IP Library Granted Patent US 9,672,362
Granted Patent B2
US 9,672,362 · App. 14/328,946 · Granted Jun 6, 2017

Systems and methods for secure delivery of public keys for operating system drivers

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,672,362
App. No.
14/328,946
Granted
Jun 6, 2017
Kind
B2
Abstract

In accordance with these and other embodiments of the present disclosure, an information handling system may include a processor and a basic input/output system (BIOS) comprising a program of instructions executable by the processor and configured to cause the processor to initialize one or more information handling resources of the information handling system. The BIOS may be further configured to authenticate a signature of a BIOS driver associated with an information handling resource of the information handling system, and, in response to authenticating the signature of the BIOS driver, extracting a vendor public key from the BIOS driver and storing the vendor public key to a key database of the BIOS, wherein the vendor public key may be used by an operating system to authenticate one or more signed operating system drivers signed with a private key corresponding to the vendor public key.

Claims (37)

1. An information handling system comprising:

a processor; and

a basic input/output system (BIOS) comprising a program of processor-executable BIOS instructions that, when executed, cause the processor to:

initialize one or more information handling resources of the information handling system; and

perform extended BIOS operations, comprising:

receiving a BIOS driver update, comprising an update of a BIOS driver configured to provide an interface between the BIOS and hardware or firmware of an information handling resource of the information handling system;

authenticating a signature of the BIOS driver update;

extracting a vendor public key from the BIOS driver update and storing the vendor public key to a key database of the BIOS; and

authenticating, in accordance with the vendor public key, a signed operating system driver, distinct from the BIOS driver and the BIOS driver update.

2. The information handling system of claim 1 , wherein the BIOS comprises a Unified Extensible Firmware Interface (UEFI).

3. The information handling system of claim 2 , wherein the BIOS driver update includes information, compliant with an Extensible Firmware Interface (EFI) adapter protocol, to determine presence of the vendor public key and to retrieve the public key from the BIOS driver.

4. The information handling system of claim 1 , wherein the BIOS driver, the BIOS driver update, and the signed operating system driver are all provided by a particular vendor and wherein the vendor public key comprises a public key of the particular vendor.

5. The information handling system of claim 1 , wherein a firmware management protocol (FMP) portion of the BIOS driver includes a public key index indicative of a location of the vendor public key within the BIOS driver.

6. The information handling system of claim 5 , wherein extracting the vendor public key comprises invoking a get image function of the BIOS in accordance with the public key index.

7. The information handling system of claim 1 , wherein extracting the vendor public key comprises extracting the vendor public key from a tail of the BIOS driver update in accordance with a predetermined size of the public key.

8. The information handling system of claim 1 , wherein the BIOS driver update includes processor-executable code for writing the vendor public key to the key database of the BIOS.

9. A method comprising:

initializing one or more information handling resources of an information handling system;

receiving a basic input/output system (BIOS) driver update, comprising an update of a BIOS update configured to provide an interface between the BIOS and hardware or firmware of an information handling resource of the information handling system;

authenticating a signature of the BIOS driver update;

extracting a vendor public key from the BIOS driver update; and

authenticating, in accordance with the vendor public key, a signed operating system driver, distinct from the BIOS driver and the BIOS driver update.

10. The method of claim 9 , wherein the BIOS comprises a Unified Extensible Firmware Interface (UEFI).

11. The method of claim 10 , wherein the BIOS driver update includes information, compliant with an Extensible Firmware Interface (EFI) adapter protocol, to determine presence of the vendor public key and to retrieve the public key from the BIOS driver.

12. The method of claim 9 , wherein the BIOS driver, the BIOS driver update, and the signed operating system driver are all provided by a particular vendor and wherein the vendor public key comprises a public key of the particular vendor.

13. The method of claim 9 , wherein a firmware management protocol (FMP) portion of the BIOS driver includes a public key index indicative of a location of the vendor public key within BIOS driver.

14. The method of claim 13 , wherein extracting the vendor public key comprises invoking a get image function of the BIOS in accordance with the public key index.

15. The method of claim 9 , wherein extracting the vendor public key comprises extracting the vendor public key from a tail of the BIOS driver update in accordance with a predetermined size of the public key.

16. The method of claim 9 , wherein the BIOS driver update includes processor-executable code for writing the vendor public key to the key database of the BIOS.

17. An article of manufacture comprising a non-transitory computer readable medium including processor-executable instructions that, when read and executed by the processor, causing the processor to perform operations comprising:

receiving a basic input/output system (BIOS) driver update, comprising an update of a BIOS driver configured to provide an interface between a BIOS of an information handling system and hardware or firmware of an information handling resource of the information handling system;

authenticating a signature of the BIOS driver update;

extracting a vendor public key from the BIOS driver update and; and

authenticating, in accordance with the vendor public key, a signed operating system driver, distinct from the BIOS driver and the BIOS driver update.

18. The article of claim 17 , wherein the BIOS comprises a Unified Extensible Firmware Interface (UEFI).

19. The article of claim 17 , wherein the BIOS driver, the BIOS driver update, and the signed operating system driver are all provided by a particular vendor and wherein the vendor public key comprises a public key of the particular vendor.

20. The article of claim 17 , wherein a firmware management protocol (FMP) portion of the BIOS driver includes a public key index indicative of a location of the vendor public key within BIOS driver and further wherein extracting the vendor public key comprises invoking a get image function of the BIOS in accordance with the public key index.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 033625 FRAME 0688 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0757 →
RELEASE OF REEL 033625 FRAME 0748 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0050 →
RELEASE OF REEL 033625 FRAME 0711 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040016/0903 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 033625/0748 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033625/0711 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 033625/0688 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2014
From: BUTCHER, ANDREW; KHATRI, MUKUND P.
To: DELL PRODUCTS L.P.
Reel/Frame 033294/0914 →