IP Library Granted Patent US 10,296,730
Granted Patent B2
US 10,296,730 · App. 14/461,632 · Granted May 21, 2019

Systems and methods for automatic generation and retrieval of an information handling system password

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,296,730
App. No.
14/461,632
Granted
May 21, 2019
Kind
B2
Abstract

In accordance with embodiments of the present disclosure, an information handling system may include a processor and a basic input/output system (BIOS). The BIOS may comprise a program of instructions executable by the processor and configured to cause the processor to initialize one or more information handling resources of the information handling system. The BIOS may further be configured to, during a boot of an information handling system, and in response to a request to set a password associated with the information handling system, generate a random password, securely store the random password in a memory such that the password may be retrieved during a subsequent boot of the information handling system by a user physically present at the information handling system, and set the random password as the password associated with the information handling system.

Claims (64)

1. An information handling system comprising:

a processor;

a network interface communicatively coupled to the processor and to a network; and

a basic input/output system (BIOS) comprising processor executable BIOS instructions that, when executed, cause the processor to perform BIOS operations including:

initializing one or more information handling resources of the information handling system;

responsive to receiving, from a remote administrator via the network interface, a remote management request for an administrator password for the information handling system, determining whether the administrator password has been set previously;

responsive to determining that the administrator password has been set previously, generating an error message;

responsive to determining that the administrator password has not been previously set, performing password setting operations, comprising:

causing the information handling system to restart;

generating a random character string;

sealing the random character string in cryptoprocessor memory and preserving a cryptoprocessor state as of the sealing, wherein the cryptoprocessor memory is accessible only to a cryptoprocessor of the information handling system wherein the cryptoprocessor state indicates a state of the cryptoprocessor; and

setting the random character string as the administrator password in firmware; and

after the random character string has been set as the administrator password, responding to receiving, during a portion of booting the information handling system prior to booting an operating system, a user request for the administrator password, by performing password revealing operations, comprising:

responsive to determining that an aspect of the user request ensures that a user making the user request is physically present at the information handling system and that a current cryptoprocessor state matches the cryptoprocessor state as of the sealing, unsealing the administrator password from cryptoprocessor memory, storing the administrator password in system memory, and

displaying the administrator password via a user interface display.

2. The information handling system of claim 1 , wherein the aspect of the user request includes at least one of:

the user request is initiated by asserting a particular key of a keyboard associated with the information handling system; and

the user request is initiated by selecting a particular BIOS menu option.

3. The information handling system of claim 1 , wherein the cryptoprocessor memory comprises non-volatile memory.

4. The information handling system of claim 1 , wherein the password revealing operations include:

responsive to an indication from the user, ceasing said displaying of the administrator password.

5. The information handling system of claim 4 , wherein the password revealing operations include:

after ceasing said displaying, causing the information handling system to reset and boot.

6. A method comprising:

responsive to receiving, from a remote administrator via a network interface of an information handling system, a remote management request for an administrator password for the information handling system, determining whether the administrator password has been set previously;

responsive to determining that the administrator password has been set previously, generating an error message;

responsive to determining that the administrator password has not been previously set, performing password setting operations, comprising:

causing the information handling system to restart;

generating a random character string;

sealing the random character string in cryptoprocessor memory and preserving a cryptoprocessor state as of the sealing, wherein the cryptoprocessor memory is accessible only to a cryptoprocessor of the information handling system wherein the cryptoprocessor state indicates a state of the cryptoprocessor; and

setting the random character string as the administrator password in firmware; and

after the random character string has been set as the administrator password, responding to receiving, during a portion of booting the information handling system prior to booting an operating system, a user request for the administrator password, by performing password revealing operations, comprising:

responsive to determining that an aspect of the user

request ensures that a user making the user request is physically present at the information handling system and that a current cryptoprocessor state matches the cryptoprocessor state as of the sealing, unsealing the administrator password from cryptoprocessor memory, storing the administrator password in system memory, and displaying the administrator password via a user interface display.

7. The method of claim 6 , further comprising:

ceasing the displaying of the administrator password; and

erasing the administrator password from a memory of the information handling system.

8. The method of claim 7 , wherein the cryptoprocessor memory comprises non-volatile memory.

9. The method of claim 6 , wherein the remote management request comprises a simple network management protocol (SNMP) compliant command.

10. The method of claim 6 , wherein determining whether the user is physically present includes at least one of:

detecting assertion of a particular key of a keyboard of the information handling system; and

detecting a user response to a BIOS prompt.

11. The method of claim 6 , wherein the cryptoprocessor is configured to generate encryption keys, generate and maintain hash key tables of hardware and software components of the information handling system, generate and maintain configuration parameters associated with hardware and software components of the information handling system.

12. An article of manufacture comprising:

a non-transitory computer readable medium including processor-executable basic input/output system (BIOS) instructions that, when executed by a processor of an information handling system, cause the processor to perform operations comprising:

responsive to receiving, from a remote administrator via a network interface of the information handling system, a remote management request for an administrator password for the information handling system, determining whether the administrator password has been set previously;

responsive to determining that the administrator password has been set previously, generating an error message;

responsive to determining that the administrator password has not been previously set, performing password setting operations, comprising:

causing the information handling system to restart;

generating a random character string;

sealing the random character string in cryptoprocessor memory and preserving a cryptoprocessor state as of the sealing, wherein the cryptoprocessor memory is accessible only to a cryptoprocessor of the information handling system wherein the cryptoprocessor state indicates a state of the cryptoprocessor; and

setting the random character string as the administrator password in firmware; and

after the random character string has been set as the administrator password, responding to receiving, during a portion of booting the information handling system prior to booting an operating system, a user request for the administrator password, by performing password revealing operations, comprising:

responsive to determining that an aspect of the user request ensures that a user making the user request is physically present at the information handling system and that a current cryptoprocessor state matches the cryptoprocessor state as of the sealing, unsealing the administrator password from cryptoprocessor memory, storing the administrator password in system memory, and displaying the administrator password via a user interface display.

13. The article of manufacture of claim 12 , wherein the operations include:

ceasing the displaying of the administrator password; and

erasing the administrator password from a memory of the information handling system.

14. The article of manufacture of claim 13 , wherein the remote management request comprises a simple network management protocol (SNMP) compliant command.

15. The article of manufacture of claim 12 , wherein ensuring the user is physically present includes at least one of:

detecting assertion of a particular key of a keyboard connected to the information handling system; and

detecting selection of a particular BIOS menu option.

16. The article of manufacture of claim 15 , wherein the cryptoprocessor is configured to generate encryption keys, generate and maintain hash key tables of hardware and software components of the information handling system, and generate and maintain configuration parameters associated with hardware and software components of the information handling system.

17. The article of manufacture of claim 16 , wherein the operations include:

after ceasing said displaying, re-booting the information handling system.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 034591 FRAME 0391 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0719 →
RELEASE OF REEL 034590 FRAME 0731 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0070 →
RELEASE OF REEL 034590 FRAME 0696 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040016/0964 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 034591/0391 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 034590/0731 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 034590/0696 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2014
From: GILLESPIE, KURT D.; MARTINEZ, RICARDO L.; GOPAL, JANARDAN RAJAGOPAL PRADEEP; CHAN, RICHARD
To: DELL PRODUCTS L.P.
Reel/Frame 033552/0815 →