IP Library Patent Application 14058789
Patent Application
App. No. 14/058,789

System and Method for Pre-Boot Authentication of a Secure Client Hosted Virtualization in an Information Handling System

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/058,789
Filed
Oct 21, 2013
Art Unit
2439
USPC
713/189
Abstract

A client hosted virtualization system (CHVS) includes a processor to execute code, a component, and a non-volatile memory. The non volatile memory includes BIOS code and code to implement a virtualization manager. The virtualization manager is operable to initialize the CHVS, launch a virtual machine on the CHVS, and assign the component to the virtual machine, such that the virtual machine has control of the component. The CHVS is configurable to execute the BIOS and not the virtualization manager, or to execute the virtualization manager and not the BIOS.

Claims (42)

1 . An information handling system comprising:

a host mapped general purpose input output (GPIO) including a plurality of registers, wherein a first register includes a system service tag associated with the information handling system;

a host processor in communication with the host mapped GPIO, the host processor including a basic input output system;

a board management controller separate from the host processor and in communication with the host mapped GPIO, the board management controller configured to control accessibility to the plurality of registers in the GPIO based on a private key received from the basic input output system requesting accessibility to the plurality of registers, wherein the private key is based on the system service tag;

a cryptography engine in communication with the board management controller, the cryptography engine configured to authenticate the private key received from the board management controller; and

wherein the board management controller is further configured to provide accessibility to the host mapped GPIO for a specific number of transactions of the basic input output system when the private key is authenticated.

2 . The information handling system of claim 1 further comprising:

a keyboard controller style in communication with the board management controller, the keyboard controller style configured to pass the private key from the basic input output system to the board management controller.

3 . The information handling system of claim 1 wherein the specific number of transactions of the basic input output system is a programmable number of transactions.

4 . The information handling system of claim 1 wherein the board management controller provides accessibility to the host mapped GPIO for a specific amount of time when the private key is authenticated.

5 . The information handling system of claim 4 wherein the specific amount of time is a programmable amount of time.

6 . The information handling system of claim 1 wherein the board management controller provides accessibility to the host mapped GPIO until the basic input output system explicitly locks the host mapped GPIO.

7 . The information handling system of claim 1 wherein the plurality of registers is locked upon an end of a power-on self-test of the system.

8 . An information handling system comprising:

a shared memory;

a host processor in communication with the shared memory, the host processor including a basic input output system;

a board management controller separate from the host processor and in communication with the shared memory, the board management controller configured to control write accessibility of the shared memory based on a private key received from the basic input output system requesting write accessibility of the shared memory, wherein the private key is based on the system service tag;

a cryptography engine in communication with the board management controller, the cryptography engine configured to authenticate the private key received from the board management controller; and

wherein the board management controller is further configured to provide the write ability to the shared memory for a specific number of transactions of the basic input output system when the private key is authenticated.

9 . The information handling system of claim 8 further comprising:

a keyboard controller style in communication with the board management controller, the keyboard controller style configured to pass the private key from the basic input output system to the board management controller.

10 . The information handling system of claim 8 wherein the specific number of transactions of the basic input output system is a programmable number of transactions.

11 . The information handling system of claim 8 wherein the board management controller provides the write ability to the shared memory for a specific amount of time when the private key is authenticated.

12 . The information handling system of claim 11 wherein the specific amount of time is a programmable amount of time.

13 . The information handling system of claim 8 wherein the board management controller provides the write ability to the shared memory until the basic input output system explicitly write protects the shared memory.

14 . The information handling system of claim 8 wherein the plurality of registers is locked upon an end of a power-on self-test of the system.

15 . The information handling system of claim 8 wherein the shared memory is write-protected upon an end of a power-on self-test.

16 . An information handling system comprising:

a host mapped general purpose input output (GPIO) including a plurality of registers, wherein a first register includes a system service tag associated with the information handling system;

a host processor in communication with the host mapped GPIO, the host processor including a basic input output system;

a board management controller separate from the host processor and in communication with the host mapped GPIO, the board management controller configured to operate as a proxy for the basic input output system, and to change an input/output state of one of the plurality of registers of the host mapped GPIO based on a state change from the basic input output system and when a private key from the basic input output system is authenticated, wherein the private key is based on the system service tag; and

a cryptography engine in communication with the board management controller, the cryptography engine configured to authenticate the private key received from the board management controller.

17 . The information handling system of claim 16 further comprising:

a keyboard controller style in communication with the board management controller, the keyboard controller style configured to pass the private key, the state change request from the basic input output system to the board management controller.

18 . The information handling system of claim 16 wherein the plurality of registers is locked upon an end of a power-on self-test of the system.

19 . An information handling system comprising:

a shared memory;

a host processor in communication with the shared memory, the host processor including a basic input output system;

a board management controller separate from the host processor and in communication with the shared memory, the board management controller configured to operate as a proxy for the basic input output system, and to write data to the shared memory based on a write request received from the basic input output system and when a private key from the basic input output system is authenticated, wherein the private key is based on the system service tag; and

a cryptography engine in communication with the board management controller, the cryptography engine configured to authenticate the private key received from the board management controller.

20 . The information handling system of claim 19 further comprising:

a keyboard controller style in communication with the board management controller, the keyboard controller style configured to pass the private key, the state change request, and the write request from the basic input output system to the board management controller.

Assignments (6)
RELEASE OF SECURITY INTEREST OF REEL 032809 FRAME 0930 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040045/0255 →
RELEASE OF REEL 032810 FRAME 0206 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0204 →
RELEASE OF REEL 032809 FRAME 0887 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040017/0314 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 032809/0930 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032809/0887 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 032810/0206 →