IP Library Granted Patent US 10,262,158
Granted Patent B1
US 10,262,158 · App. 15/661,397 · Granted Apr 16, 2019

Restricting the use of a firmware tool to a specific platform

Inventors: Stefano Righi (Lawrenceville, GA); Paul Anthony Rhea (Lawrenceville, GA)
Assignee: American Megatrends, Inc.
G06F21/629H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,262,158
App. No.
15/661,397
Granted
Apr 16, 2019
Kind
B1
Abstract

A firmware includes a firmware module for copying a digitally signed binary file that includes a firmware globally unique identifier (GUID), tool GUIDs, and feature GUIDs to an Advanced Configuration and Power Management interface (ACPI) table (the Firmware Enabled Tool Registry (FETR) table). If the FETR table is stored in memory, a firmware tool determines whether a digital signature of the signed binary file can be verified. If the digital signature can be verified, the firmware tool determines if the firmware GUID stored in the FETR table matches a firmware GUID stored in another ACPI table. If the firmware GUIDs match, the firmware tool determines whether its tool GUID matches a tool GUID stored in the FETR table. The firmware tool can continue to execute if the tool GUIDs match. Firmware tool features are enabled if feature GUIDs in the FETR table match feature GUIDs of the firmware tool.

Claims (58)

1. A computer-implemented method, comprising:

receiving a request at a computing system to execute a firmware tool;

responsive to the request, determining if a first Advanced Configuration and Power Interface (ACPI) table is stored in a memory of the computing system;

responsive to determining that the first ACPI table is stored in a memory of the computing system,

reading a first firmware globally unique identifier (GUID), one or more first firmware tool GUIDs, and one or more first feature GUIDs from the first ACPI table, and

verifying a digital signature associated with the first firmware GUID, the one or more first firmware tool GUIDs, and the one or more first feature GUIDs;

responsive to verifying the digital signature,

reading a second firmware GUID from a second ACPI table stored in the memory of the computing system, and

determining if the first firmware GUID is the same as the second firmware GUID;

responsive to determining that the first firmware GUID is the same as the second firmware GUID, determining if a second firmware tool GUID is the same as at least one of the one or more first firmware tool GUIDs; and

enabling execution of the firmware tool responsive to determining that the second firmware tool GUID is the same as at least one of the one or more first firmware tool GUIDs, wherein the at least one of the one or more first firmware tool GUIDs is associated with the firmware tool.

2. The computer-implemented method of claim 1 , further comprising:

determining whether a second feature GUID is the same as at least one of the one or more first feature GUIDs; and

responsive to determining that the second feature GUID is the same as at least one of the one or more first feature GUIDs, enabling a feature of the firmware tool associated with the second feature GUID.

3. The computer-implemented method of claim 2 , further comprising disabling the feature of the firmware tool associated with the second feature GUID responsive to determining that the second feature GUID is not the same as at least one of the one or more first feature GUIDs.

4. The computer-implemented method of claim 1 , further comprising blocking execution of the firmware tool responsive to determining that the first ACPI table is not stored in the memory of the computing system.

5. The computer-implemented method of claim 1 , further comprising blocking execution of the firmware tool responsive to determining that the digital signature is not verified.

6. The computer-implemented method of claim 1 , further comprising blocking execution of the firmware tool responsive to determining that the first firmware GUID is not the same as the second firmware GUID.

7. The computer-implemented method of claim 1 , further comprising blocking execution of the firmware tool responsive to determining that the second firmware tool GUID is not the same as at least one of the one or more first firmware tool GUIDs.

8. A non-transitory computer-readable storage medium storing computer-executable instructions which, when executed by a computer, cause the computer to:

receive a request at a computing system to execute a firmware tool;

responsive to the request, determine if a first Advanced Configuration and Power Interface (ACPI) table is stored in a memory of the computing system;

responsive to determining that the first ACPI table is stored in a memory of the computing system,

read a first firmware globally unique identifier (GUID), one or more first firmware tool GUIDs, and one or more first feature GUIDs from the first ACPI table, and

verify a digital signature associated with the first firmware GUID, the one or more first firmware tool GUIDs, and the one or more first feature GUIDs;

responsive to verifying the digital signature,

read a second firmware GUID from a second ACPI table stored in the memory of the computing system, and

determine if the first firmware GUID is the same as the second firmware GUID;

responsive to determining that the first firmware GUID is the same as the second firmware GUID, determine if a second firmware tool GUID is the same as at least one of the one or more first firmware tool GUIDs; and

enable execution of the firmware tool responsive to determining that the second firmware tool GUID is the same as at least one of the one or more first firmware tool GUIDs, wherein the at least one of the one or more first firmware tool GUIDs is associated with the firmware tool.

