IP Library Granted Patent US 10,395,039
Granted Patent B2
US 10,395,039 · App. 15/262,236 · Granted Aug 27, 2019

Customer-owned trust of device firmware

Inventors: Mukund P. Khatri (Austin, TX); Bill C. Munger (Round Rock, TX)
Assignee: Dell Products, L.P.
G06F21/575H04L9/3247H04L9/3263G06F9/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,395,039
App. No.
15/262,236
Granted
Aug 27, 2019
Kind
B2
Abstract

Systems and methods for providing and verifying customer-owned trust of device firmware are described. In some embodiments, an Information Handling System (IHS), may include a processor and a Basic Input/Output System (BIOS) coupled to the processor, the BIOS having program instructions stored thereon that, upon execution, cause the IHS to: receive, from a user, selection of a pre-boot code module; export a digest of the pre-boot code module to the user; and import the digest signed by the user.

Claims (54)

1. An Information Handling System (IHS), comprising:

a processor; and

a Basic Input/Output System (BIOS) coupled to the processor, the BIOS having program instructions stored thereon that, upon execution, cause the IHS to:

receive, from a user during a boot process, selection of a pre-boot code module;

export, during the boot process, a digest of the pre-boot code module to the user;

import, during the boot process, a signed digest signed by the user;

store a public key or certificate usable to authenticate the signed digest in a primary database (db) of a Secure Boot policy, wherein the primary database (db) does not allow storage of the signed digest;

store the signed digest in a secondary database (db2) of the Secure Boot policy, wherein the secondary database is distinct from a revoked signature database (dbx) of the Secure Boot policy; and

in response to the pre-boot code module failing Secure Boot verification during a subsequent booting of the IHS:

calculate a digest for the pre-boot code module;

search the secondary database (db2) of the Secure Boot policy for a digest matching the calculated digest;

in response to finding the matching digest in the secondary database (db2), verify the signature of the matching digest against one or more public keys or certificates stored in the primary database (db) of the Secure Boot policy; and

in response to verification of the signature of the matching digest, load the pre-boot code module.

2. The IHS of claim 1 , wherein the pre-boot code module includes an input/output (I/O) device firmware.

3. The IHS of claim 1 , wherein the pre-boot code module includes an Operating System (OS) boot loader.

4. The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to provide a list of pre-boot code modules to the user prior to receiving the selection from the user.

5. The IHS of claim 1 , wherein the receiving, exporting, and importing operations are performed via a baseboard management controller (BMC).

6. The IHS of claim 1 , wherein the selection includes other pre-boot code modules, wherein exporting the digest includes exporting a distinct digest for each of the selected pre-boot code modules, and wherein importing the digest includes importing each of the distinct digests signed with a same or a different key.

7. The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to allow the user to remove the Certificate Authority (CA)-issued public key or certificate corresponding to the selected pre-boot code module from the primary database (db).

8. The IHS of claim 1 , wherein the pre-boot code module is selected indirectly as part of an operation initiated by the user to trust a current IHS configuration.

9. The IHS of claim 8 , wherein the current IHS configuration includes additional pre-boot code modules.

10. The IHS of claim 8 , wherein the program instructions, upon execution, further cause the IHS to:

remove digests from the primary database (db) of the Secure Boot policy for pre-boot code modules previously trusted as part of a previous IHS configuration;

calculate digests for pre-boot code modules part of the current IHS configuration; and

store the calculated digests in the primary database (db) of the Secure Boot policy.

11. The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to:

receive, from the user, selection of another pre-boot code module; and

add a digest of the another pre-boot code module to the revoked signature database (dbx) of the Secure Boot policy.

