IP Library Granted Patent US 12694091
Granted Patent B2
US 12694091 · App. 18/177,901 · Granted Jul 28, 2026

Systems and methods for collective attestation of SPDM-enabled devices in an information handling system (IHS)

Inventors: Rama Rao Bisa (Bangalore, IN); Dharma Bhushan Ramaiah (Bangalore, IN); Vineeth Radhakrishnan (Palakkad, IN); Mini Thottunkal Thankappan (Bangalore, IN); Shinose Abdul Rahiman (Bangalore, IN); Chandrashekar Nelogal (Round Rock, TX); Mukund P. Khatri (Austin, TX); A Anis Ahmed (Bangalore, IN); Marshal F. Savage (Austin, TX); Jason Matthew Young (Round Rock, TX)
Assignee: Dell Products L.P.
G06F21/44G06F21/572G06F21/602G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12694091
App. No.
18/177,901
Granted
Jul 28, 2026
Kind
B2
Abstract

According to embodiments of the present disclosure, an Information Handling System (IHS) including multiple Security Protocol and Data Model (SPDM)-enabled devices is configured to perform collective attestation. The collective attestation is provided by computer-executable instructions that, when executed by a processor of the IHS, receive an attestation request from a requesting device and a device identity certificate from each of the devices. Using the device identity certificates, the instructions perform a cryptographic hash over the received device identity certificates, and send the cryptographic hash to the requesting device in response to the request.

Claims (48)

1 . An Information Handling System (IHS) comprising:

a plurality of Security Protocol and Data Model (SPDM)-enabled devices conforming to a SPDM specification; and

at least one memory coupled to at least one processor, the at least one memory having program instructions stored thereon that, upon execution by the at least one processor, cause the instructions to:

receive an attestation request from a requesting device;

receive a device identity certificate from each of the devices;

perform a firmware measurement of each of the devices;

perform a single cryptographic hash over the firmware measurements and the received device identity certificates to generate a single measurement; and

send the single measurement to the requesting device in response to the request.

2 . The IHS of claim 1 , wherein the program instructions are performed by a Baseboard Management Controller (BMC) configured in the IHS.

3 . The IHS of claim 2 , wherein the program instructions, upon execution, further cause the IHS to:

perform a BMC firmware measurement of the BMC; and

add the BMC firmware measurement to the cryptographic hash to generate the single measurement.

4 . The IHS of claim 2 , wherein the program instructions, upon execution, further cause the IHS to:

obtain a BMC device identity certificate associated with the BMC; and

add the BMC device identity certificate to the cryptographic hash to generate the single measurement.

5 . The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to:

receive a device identity certificate from a portion of the SPDM-enabled devices configured in the IHS; and

perform a cryptographic hash over the portion of received device identity certificates to generate the single measurement.

6 . The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to reject the attestation request when the attestation request is directed to a subset of the SPDM-enabled devices.

7 . The IHS of claim 1 , wherein the requesting device is configured to compare the single measurement against a golden thumbprint, and generate an alert message when the cryptographic hash does not match the golden thumbprint.

8 . The IHS of claim 1 , wherein the program instructions, upon execution, cause the IHS to populate a Secure Component Verification (SCV)-based manifest with the received device identity certificates; and send the populated SCV-based manifest to the requesting device in response to the request, wherein the requester is configured to compare the SCV-based manifest with a SCV certificate, and validate the SCV-based manifest based upon the comparison.

9 . A collective attestation method comprising:

receiving an attestation request from a requesting device;

receiving a device identity certificate from each of a plurality of Security Protocol and Data Model (SPDM)-enabled devices conforming to a SPDM specification;

perform a firmware measurement of each of the devices;

performing a single cryptographic hash over the firmware measurements and the received device identity certificates to generate a single measurement; and

sending the single measurement to the requesting device in response to the request.

10 . The collective attestation method of claim 9 , further comprising:

performing a BMC firmware measurement of a Baseboard Management Controller (BMC) configured in an Information Handling System (IHS); and

adding the BMC firmware measurement to generate the single measurement.

11 . The collective attestation method of claim 10 , further comprising:

obtaining a BMC device identity certificate associated with the BMC; and

adding the BMC device identity certificate to the single measurement.

12 . The collective attestation method of claim 9 , further comprising:

receiving a device identity certificate from a portion of the SPDM-enabled devices configured in the IHS; and

performing a cryptographic hash over the portion of received device identity certificates to generate the single measurement.

13 . The collective attestation method of claim 9 , further comprising rejecting the attestation request when the attestation request is directed to a subset of the SPDM-enabled devices.

14 . The collective attestation method of claim 9 , further comprising comparing, by the requesting device, the single measurement against a golden thumbprint, and generating, by the requesting device, an alert message when the cryptographic hash does not match the golden thumbprint.

15 . A computer program product comprising a non-transitory computer readable storage medium having program instructions stored thereon that, upon execution by an Information Handling System (IHS), cause the IHS to:

receive an attestation request from a requesting device;

receive a device identity certificate from each of a plurality of Security Protocol and Data Model (SPDM)-enabled devices conforming to a SPDM specification;

perform a firmware measurement of each of the devices;

perform a single cryptographic hash over the firmware measurements and the received device identity certificates to generate a single measurement; and

send the single measurement to the requesting device in response to the request.

16 . The computer program product of claim 15 , wherein the program instructions, upon execution, further cause the IHS to:

perform a BMC firmware measurement of a Baseboard Management Controller (BMC) configured in an Information Handling System (IHS); and

add the BMC firmware measurement to the cryptographic hash to generate the single measurement.

17 . The computer program product of claim 15 , wherein the program instructions, upon execution, cause the IHS to populate a Secure Component Verification (SCV)-based manifest with the received device identity certificates; and send the populated SCV-based manifest to the requesting device in response to the request, wherein the requester is configured to compare the SCV-based manifest with a SCV certificate, and validate the SCV-based manifest based upon the comparison.