IP Library Granted Patent US 10,713,363
Granted Patent B2
US 10,713,363 · App. 15/964,595 · Granted Jul 14, 2020

System and method of configuring information handling systems

Inventors: Marshal F. Savage (Austin, TX); Jason Matthew Young (Round Rock, TX)
Assignee: Dell Products L.P.
G06F21/572G06F21/6218H04L9/321H04L9/3247H04L9/3268H04L41/0806H04L9/006
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,713,363
App. No.
15/964,595
Granted
Jul 14, 2020
Kind
B2
Abstract

In one or more embodiments, one or more systems, methods, and/or processes may receive a digital signature, signed by a signing authority, for a request for utilization of an information handling system firmware application programming interface (API) of the information handling system firmware, signed based at least on information associated with a certificate signed by a certificate authority; may determine that the signing authority is authorized for the request for utilization of the information handling system firmware API; may determine that the signing authority is authorized for the request for utilization of the information handling system firmware API on a platform model of the information handling system; may determine that the certificate is not on a certificate revocation list; and may permit utilization of the information handling system firmware API.

Claims (68)

1. An information handling system, comprising:

at least one processor;

a memory medium that is coupled to the at least one processor and that stores information handling system firmware, executable by the at least one processor; and

a remote access controller that is coupled to the at least one processor;

wherein the remote access controller is configured to:

receive a digital signature, signed by a signing authority, for a request for utilization of an information handling system firmware application programming interface (API) of the information handling system firmware, signed based at least on information associated with a certificate signed by a certificate authority;

decrypt the digital signature, utilizing a public key associated with the certificate, to determine a first hash value;

determine a second hash value of the request for utilization of the information handling system firmware API;

determine that the first hash value matches the second hash value;

determine that the signing authority is authorized for the request for utilization of the information handling system firmware API;

determine that the signing authority is authorized for the request for utilization of the information handling system firmware API on a platform model of the information handling system;

permit utilization of the information handling system firmware API; and

permit, without authentication, utilization of another information handling system firmware API.

2. The information handling system of claim 1 , wherein the remote access controller is further configured to determine that the certificate is not on a certificate revocation list.

3. The information handling system of claim 2 ,

wherein firmware of the remote access controller includes the certificate revocation list; and

wherein, to determine that the certificate is not on the certificate revocation list, the remote access controller is further configured to access the firmware of the remote access controller for the certificate revocation list.

4. The information handling system of claim 1 , wherein, to determine that the signing authority is authorized for the request for utilization of the information handling system firmware API, the remote access controller is further configured to:

determine one or more scope qualifiers from the certificate; and

determine that at least one of the one or more scope qualifiers is associated with utilization of the information handling system firmware API.

5. The information handling system of claim 1 , wherein the information handling system firmware API is configured to configure at least a portion of the information handling system.

6. The information handling system of claim 1 , wherein the remote access controller is further configured to:

determine a current time; and

determine that the current time satisfies a timing constraint of the certificate.

7. A method, comprising:

a remote access controller, of an information handling system, receiving a digital signature, signed by a signing authority, for a request for utilization of an information handling system firmware application programming interface (API), signed based at least on information associated with a certificate signed by a certificate authority;

the remote access controller decrypting the digital signature, utilizing a public key associated with the certificate, to determine a first hash value;

the remote access controller determining a second hash value of the request for utilization of the information handling system firmware API;

the remote access controller determining that the first hash value matches the second hash value;

the remote access controller determining that the signing authority is authorized for the request for utilization of the information handling system firmware API;

the remote access controller determining that the signing authority is authorized for the request for utilization of the information handling system firmware API on a platform model of the information handling system;

the remote access controller permitting utilization of the information handling system firmware API; and

the remote access controller permitting, without authorization, utilization of another information handling system firmware API.

8. The method of claim 7 , further comprising:

the remote access controller determining that the certificate is not on a certificate revocation list.

9. The method of claim 8 ,

wherein firmware of the remote access controller includes the certificate revocation list; and

wherein the remote access controller determining that the certificate is not on the certificate revocation list includes the remote access controller accessing the firmware of the remote access controller for the certificate revocation list.

10. The method of claim 7 , wherein the remote access controller determining that the signing authority is authorized for the request for utilization of the information handling system firmware API includes:

determining one or more scope qualifiers from the certificate; and

determining that at least one of the one or more scope qualifiers is associated with utilization of the information handling system firmware API.

11. The method of claim 7 , wherein the information handling system firmware API is configured to configure at least a portion of the information handling system.

12. The method of claim 7 , further comprising:

the remote access controller determining a current time; and

the remote access controller determining that the current time satisfies a timing constraint of the certificate.

13. A remote access controller, comprising:

at least one processor;

a memory medium that is coupled to the at least one processor and that stores firmware that includes instructions, which when executed by the at least one processor, cause the remote access controller to:

receive a digital signature, signed by a signing authority, for a request for utilization of an information handling system firmware application programming interface (API) of the information handling system firmware, signed based at least on information associated with a certificate signed by a certificate authority;

decrypt the digital signature, utilizing a public key associated with the certificate, to determine a first hash value;

determine a second hash value of the request for utilization of the information handling system firmware API;

determine that the first hash value matches the second hash value;

determine that the signing authority is authorized for the request for utilization of the information handling system firmware API;

determine that the signing authority is authorized for the request for utilization of the information handling system firmware API on a platform model of the information handling system;

determine that the certificate is not on a certificate revocation list;

permit utilization of the information handling system firmware API; and

permit, without authentication, utilization of another information handling system firmware API.

14. The remote access controller of claim 13 , wherein the instructions further cause the remote access controller to determine that the certificate is not on a certificate revocation list.

15. The remote access controller of claim 14 ,

wherein firmware of the remote access controller includes the certificate revocation list; and

wherein, to determine that the certificate is not on the certificate revocation list, the instructions further cause the remote access controller to access the firmware of the remote access controller for the certificate revocation list.

16. The remote access controller of claim 1 , wherein, to determine that the signing authority is authorized for the request for utilization of the information handling system firmware API, the instructions further cause the remote access controller:

determine one or more scope qualifiers from the certificate; and

determine that at least one of the one or more scope qualifiers is associated with utilization of the information handling system firmware API.

17. The remote access controller of claim 13 , wherein the information handling system firmware API is configured to configure at least a portion of the information handling system.

18. The remote access controller of claim 13 , wherein the instructions further cause the remote access controller to:

determine a current time; and

determine that the current time satisfies a timing constraint of the certificate.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060450/0306 →
RELEASE OF SECURITY INTEREST AT REEL 046286 FRAME 0653 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0093 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2018
From: SAVAGE, MARSHAL F.; YOUNG, JASON MATTHEW
To: DELL PRODUCTS L.P.
Reel/Frame 045654/0425 →
Continuity (1)
Related Publication 20190332775A1 · Oct 31, 2019