IP Library Granted Patent US 9,418,223
Granted Patent B2
US 9,418,223 · App. 14/258,862 · Granted Aug 16, 2016

System and method for securing embedded controller communications by verifying host system management mode execution

Inventors: Matthew G. Page (Round Rock, TX); Richard M. Tonry (Austin, TX)
Assignee: Dell Products, LP
G06F21/554G06F21/566G06F21/74
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,418,223
App. No.
14/258,862
Granted
Aug 16, 2016
Kind
B2
Abstract

An information handling system includes a processor operable to provide a branch trace message, and an embedded controller coupled to the processor via a primary interface and via a management interface. The embedded controller receives a management transaction from the processor via the primary interface. In response to receiving the management transaction, the embedded controller requests the branch trace message via the management interface and determines if the processor is operating in a system management mode based upon the branch trace message.

Claims (58)

1. An information handling system, comprising:

a processor operable to provide a branch trace message; and

an embedded controller coupled to the processor via a primary interface and via a management interface, wherein the embedded controller is operable to:

receive a management transaction from the processor via the primary interface; and

in response to receiving the management transaction, to:

request, via the management interface, the branch trace message; and

determine if the processor is operating in a system management mode based upon the branch trace message.

2. The information handling system of claim 1 , wherein the embedded controller is further operable to:

execute the management transaction in response to determining that the processor is operating in the system management mode.

3. The information handling system of claim 1 , wherein the embedded controller is further operable to:

drop the management transaction in response to determining that the processor is not operating in the system management mode.

4. The information handling system of claim 1 , further comprising:

a memory including a system management mode memory range;

wherein the embedded controller stores the system management mode memory range.

5. The information handling system of claim 4 , wherein the embedded controller is further operable to receive the system management mode memory range from the processor.

6. The information handling system of claim 4 , wherein in determining if the processor is operating in a system management mode, the embedded controller is further operable to:

determine a memory location of code being executed by the processor from the branch trace message; and

compare the memory location with the system management mode memory range; and

determine if the processor is operating in the system management mode based upon the comparison.

7. The information handling system of claim 6 , wherein the processor is determined to be operating in the system management mode when the memory location is in the system management mode memory range.

8. The information handling system of claim 6 , wherein the processor is determined to not be operating in the system management mode when the memory location is not in the system management mode memory range.

9. The information handling system of claim 1 , wherein:

the embedded controller includes a security mode; and

the embedded controller operates to request the branch trace message and to determine if the processor is operating in the system management mode when the embedded controller is operating in the security mode.

10. A method comprising:

receiving, at an embedded controller of an information handling system, a management transaction from a processor of the information handling system, wherein the embedded controller is coupled to the processor via a primary interface and via a management interface, and the management transaction is received via the primary interface; and

in response to receiving the management transaction, to:

request, via the management interface, a branch trace message; and

determine, by the embedded controller, if the processor is operating in a system management mode based upon the branch trace message.

11. The method of claim 10 , further comprising:

executing, by the embedded controller, the management transaction in response to determining that the processor is operating in the system management mode.

12. The method of claim 10 , further comprising:

dropping, by the embedded controller, the management transaction in response to determining that the processor is not operating in the system management mode.

13. The method of claim 10 , wherein:

the information handling system comprises a memory including a system management mode memory range;

the method further comprising storing, by the embedded controller, the system management mode memory range.

14. The method of claim 13 , further comprising:

receiving, by the embedded controller, the system management mode memo range from the processor.

15. The method of claim 13 , wherein in determining if the processor is operating in a system management mode, the method further comprises:

determining, by the embedded controller, a memory location of code being executed by the processor from the branch trace message; and

comparing the memory location with the system management mode memory range; and

determining if the processor is operating in the system management mode based upon the comparison.

16. The method of claim 10 , wherein:

the embedded controller includes a security mode; and

the embedded controller operates to request the branch trace message and to determine if the processor is operating in the system management mode when the embedded controller is operating in the security mode.

17. A non-transitory computer-readable medium including code for performing a method, the method comprising:

receiving, at an embedded controller of an information handling system, a management transaction from a processor of the information handling system, wherein the embedded controller is coupled to the processor via a primary interface and via a management interface, and the management transaction is received via the primary interface; and

in response to receiving the management transaction:

requesting, via the management interface, a branch trace message; and

determining, by the embedded controller, if the processor is operating in a system management mode based upon the branch trace message.

18. The computer-readable medium of claim 17 , the method further comprising:

executing, by the embedded controller, the management transaction in response to determining that the processor is operating in the system management mode.

19. The computer-readable medium of claim 17 , wherein:

the information handling system comprises a memory including a system management mode memory range;

the method further comprising storing, by the embedded controller, the system management mode memory range.

20. The computer-readable medium of claim 17 , wherein:

the embedded controller includes a security mode; and

the embedded controller operates to request the branch trace message and to determine if the processor is operating in the system management mode when the embedded controller is operating in the security mode.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF REEL 033625 FRAME 0688 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0757 →
RELEASE OF REEL 033625 FRAME 0748 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0050 →
RELEASE OF REEL 033625 FRAME 0711 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040016/0903 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033625/0711 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 033625/0748 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 033625/0688 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2014
From: PAGE, MATTHEW G.; TONRY, RICHARD M.
To: DELL PRODUCTS, LP
Reel/Frame 032923/0732 →
Continuity (1)
Related Publication 20150302199A1 · Oct 22, 2015