IP Library Granted Patent US 10,949,540
Granted Patent B2
US 10,949,540 · App. 15/926,551 · Granted Mar 16, 2021

Security policy enforcement based on dynamic security context updates

Inventors: Carlton A. Andrews (Austin, TX); Charles D. Robison (Buford, GA); Andrew T. Fausak (Coppell, TX); David Konetski (Austin, TX); Girish S. Dhoble (Austin, TX); Ricardo L. Martinez (Leander, TX); Joseph Kozlowski (Hutto, TX)
Assignee: Dell Products L.P.
G06F21/577G06F21/602G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,949,540
App. No.
15/926,551
Granted
Mar 16, 2021
Kind
B2
Abstract

An information handling system (IHS) includes a memory having a BIOS, at least one sensor that generates security related data for the IHS, a controller, and one or more I/O drivers. The memory, at least one sensor and controller operate within a secure environment of the IHS; the I/O driver(s) operate outside of the secure environment. The controller includes a security policy management engine, which is executable during runtime of the IHS to continuously monitor security related data generated by the at least one sensor, determine whether the security related data violates at least one security policy rule specified for the IHS, and provide a notification of security policy violation to the BIOS, if the security related data violates at least one security policy rule. The I/O driver(s) include a security enforcement engine, which is executable to receive the notification of security policy violation from the BIOS, and perform at least one security measure in response thereto.

Claims (64)

1. An information handling system (IHS), comprising:

a memory having a basic input output system (BIOS), which operates within a secure environment within the IHS;

at least one sensor, which operates within the secure environment to generate security related data for the IHS; and

a controller, which operates within the secure environment, wherein the controller is distinct from, yet operatively coupled to the at least one sensor and the BIOS for communicating information securely there between, and wherein the controller comprises a security policy management engine, which is executable during runtime of the IHS to continuously:

monitor the security related data generated by the at least one sensor;

determine whether the security related data violates at least one security policy rule specified for the IHS, wherein if the security related data violates the at least one security policy rule, the security policy management engine is further executable to:

provide a notification of security policy violation to the BIOS; and

update security context information stored within the BIOS to reflect a particular security violation or a change in a security compliance state.

2. The information handling system as recited in claim 1 , wherein a plurality of security policy rules specified for the IHS are stored within the BIOS or the controller.

3. The information handling system as recited in claim 1 , wherein the at least one sensor is configured to generate security related data in response to at least one of the following:

detecting intrusion into a chassis of the IHS;

detecting corruption of program code or data within the BIOS;

detecting a GPS location of the IHS;

determining a connection state of a USB port included within the IHS;

determining a communication state of a network interface device included within the IHS;

determining a power state of the IHS; and

determining a docking state of the IHS.

4. The information handling system as recited in claim 1 , further comprising at least one input/output (I/O) driver, which operates outside of the secure environment and comprises a security enforcement engine that is executable to:

receive the notification of security policy violation or the updated security context information from the BIOS over a secure communications channel; and

perform at least one security measure upon receiving the notification of security policy violation or the updated security context information.

5. The information handling system as recited in claim 4 , wherein the security enforcement engine is configured to receive the notification of security policy violation immediately in response to the notification being provided to the BIOS.

6. The information handling system as recited in claim 4 , wherein the security enforcement engine is configured to receive the notification of security policy violation from the BIOS in response to a security update request transmitted from the at least one I/O driver to the BIOS over the secure communications channel.

7. The information handling system as recited in claim 6 , wherein the at least one I/O driver transmits the security update request continuously or periodically during runtime of the IHS, or in response to an event detected by the at least one I/O driver.

8. The information handling system as recited in claim 7 , wherein the event comprises at least one of the following:

a request to access or decrypt data stored within a storage medium of the IHS; and

a request to communicate with the IHS via a network.

9. The information handling system as recited in claim 4 , wherein the at least one security measure performed by the security enforcement engine comprises destroying, encrypting or revoking access to a key, which is used by the I/O driver to decrypt encrypted data stored within a storage medium of the IHS, so that the encrypted data cannot be decrypted by the I/O driver.

10. The information handling system as recited in claim 4 , wherein the at least one security measure performed by the security enforcement engine comprises one or more of the following:

disabling one or more input devices of the IHS;

disabling one or more output devices of the IHS; and

disabling at least one of a network interface, a device interface and an optical disc drive to block access to data stored within a storage medium of the IHS.

