IP Library Granted Patent US 10,013,565
Granted Patent B2
US 10,013,565 · App. 14/462,199 · Granted Jul 3, 2018

System and method for secure transport of data from an operating system to a pre-operating system environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,013,565
App. No.
14/462,199
Granted
Jul 3, 2018
Kind
B2
Abstract

An information handling system includes a trusted platform module (TPM) and a storage device, the TPM provides boot authentication for the information handling system such that, during a pre-boot phase, the TPM can access a platform configuration register (PCR). During a first instance of the pre-boot phase, the information handling system provides a public/private key pair including a public key and a private key, stores the private key to an encrypted storage of the TPM, seals the private key in the encrypted storage to the PCR, and stores the public key to the storage device. During an operating system phase that is after the first instance of the pre-boot phase, the information handling system retrieves the public key from the storage device, encrypts transfer data using the public key, and stores the encrypted transfer data to the storage device.

Claims (97)

1. An information handling system comprising:

a key generator;

a trusted platform module (TPM) operable to provide boot authentication for the information handling system, such that, during a first pre-boot phase, the TPM is operable to provide access to a first platform configuration register (PCR) of the TPM; and

a storage device;

wherein, during a first in time instance of the first pre-boot phase, the information handling system is operable to:

direct the key generator to provide a first public/private key pair including a first public key and a first private key;

store the first private key to an encrypted storage of the TPM, wherein the TPM is operable to provide boot authentication for the information handling system, such that, during the first pre-boot phase, the TPM is operable to provide access to the first PCR;

seal the first private key to the first PCR in the first pre-boot phase; and

store the first public key to the storage device; and

wherein, during an operating system (OS) phase that is after the first in time instance of the first pre-boot phase, the information handling system is further operable to:

retrieve the first public key from the storage device;

encrypt first transfer data using the first public key, wherein the first transfer data is to be securely transported between the OS phase and the first pre-boot phase, wherein the first transfer data including an Advanced Configuration and Power interface (ACPI) table for the information handling system; and

store the encrypted first transfer data to the storage device.

2. The information handling system of claim 1 , wherein further, during a second in time instance of the first pre-boot phase that is after the OS phase, the information handling system is further operable to:

retrieve the first private key sealed to the first PCR from the encrypted storage;

retrieve the encrypted first transfer data from the storage device; and

decrypt the encrypted first transfer data using the first private key.

3. The information handling system of claim 2 , wherein, during the OS phase, the information handling system is further operable to:

encrypt second transfer data using the first public key, wherein the second transfer data is to be securely transported between the OS phase and the first pre-boot phase; and

store the encrypted second transfer data to the storage device.

4. The information handling system of claim 3 , wherein further, during the second in time instance of the first pre-boot phase, the information handling system is further operable to:

retrieve the encrypted second transfer data from the storage device; and

decrypt the encrypted second transfer data using the first private key.

5. The information handling system of claim 1 , wherein:

during a second pre-boot phase, the TPM is operable to provide access to a second PCR of the TPM;

during a first in time instance of the second pre-boot phase that is before the OS phase, the information handling system is further operable to:

provide a second public/private key pair including a second public key and a second private key;

store the second private key to the encrypted storage;

seal the second private key to the second PCR in the second pre-boot phase; and

store the second public key to the storage device; and

during the OS phase, the information handling system is further operable to:

retrieve the second public key from the storage device;

encrypt second transfer data using the second public key, wherein the second transfer data is to be securely transported between the OS phase and the first pre-boot phase; and

store the encrypted second transfer data to the storage device.

6. The information handling system of claim 5 , wherein further, during a second in time instance of the second pre-boot phase that is after the OS phase, the information handling system is further operable to:

retrieve the second private key sealed to the second PCR from the encrypted storage;

retrieve the encrypted second transfer data from the storage device; and

decrypt the encrypted second transfer data using the second private key.

7. The information handling system of claim 1 , wherein the first transfer data comprises network proxy authentication information.

8. A method comprising:

providing, by a key generator of an information handling system and during a first in time instance of a first pre-boot phase for the information handling system a first public/private key pair including a first public key and a first private key;

storing, during the first in time instance of the first pre-boot phase, the first private key to an encrypted storage of a trusted platform module (TPM) of the information handling system;

sealing the first private key to a first platform configuration register (PCR) of the TPM in the first pre-boot phase, wherein the TPM is operable to provide boot authentication for the information handling system, such that, during the first pre-boot phase, the TPM is operable to provide access to the first PCR;

storing, during the first in time instance of the first pre-boot phase, the first public key to a storage device of the information handling system;

retrieving, during an operating system (OS) phase that is after the first in time instance of the first pre-boot phase, the first public key from the storage device;

encrypting, during the OS phase, first transfer data using the first public key, wherein the first transfer data is to be securely transported between the OS phase and the first pre-boot phase, the first transfer data including an Advanced Configuration and Power Interface (ACPI) table for the information handling system; and

storing, during the OS phase, the encrypted first transfer data to the storage device.

9. The method of claim 8 , further comprising:

retrieving, during a second in time instance of the first pre-boot phase that is after the OS phase, the first private key sealed to the first PCR from the encrypted storage;

retrieving, during the second in time instance of the first pre-boot phase, the encrypted first transfer data from the storage device; and

decrypting, during the second in time instance of the first pre-boot phase, the encrypted first transfer data using the first private key.

