undo instruction is at least partially authenticated in response to being received via the authenticated communication session enabled using the first one-time programming undo information.

6 . The system of claim 1 , wherein the component is a storage device.

7 . An Information Handling System (IHS), comprising:

a processing system; and

a memory system that is coupled to the processing system and that includes instructions that, when executed by the processing system, cause the processing system to provide a component engine that is configured to:

receive, from a component configuration system that is coupled to the processing system, first personality configuration information;

provide the first personality configuration information in a secure memory subsystem that is coupled to the processing system to configure the component engine to perform first component operations;

receive, from the component configuration system, a first one-time programming instruction and first one-time programming undo information;

configure, in response to receiving the first one-time programming instruction, the secure memory subsystem to prevent modification to the first personality configuration information;

store the first one-time programming undo information in the secure memory subsystem;

receive, from the component configuration system subsequent to configuring the secure memory subsystem to prevent modification to the first personality configuration information, a one-time programming undo instruction;

authenticate, based on the first one-time programming undo information stored in the secure memory subsystem, the one-time programing undo instruction; and

configure, in response to authenticating the first one-time programming instruction, the secure memory subsystem to allow modification to the first personality configuration information.

8 . The IHS of claim 7 , wherein the first component operations include encryption operations that prevent the reading and writing of data without authentication credentials.

9 . The IHS of claim 7 , wherein the component engine is configured to:

receive, from the component configuration system subsequent to configuring the secure memory subsystem to allow modification to the first personality configuration information, second personality configuration information;

provide the second personality configuration information in the secure memory subsystem in place of the first personality configuration information to configure the component engine to perform second component operations that are different than the first component operations;

receive, from the component configuration system, a second one-time programming instruction and second one-time programming undo information;

configure, in response to receiving the second one-time programming instruction, the secure memory subsystem to prevent modification to the second personality configuration information; and

store the second one-time programming undo information in the secure memory subsystem.

10 . The IHS of claim 9 , wherein the second component operations allow the reading and writing of data without authentication credentials.

11 . The IHS of claim 7 , wherein the first one-time programming undo information is a first code that is stored in the secure memory subsystem, the one-time programming undo instruction includes a second code, and the one-time programing undo instruction is authenticated based on the second code matching the first code.

12 . The IHS of claim 7 , wherein the first one-time programming undo information is configured for use in enabling an authenticated communication session, and the one-time programing undo instruction is at least partially authenticated in response to being received via the authenticated communication session enabled using the first one-time programming undo information.

13 . The IHS of claim 7 , wherein the IHS is a storage device.

14 . A method for securely undoing one-time programming of a component, comprising:

receiving, by a component from a component configuration system, first personality configuration information;

providing, by the component, the first personality configuration information in a secure memory subsystem to configure the component to perform first component operations;

receiving, by the component from the component configuration system, a first one-time programming instruction and first one-time programming undo information;

configuring, by the component in response to receiving the first one-time programming instruction, the secure memory subsystem to prevent modification to the first personality configuration information;

storing, by the component, the first one-time programming undo information in the secure memory subsystem;

receiving, by the component from the component configuration system subsequent to configuring the secure memory subsystem to prevent modification to the first personality configuration information, a one-time programming undo instruction;

authenticating, by the component based on the first one-time programming undo information stored in the secure memory subsystem, the one-time programing undo instruction; and

configuring, by the component in response to authenticating the first one-time programming instruction, the secure memory subsystem to allow modification to the first personality configuration information.

15 . The method of claim 14 , wherein the first component operations include encryption operations that prevent the reading and writing of data without authentication credentials.

16 . The method of claim 14 , further comprising:

receiving, by the component from the component configuration system subsequent to configuring the secure memory subsystem to allow modification to the first personality configuration information, second personality configuration information;

providing, by the component, the second personality configuration information in the secure memory subsystem in place of the first personality configuration information to configure the component to perform second component operations that are different than the first component operations;

receiving, by the component from the component configuration system, a second one-time programming instruction and second one-time programming undo information;

configuring, by the component in response to receiving the second one-time programming instruction, the secure memory subsystem to prevent modification to the second personality configuration information; and

storing, by the component, the second one-time programming undo information in the secure memory subsystem.

17 . The method of claim 16 , wherein the second component operations allow the reading and writing of data without authentication credentials.

18 . The method of claim 14 , wherein the first one-time programming undo information is a first code that is stored in the secure memory subsystem, the one-time programming undo instruction includes a second code, and the one-time programing undo instruction is authenticated based on the second code matching the first code.

19 . The method of claim 14 , wherein the first one-time programming undo information is configured for use in enabling an authenticated communication session, and the one-time programing undo instruction is at least partially authenticated in response to being received via the authenticated communication session enabled using the first one-time programming undo information.

20 . The method of claim 14 , wherein the component is a storage device.