IP Library Granted Patent US 11,416,616
Granted Patent B2
US 11,416,616 · App. 15/827,509 · Granted Aug 16, 2022

Secure boot chain for live boot systems

Inventors: Robert W. Kliewer (Wylie, TX); Micky S. Martin (Rowlett, TX); Mickey J. Malone, II (Rowlett, TX)
Assignee: FORCEPOINT LLC
G06F21/575G06F9/4401G06F9/4406G06F9/545H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,416,616
App. No.
15/827,509
Granted
Aug 16, 2022
Kind
B2
Abstract

A system is provided for managing booting of an OS that includes a UEFI controller comprising embedded application code instructions and a pre-loaded signed certificate, a boot process controller comprising application code instructions for the OS, pre-loaded signed certificates, and a plurality of application hash identifiers. The boot process controller receives signed communications from the UEFI controller and determines if the UEFI controller is authorized to manage the OS. The UEFI controller manages the OS in response to a positive authorization. The boot process controller determines if the UEFI controller is authorized to manage the OS in response to installation or execution of the OS. The UEFI controller receives a signed communication from the boot loader program, compares the signed communications with the plurality of application identifiers, and executes the boot loader program in response to the pre-loaded signed certificate matching an application identifier from the plurality.

Claims (65)

1. A system for managing booting of an operating system, the system comprising:

a Unified Extensible Firmware Interface (UEFI) controller 14 operating on a hardware processor and comprising embedded application code instructions;

a boot process controller operating on the processor comprising application code instructions for the operating system, a pre-loaded signed platform key, key exchange key and a signature database, and a plurality of application hash identifiers, and

the boot process controller receives signed communications from the UEFI controller and determines if the UEFI controller is authorized to functionally manage the operating system by comparing the signed communications to one of the pre-loaded signed platform key, key exchange key and a signature database for a boot loader;

wherein the boot process controller further compares the signed communications to one of the pre-loaded signed platform key, key exchange key and a signature database for a kernel image;

wherein the boot process controller further compares the signed communications to one of the pre-loaded signed platform key, key exchange key and a signature database for an operating system image;

wherein the boot processor controller allows the UEFI controller to control the operating system in response to a positive authorization for the boot loader, the kernel image and the operating system image;

wherein the operating system comprises a boot loader program, an initial RAM file system, the kernel image, configuration image files, and pre-signed certificates associated with each.

2. The system of claim 1 wherein the UEFI controller and the boot process controller exchange public keys using a Key Exchange Server (KES) and a Key Exchange Client (KEC).

3. The system of claim 1 wherein the boot process controller determines if the UEFI controller is authorized to access the operating system in response to installation of the operating system.

4. The system of claim 1 wherein the boot process controller determines if the UEFI controller is authorized to control the operating system in response to execution of the operating system.

5. The system of claim 1 wherein the UEFI controller:

reads the signature from the boot loader program;

compares the signature with the plurality of application hash identifiers; and

executes the boot loader program in response to the signature matching an application hash identifier from the plurality of application hash identifiers.

6. The system of claim 5 wherein the boot loader program:

receives pre-loaded signatures of the kernel image and initial RAM file system;

compares the pre-loaded signatures of the kernel image and initial RAM file system with the plurality of application hash identifiers; and

executes the kernel image with the initial RAM file system in response to the pre-loaded signature matching an application hash identifier from the plurality of application hash identifiers.

7. The system of claim 6 wherein the initial RAM file system:

reads signatures from the base OS image and configuration image files;

compares the signatures with the plurality of application hash identifiers; and

executes the base OS image with the configuration image in response to the signatures matching an application hash identifier from the plurality of application hash identifiers.

8. A method for managing booting of an operating system, the method comprising:

embedding application code instructions and a plurality of pre-loaded signed platform key, key exchange key and a signature database in a Unified Extensible Firmware Interface (UEFI) controller;

storing application code instructions for the operating system, the pre-loaded signed platform key, key exchange key and a signature database, and a plurality of application hash identifiers in a boot process controller,

receiving at the boot process controller signed communications from the UEFI controller; and

determining if the UEFI controller is authorized to functionally manage the operating system by comparing the boot process controller signed communications to one of the pre-loaded signed platform key, key exchange key and a signature database for a boot loader, one of the pre-loaded signed platform key, key exchange key and a signature database for a kernel image and one of the pre-loaded signed platform key, key exchange key and a signature database for an operating system image;

wherein the UEFI controller functionally manages the operating system in response to a positive authorization for the boot loader, the kernel image and the operating system image;

wherein the operating system comprises a boot loader program, the kernel image and an initial RAM file system, base OS image and configuration image files, and pre-signed certificates associated with each.