10. The method of claim 9 , further comprising:

encrypting, during the OS phase, second transfer data using the first public key, wherein the second transfer data is to be securely transported between the OS phase and the first pre-boot phase; and

storing, during the OS phase, the encrypted second transfer data to the storage device.

11. The method of claim 10 , further comprising:

retrieving, during the second in time instance of the first pre-boot phase, the encrypted second transfer data from the storage device; and

decrypting, during the second in time instance of the first pre-boot phase, the encrypted second transfer data using the first private key.

12. The method of claim 8 , further comprising:

providing, by the information handling system and during a first in time instance of a second pre-boot phase for the information handling system that is before the OS phase, a second public/private key pair including a second public key and a second private key;

storing, during the first in time instance of the second pre-boot phase, the second private key to the encrypted storage;

sealing the second private key to a second PCR of the TPM in the second pre-boot phase, wherein the TPM is further operable to provide the boot authentication, such that, during the second pre-boot phase, the TPM is operable to provide access to the second PCR;

storing, during the first in time instance of the second pre-boot phase, the second public key to the storage device; and

retrieving, during the OS phase, the second public key from the storage device;

encrypting, during the OS phase, second transfer data using the second public key, wherein the second transfer data is to be securely transported between the OS phase and the first pre-boot phase; and

storing, during the OS phase, the encrypted second transfer data to the storage device.

13. The method of claim 12 , further comprising:

retrieving, during a second in time instance of the second pre-boot phase that is after the OS phase, the second private key sealed to the second PCR from the encrypted storage;

retrieving, during the second in time instance of the second pre-boot phase, the encrypted second transfer data from the storage device; and

decrypting, during the second in time instance of the first pre-boot phase, the encrypted second transfer data using the second private key.

14. The method of claim 8 , wherein the first transfer date comprises network proxy authentication information.

15. A non-transitory computer-readable medium including code for performing a method, the method comprising:

providing, by a key generator of an information handling system and during a first in time instance of a first pre-boot phase for the information handling system a first public/private key pair including a first public key and a first private key;

storing, during the first in time instance of the first pre-boot phase, the first private key to an encrypted storage of a trusted platform module (TPM) of the information handling system;

sealing the first private key to a first platform configuration register (PCR) of the TPM in the first pre-boot phase, wherein the TPM is operable to provide boot authentication for the information handling system, such that, during the first pre-boot phase, the TPM is operable to provide access to the first PCR;

storing, during the first in time instance of the first pre-boot phase, the first public key to a storage device of the information handling system;

retrieving, during an operating system (OS) phase that is after the first in time instance of the first pre-boot phase, the first public key from the storage device;

encrypting, during the OS phase, first transfer data using the first public key, wherein the first transfer data is to be securely transported between the OS phase and the first pre-boot phase, the first transfer data including a System Management BIOS (SMBIOS) for the information handling system; and

storing, during the OS phase, the encrypted first transfer data to the storage device.

16. The computer-readable medium of claim 15 , the method further comprising:

retrieving, during a second in time instance of the first pre-boot phase that is after the OS phase, the first private key sealed to the first PCR from the encrypted storage;

retrieving, during the second in time instance of the first pre-boot phase, the encrypted first transfer data from the storage device; and

decrypting, during the second in time instance of the first pre-boot phase, the encrypted first transfer data using the first private key.

17. The computer-readable medium of claim 16 , the method further comprising:

encrypting, during the OS phase, second transfer data using the first public key, wherein the second transfer data is to be securely transported between the OS phase and the first pre-boot phase; and

storing, during the OS phase, the encrypted second transfer data to the storage device.

18. The computer-readable medium of claim 17 , the method further comprising:

retrieving, during the second in time instance of the first pre-boot phase, the encrypted second transfer data from the storage device; and

decrypting, during the second in time instance of the first pre-boot phase, the encrypted second transfer data using the first private key.

19. The computer-readable medium of claim 15 , the method further comprising:

providing, by the information handling system and during a first in time instance of a second pre-boot phase for the information handling system that is before the OS phase, a second public/private key pair including a second public key and a second private key;

storing, during the first in time instance of the second pre-boot phase, the second private key to the encrypted storage;

sealing the second private key to a second PCR of the TPM in the second pre-boot phase, wherein the TPM is further operable to provide the boot authentication, such that, during the second pre-boot phase, the TPM is operable to provide access to the second PCR;

storing, during the first in time instance of the second pre-boot phase, the second public key to the storage device; and

retrieving, during the OS phase, the second public key from the storage device;

encrypting, during the OS phase, second transfer data using the second public key, wherein the second transfer data is to be securely transported between the OS phase and the first pre-boot phase; and

storing, during the OS phase, the encrypted second transfer data to the storage device.

20. The computer-readable medium of claim 15 , wherein the first transfer date comprises network proxy authentication information.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 034591 FRAME 0391 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0719 →
RELEASE OF REEL 034590 FRAME 0731 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0070 →
RELEASE OF REEL 034590 FRAME 0696 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040016/0964 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 034591/0391 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 034590/0731 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 034590/0696 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2014
From: MARTINEZ, RICARDO L.; JOSHI, ANAND P.
To: DELL PRODUCTS, LP
Reel/Frame 033811/0246 →