IP Library Granted Patent US 9,521,153
Granted Patent B2
US 9,521,153 · App. 14/461,474 · Granted Dec 13, 2016

Platform trust extension

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,521,153
App. No.
14/461,474
Granted
Dec 13, 2016
Kind
B2
Abstract

A system and method of providing a platform trust extension for an information handling system is disclosed herein. The platform trust extension receives a notification that an application is selected for installation or execution on an information handling system. The identify of the application or the source of the application is identified based upon a signature of the application. The platform trust extension determines whether the application or the source of the application is semi-trusted based upon the signature of the application. If the application is semi-trusted, the platform trust extension permits the application to run at an additional trust level.

Claims (64)

1. An information handling system comprising:

one or more processors; and

a memory coupled to the processors comprising instructions executable by the processors, the processors being operable when executing the instructions to:

present a list of one or more applications installed at the information handling system;

present a list of one or more applications available to be installed at the information handling system;

present an application source associated with each of the list of one or more applications installed and the list of one or more applications available to be installed;

enumerate one or more semi-trusted keys used to sign each of the list of one or more applications installed and the list of one or more applications available to be installed;

present a key source associated with each of the one or more semi-trusted keys; and

by a platform trust extension:

defining an additional trust level, wherein the additional trust level is granted a subset of permissions granted to the platform trust extension;

maintaining the one or more semi-trusted keys;

receiving a notification that at least one application from the list of one or more applications available to be installed or the list of one or more applications installed is selected for installation or execution on the information handling system;

identifying the at least one application or the application source of the at least one application based, at least in part, on a signature of the at least one application;

determining whether the at least one application or the application source of the at least one application is semi-trusted based at least in part upon the signature of the at least one application, wherein at least one of the one or more semi-trusted keys is used to sign the at least one application;

setting the at least one application to run at the additional trust level if the at least one application or the application source of the at least one application and the at least one of the one or more semi-trusted keys are semi-trusted; and

adding the one or more semi-trusted keys to a data store associated with the platform trust extension.

2. The information handling system of claim 1 , wherein determining whether the at least one application or the application source is semi-trusted comprises comparing the identity of the at least one application or the application source against a list of semi-trusted applications or semi-trusted sources of applications, wherein finding a match indicates that the at least one application or the application source is semi-trusted.

3. The information handling system of claim 2 , wherein the list of semi-trusted applications or semi-trusted sources of applications is received from a user of the information handling system.

4. The information handling system of claim 2 , wherein the list of semi-trusted applications or semi-trusted sources of applications is received from an organization that owns or controls the information handling system.

5. The information handling system of claim 1 , wherein determining whether the at least one application is semi-trusted comprises comparing the at least one of the one or more semi-trusted keys used to sign the at least one application to a key associated with a platform trust extension provider, wherein finding a match indicates that the at least one application is semi-trusted.

6. The information handling system of claim 1 , wherein determining whether the at least one application is semi-trusted comprises comparing the at least one of the one or more semi-trusted keys used to sign the at least one application to a list of semi-trusted keys received from a provider of the platform trust extension, wherein finding a match indicates that the application is semi-trusted.

7. The information handling system of claim 6 , wherein the list of semi-trusted keys is a file stored on the information handling system.

8. The information handling system of claim 6 , wherein the list of semi-trusted keys is received from a cloud service.

9. One or more computer-readable non-transitory storage media embodying logic that is operable when executed to:

present a list of one or more applications installed at the information handling system;

present a list of one or more applications available to be installed at the information handling system;

present an application source associated with each of the list of one or more applications installed and the list of one or more applications available to be installed;

enumerate one or more semi-trusted keys used to sign each of the list of one or more applications installed and the list of one or more applications available to be installed;

present a key source associated with each of the one or more semi-trusted keys; and

by a platform trust extension:

defining an additional trust level, wherein the additional trust level is granted a subset of permissions granted to the platform trust extension;

maintaining the one or more semi-trusted keys;

receiving a notification that at least one application from the list of one or more applications available to be installed or the list of one or more applications installed is selected for installation or execution on an information handling system;

identifying the at least one application or the application source of the at least one application based, at least in part, on a signature of the at least one application;

determining whether the at least one application or the application source of the at least one application is semi-trusted based at least in part upon the signature of the at least one application, wherein at least one of the one or more semi-trusted keys is used to sign the at least one application;

setting the at least one application to run at the additional trust level if the at least one application or the application source of the at least one application and the at least one of the one or more semi-trusted keys are semi-trusted; and

adding the one or more semi-trusted keys to a data store associated with the platform trust extension.

