IP Library Granted Patent US 10,742,427
Granted Patent B2
US 10,742,427 · App. 15/814,476 · Granted Aug 11, 2020

Tamper-proof secure storage with recovery

Inventors: Charles D. Robison (Buford, GA); Carlton A. Andrews (Austin, TX); Girish S. Dhoble (Austin, TX); Joseph Kozlowski (Hutto, TX); Andrew T. Fausak (Coppell, TX); David Konetski (Austin, TX); Ricardo L. Martinez (Leander, TX)
Assignee: Dell Products, L.P.
H04L9/3268H04L9/0825H04L9/0891H04L9/0894H04L9/0897H04L63/0442
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,742,427
App. No.
15/814,476
Granted
Aug 11, 2020
Kind
B2
Abstract

Systems and methods for tamper-proof detection triggering of automatic lockdown using a recoverable encryption mechanism issued from a secure escrow service. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include: a processor; a secure storage device coupled to the processor, wherein the secure storage device comprises a container encrypted with a derived container key; and a memory coupled to the processor, the memory including program instructions stored thereon that, upon execution, cause the IHS to: receive a digital certificate from a remote server, wherein the digital certificate includes a public key and, in response to a detection of a tampering event, encrypt the derived container key using the public key.

Claims (46)

1. An Information Handling System (IHS), comprising:

a processor;

a secure storage device coupled to the processor, wherein the secure storage device comprises a container encrypted with a derived container key; and

a memory coupled to the processor, the memory including program instructions stored thereon that, upon execution, cause the IHS to:

receive a digital certificate from a remote server, wherein the digital certificate includes a public key; and

in response to a detection of a tampering event with regard to the IHS, encrypt the derived container key using the public key received from the remote server.

2. The IHS of claim 1 , further comprising a sensor coupled to the processor, the sensor configured to detect the tampering event under control of a Basic Input/Output System (BIOS) and independently of the operation of any Operating System (OS) in execution by the IHS.

3. The IHS of claim 1 , wherein the sensor comprises one or more of: a current sensor, a voltage sensor, a movement sensor, a pressure sensor, a microphone, a temperature sensor, or an optical sensor.

4. The IHS of claim 1 , wherein the sensor comprises a biometric sensor.

5. The IHS of claim 1 , wherein the tampering event is triggered by another remote server distinct from the IHS.

6. The IHS of claim 1 , wherein the tampering event is triggered in response to the other remote server receiving IHS usage data and identifying a pattern indicative of tampering in the IHS usage data.

7. The IHS of claim 6 , wherein the IHS usage data includes mechanical shock events.

8. The IHS of claim 6 , wherein the IHS usage data indicates a geo-fence violation.

9. The IHS of claim 1 , wherein the program instructions, upon execution, cause the IHS to:

receive a tamper policy setting from a user of the IHS;

determine that a type of the tampering event matches a selected type included in the tamper policy setting; and

take an action corresponding to the selected type.

10. The IHS of claim 1 , wherein the action includes electronically notifying the user or an administrator of the tampering event.

11. The IHS of claim 1 , wherein the program instructions, upon execution, cause the IHS to:

establish a secure communication channel with the remote server;

transmit the public key-encrypted derived container key to the remote server; and

receive a decrypted derived container key from the remote server in response to the remote server decrypting the public key-encrypted derived container key using a private key associated with the digital certificate.

12. The IHS of claim 11 , wherein the program instructions, upon execution, cause the IHS to:

restore access to the secure storage by replacing the public key-encrypted derived container key with the decrypted derived container key.

13. A hardware memory device having program instructions stored thereon that, upon execution by an Information Handling System (IHS), cause the IHS to:

receive a digital certificate from a remote server, wherein the digital certificate includes a public key; and

in response to a detection of a tampering event with regard to the IHS, encrypt a derived container key using the public key received from the remote server, wherein the derived container key is used to encrypt a container of a secure storage device.

14. The hardware memory device of claim 13 , wherein the program instructions, upon execution by an Information Handling System (IHS), cause the IHS to:

detect the tampering event using a sensor comprises one or more of: a current sensors, a voltage sensor, a movement sensor, a pressure sensor, a microphone, a temperature sensor, an optical sensor, or a biometric sensor.

15. The hardware memory device of claim 13 , wherein the tampering event is triggered by another remote server distinct from the IHS.

16. The hardware memory device of claim 13 , wherein the tampering event is triggered in response to the other remote server receiving IHS usage data and identifying a pattern indicative of tampering in the IHS usage data.

17. The hardware memory device of claim 13 , wherein the program instructions, upon execution, cause the IHS to:

establish a secure communication channel with the remote server;

transmit the public key-encrypted derived container key to the remote server;

receive a decrypted derived container key from the remote server in response to the remote server decrypting the public key-encrypted derived container key using a private key associated with the digital certificate; and

restore access to the secure storage by replacing the public key-encrypted derived container key with the decrypted derived container key.

18. A method, comprising:

receiving a digital certificate from a remote server, wherein the digital certificate includes a public key; and

in response to a detection of a tampering event with regard to the IHS, encrypting a derived container key using the public key received from the remote server, wherein the derived container key is used to encrypt a container of a secure storage device.

19. The method of claim 18 , further comprising:

detecting the tampering event using a sensor comprises one or more of: a current sensors, a voltage sensor, a movement sensor, a pressure sensor, a microphone, a temperature sensor, an optical sensor, or a biometric sensor.

20. The method of claim 18 , further comprising:

establishing a secure communication channel with the remote server;

transmitting the public key-encrypted derived container key to the remote server;

receiving a decrypted derived container key from the remote server in response to the remote server decrypting the public key-encrypted derived container key using a private key associated with the digital certificate; and

restoring access to the secure storage by replacing the public key-encrypted derived container key with the decrypted derived container key.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 061749/0924 →
RELEASE OF SECURITY INTEREST AT REEL 045482 FRAME 0395 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0314 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2017
From: ROBISON, CHARLES D.; ANDREWS, CARLTON A.; DHOBLE, GIRISH S.; KOZLOWSKI, JOSEPH; FAUSAK, ANDREW T.; KONETSKI, DAVID; MARTINEZ, RICARDO L.
To: DELL PRODUCTS, L.P.
Reel/Frame 044158/0168 →
Continuity (1)
Related Publication 20190149341A1 · May 16, 2019