9. The method of claim 8 further comprising the UEFI controller and the boot process controller exchanging public keys using a Key Exchange Server (KES) and Key Exchange Client (KEC).

10. The method of claim 8 further comprising the boot process controller determining if the UEFI controller is authorized to functionally manage the operating system in response to installation of the operating system.

11. The method of claim 8 further comprising the boot process controller determining if the UEFI controller is authorized to functionally manage the operating system in response to execution of the operating system.

12. The method of claim 8 further comprising the UEFI controller:

reading the signature from the boot loader program;

comparing the signature with the plurality of application hash identifiers; and

executing the boot loader program in response to the signature matching an application hash identifier from the plurality of application hash identifiers.

13. The method of claim 12 further comprising the boot loader program:

receiving pre-loaded signatures of the kernel image and initial RAM file system;

comparing the pre-loaded signatures of the kernel image and initial RAM file system with the plurality of application hash identifiers; and

executing the kernel image with the initial RAM file system in response to the pre-loaded signatures matching an application hash identifier from the plurality of application hash identifiers.

14. The method of claim 13 further comprising the initial RAM file system:

reading signatures from the base OS image and configuration image files;

comparing the signatures with the plurality of application hash identifiers; and

executing the base OS image with the configuration image in response to the signatures matching an application hash identifier from the plurality of application hash identifiers.

15. An apparatus for managing booting of an operating system, the apparatus comprising:

a Unified Extensible Firmware Interface (UEFI) controller operating on a hardware processor and comprising embedded application code instructions and a pre-loaded signed certificate;

a boot process controller comprising application code instructions for the operating system, pre-loaded signed platform key, key exchange key and a signature database, and a plurality of application hash identifiers, and

the boot process controller receives signed communications from the UEFI controller and determines if the UEFI controller is authorized to functionally manage the operating system by comparing the signed communications to one of the pre-loaded signed platform key, key exchange key and a signature database for a boot loader;

wherein the UEFI controller functionally manages the operating system in response to a positive authorization for the boot loader, the kernel image and the operating system image;

wherein the operating system comprises a boot loader program, an initial RAM file system, the kernel image, configuration image files, and pre-signed certificates associated with each.

16. The apparatus of claim 15 wherein the boot process controller determines if the UEFI controller is authorized to functionally manage the operating system in response to installation of the operating system.

17. The apparatus of claim 15 wherein the boot process controller determines if the UEFI controller is authorized to functionally manage the operating system in response to execution of the operating system.

18. The apparatus of claim 15 wherein the UEFI controller:

reads the signature from the boot loader program;

compares the signature with the plurality of application hash identifiers; and

executes the boot loader program in response to the signature matching an application hash identifier from the plurality of application hash identifiers.

19. The apparatus of claim 18 wherein the boot loader program:

receives pre-loaded signatures of the kernel image and initial RAM file system;

compares the pre-loaded signatures of the kernel image and initial RAM file system with the plurality of application hash identifiers; and

executes the kernel image with the initial RAM file system in response to the pre-loaded signatures matching an application hash identifier from the plurality of application hash identifiers.

20. The apparatus of claim 19 wherein the initial RAM file system:

reads a signatures from the base OS image and configuration image files;

compares the signatures with the plurality of application hash identifiers; and

executes the base OS image with the configuration image in response to the signatures matching an application hash identifier from the plurality of application hash identifiers.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
CHANGE OF NAME Recorded Feb 13, 2024
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 066582/0531 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055492/0266 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Jul 6, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 046495/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2017
From: KLIEWER, ROBERT W.; MARTIN, MICKY S.; MALONE, MICKEY J., II
To: FORCEPOINT LLC
Reel/Frame 044264/0310 →
Continuity (1)
Related Publication 20190163911A1 · May 30, 2019