10. The one or more computer-readable non-transitory storage media of claim 9 , wherein determining whether the at least one application or the application source is semi-trusted comprises comparing the identity of the at least one application or the application source against a list of semi-trusted applications or semi-trusted sources of applications, wherein finding a match indicates that the at least one application or the application source is semi-trusted.

11. The one or more computer-readable non-transitory storage media of claim 10 , wherein the list of semi-trusted applications or semi-trusted sources of applications is received from a user of the information handling system.

12. The one or more computer-readable non-transitory storage media of claim 10 , wherein the list of semi-trusted applications or semi-trusted sources of applications is received from an organization that owns or controls the information handling system.

13. The one or more computer-readable non-transitory storage media of claim 9 , wherein determining whether the at least one application is semi-trusted comprises comparing the at least one of the one or more semi-trusted keys used to sign the at least one application to a key associated with a platform trust extension provider, wherein finding a match indicates that the at least one application is semi-trusted.

14. The one or more computer-readable non-transitory storage media of claim 9 , wherein determining whether the at least one application is semi-trusted comprises comparing the at least one of the one or more semi-trusted keys used to sign the at least one application to a list of semi-trusted keys received from a provider of the platform trust extension, wherein finding a match indicates that the application is semi-trusted.

15. The one or more computer-readable non-transitory storage media of claim 14 , wherein the list of semi-trusted keys is a file stored on the information handling system.

16. The one or more computer-readable non-transitory storage media of claim 14 , wherein the list of semi-trusted keys is received from a cloud service.

17. A method of providing platform trust extension comprising:

presenting a list of one or more applications installed at the information handling system;

presenting a list of one or more applications available to be installed at the information handling system;

presenting an application source associated with each of the list of one or more applications installed and the list of one or more applications available to be installed;

enumerating one or more semi-trusted keys used to sign each of the list of one or more applications installed and the list of one or more applications available to be installed;

presenting a key source associated with each of the one or more semi-trusted keys; and

by a platform trust extension:

defining an additional trust level, wherein the additional trust level is granted a subset of permissions granted to the platform trust extension;

maintaining the one or more semi-trusted keys;

receiving a notification that at least one application from the list of one or more applications available to be installed or the list of one or more applications installed is selected for installation or execution on an information handling system;

identifying the at least one application or the application source of the at least one application based, at least in part, upon on a signature of the at least one application;

determining whether the at least one application or the application source of the at least one application is semi-trusted based at least in part upon the signature of the at least one application, wherein at least one of the one or more semi-trusted keys is used to sign the at least one application; and

setting the at least one application to run at the additional trust level if the at least one application or the application source of the at least one application and the at least one of the one or more semi-trusted keys are semi-trusted; and

adding the one or more semi-trusted keys to a data store associated with the platform trust extension.

18. The method of claim 17 , wherein the step of determining whether the at least one application or the application source of the application is semi-trusted comprises:

comparing the identity of the at least one application or the application source against a list of semi-trusted applications or semi-trusted sources of applications, wherein finding a match indicates that the at least one application or the application source is semi-trusted.

19. The method of claim 17 , wherein the step determining whether the application is semi-trusted comprises:

comparing the at least one of the one or more semi-trusted keys used to sign the at least one application to a key associated with a platform trust extension provider, wherein finding a match indicates that the at least one application is semi-trusted.

20. The method of claim 17 , wherein the step of determining whether the at least one application is semi-trusted comprises:

comparing the at least one of the one or more semi-trusted keys used to sign the at least one application to a list of semi-trusted keys received from a provider of the platform trust extension, wherein finding a match indicates that the application is semi-trusted.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 034590 FRAME 0731 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0070 →
RELEASE OF REEL 034591 FRAME 0391 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0719 →
RELEASE OF REEL 034590 FRAME 0696 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040016/0964 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 034590/0731 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 034591/0391 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 034590/0696 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2014
From: GROSSKOPF, GABRIEL JAKOBUS
To: DELL PRODUCTS L.P.
Reel/Frame 033551/0329 →