IP Library Granted Patent US 9,563,773
Granted Patent B2
US 9,563,773 · App. 14/190,465 · Granted Feb 7, 2017

Systems and methods for securing BIOS variables

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,563,773
App. No.
14/190,465
Granted
Feb 7, 2017
Kind
B2
Abstract

In accordance with embodiments of the present disclosure, a method may include generating a master cryptographic key for encrypting and decrypting the one or more variables stored in a non-transitory computer-readable medium accessible to a basic input/output system of an information handling system. The method may also include encrypting the master cryptographic key with a system password, such that the master cryptographic key as encrypted with the system password may be decrypted and used to encrypt and decrypt the one or more variables in response to entry by a user of the system password. The method may further include encrypting the master cryptographic key with an administrator password, such that the master cryptographic key as encrypted with the administrator password may be decrypted and used to encrypt and decrypt the one or more variables in response to entry by an administrator of the administrator password.

Claims (73)

1. An information handling system, comprising:

a processor;

a basic input/output system comprising a first program of instructions executable by the processor and configured to cause the processor to initialize one or more information handling resources of the information handling system;

a non-transitory computer readable medium accessible by the basic input/output system configured to store one or more variables; and

an encryption module comprising a second program of instructions executable by the processor and configured to cause the processor to:

receive a new password;

in response to receipt of the new password, determine if the new password is a system password or an administrator password;

if the new password is the system password:

determine whether an administrator password is active on the information handling system;

in response to determining that the administrator password is not active:

generate a master cryptographic key for encrypting and decrypting the one or more variables;

encrypt or decrypt the one or more variables with the master cryptographic key; and

encrypt the master cryptographic key based on the system password; and

in response to determining that the administrator password is active:

retrieve the master cryptographic key as encrypted by the administrator password;

decrypt the master cryptographic key with the administrator password; and

encrypt the master cryptographic key with the system password; and

if the new password is an administrator password:

determine whether the system password is active on the information handling system;

in response to determining that the system password is not active:

generate the master cryptographic key for encrypting and decrypting the one or more variables; and

encrypt the master cryptographic key based on the administrator password; and

in response to determining that the system password is active:

retrieve the master cryptographic key as encrypted by the system password;

decrypt the master cryptographic key with the system password; and

encrypt the master cryptographic key with the administrator password.

2. A method comprising:

receiving a new password;

in response to receipt of the new password, determining if the new password is a system password or an administrator password;

if the new password is the system password:

determining whether an administrator password is active on an information handling system;

in response to determining that the administrator password is not active:

generating a master cryptographic key for encrypting and decrypting one or more variables of a basic input/output system;

encrypting or decrypting the one or more variables with the master cryptographic key; and

encrypting the master cryptographic key based on the system password; and

in response to determining that the administrator password is active:

retrieving the master cryptographic key as encrypted by the administrator password;

decrypting the master cryptographic key with the administrator password; and

encrypting the master cryptographic key with the system password; and

if the new password is an administrator password:

determining whether the system password is active on the information handling system;

in response to determining that the system password is not active:

generating the master cryptographic key for encrypting and decrypting the one or more variables; and

encrypting the master cryptographic key based on the administrator password; and

in response to determining that the system password is active:

retrieving the master cryptographic key as encrypted by the system password;

decrypting the master cryptographic key with the system password; and

encrypting the master cryptographic key with the administrator password.

3. An article of manufacture, comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

receive a new password;

in response to receipt of the new password, determine if the new password is a system password or an administrator password;

if the new password is the system password:

determine whether an administrator password is active on an information handling system;

in response to determining that the administrator password is not active:

generate a master cryptographic key for encrypting and decrypting one or more variables of a basic input/output system;

encrypt or decrypt the one or more variables with the master cryptographic key; and

encrypt the master cryptographic key based on the system password; and

and

in response to determining that the administrator password is active:

retrieve the master cryptographic key as encrypted by the administrator password;

decrypt the master cryptographic key with the administrator password; and

encrypt the master cryptographic key with the system password; and

if the new password is an administrator password:

determine whether the system password is active on the information handling system;

in response to determining that the system password is not active:

generate the master cryptographic key for encrypting and decrypting the one or more variables; and

encrypt the master cryptographic key based on the administrator password; and

in response to determining that the system password is active:

retrieve the master cryptographic key as encrypted by the system password;

decrypt the master cryptographic key with the system password; and

encrypt the master cryptographic key with the administrator password.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 032810 FRAME 0038 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040027/0686 →
RELEASE OF REEL 032809 FRAME 0987 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040026/0953 →
RELEASE OF REEL 032810 FRAME 0023 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040014/0320 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 032810/0038 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032810/0023 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 032809/0987 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2014
From: BARKELEW, JONATHAN BRET; TONRY, RICHARD M.; HUDGINS, GREGORY S.
To: DELL PRODUCTS L.P.
Reel/Frame 032301/0941 →