IP Library Granted Patent US 9,317,691
Granted Patent B2
US 9,317,691 · App. 14/273,173 · Granted Apr 19, 2016

Pre-boot software verification

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,317,691
App. No.
14/273,173
Granted
Apr 19, 2016
Kind
B2
Abstract

Methods and systems for implementing pre-boot software verification may involve using an embedded controller (EC) and a basic input/output system (BIOS) to confirm each other's firmware using hash values. The hash values may be generated from certain portions of the firmware, which may overlap and may be specific to a particular firmware version.

Claims (60)

1. A method, comprising:

sending, by a basic/input output system (BIOS) firmware included in an information handling system, a first request for a first hash value;

responsive to receiving the first request, computing, by an embedded controller (EC) firmware included in the information handling system, the first hash value;

sending, by the EC firmware, the first hash value to the BIOS firmware;

when the BIOS firmware determines that the first hash value matches a first reference hash value, sending, by the BIOS firmware, a first confirmation to the EC firmware that the first hash value is accepted;

responsive to receiving the first confirmation, sending, by the EC firmware, a second request for a second hash value;

responsive to receiving the second request, computing, by the BIOS firmware, the second hash value;

sending, by the BIOS firmware, the second hash value to the EC firmware; and

when the EC firmware determines that the second hash value matches a second reference hash value, sending, by the EC firmware, a second confirmation to the BIOS firmware that the second hash value is accepted.

2. The method of claim 1 , wherein the first request specifies a first memory range associated with the EC firmware for calculating the first hash value, and wherein the second request specifies a second memory range associated with the BIOS firmware for calculating the second hash value.

3. The method of claim 2 , wherein the first memory range and the second memory range are unique to both a first version of the EC firmware and a second version of the BIOS firmware.

4. The method of claim 2 , further comprising:

repeating sending, by the BIOS firmware, the first request specifying the first memory range, wherein each repeated first request specifies a different value for the first memory range; and

repeating sending, by the EC firmware, the second request specifying the second memory range, wherein each repeated second request specifies a different value for the second memory range.

5. The method of claim 4 , wherein the first memory range specified by a repeated first request overlaps with the first memory range specified by a previous first request, and wherein the second memory range specified by a repeated second request overlaps with the second memory range specified by a previous second request.

6. The method of claim 1 , wherein the first reference hash value is stored in a first file accessible to the BIOS firmware, and wherein the second reference hash value is stored in a second file accessible to the EC firmware.

7. The method of claim 1 , wherein the BIOS firmware is stored in a first non-volatile memory, and wherein the EC firmware is stored in a second non-volatile memory.

8. The method of claim 1 , further comprising:

responsive to receiving the second indication, booting the information handling system.

9. The method of claim 1 , when the BIOS firmware determines that the first hash value does not match the first reference hash value, or when the EC firmware determines that the second hash value does not match the second reference hash value, further comprising:

restricting access to a hardware component included in the information handling system.

10. The method of claim 9 , wherein the hardware component is selected from at least one of:

a network interface controller

a storage controller;

a system bus;

a memory device;

a storage device;

a camera; and

a microphone.

11. An information handling system, comprising:

a processor subsystem having access to a basic/input output system (BIOS) firmware, wherein the BIOS firmware includes first instructions executable by the processor subsystem; and

an embedded controller (EC) including a second processor having access to EC firmware, wherein the EC firmware includes second instructions executable by the second processor, wherein the first instructions and the second instructions are executable to:

send, by the BIOS firmware, a first request for a first hash value;

responsive to receiving the first request, compute, by the EC firmware, the first hash value;

send, by the EC firmware, the first hash value to the BIOS firmware;

when the BIOS firmware determines that the first hash value matches a first reference hash value, send, by the BIOS firmware, a first confirmation to the EC firmware that the first hash value is accepted;

responsive to receiving the first confirmation, send, by the EC firmware, a second request for a second hash value;

responsive to receiving the second request, compute, by the BIOS firmware, the second hash value;

send, by the BIOS firmware, the second hash value to the EC firmware; and

when the EC firmware determines that the second hash value matches a second reference hash value, send, by the EC firmware, a second confirmation to the BIOS firmware that the second hash value is accepted.

12. The information handling system of claim 11 , wherein the first request specifies a first memory range associated with the EC firmware for calculating the first hash value, and wherein the second request specifies a second memory range associated with the BIOS firmware for calculating the second hash value.

13. The information handling system of claim 12 , wherein the first memory range and the second memory range are unique to both a first version of the EC firmware and a second version of the BIOS firmware.

14. The information handling system of claim 12 , wherein the first instructions and the second instructions are further executable to:

repeat sending, by the BIOS firmware, the first request specifying the first memory range, wherein each repeated first request specifies a different value for the first memory range; and

repeat sending, by the EC firmware, the second request specifying the second memory range, wherein each repeated second request specifies a different value for the second memory range.

15. The information handling system of claim 14 , wherein the first memory range specified by a repeated first request overlaps with the first memory range specified by a previous first request, and wherein the second memory range specified by a repeated second request overlaps with the second memory range specified by a previous second request.

16. The information handling system of claim 11 , wherein the first reference hash value is stored in a first file accessible to the BIOS firmware, and wherein the second reference hash value is stored in a second file accessible to the EC firmware.

17. The information handling system of claim 11 , wherein the BIOS firmware is stored in a first non-volatile memory accessible to the processor subsystem, and wherein the EC firmware is stored in a second non-volatile memory accessible to the second processor.

18. The information handling system of claim 11 , further comprising first instructions to:

responsive to receiving the second indication, boot the information handling system.

19. The information handling system of claim 11 , when the BIOS firmware determines that the first hash value does not match the first reference hash value, or when the EC firmware determines that the second hash value does not match the second reference hash value, further comprising first instructions to:

restrict access to a hardware component included in the information handling system.

20. The information handling system of claim 19 , wherein the hardware component is selected from at least one of:

a network interface controller

a storage controller;

a system bus;

a memory device;

a storage device;

a camera; and

a microphone.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 033625 FRAME 0688 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0757 →
RELEASE OF REEL 033625 FRAME 0748 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0050 →
RELEASE OF REEL 033625 FRAME 0711 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040016/0903 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 033625/0748 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033625/0711 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 033625/0688 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2014
From: LOCKE, KEVIN B.
To: DELL PRODUCTS L.P.
Reel/Frame 032853/0101 →