IP Library Granted Patent US 9,524,390
Granted Patent B2
US 9,524,390 · App. 14/481,111 · Granted Dec 20, 2016

Method for authenticating firmware volume and system therefor

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,524,390
App. No.
14/481,111
Granted
Dec 20, 2016
Kind
B2
Abstract

A first firmware volume of a Unified Extensible Firmware Interface (UEFI) compliant information handling system is accessed. Authentication information is retrieved from the first firmware volume using a UEFI Secure Architecture Protocol. Based on the authentication information, it is determined if the first firmware volume is a first type of firmware volume. If the first firmware volume is the first type of firmware volume, the first firmware volume is authenticated using the first authentication information and an authentication procedure other than Secure Boot authentication. If the first firmware volume is a second type of firmware volume, the second type different than the first type, the first firmware volume is authenticated using the first authentication information and the Secure Boot authentication.

Claims (48)

1. A method comprising:

accessing a first firmware volume of a Unified Extensible Firmware Interface (UEFI) compliant information handling system;

retrieving, using a computer, authentication information from the first firmware volume using a UEFI Secure Architecture Protocol (SAP);

determining, based on the authentication information, if the first firmware volume is a first type of firmware volume;

if the first firmware volume is the first type of firmware volume, then authenticating the first firmware volume using the first authentication information and an authentication procedure other than Secure Boot authentication; and

if the first firmware volume is a second type of firmware volume, the second type different than the first type, then authenticating the first firmware volume using the first authentication information and the Secure Boot authentication.

2. The method of claim 1 , wherein the first type of firmware volume is a firmware volume provided by an original equipment manufacturer (OEM) of the information handling system.

3. The method of claim 1 , wherein the second type of firmware volume is a firmware volume provided by an original design manufacture (ODM), the ODM associated with a component of the information handling system.

4. The method of claim 1 , further comprising:

executing a plurality of images at the first firmware volume, without conducting further authentication of the images, in response to successful authentication of the first firmware volume.

5. The method of claim 1 , wherein a section at the first firmware volume includes a proprietary secure architecture policy and the authentication information, the policy accessed using the SAP.

6. The method of claim 5 , wherein the proprietary secure architecture policy identifies a subset of images included at the first firmware volume, the subset including a plurality of images, the subset of images authenticated using only one Secure Boot certificate.

7. The method of claim 1 , wherein prior to retrieving the authentication information, a UEFI platform initialization process is not aware of whether the first firmware volume is the first type of firmware volume.

8. A method comprising:

determining, using a Unified Extensible Firmware Interface (UEFI) Secure Architecture Protocol (SAP), that a first firmware volume is provided by an original equipment manufacturer (OEM) of an information handling system;

authenticating the first firmware volume using a computer and a first authentication procedure, the first authentication procedure other than Secure Boot authentication;

determining, using the UEFI SAP, that a second firmware volume is provided by an original design manufacture (ODM), the ODM associated with a component of the information handling system; and

authenticating the second firmware volume using Secure Boot authentication.

9. The method of claim 8 , wherein authenticating the first firmware volume comprises:

retrieving first authentication information from the first firmware volume using the UEFI SAP;

authenticating the first firmware volume using the first authentication information; and

executing a plurality of images included at the first firmware volume, without performing further authentication of the images, in response to determining that the authenticating was successful.

10. The method of claim 8 , wherein authenticating the second firmware volume comprises:

retrieving a Secure Boot certificate from the second firmware volume using the UEFI SAP;

authenticating the second firmware volume using the Secure Boot certificate; and

executing a plurality of images included at the second firmware volume without performing further authentication of the images.

11. The method of claim 8 , wherein authenticating the second firmware volume comprises:

retrieving authentication information from the second firmware volume using the UEFI SAP;

failing to authenticate the second firmware volume using the first authentication procedure; and

determining that the second firmware volume is not an OEM firmware volume based on the failing to authenticate.

12. The method of claim 8 , wherein a section at the first firmware volume includes a proprietary secure architecture policy and the first authentication information, the policy accessed using the UEFI SAP.

13. An information handling system comprising:

a Unified Extensible Firmware Interface (UEFI) compliant basic input-output system (BIOS);

a data storage device for storing a first firmware volume and a second firmware volume; and

a processor to:

access the first firmware volume;

retrieve authentication information from the first firmware volume using a UEFI Secure Architecture Protocol (SAP); and

classify the first firmware volume as one of two distinct types of firmware volumes based on the authentication information, the two distinct types including a first type and a second type.

14. The information handling system of claim 13 , wherein:

if the first firmware volume is the first type of firmware volume, the processor is further to authenticate the first firmware volume using the authentication information and an authentication procedure other than Secure Boot authentication; and

if the first firmware volume is the second type of firmware volume, the processor is further to authenticate the first firmware volume using the authentication information and Secure Boot authentication.

15. The information handling system of claim 13 , wherein a first type of firmware volume is a firmware volume provided by an original equipment manufacturer (OEM) of the information handling system.

16. The information handling system of claim 13 , wherein the second type of firmware volume is a firmware volume provided by an original design manufacture (ODM), the ODM associated with a component of the information handling system.

17. The information handling system of claim 13 , wherein the processor is further to:

execute a plurality of images at the first firmware volume, without conducting further authentication of the images, in response to successful authentication of the first firmware volume.

18. The information handling system of claim 13 , wherein a section at the first firmware volume includes a proprietary secure architecture policy and the authentication information, the policy accessed using the SAP.

19. The information handling system of claim 18 , wherein the proprietary secure architecture policy identifies a subset of images included at the first firmware volume, the subset including a plurality of images, the subset of images authenticated using only one Secure Boot certificate.

20. The information handling system of claim 13 , wherein prior to retrieving the authentication information, a UEFI platform initialization process is not aware of whether the first firmware volume is the first type of firmware volume or the second type of firmware volume.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF REEL 034590 FRAME 0731 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0070 →
RELEASE OF REEL 034591 FRAME 0391 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0719 →
RELEASE OF REEL 034590 FRAME 0696 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040016/0964 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 034591/0391 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 034590/0696 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 034590/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2014
From: KULKARNI, YOGESH P.; DASAR, SUNDAR; VIDYADHARA, SUMANTH
To: DELL PRODUCTS, LP
Reel/Frame 033811/0312 →