IP Library Granted Patent US 9,189,631
Granted Patent B2
US 9,189,631 · App. 13/912,330 · Granted Nov 17, 2015

Firmware authentication

Inventors: Wei G. Liu (Austin, TX); Mark W. Shutt (Austin, TX)
Assignee: Dell Inc.
G06F21/572
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,189,631
App. No.
13/912,330
Filed
Jun 7, 2013
Granted
Nov 17, 2015
Kind
B2
Art Unit
2116
USPC
713/2
Abstract

Firmware authentication in Information Handling Systems (IHSs) are disclosed. In some embodiments, an IHS may include a controller having a memory, the memory configured to store a plurality of firmware volumes, each of the plurality of firmware volumes including a plurality of firmware files. The IHS may also include a Basic Input/Output System (BIOS) operably coupled to the controller, the BIOS having program instructions stored thereon that, upon execution, cause the BIOS to authenticate two or more firmware files within a given one of the plurality of firmware volumes using a single digital signature. In another embodiment, a method may include creating a firmware volume, adding a plurality of firmware files to the firmware volume, and creating a digital signature based upon at least one of the plurality of firmware files, where the digital signature, upon being authenticated, allows a BIOS to load any of the plurality of firmware files.

Claims (34)

1. An Information Handling System (IHS), comprising:

a controller including a memory configured to store a plurality of firmware volumes, wherein each of the plurality of firmware volumes includes a plurality of firmware files, wherein all of the plurality of firmware volumes are encapsulated into a header file, wherein the header file includes a table that lists a plurality of digital signatures, wherein the table associates each digital signature with a different set of firmware file(s) within each firmware volume, and wherein each set of firmware file(s) can be authenticated its associated digital signature; and

a Basic Input/Output System (BIOS) operably coupled to the controller, the BIOS having program instructions stored thereon that, upon execution, cause the BIOS to authenticate two or more firmware files using a single digital signature, wherein a first one of the two or more firmware files belongs to a first firmware volume and a second one of the two of more firmware files belongs to a second firmware volume distinct from the first firmware volume, and wherein at least one of the first or second firmware volumes includes at least one firmware file that cannot be authenticated using the digital signature.

2. The IHS of claim 1 , wherein the BIOS is Unified Extensible Firmware Interface (UEFI) compliant.

3. The IHS of claim 1 , wherein the BIOS is operably coupled to the controller via a southbridge chipset.

4. The IHS of claim 3 , wherein a given one of the plurality of firmware volumes is exposed to the BIOS as a virtual mass storage device.

5. The IHS of claim 1 , wherein the firmware files include at least one of: a firmware driver, an UEFI application, an Operating System (OS) loader, or an Option Read-Only-Memory (OPROM) file.

6. The IHS of claim 1 , wherein the digital signature is included in a separate file outside the given one of the plurality of firmware volumes.

7. The IHS of claim 1 , wherein the header file includes the given digital signature.

8. The IHS of claim 1 , wherein to authenticate the two or more firmware files, the program instructions, upon execution, further cause the BIOS to create a hash based upon one of the two or more firmware files, decode the digital signature using a public key stored in the BIOS, and compare the hash to the decoded digital signature.

9. The IHS of claim 8 , wherein the BIOS is configured to authenticate the two or more firmware files in response to the hash matching the decoded digital signature.

10. A method, comprising:

creating a header file including a table and a plurality of firmware volumes, wherein each firmware volume includes a plurality of firmware files, wherein the table lists a plurality of digital signatures, wherein each digital signature is associated with a different set of firmware file(s) within each firmware volume, and wherein each set of firmware file(s) can be authenticated its associated digital signature;

adding firmware file to a given firmware volume; and

creating a digital signature based upon the firmware file, wherein the digital signature, upon being authenticated, allows a Basic Input/Output System (BIOS) to load two or more firmware files, wherein a first one of the two or more firmware files belongs to a first firmware volume and a second one of the two of more firmware files belongs to a second firmware volume distinct from the first firmware volume, and wherein at least one of the first or second firmware volumes includes at least one firmware file that cannot be authenticated using the digital signature.

11. The method of claim 10 , wherein the firmware files include at least one of: a firmware driver, a Unified Extensible Firmware Interface (UEFI) application, an Operating System (OS) loader, or an Option Read-Only-Memory (OPROM) file.

12. The method of claim 10 , wherein the digital signature is created based upon a hash of a single one of the plurality of firmware files, and wherein the hash is signed with an authorized private key.

13. The method of claim 10 , wherein the digital signature is created based upon a hash of two or more but fewer than all of the plurality of firmware files, and wherein the hash is signed with an authorized private key.

14. The method of claim 10 , further comprising:

adding the digital signature to the given firmware volume; or

storing the digital signature as a distinct file separately from the given firmware volume.

15. The method of claim 14 , wherein adding the digital signature to the firmware volume includes adding the digital signature to the header file.

16. A Basic Input/Output System (BIOS) having program instructions stored thereon that, upon execution, cause an Information Handling System (IHS) to:

access a header file external to the BIOS, the header file including a table and a plurality of firmware volumes, wherein each firmware volume includes a plurality of firmware files, wherein the table lists a plurality of digital signatures, wherein each digital signature is associated with a different set of firmware files, and wherein each set of firmware files can be authenticated using its associated digital signature;

receive a digital signature;

authenticate two or more firmware files using the digital signature, wherein a first one of the two or more firmware files belongs to a first firmware volume and a second one of the two of more firmware files belongs to a second firmware volume distinct from the first firmware volume, and wherein at least one of the first or second firmware volumes includes at least one firmware file that cannot be authenticated using the digital signature; and

load the two or more firmware files during a booting process.

17. The BIOS of claim 16 , wherein the first firmware volume is stored in a memory device external to the BIOS and accessible to the BIOS via a southbridge chipset as a virtual mass storage device.

18. The BIOS of claim 16 , wherein the two or more firmware files include at least one of: a firmware driver, a Unified Extensible Firmware Interface (UEFI) application, an Operating System (OS) loader, or an Option Read-Only-Memory (OPROM) file.

19. The BIOS of claim 16 , wherein to authenticate the two or more firmware files, the program instructions, upon execution, further cause the IHS to:

create a hash based upon one of the two or more firmware files using a same algorithm used in the creation of the digital signature;

decode the digital signature using a public key; and

compare the hash to the decoded digital signature.

20. The BIOS of claim 19 , wherein the program instructions, upon execution, further cause the IHS to authenticate the two or more firmware files in response to the hash matching the decoded digital signature.

Assignments (16)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.; DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2016
From: DELL INC.
To: DELL PRODUCTS L.P.
Reel/Frame 038222/0748 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2013
From: LIU, WEI G.; SHUTT, MARK W.
To: DELL INC
Reel/Frame 030565/0907 →
Continuity (1)
Related Publication 20140365755A1 · Dec 11, 2014