IP Library Granted Patent US 8,738,915
Granted Patent B2
US 8,738,915 · App. 13/174,462 · Granted May 27, 2014

System and method for establishing perpetual trust among platform domains

Inventors: Muhammed Jaber (Austin, TX); Marshal Savage (Austin, TX); Mukund Purshottam Khatri (Austin, TX)
Assignee: Dell Products L.P.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,738,915
App. No.
13/174,462
Filed
Jun 30, 2011
Granted
May 27, 2014
Kind
B2
Art Unit
2436
USPC
713/171
Abstract

A method may include generating a first shared secret for a present boot session of the information handling system and determining if a second shared secret existed for a prior boot session of the information handling system. If the second shared secret existed for the prior boot session, the method may include encrypting the first shared secret with the second shared secret and communicating the first shared secret encrypted by the second shared secret from a first information handling resource to a second information handling resource. If the second shared secret did not exist for the prior boot session, the method may include communicating the first shared secret unencrypted from the first information handling resource to the second information handling resource. The method may additionally include securely communicating between the first information handling resource and the second information handling resource using the first shared secret for encryption and decryption.

Claims (56)

1. An information handling system comprising:

a processor;

a service processor;

a basic input/output system (BIOS);

a non-transitory memory accessible to the processor;

a first information handling resource configured to:

generate a first shared secret for a present boot session of the information handling system;

determine if a second shared secret existed for a prior boot session of the information handling system;

if the second shared secret existed for the prior boot session:

encrypt the first shared secret with the second shared secret; and

communicate the first shared secret encrypted by the second shared secret; and

if the second shared secret did not exist for the prior boot session, communicate the first shared secret unencrypted; and

a second information handling resource configured to:

receive the first shared secret; and

if the second shared secret existed for the prior boot session, decrypt the first shared secret with the second shared secret; and

the first information handling resource and the second information handling resource further configured to securely communicate during the present boot session using the first shared secret for encryption and decryption of communications,

wherein the first information handling resource and the second information handling resource are selected from: the basic input/output system (BIOS) and the service processor.

2. An information handling system according to claim 1 , the first information handling resource comprising the basic input/output system (BIOS) and the second information handling resource comprising the service processor.

3. An information handling system according to claim 1 , the first information handling resource comprising the service processor and the second information handling resource comprising the basic input/output system (BIOS).

4. An information handling system according to claim 1 , further comprising:

a key manager, the key manager comprising a program of instructions executable by the processor for causing the processor to manage access by applications executing on the processor to at least one of the first information handling resource and the second information handling resource

at least one of the first information handling resource and the second information handling resource further configured to communicate the first shared secret to the key manager; and

the key manager configured to communicate the first shared secret to an application authenticating to the key manager, such that the application may communicate with at least one of the first information handling resource and the second information handling resource using the first shared secret for encryption and decryption of communications.

5. An information handling system according to claim 1 , wherein the first shared secret and the second shared secret each comprise one of a symmetric key and a public/private key pair.

6. A method comprising:

generating a first shared secret for a present boot session of an information handling system;

determining if a second shared secret existed for a prior boot session of the information handling system;

if the second shared secret existed for the prior boot session:

encrypting the first shared secret with the second shared secret; and

communicating the first shared secret encrypted by the second shared secret from a first information handling resource to a second information handling resource;

if the second shared secret did not exist for the prior boot session, communicating the first shared secret unencrypted from the first information handling resource to the second information handling resource;

at the second information handling resource:

receiving the first shared secret; and

if the second shared secret existed for the prior boot session, decrypting the first shared secret with the second shared secret; and

securely communicating between the first information handling resource and the second information handling resource using the first shared secret for encryption and decryption of communications,

wherein the first information handling resource and the second information handling resource are included in the information handling system and are selected from: a basic input/output system (BIOS) and a service processor.

7. A method according to claim 6 , the first information handling resource comprising the basic input/output system (BIOS) and the second information handling resource comprising the service processor.

8. A method according to claim 6 , the first information handling resource comprising the service processor and the second information handling resource comprising the basic input/output system (BIOS).

9. A method according to claim 6 , further comprising:

communicating the first shared secret to a key manager, the key manager comprising a program of instructions executable by a processor for causing the processor to manage access by applications executing on the processor to at least one of the first information handling resource and the second information handling resource; and

communicating, by the key manager, the first shared secret to an application authenticating to the key manager, such that the application may communicate with at least one of the first information handling resource and the second information handling resource using the first shared secret for encryption and decryption of communications.

10. A method according to claim 6 , wherein the first shared secret and the second shared secret each comprise one of a symmetric key and a public/private key pair.

11. An information handling resource comprising:

a non-transitory memory accessible to a processor, wherein the information handling resource is configured to:

generate a first shared secret for a present boot session of an information handling system;

determine if a second shared secret existed for a prior boot session of the information handling system;

if the second shared secret existed for the prior boot session:

encrypt the first shared secret with the second shared secret; and

communicate the first shared secret encrypted by the second shared secret to a second information handling resource;

if the second shared secret did not exist for the prior boot session, communicate the first shared secret unencrypted to the second information handling resource; and

securely communicate with the second information handling resource using the first shared secret for encryption and decryption of communications,

wherein the information handling resource and the second information handling resource are included in the information handling system and are selected from: a basic input/output system (BIOS) and a service processor, and wherein the second information handling resource comprises a second non-transitory memory accessible to a second processor.

12. An information handling resource according to claim 11 , the information handling resource comprising the basic input/output system (BIOS) and the second information handling resource comprising the service processor.

13. An information handling resource according to claim 11 , the information handling resource comprising the service processor and the second information handling resource comprising the basic input/output system (BIOS).

14. An information handling resource according to claim 11 , further configured to:

communicate the first shared secret to a key manager, the key manager comprising a program of instructions executable by a processor for causing the processor to manage access by applications executing on the processor to at least one of the first information handling resource and the second information handling resource, such that the key manager may communicate the first shared secret to an application authenticating to the key manager, such that the application may communicate with at least one of the first information handling resource and the second information handling resource using the first shared secret for encryption and decryption of communications.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2011
From: JABER, MUHAMMED; SAVAGE, MARSHAL; KHATRI, MUKUND PURSHOTTAM
To: DELL PRODUCTS L.P.
Reel/Frame 026532/0831 →
Continuity (1)
Related Publication 20130007455A1 · Jan 3, 2013