12. A Basic I/O System (BIOS) having program instructions stored thereon that, upon execution by a processor of an Information Handling System (IHS), cause the IHS to:

provide, during a boot process, a list of pre-boot code modules to a user;

receive, from the user during the boot process, selection of a pre-boot code module;

export, during the boot process, a digest of the pre-boot code module to the user;

import, during the boot process, a digest signed by the user;

store, during the boot process, a public key or certificate usable to authenticate the signed digest in a primary database (db) of the Secure Boot policy, wherein the primary database (db) does not allow storage of the signed digest;

store, during the boot process, the signed digest in a secondary database (db2) of the Secure Boot policy wherein the secondary database (db2) is distinct from a revoked signature database (dbx) of the Secure Boot policy; and

in response to the pre-boot code module failing Secure Boot verification during a subsequent booting of the IHS:

calculate a digest for the pre-boot code module;

search the secondary database (db2) of the Secure Boot policy for a digest matching the calculated digest;

in response to finding the matching digest in the secondary database (db2), verify the signature of the matching digest against one or more public keys or certificates stored in the primary database (db) of the Secure Boot policy; and

in response to verification of the signature of the matching digest, load the pre-boot code module.

13. The BIOS of claim 12 , wherein the pre-boot code module includes an input/output (I/O) device firmware or an Operating System (OS) boot loader.

14. In an Information Handling System (IHS) having a Basic I/O System (BIOS), a method comprising:

providing, during a boot process by the IHS through execution of program instructions stored in the BIOS, a list of pre-boot code modules;

receiving, during the boot process at the IHS through execution of program instructions stored in the BIOS, selection of a pre-boot code module;

exporting, during the boot process by the IHS through execution of program instructions stored in the BIOS, a digest of the pre-boot code module;

importing, during the boot process by the IHS through execution of program instructions stored in the BIOS, the digest signed by the user;

storing, during the boot process by the IHS through execution of program instructions stored in the BIOS, a public key or certificate usable to authenticate the signed digest in a primary database (db) of the Secure Boot policy, wherein the primary database (db) does not allow storage of the signed digest;

storing, during the boot process by the IHS through execution of program instructions stored in the BIOS, the signed digest in a secondary database (db2) of the Secure Boot policy, wherein the secondary database (db2) is distinct from a revoked signature database (dbx) of the Secure Boot policy; and

in response to the pre-boot code module failing Secure Boot verification during a subsequent booting of the IHS:

calculating, by the IHS through execution of program instructions stored in the BIOS, a digest for the pre-boot code module;

searching, by the IHS through execution of program instructions stored in the BIOS, the secondary database (db2) of the Secure Boot policy for a digest matching the calculated digest;

in response to finding the matching digest in the secondary database (db2), verifying, by the IHS through execution of program instructions stored in the BIOS, the signature of the matching digest against one or more public keys or certificates stored in the primary database (db) of the Secure Boot policy; and

in response to verification of the signature of the matching digest, loading, by the IHS through execution of program instructions stored in the BIOS, the pre-boot code module.

15. The method of claim 14 , wherein the pre-boot code module includes an input/output (I/O) device firmware or an Operating System (OS) boot loader.

Assignments (12)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (051302/0528) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.); SECUREWORKS CORP.
Reel/Frame 060438/0593 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040679/0386) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 059803/0666 →
RELEASE OF SECURITY INTEREST AT REEL 040633 FRAME 0799 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL INTERNATIONAL, L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
Reel/Frame 058297/0427 →
RELEASE OF SECURITY INTEREST AT REEL 051449 FRAME 0728 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
Reel/Frame 058002/0010 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Dec 31, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 051449/0728 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 16, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 051302/0528 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Nov 23, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 040679/0386 →
SECURITY INTEREST Recorded Nov 16, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040633/0799 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2016
From: KHATRI, MUKUND P.; MUNGER, BILL C.
To: DELL PRODUCTS, L.P.
Reel/Frame 039698/0950 →
Continuity (1)
Related Publication 20180075242A1 · Mar 15, 2018
Cited By (19)
US 12,306,708 US 12,326,964 US 12,341,764 US 12,348,569 US 12,348,650 US 12,360,851 US 12,425,452 US 12,432,219 US 12,438,713 US 12,450,400 US 12,461,823 US 12,468,553 US 12,470,499 US 12,476,794 US 12,483,568 US 12,507,147 US 12,531,913 US 12,598,213 US 12,632,580