IP Library Granted Patent US 10,148,429
Granted Patent B2
US 10,148,429 · App. 15/342,343 · Granted Dec 4, 2018

System and method for recovery key management

Inventors: Viswanathan Balakrishnan (Bangalore, IN); Santosh Bhadri (Bangalore, IN); Mukund P. Khatri (Austin, TX); Kevin T. Marks (Round Rock, TX); Narayanan Subramaniam (Bangalore, IN); Venkatesan Balakrishnan (Tamil Nadu, IN)
Assignee: Dell Products L.P.
H04L9/0816G06F11/1402G06F21/575H04L9/3223H04L9/3236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,148,429
App. No.
15/342,343
Granted
Dec 4, 2018
Kind
B2
Abstract

A system and method for managing the recovery key of a computer system is disclosed. The computer system includes a security layer, and the recovery key is stored locally to a memory location on the computer system, including, as examples, flash memory on the motherboard of the computer system or a USB port on the computer system. In operation, when it becomes necessary for the computer system to authenticate the recovery key, the recovery key may be retrieved from the local memory. The retrieval and storage of the recovery key may be managed by a remote administrator. The recovery key may be stored in a hidden partition in the storage location, and the recovery key may be cryptographically wrapped to add an additional layer of security.

Claims (40)

1. A method for managing a security layer of a computer system, wherein the computer system includes a security layer that requires authentication of a key, comprising:

identifying a change to a configuration of the computer system;

determining if a configuration change to the computer system has occurred since the last boot based on a hash analysis, wherein the hash analysis compares a first hash code representing a previous hardware or software configuration of the computer system and a second hash code representing a current hardware or software configuration of the computer system;

requesting a new key for authentication of the computer system based on the determination of the configuration change; and

providing the new key through a storage location associated with the computer system, wherein providing the new key comprises receiving a memory mapping command to hide a partition of the storage location comprising the new key.

2. The method for managing the security layer of the computer system of claim 1 , wherein the partition is designated for storage of the new key.

3. The method for managing the security layer of the computer system of claim 1 , wherein the step of providing the new key comprises the step of providing the new key through a remote administrator.

4. The method for managing the security layer of the computer system of claim 1 , wherein the step of providing the new key comprises the step of cryptographically unwrapping the new key before providing the new key for authentication.

5. The method for managing the security layer of the computer system of claim 1 , wherein the storage location is flash memory internal to the computer system.

6. The method for managing the security layer of the computer system of claim 1 , further comprising:

setting a flag indicative of the determination of the configuration change; and

wherein the new key is requested based, at least in part, on the flag.

7. The method for managing the security layer of the computer system of claim 1 , wherein the flag is a BIOS flag.

8. The method for managing the security layer of the computer system of claim 1 , further comprising authenticating the new key.

9. A system for managing a security layer of a computer system, comprising:

at least one processor; and

a non-transitory memory coupled to the at least one processor, wherein the non-transitory memory includes one or more software components that, when executed by the at least one processor, cause the at least one processor to:

identify a change to a configuration of the computer system;

determine if a configuration change to the computer system has occurred since the last boot based on a hash analysis, wherein the hash analysis compares a first hash code representing a previous hardware or software configuration of the computer system and a second hash code representing a current hardware or software configuration of the computer system;

request a new key for authentication of the computer system based on the determination of the configuration change; and

provide the new key through a storage location associated with the computer system, wherein providing the new key comprises receiving a memory mapping command to hide a partition of the storage location comprising the new key.

10. The system for managing a security layer of a computer system of claim 9 , wherein the partition of the storage location is designated for storage of the new key.

11. The system for managing a security layer of a computer system of claim 9 , wherein the step of providing the new key comprises the step of providing the new key through a remote administrator.

12. The system for managing a security layer of a computer system of claim 9 , wherein the step of providing the new key comprises the step of cryptographically unwrapping the new key before providing the new key for authentication.

13. The system for managing a security layer of a computer system of claim 9 , wherein the storage location is flash memory internal to the computer system.

14. The system for managing a security layer of a computer system of claim 9 , wherein the one or more software components further cause the at least one processor to:

set a flag indicative of the determination of the configuration change; and

wherein the new key is requested based, at least in part, on the flag.

15. The system for managing a security layer of a computer system of claim 9 , further comprising authenticating the new key.

16. A non-transitory computer readable medium storing one or more software components that, when executed, cause a processor to:

identify a change to a configuration of the computer system;

determine if a configuration change to the computer system has occurred since the last boot based on a hash analysis, wherein the hash analysis compares a first hash code representing a previous hardware or software configuration of the computer system and a second hash code representing a current hardware or software configuration of the computer system; and

request a new key for authentication of the computer system based on the determination of the configuration change; and

provide the new key through a storage location associated with the computer system, wherein providing the new key comprises receiving a memory mapping command to hide a partition of the storage location comprising the new key.

17. The non-transitory computer-readable medium of claim 16 , the partition of the storage location is designated for storage of the new key.

18. The non-transitory computer-readable medium of claim 16 , wherein the step of providing the new key comprises the step of providing the new key through a remote administrator.

19. The non-transitory computer-readable medium of claim 16 , wherein the step of providing the new key comprises the step of cryptographically unwrapping the new key before providing the new key for authentication.

20. The non-transitory computer-readable medium of claim 16 , wherein the one or more software components, when executed, further cause the processor to:

set a flag indicative of the determination of the configuration change; and

wherein the new key is requested based, at least in part, on the flag.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (041829/0873) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 059803/0724 →
RELEASE OF SECURITY INTEREST AT REEL 041808 FRAME 0516 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL INTERNATIONAL, L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058297/0573 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY INTEREST (NOTES) Recorded Feb 28, 2017
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 041829/0873 →
PATENT SECURITY INTEREST (CREDIT) Recorded Feb 24, 2017
From: DELL INTERNATIONAL, L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 041808/0516 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2016
From: BALAKRISHNAN, VISWANATHAN; BHADRI, SANTOSH; KHATRI, MUKUND P.; MARKS, KEVIN T.; SUBRAMANIAM, NARAYANAN; BALAKRISHNAN, VENKATESAN
To: DELL PRODUCTS L.P.
Reel/Frame 040212/0464 →
Continuity (3)
Continuation 14528758 · Oct 30, 2014
Continuation 12424787 · Apr 16, 2009
Related Publication 20170063539A1 · Mar 2, 2017
Cited By (1)
US 12,475,264