IP Library Granted Patent US 10,133,637
Granted Patent B2
US 10,133,637 · App. 15/228,656 · Granted Nov 20, 2018

Systems and methods for secure recovery of host system code

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,133,637
App. No.
15/228,656
Granted
Nov 20, 2018
Kind
B2
Abstract

A management controller may be configured to control connectivity among a host system processor, a primary ROM, and a recovery ROM in accordance with a plurality of modes of operation including at least a normal mode that occurs in response to absence of a corruption of the ROM code in which the management controller causes the host system processor to be communicatively coupled to the primary ROM and communicatively decoupled from the recovery ROM, such that the host system processor loads and executes the ROM code during boot of the host system, and a primary ROM recovery mode that occurs in response to presence of the corruption of the ROM code in which the management controller causes the host system processor to be coupled to the primary ROM and the recovery ROM, such that the host system processor loads and executes the recovery code during boot of the host system.

Claims (41)

1. An information handling system comprising:

a host system comprising:

a host system processor;

a primary read-only memory (ROM) for storing ROM code for execution by the host system processor; and

a recovery ROM for storing recovery code for execution by the host system processor in an event of corruption of the ROM code; and

a management controller communicatively coupled to the host system processor and configured to provide management of the information handling system via management traffic communicated between the management controller and a dedicated management network external to the information handling system, the management controller further configured to control connectivity among the host system processor, the primary ROM, and the recovery ROM in accordance with a plurality of modes of operation including at least:

a normal mode of operation that occurs in response to absence of a corruption of the ROM code in which the management controller causes the host system processor to be communicatively coupled to the primary ROM and communicatively decoupled from the recovery ROM, such that the host system processor loads and executes the ROM code during boot of the host system;

a primary ROM recovery mode of operation that occurs in response to presence of the corruption of the ROM code in which the management controller causes the host system processor to be communicatively coupled to the primary ROM and the recovery ROM, such that the host system processor loads and executes the recovery code during boot of the host system; and

a recovery ROM update mode in which the management controller causes the host system processor to be communicatively coupled to the primary ROM and communicatively decoupled from the recovery ROM and causes the management controller to be sequentially communicatively coupled to non-transitory computer-readable media having a recovery source image and communicatively coupled to the recovery ROM, such that the management controller updates the recovery ROM based on content of the recovery source image.

2. The information handling system of claim 1 , wherein in the primary ROM recovery mode of operation, the management controller causes the host system processor to be communicatively coupled to the primary ROM and the recovery ROM such that the recovery code executing on the host system processor repairs the corruption of the ROM code.

3. The information handling system of claim 2 , wherein in the primary ROM recovery mode of operation and responsive to a completion of copying of at least the portion of the recovery code to the primary ROM in order to repair the corruption of the ROM code, the management controller causes the host system processor to be communicatively coupled to the primary ROM and communicatively decoupled from the recovery ROM and further causes the host system to reboot, such that the host system processor loads and executes the ROM code during the reboot of the host system.

4. The information handling system of claim 1 , wherein the management controller updates the recovery ROM without accessing the primary ROM.

5. The information handling system of claim 1 , wherein the management controller verifies authenticity of the recovery source image before updating the recovery ROM.

6. The information handling system of claim 1 , wherein the ROM code comprises a basic input/output system.

7. The information handling system of claim 1 , wherein the management controller comprises a baseboard management controller.

8. A method comprising:

controlling connectivity among a host system processor of a host system of an information handling system, a primary read-only memory (ROM) of the host system for storing ROM code for execution by the host system processor, and a recovery ROM of the host system for storing recovery code for execution by the host system processor in an event of corruption of the ROM code, in accordance with a plurality of modes of operation including at least:

a normal mode of operation that occurs in response to absence of a corruption of the ROM code in which the controlling of connectivity causes the host system processor to be communicatively coupled to the primary ROM and communicatively decoupled from the recovery ROM, such that the host system processor loads and executes the ROM code during boot of the host system;

a primary ROM recovery mode of operation that occurs in response to presence of the corruption of the ROM code in which the controlling of connectivity causes the host system processor to be communicatively coupled to the primary ROM and the recovery ROM, such that the host system processor loads and executes the recovery code during boot of the host system; and

a recovery ROM update mode in which the controlling of the connectivity causes the host system processor to be communicatively coupled to the primary ROM and communicatively decoupled from the recovery ROM and causes a management controller communicatively coupled to the host system processor and configured to provide management of the information handling system via management traffic communicated between the management controller and a dedicated management network external to the information handling system to be sequentially communicatively coupled to non-transitory computer-readable media having a recovery source image and communicatively coupled to the recovery ROM, such that the management controller updates the recovery ROM based on content of the recovery source image.

