IP Library Granted Patent US 10,489,596
Granted Patent B2
US 10,489,596 · App. 15/452,162 · Granted Nov 26, 2019

Configuring a trusted platform module

Inventors: Andrew J. O'Rourke (Cedar Park, TX); Darin R. Dearwater (Temple, TX); Johan Rahardjo (Austin, TX); Jeffrey R. Azulay (Austin, TX)
Assignee: DELL PRODUCTS, LP
G06F21/575G06F9/4401G06F21/57
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,489,596
App. No.
15/452,162
Granted
Nov 26, 2019
Kind
B2
Abstract

A method includes storing configuration data for a Trusted Platform Module (TPM) in a pre-boot environment such as Unified Extensible Firmware Interface (UEFI), reading the configuration data, and automatically configuring the TPM based upon the configuration data. The configuring includes storing values of TPM parameters in non-volatile memory of the TPM. A method includes UEFI firmware of a circuit board on an assembly line configuring a TPM. An information handling system includes UEFI firmware and a TPM. The UEFI firmware configures the TPM from a configuration file stored in memory of the UEFI firmware.

Claims (44)

1. An information handling system comprising:

a processor;

a Trusted Platform Module (TPM); and

a first non-volatile memory to store Basic Input/Output System (BIOS) firmware and to store data to provision the TPM for operation, wherein execution of the BIOS firmware by the processor includes:

issuing a command to the TPM by a UEFI shell application to provision the TPM for Trusted Execution Technology and Physical Presence interface;

issuing a command to the TPM by the UEFI shell application, the command to generate an endorsement key based on the data; and

issuing another command by the UEFI shell application to the TPM, the other command to store the endorsement key at a second non-volatile memory within the TPM.

2. The information handling system of claim 1 , wherein the provisioning includes a UEFI tool running in the UEFI shell to read the data and to issue the command to generate the endorsement key.

3. The information handling system of claim 1 , wherein the provisioning includes:

resetting the BIOS firmware; and

in response to the resetting, the BIOS firmware reading the data and issuing commands to the TPM based upon the data, the commands including the command to the TPM to generate the endorsement key.

4. The information handling system of claim 1 , further comprising an operating system to issue a command to the TPM to generate an endorsement key.

5. The information handling system of claim 4 , further comprising a TPM base services driver to enable the operating system to issue the command to the TPM to generate the endorsement key.

6. The information handling system of claim 1 , wherein the BIOS firmware includes Unified Extensible Firmware Interface compliant firmware.

7. The information handling system of claim 1 , wherein the data is received from a test system external to the information handling system.

8. A method comprising:

receiving data during the manufacture of an information handling system, the data to provision a Trusted Platform Module (TPM) for operation; and

storing the data in a first non-volatile memory at the information handling system, the first non-volatile memory further to store Basic Input/Output Sytem (BIOS) firmware;

wherein execution of the BIOS firmware includes:

issuing a command to the TPM by a UEFI shell application to provision the TPM for Trusted Execution Technology and Physical Presence interface;

issuing a command to the TPM by the UEFI shell application, the command to generate an endorsement key based on the data; and

issuing a command to the TPM by the UEFI shell application, the command to store the endorsement key at a second non-volatile memory within the TPM.

9. The method of claim 8 , further comprising:

providing a UEFI tool running in the UEFI shell,

the UEFI tool to provision the TPM based upon the data.

10. The method of claim 8 , further comprising an operating system issuing a command to the TPM to generate an endorsement key.

11. The method of claim 10 , further comprising loading a TPM base services driver to enable the operating system to issue the command to the TPM to generate the endorsement key.

12. The method of claim 8 , wherein the BIOS firmware includes Unified Extensible Firmware Interface compliant firmware.

13. The method of claim 8 , wherein the data is received from a test system external to the information handling system.

14. A method comprising:

attaching a golden processor to a circuit board;

attaching a golden memory to the circuit board, wherein the golden processor and the golden memory are used during the provisioning of the TPM and the golden processor and the golden memory are replaced on the circuit board before shipping the information handling system to a customer;

receiving data during the manufacture of an information handling system, the data to provision a Trusted Platform Module (TPM) for operation;

storing the data in a first non-volatile memory of a circuit board on an assembly line of an original equipment manufacturer (OEM) for the manufacture of the information handling system, the first non-volatile memory further to store Basic Input/Output System (BIOS) firmware; and

attaching the TPM to the circuit board;

wherein execution of the BIOS firmware includes:

issuing a command to the TPM, the command to generate an endorsement key based on the data; and

storing the endorsement key at a second non-volatile memory within the TPM.

15. The method of claim 14 , wherein the provisioning includes running the circuit board under a test host.

16. The method of claim 8 , further comprising:

attaching a golden processor to the circuit board; and

attaching a golden memory to the circuit board, wherein the golden processor and golden memory are used during the provisioning of the TPM and the golden processor and golden memory are replaced on the circuit board before shipping the information handling system to the customer.

17. The method of claim 14 , wherein the provisioning comprises provisioning the TPM based upon characteristics of the information handling system pursuant to a policy of the OEM.

18. The method of claim 14 , wherein the BIOS firmware includes Unified Extensible Firmware Interface compliant firmware.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (042769/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 059803/0802 →
RELEASE OF SECURITY INTEREST AT REEL 042768 FRAME 0585 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058297/0536 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY INTEREST (NOTES) Recorded Jun 12, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 042769/0001 →
PATENT SECURITY INTEREST (CREDIT) Recorded Jun 12, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 042768/0585 →