IP Library Granted Patent US 9,426,147
Granted Patent B2
US 9,426,147 · App. 14/466,447 · Granted Aug 23, 2016

Protected device management

Inventors: Ned M. Smith (Beaverton, OR); Victoria C. Moore (Phoenix, AZ); Steven L. Grobman (El Dorado Hills, CA)
Assignee: Intel Corporation
H04L63/083G06F21/305G06F21/74G06F21/78G06F21/85H04L9/0894H04L9/321H04L29/06979H04L63/08H04L63/0807G06F2221/2147G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,426,147
App. No.
14/466,447
Granted
Aug 23, 2016
Kind
B2
Abstract

A method, apparatus, system, and computer program product for management of storage devices protected by encryption, user authentication, and password protection and auditing schemes in virtualized and non-virtualized environments.

Claims (29)

1. A computer-implemented method comprising:

authenticating first credentials of a user of a system before access is allowed to any device of a plurality of devices attached to the system;

intercepting an event indicating a hot-plug attachment of a new device to the system, wherein the intercepting is performed by firmware in a secure partition of the system, and the secure partition is isolated from a host operating system of the system;

requesting second credentials to access the new device using the firmware to establish trusted path connections to a display device to display a request for the second credentials and a user input device to receive the second credentials, wherein the second credentials are requested by the firmware without rebooting the system;

authenticating the second credentials;

enabling access to the new device after authenticating the second credentials; and

delivering a hot plug event for the new device from the secure partition to the host operating system.

2. The method of claim 1 , wherein enabling access to the new device comprises using a native command for the device to enable decryption of the new device.

3. The method of claim 1 , wherein the second credentials comprise a password for the new device; and

enabling access to the new device comprises using the password to unlock the new device.

4. The method of claim 1 , wherein the second credentials comprise a user identifier; and

enabling access to the new device comprises providing the user identifier to a trusted third party and enabling access to the new device if the trusted third party authenticates the user identifier.

5. An apparatus comprising: at least one processor;

a secure partition isolated from a host operating system executing on the processor; and

a memory comprising instructions for firmware executing in the secure partition to perform the following:

authenticating first credentials of a user of a system before access is allowed to any device of a plurality of devices attached to the system;

intercepting an event indicating a hot-plug attachment of a new device to the system, wherein the intercepting is performed by the secure partition;

requesting second credentials to access the new device using the firmware to establish trusted path connections to a display device to display a request for the second credentials and a user input device to receive the second credentials, wherein the second credentials are requested by the firmware without rebooting the system;

authenticating the second credentials;

enabling access to the new device after authenticating the second credentials; and

delivering a hot plug event for the new device from the secure partition to the host operating system.

6. A computer program product comprising: a non-transitory computer-readable storage medium; and

instructions in the computer-readable storage medium, wherein the instructions, when executed in a secure partition of a processing system, cause firmware executing in the secure partition to perform operations comprising:

authenticating first credentials of a user of a system before access is allowed to any device of a plurality of devices attached to the system;

intercepting an event indicating a hot-plug attachment of a new device to the system, wherein the intercepting is performed by the secure partition, and the secure partition is isolated from a host operating system of the system;

requesting second credentials to access the new device using the firmware to establish trusted path connections to a display device to display a request for the second credentials and a user input device to receive the second credentials, wherein the second credentials are requested by the firmware without rebooting the system;

authenticating the second credentials;

enabling access to the new device after authenticating the second credentials; and

delivering a hot plug event for the new device from the secure partition to the host operating system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2023
From: INTEL CORPORATION
To: SK HYNIX NAND PRODUCT SOLUTIONS CORP.
Reel/Frame 062702/0048 →
Continuity (2)
Division 12653796 · Dec 21, 2009
Related Publication 20140366116A1 · Dec 11, 2014