9. The non-transitory computer-readable storage medium of claim 8 storing further computer-executable instructions:

determine whether a second feature GUID is the same as at least one of the one or more first feature GUIDs; and

responsive to determining that the second feature GUID is the same as at least one of the one or more first feature GUIDs, enable a feature of the firmware tool associated with the second feature GUID.

10. The non-transitory computer-readable storage medium of claim 9 storing further computer-executable instructions to disable the feature of the firmware tool associated with the second feature GUID responsive to determining that the second feature GUID is not the same as at least one of the one or more first feature GUIDs.

11. The non-transitory computer-readable storage medium of claim 8 storing further computer-executable instructions to block execution of the firmware tool responsive to determining that the first ACPI table is not stored in the memory of the computing system.

12. The non-transitory computer-readable storage medium of claim 8 storing further computer-executable instructions to block execution of the firmware tool responsive to determining that the digital signature is not verified.

13. The non-transitory computer-readable storage medium of claim 8 storing further computer-executable instructions to block execution of the firmware tool responsive to determining that the first firmware GUID is not the same as the second firmware GUID.

14. The non-transitory computer-readable storage medium of claim 8 , storing further computer-executable instructions to block execution of the firmware tool responsive to determining that the second firmware tool GUID is not the same as at least one of the one or more first firmware tool GUIDs.

15. A system, comprising:

one or more processors; and

at least one non-transitory computer-readable storage medium storing computer-executable instructions which, when executed by the one or more processors, cause the system to:

receive a request at a computing system to execute a firmware tool;

responsive to the request, determine if a first Advanced Configuration and Power Interface (ACPI) table is stored in a memory of the computing system;

responsive to determining that the first ACPI table is stored in a memory of the computing system,

read a first firmware globally unique identifier (GUID), one or more first firmware tool GUIDs, and one or more first feature GUIDs from the first ACPI table, and

verify a digital signature associated with the first firmware GUID, the one or more first firmware tool GUIDs, and the one or more first feature GUIDs;

responsive to verifying the digital signature,

read a second firmware GUID from a second ACPI table stored in the memory of the computing system, and

determine if the first firmware GUID is the same as the second firmware GUID;

responsive to determining that the first firmware GUID is the same as the second firmware GUID, determine if a second firmware tool GUID is the same as at least one of the one or more first firmware tool GUIDs; and

enable execution of the firmware tool responsive to determining that the second firmware tool GUID is the same as at least one of the one or more first firmware tool GUIDs, wherein the at least one of the one or more first firmware tool GUIDs is associated with the firmware tool.

16. The system of claim 15 , wherein the at least one non-transitory computer-readable storage medium stores further computer-executable instructions to:

determine whether a second feature GUID is the same as at least one of the one or more first feature GUIDs; and

responsive to determining that the second feature GUID is the same as at least one of the one or more first feature GUIDs, enable a feature of the firmware tool associated with the second feature GUID.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the at least one non-transitory computer-readable storage medium stores further computer-executable instructions to disable the feature of the firmware tool associated with the second feature GUID responsive to determining that the second feature GUID is not the same as at least one of the one or more first feature GUIDs.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the at least one non-transitory computer-readable storage medium stores further computer-executable instructions to block execution of the firmware tool responsive to determining that the first ACPI table is not stored in the memory of the computing system.

19. The non-transitory computer-readable storage medium of claim 15 , wherein the at least one non-transitory computer-readable storage medium stores further computer-executable instructions to block execution of the firmware tool responsive to determining that the digital signature is not verified.

20. The non-transitory computer-readable storage medium of claim 15 , wherein the at least one non-transitory computer-readable storage medium stores further computer-executable instructions to block execution of the firmware tool responsive to determining that the first firmware GUID is not the same as the second firmware GUID or in response to determining that the second firmware tool GUID is not the same as at least one of the one or more first firmware tool GUIDs.

Assignments (5)
PATENT SECURITY AGREEMENT Recorded Oct 23, 2024
From: AMERICAN MEGATRENDS INTERNATIONAL, LLC
To: BAIN CAPITAL CREDIT, LP, AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 069229/0834 →
RELEASE OF SECURITY INTEREST Recorded Oct 17, 2024
From: MIDCAP FINANCIAL TRUST
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 069205/0795 →
SECURITY INTEREST Recorded May 6, 2019
From: AMERICAN MEGATRENDS INTERNATIONAL, LLC
To: MIDCAP FINANCIAL TRUST, AS COLLATERAL AGENT
Reel/Frame 049087/0266 →
ENTITY CONVERSION Recorded Apr 15, 2019
From: AMERICAN MEGATRENDS, INC.
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 049091/0973 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2017
From: RIGHI, STEFANO; RHEA, PAUL ANTHONY
To: AMERICAN MEGATRENDS, INC.
Reel/Frame 043449/0409 →