11. The information handling system as recited in claim 1 , wherein the BIOS, the at least one sensor and the controller are provided on a secure platform of the IHS, which isolates the BIOS, the at least one sensor and the controller from other IHS components and provides a secure environment that is resistant to security attacks.

12. The information handling system as recited in claim 11 , wherein the controller is directly connected to the at least one sensor on the secure platform and configured to receive an unadulterated stream of security related data from the at least one sensor that cannot be changed by malicious software.

13. An information handling system (IHS), comprising:

a memory having a basic input output system (BIOS), which operates within a secure environment within the IHS;

at least one sensor, which operates within the secure environment to generate security related data for the IHS;

a controller coupled between the at least one sensor and the BIOS, wherein the controller operates within the secure environment and comprises a security policy management engine, which is executable during runtime of the IHS to continuously:

monitor the security related data generated by the at least one sensor;

determine whether the security related data violates at least one security policy rule specified for the IHS; and

modify a security compliance state stored within the BIOS to reflect a security violation, if the security related data violates the at least one security policy rule; and

a filter driver, which operates outside of the secure environment and comprises a security enforcement engine that is executable to:

access the security compliance state stored within the BIOS via a secure communications channel connecting the filter driver to the BIOS; and

revoke access to a key used to encrypt and decrypt data, if the security compliance state reflects a security violation.

14. The information handling system as recited in claim 13 , wherein the filter driver further comprises:

a key management unit configured to store the key used to encrypt and decrypt data; and

an encryption/decryption unit configured to use the key to encrypt and decrypt data.

15. The information handling system as recited in claim 14 , wherein if the security compliance state reflects a security violation, the security enforcement engine is configured to revoke access to the key by encrypting the key, thereby preventing the encryption/decryption unit from decrypting encrypted data stored within a storage medium of the IHS.

16. The information handling system as recited in claim 15 , wherein the security enforcement engine is configured to encrypt the key using a public key obtained from a digital certificate provided to the IHS by a certificate authority.

17. The information handling system as recited in claim 16 , wherein the security enforcement engine is configured to send the encrypted key to a key recovery service for decryption with a private key.

18. The information handling system as recited in claim 17 , wherein the security enforcement engine is configured to receive the decrypted key from the key recovery service and configured to store the decrypted key in the key management unit.

19. The information handling system as recited in claim 13 , wherein the security enforcement engine is configured to access the security compliance state stored within the BIOS continuously or periodically during runtime of the IHS.

20. The information handling system as recited in claim 13 , wherein the security enforcement engine is configured to access the security compliance state stored within the BIOS in response to a request detected by the filter driver to access or decrypt data stored within a storage medium of the IHS.

21. A method to enforce security within an information handling system (IHS), the method comprising using a controller operating within a secure environment to:

monitor security related data generated by at least one sensor operating within a secure environment of the IHS;

determine whether the security related data violates at least one security policy rule specified for the IHS;

provide a notification of security policy violation to a basic input/output system (BIOS) of the IHS, if the security related data violates the at least one security policy rule; and

update security context information stored within the BIOS to reflect a particular security violation or a change in a security compliance state, if the security related data violates the at least one security policy rule;

wherein the controller is distinct from, yet operatively coupled to the at least one sensor and the BIOS for communicating information securely there between.

22. The method as recited in claim 21 , further comprising

receiving the notification of security policy violation from the BIOS over a secure communications channel; and

performing at least one security measure upon receiving the notification of security policy violation.

23. The method as recited in claim 22 , wherein:

the steps of monitoring, determining, providing and updating are conducted by a security policy management engine operating within the secure environment of the IHS; and

the steps of receiving and performing are conducted by a security enforcement engine operating outside of the secure environment of the IHS.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060450/0306 →
RELEASE OF SECURITY INTEREST AT REEL 046286 FRAME 0653 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0093 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2018
From: ANDREWS, CARLTON A.; ROBISON, CHARLES D.; FAUSAK, ANDREW T.; KONETSKI, DAVID; DHOBLE, GIRISH S.; MARTINEZ, RICARDO L.; KOZLOWSKI, JOSEPH
To: DELL PRODUCTS L.P.
Reel/Frame 045533/0545 →
Continuity (1)
Related Publication 20190294800A1 · Sep 26, 2019
Cited By (2)
US 12,265,632 US 12,373,569