IP Library Granted Patent US 10,534,620
Granted Patent B2
US 10,534,620 · App. 15/826,922 · Granted Jan 14, 2020

Systems and methods for establishing core root of trust measurement (CRTM) for basic input/output (BIOS) image recovery

Inventors: Balasingh Ponraj Samuel (Round Rock, TX); Ricardo L. Martinez (Leander, TX); Richard M. Tonry (Austin, TX); Wai-Ming Richard Chan (Austin, TX)
Assignee: Dell Products, L.P.
G06F9/4411G06F11/1417G06F11/1469G06F13/4282G06F2201/805G06F2201/82
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,534,620
App. No.
15/826,922
Granted
Jan 14, 2020
Kind
B2
Abstract

Systems and methods for establishing Core Root of Trust Measurement (CRTM) for Basic Input/Output (BIOS) image recovery are described. In some embodiments, an Information Handling System (IHS) may include a processor and a BIOS coupled to the processor, the BIOS having program instructions that, upon execution, cause the IHS to: during a boot process, verify integrity of a BIOS recovery image using a CRTM, and determine whether to restore the BIOS recovery image in response to the verification.

Claims (33)

1. An information Handling System (IHS), comprising:

a processor; and

a memory containing a Basic Input/Output System (BIOS) coupled to the processor, the BIOS comprising program instructions that, upon execution, cause the IHS to:

during a boot process, verify integrity of a BIOS recovery image using a Core Root of Trust Measurement (CRTM);

determine whether to restore the BIOS recovery image in response to the verification, wherein the BIOS includes a first pre-efi initialization phase (PEI) portion and a first Driver Execution Environment (DXE)/System Management Mode (SMM) portion, and wherein the BIOS recovery image includes a second DXE/SMM portion; and

verify the integrity of the first PEI portion using a hardware Root of Trust, wherein the program instructions, upon execution, further cause the first PEI portion to chain the CRTM to the second DXE/SMM portion to verify the second DXE/SMM portion.

2. The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to:

detect changes in the BIOS recovery image; and

prevent the IHS from booting.

3. The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to:

detect no changes in the BIOS recovery image; and

allow the IHS to boot.

4. The IHS of claim 1 , wherein the program instructions, upon execution, further cause the first PEI portion to compare a DXE measurement of the second DXE/SMM portion with a known value stored in the first PEI portion.

5. The IHS of claim 4 , wherein the known value includes a value stored in a Platform Configuration Register (PCR) prior to initiation of the restore.

6. The IHS of claim 4 , wherein the program instructions, upon execution, further cause the IHS to write contents of the second DXE/SMM portion to a Serial Peripheral Interface (SPI) module.

7. The IHS of claim 4 , wherein the program instructions, upon execution, further cause the IHS to:

verify the DXE/SMM contents on the SPI; and

in response to the verification, hand off execution to the second DXE/SMM portion on the SPI module.

8. A memory containing a Basic I/O System (BIOS) comprising program instructions that, upon execution by an information Handling System (IHS), cause the IHS to:

during a boot process, verify integrity of a BIOS recovery image using a Core Root of Trust Measurement (CRTM), wherein the BIOS includes a first pre-efi initialization phase (PEI) portion and a first Driver Execution Environment (DXE)/System Management Mode (SMM) portion, and wherein the BIOS recovery image includes a second DXE/SMM portion;

determine whether to restore the BIOS recovery image in response to the verification;

verify the integrity of the first PEI portion using a hardware Root of Trust, wherein the program instructions, upon execution, further cause the first PEI portion to chain the CRTM to the second DXE/SMM portion to verify the second DXE/SMM portion.

9. The BIOS of claim 8 , wherein the program instructions, upon execution, further cause the first PEI portion to compare a DXE measurement of the second DXE/SMM portion with a known value stored in the first PEI portion.

10. The BIOS of claim 9 , wherein the program instructions, upon execution, further cause the IHS to write contents of the second DXE/SMM portion to a Serial Peripheral Interface (SPI) module.

11. The BIOS of claim 10 , wherein the program instructions, upon execution, further cause the IHS to:

verify the DXE/SMM contents on the SPI; and

in response to the verification, hand off execution to the second DXE/SMM portion on the SPI module.

12. In an Information Handling System (IHS) comprising a memory containing a Basic I/O System (BIOS) coupled to a processor, a method comprising:

during a boot process, verifying integrity of a BIOS recovery image using a Core Root of Trust Measurement (CRTM), wherein the BIOS includes a first pre-efi initialization phase (PEI) portion and a first Driver Execution Environment (DXE)/System Management Mode (SMM) portion, and wherein the BIOS recovery image includes a second DXE/SMM portion;

determining whether to restore the BIOS recovery image in response to the verification; and

verifying the integrity of the first PEI portion using a hardware Root of Trust, and causing the first PEI portion to chain the CRTM to the second DXE/SMM portion.

13. The method of claim 12 , wherein the program instructions, upon execution, further cause the first PEI portion to compare a DXE measurement of the second DXE/SMM portion with a known value stored in the first PEI portion, and to write contents of the second DXE/SMM portion to a Serial Peripheral Interface (SPI) module.

14. The method of claim 13 , further comprising verify the DXE/SMM contents on the SPI; and in response to the verification, handing off execution to the second DXE/SMM portion on the SPI module.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 061749/0924 →
RELEASE OF SECURITY INTEREST AT REEL 045482 FRAME 0395 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0314 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2017
From: SAMUEL, BALASINGH PONRAJ; MARTINEZ, RICARDO L.; TONRY, RICHARD M.; CHAN, WAI-MING RICHARD
To: DELL PRODUCTS, LP.
Reel/Frame 044258/0518 →
Cited By (3)
US 12,488,111 US 12,574,244 US 12,688,047