9. The method of claim 8 , wherein in the primary ROM recovery mode of operation, controlling of the connectivity causes the host system processor to be communicatively coupled to the primary ROM and the recovery ROM such that the recovery code executing on the host system processor repairs the corruption of the ROM code.

10. The method of claim 9 , wherein in the primary ROM recovery mode of operation the controlling of the connectivity causes, responsive to a completion of copying of at least the portion of the recovery code to the primary ROM in order to repair the corruption of the ROM code, the host system processor to be communicatively coupled to the primary ROM and communicatively decoupled from the recovery ROM and further causes the host system to reboot, such that the host system processor loads and executes the ROM code during the reboot of the host system.

11. The method of claim 8 , wherein the management controller comprises a baseboard management controller.

12. The method of claim 8 , wherein the management controller updates the recovery ROM without accessing the primary ROM.

13. The method of claim 8 , wherein the management controller verifies authenticity of the recovery source image before updating the recovery ROM.

14. The method of claim 8 , wherein the ROM code comprises a basic input/output system.

15. The method of claim 8 , wherein the controlling of the connectivity is performed by a management controller.

16. An article of manufacture comprising:

a non-transitory computer-readable medium; and

computer-executable instructions carried on the computer-readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

control connectivity among a host system processor of a host system of an information handling system, a primary read-only memory (ROM) of the host system for storing ROM code for execution by the host system processor, and a recovery ROM of the host system for storing recovery code for execution by the host system processor in an event of corruption of the ROM code, in accordance with a plurality of modes of operation including at least:

a normal mode of operation that occurs in response to absence of a corruption of the ROM code in which the controlling of connectivity causes the host system processor to be communicatively coupled to the primary ROM and communicatively decoupled from the recovery ROM, such that the host system processor loads and executes the ROM code during boot of the host system;

a primary ROM recovery mode of operation that occurs in response to presence of the corruption of the ROM code in which the controlling of connectivity causes the host system processor to be communicatively coupled to the primary ROM and the recovery ROM, such that the host system processor loads and executes the recovery code during boot of the host system; and

a recovery ROM update mode in which the controlling of the connectivity causes the host system processor to be communicatively coupled to the primary ROM and communicatively decoupled from the recovery ROM and causes a management controller communicatively coupled to the host system processor and configured to provide management of the information handling system via management traffic communicated between the management controller and a dedicated management network external to the information handling system to be sequentially communicatively coupled to non-transitory computer-readable media having a recovery source image and communicatively coupled to the recovery ROM, such that the management controller updates the recovery ROM based on content of the recovery source image.

17. The article of claim 16 , wherein in the primary ROM recovery mode of operation, controlling of the connectivity causes the host system processor to be communicatively coupled to the primary ROM and the recovery ROM such that the recovery code executing on the host system processor repairs the corruption of the ROM code.

18. The article of claim 17 , wherein in the primary ROM recovery mode of operation the controlling of the connectivity causes, responsive to a completion of copying of at least the portion of the recovery code to the primary ROM in order to repair the corruption of the ROM code, the host system processor to be communicatively coupled to the primary ROM and communicatively decoupled from the recovery ROM and further causes the host system to reboot, such that the host system processor loads and executes the ROM code during the reboot of the host system.

19. The article of claim 16 , wherein the management controller comprises a baseboard management controller.

20. The article of claim 16 , wherein the management controller updates the recovery ROM without accessing the primary ROM.

21. The article of claim 16 , wherein the management controller verifies authenticity of the recovery source image before updating the recovery ROM.

22. The article of claim 16 , wherein the ROM code comprises a basic input/output system.

23. The article of claim 16 , wherein the controlling of the connectivity is performed by a management controller.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040679/0386) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 059803/0666 →
RELEASE OF SECURITY INTEREST AT REEL 048825 FRAME 0489 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058000/0916 →
RELEASE OF SECURITY INTEREST AT REEL 040633 FRAME 0799 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL INTERNATIONAL, L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
Reel/Frame 058297/0427 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Apr 8, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 048825/0489 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Nov 23, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 040679/0386 →
SECURITY INTEREST Recorded Nov 16, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040633/0799 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2016
From: LAMBERT, TIMOTHY M.; RAHARDJO, JOHAN; KHATRI, MUKUND P.
To: DELL PRODUCTS L.P.
Reel/Frame 039346/0231 →