IP Library Granted Patent US 9,558,354
Granted Patent B2
US 9,558,354 · App. 14/551,745 · Granted Jan 31, 2017

Method for generating and executing encrypted BIOS firmware and system therefor

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,558,354
App. No.
14/551,745
Granted
Jan 31, 2017
Kind
B2
Abstract

A firmware image is received at an information handling system. A symmetric key is generated and stored at a trusted platform module (TPM). The firmware image is encrypted using the symmetric key. The encrypted firmware image is stored in a non-volatile memory.

Claims (55)

1. A method comprising:

receiving an unencrypted firmware image at system memory at an information handling system;

generating a symmetric key;

storing the symmetric key at a trusted platform module (TPM);

encrypting a first portion of the unencrypted firmware image using the symmetric key to provide an encrypted firmware image the first portion including instructions executed during a Driver Execution Environment (DXE) phase of a platform innovation framework for extensible firmware interface (EFI) boot sequence; and

storing the encrypted firmware image in a non-volatile memory.

2. The method of claim 1 , further comprising storing the symmetric key sealed to a first TPM platform configuration register (PCR) state corresponding to a pre-extensible firmware interface (PEI) phase of the platform innovation framework for EFI boot sequence.

3. The method of claim 1 , further comprising storing the symmetric key during a pre-extensible firmware interface (PEI) phase of the platform innovation framework for EFI boot sequence.

4. The method of claim 1 , wherein a second portion of the encrypted firmware image that is to be executed during a pre-extensible firmware interface (PEI) phase of the platform innovation framework for EFI boot sequence is not encrypted.

5. The method of claim 1 , further comprising initiating a system boot at the information handling system after receiving the unencrypted firmware image and before generating the symmetric key.

6. The method of claim 1 , wherein receiving the firmware image further comprises:

storing the unencrypted firmware image at a system memory;

setting a firmware update flag;

initiating a boot process at the information handling system; and

determining the firmware update flag is set.

7. The method of claim 1 , further comprising encrypting the unencrypted firmware image during the DXE phase of the platform innovation framework for EFI boot sequence.

8. The method of claim 1 , wherein generating the symmetric key further comprises:

storing the symmetric key at a system memory; and

deleting the symmetric key from the system memory after encrypting the firmware image.

9. The method of claim 1 , further comprising:

retrieving the symmetric key from the TPM;

retrieving the encrypted firmware image from the non-volatile memory; and

decrypting the first portion of the encrypted firmware image using the symmetric key.

10. The method of claim 9 , wherein retrieving the symmetric key further comprises un-sealing the symmetric key at the TPM based on a current TPM platform configuration register (PCR) state corresponding to a pre-extensible firmware interface (PEI) phase of the platform innovation framework for EFI boot sequence.

11. A method comprising:

initializing a trusted platform module (TPM) and system memory at an information handling system;

retrieving a symmetric key from the TPM during a pre-extensible firmware interface (PEI) phase of a platform innovation framework for extensible firmware interface (EFI) boot sequence;

retrieving an encrypted firmware image from a non-volatile memory, wherein a first portion of the encrypted firmware image that includes instructions executed during a Driver Execution Environment (DXE) phase of the platform innovation framework for EFI boot sequence is encrypted, and wherein a second portion of the encrypted firmware image that is to be executed during a pre-extensible firmware interface (PEI) phase of the platform innovation framework for EFI boot sequence is not encrypted;

decrypting the first portion of the encrypted firmware image using the symmetric key to provide a decrypted firmware image;

decompressing the decrypted firmware image;

measuring the decompressed firmware image to a TPM platform configuration register (PCR) during the PEI phase of the platform innovation framework for EFI boot sequence; and

executing the decompressed firmware image to complete booting of the information handling system.

12. The method of claim 11 , wherein retrieving the symmetric key further comprises un-sealing the symmetric key based on a current PCR state corresponding to the PEI phase of the platform innovation framework for EFI boot sequence.

13. The method of claim 11 , wherein retrieving the symmetric key further comprises:

storing the symmetric key in a system memory; and

clearing the symmetric key from the system memory after the decrypting.

14. An information handling system comprising:

a trusted platform module (TPM)

a system memory;

a non-volatile memory; and

a processor coupled to the TPM and the non-volatile memory, the processor configured to execute instructions to:

receive an unencrypted firmware image at the information handling system;

generate a symmetric key;

store the symmetric key at the TPM;

encrypt a first portion of the unencrypted firmware image using the symmetric key to provide an encrypted firmware image, wherein the first portion includes instructions executed during a Driver Execution Environment (DXE) phase of a platform innovation framework for extensible firmware interface (EFI) boot sequence, and a second portion of the encrypted firmware image that is to be executed during a pre-extensible firmware interface (PEI) phase of the platform innovation framework for EFI boot sequence is not encrypted; and

store the encrypted firmware image in the non-volatile memory.

15. The information handling system of claim 14 , wherein the processor is further to store the symmetric key sealed to a first TPM platform configuration register (PCR) state corresponding to the PEI phase of the platform innovation framework for EFI boot sequence.

16. The information handling system of claim 14 , wherein the processor is further to store the symmetric key during the PEI phase of the platform innovation framework for EFI boot sequence.

17. The information handling system of claim 14 , wherein the processor is further to initiate a system boot at the information handling system after receiving the unencrypted firmware image and before generating the symmetric key.

18. The information handling system of claim 14 , wherein the processor is further to encrypt the unencrypted firmware image during the DXE phase of the platform innovation framework for EFI boot sequence.

19. The information handling system of claim 14 , wherein the processor is further to:

retrieve the symmetric key from the TPM;

retrieve the encrypted firmware image from the non-volatile memory; and

decrypt the first portion of the encrypted firmware image using the symmetric key.

20. The information handling system of claim 19 , wherein retrieving the symmetric key further comprises un-sealing the symmetric key at the TPM based on a current TPM platform configuration register (PCR) state corresponding to the PEI phase of the platform innovation framework for EFI boot sequence.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 035103 FRAME 0809 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0934 →
RELEASE OF REEL 035104 FRAME 0043 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0123 →
RELEASE OF REEL 035103 FRAME 0536 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040016/0864 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2015
From: MARTINEZ, RICARDO L.
To: DELL PRODUCTS, LP
Reel/Frame 035192/0412 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035104/0043 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035103/0809 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035103/0536 →