IP Library Granted Patent US 9,639,700
Granted Patent B2
US 9,639,700 · App. 14/663,452 · Granted May 2, 2017

Unified extensible firmware interface (UEFI) database for secure bootstrap of a computer

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,639,700
App. No.
14/663,452
Granted
May 2, 2017
Kind
B2
Abstract

Embodiments of the present invention provide a method, system and computer program product for UEFI firmware database management of keys and certificates during a UEFI secure bootstrap enabled boot of a computer. In an embodiment of the invention, a method for UEFI firmware database management for secure bootstrap of a computer includes initially receiving a request to modify a database in UEFI firmware of an operating computer. Thereafter, an impact of the request is determined in memory of the operating computer in terms of the operability of an accessory driver. As such, a prompt warning of the determined impact is generated in the memory and displayed in a display of the operating computer.

Claims (28)

1. A method for Unified Extensible Firmware Interface (UEFI) firmware database management for secure bootstrap of a computer, the method comprising:

receiving a request to modify a database in UEFI firmware of an operating computer;

determining in memory of the operating computer an impact of the request in terms of the operability of an accessory driver; and,

generating in the memory and displaying in a display of the operating computer a prompt warning of the determined impact.

2. The method of claim 1 , wherein the request comprises a request to enroll a new database in the UEFI firmware.

3. The method of claim 1 , wherein the request comprises a request to remove a database from the UEFI firmware.

4. The method of claim 1 , wherein the impact comprises a new operability of a previously inoperable accessory driver in the operating computer.

5. The method of claim 1 , wherein the impact comprises a new inoperability of a previously operable driver in the operating computer.

6. The method of claim 1 , further comprising processing the request without a re-boot if the impact is that a previously operable accessory driver remains operable, or that a previously inoperable accessory driver remains inoperable, but otherwise generating and displaying an additional prompt to re-boot the operating computer.

7. A computer data processing system comprising Unified Extensible Firmware Interface (UEFI) firmware for database management during secure bootstrap of a computer, the system comprising:

an operating computer comprising memory and at least one processor;

UEFI firmware managing bootstrap of the operating computer;

a multiplicity of databases disposed in the UEFI firmware, selected ones of the databases storing driver data for the UEFI firmware and other ones of the databases storing signing keys for the selected ones of the databases; and

a UEFI database management module executing in memory of the operating computer, the module comprising program code enabled upon execution in the memory of the operating computer to receive a request to modify one of the databases, to determine an impact of the request in terms of the operability of an accessory driver for the operating computer, and to generate and display in the operating computer a prompt warning of the determined impact.

8. The system of claim 7 , wherein the request comprises a request to enroll a new database in the UEFI firmware.

9. The system of claim 7 , wherein the request comprises a request to remove a database from the UEFI firmware.

10. The system of claim 7 , wherein the impact comprises a new operability of a previously inoperable accessory driver in the operating computer.

11. The system of claim 7 , wherein the impact comprises a new inoperability of a previously operable driver in the operating computer.

12. The system of claim 7 , wherein the program code is further enabled to process the request without a re-boot if the impact is that a previously operable accessory driver remains operable, or that a previously inoperable accessory driver remains inoperable, but otherwise to generate and display an additional prompt to re-boot the operating computer.

13. A computer program product for Unified Extensible Firmware Interface (UEFI) firmware database management for secure bootstrap of a computer, the computer program product comprising a computer readable storage memory device having program instructions embodied therewith, the program instructions executable by a device to cause the device to perform a method comprising:

receiving a request to modify a database in UEFI firmware of an operating computer;

determining in memory of the operating computer an impact of the request in terms of the operability of an accessory driver; and,

generating in the memory and displaying in a display of the operating computer a prompt warning of the determined impact.

14. The computer program product of claim 13 , wherein the request comprises a request to enroll a new database in the UEFI firmware.

15. The computer program product of claim 13 , wherein the request comprises a request to remove a database from the UEFI firmware.

16. The computer program product of claim 13 , wherein the impact comprises a new operability of a previously inoperable accessory driver in the operating computer.

17. The computer program product of claim 13 , wherein the impact comprises a new inoperability of a previously operable driver in the operating computer.

18. The computer program product of claim 13 , wherein the method further comprises processing the request without a re-boot if the impact is that a previously operable accessory driver remains operable, or that a previously inoperable accessory driver remains inoperable, but otherwise generating and displaying an additional prompt to re-boot the operating computer.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2025
From: LENOVO GLOBAL TECHNOLOGIES INTERNATIONAL LIMITED
To: LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
Reel/Frame 069869/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2019
From: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD.
To: LENOVO GLOBAL TECHNOLOGIES INTERNATIONAL LTD
Reel/Frame 050298/0650 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2015
From: CAMPBELL, NATHAN K.; OLIVER, DOUG W.; TANG, WEN WEI
To: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE. LTD.
Reel/Frame 035269/0519 →