IP Library Granted Patent US 10,853,086
Granted Patent B2
US 10,853,086 · App. 15/966,800 · Granted Dec 1, 2020

Information handling systems and related methods for establishing trust between boot firmware and applications based on user physical presence verification

Inventors: Alok Pant (Austin, TX); Ricardo L. Martinez (Leander, TX)
Assignee: Dell Products L.P.
G06F9/4406H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,853,086
App. No.
15/966,800
Granted
Dec 1, 2020
Kind
B2
Abstract

The present disclosure provides an information handling system (IHS) and related methods that use physical presence verification to establish unique trust relationships between boot firmware and one or more individual applications provided within an IHS. The IHS and methods disclosed herein provide secure verification of user physical presence by verifying the physical presence of a user during a pre-boot phase of the boot firmware (i.e., before an operating system (OS) is loaded and running). After user physical presence is verified during the pre-boot phase, the IHS and methods disclosed herein generate a physical presence (PP) bind token during OS runtime that may be used to establish a unique trust relationship between the boot firmware and one or more individual applications provided within the IHS.

Claims (54)

1. An information handling system (IHS), comprising:

a computer readable storage medium storing an operating system (OS) and at least one application;

a computer readable memory storing boot firmware including boot services and runtime services;

at least one processing device coupled to the computer readable storage medium and to the computer readable memory, wherein the at least one processing device is configured to execute:

a first set of program instructions included within the boot services of the boot firmware to interact with a user of the IHS and receive user input via an input device of the IHS during a pre-boot phase of the boot firmware, wherein the pre-boot phase begins when the IHS is booted and ends when the OS is loaded and running; and

a second set of program instructions included within the runtime services of the boot firmware to verify a physical presence of the user during OS runtime, wherein the verification of the physical presence of the user is based on at least a subset of the user input received during the pre-boot phase.

2. The information handling system as recited in claim 1 , wherein the user input is selected from a group including: a key press on a keyboard or a touch screen, a swipe across the touch screen, a click/scroll on a mouse, a string of one or more characters entered on the keyboard or the touch screen, and a challenge string entered on the keyboard or the touch screen.

3. The information handling system as recited in claim 1 , wherein the first set of program instructions are executed by the at least one processing device during the pre-boot phase to display a text command on a display screen of the IHS requesting the user to enter the user input via the input device of the IHS.

4. The information handling system as recited in claim 3 , wherein the second set of program instructions executed by the at least one processing device during OS runtime is configured to verify the physical presence of the user if the user input received during the pre-boot phase matches user input requested in the text command.

5. An information handling system (IHS), comprising:

a computer readable storage medium storing an operating system (OS) and at least one application;

a computer readable memory storing boot firmware including boot services and runtime services;

at least one processing device coupled to the computer readable storage medium and to the computer readable memory, wherein the at least one processing device is configure to execute:

a first set of program instructions included within the boot services of the boot firmware to interact with a user of the IHS and receive user input via an input device of the IHS during a pre-boot phase of the boot firmware; and

a second set of program instructions included within the runtime services of the boot firmware to verify a physical presence of the user during OS runtime, wherein the verification of the physical presence of the user is based on at least a subset of the user input received during the pre-boot phase;

wherein the at least one application includes a third set of program instructions, which is executed by the at least one processing device during OS runtime to:

generate an application token unique to that application; and

provide the application token to the boot firmware.

6. The information handling system as recited in claim 5 , wherein the application token includes one or more of the following:

one or more keys associated with the at least one application;

a plain text or hash of a challenge string displayed to the user of the IHS;

a random number generated by the at least one application;

a random number generated by the boot firmware and forwarded to the at least one application; and

one or more access requests associated with the application.

7. The information handling system as recited in claim 5 , wherein the runtime services of the boot firmware include a fourth set of program instructions, which is executed by the at least one processing device during OS runtime to generate a boot firmware token if the physical presence of the user is verified.

8. The information handling system as recited in claim 7 , wherein the boot firmware token includes one or more of the following:

one or more keys associated with the boot firmware;

a random number generated by the boot firmware;

a random number generated by the at least one application; and

a status of permissions granted and/or denied for one or more access requests associated with the application.

9. The information handling system as recited in claim 7 , wherein the at least one application includes a fifth set of program instructions, which is executed by the at least one processing device during OS runtime to:

receive the boot firmware token if the physical presence of the user is verified;

open a secure communication tunnel between the boot firmware and the at least one application;

generate a physical presence (PP) bind token including at least a subset of information included within the application token and the boot firmware token; and

provide the PP bind token to the boot firmware.

10. The information handling system as recited in claim 9 , wherein the runtime services of the boot firmware include a sixth set of program instructions, which is executed by the at least one processing device during OS runtime to establish a trust relationship between the boot firmware and the at least one application using the PP bind token.

11. A method for generating a trust relationship between boot firmware and at least one application stored within an information handling system (IHS), the method comprising:

providing an application token unique to the at least one application to the boot firmware;

storing the application token;

subsequently rebooting the IHS to enter a pre-boot phase of the boot firmware, wherein during the pre-boot phase the method further comprises:

prompting the user to provide user input; and

receiving the user input via an input device of the IHS; and

verifying a physical presence of the user based on at least a subset of the user input received during the pre-boot phase.

12. The method as recited in claim 11 , wherein prior to providing the application token, the method further comprises generating the application token, wherein the application token includes at least one application access request and a challenge string that was previously displayed to the user.

13. The method as recited in claim 12 , wherein said verifying includes comparing the received user input to the challenge string included within the application token to verify the physical presence of the user.

14. The method as recited in claim 12 , wherein said prompting the user to provide user input and said receiving user input via an input device of the IHS respectively comprise:

prompting the user to provide the challenge string that was previously displayed to the user and grant permission for the at least one application access request included within the application token; and

receive a user response to the challenge string and any permissions granted by the user.

15. The method as recited in claim 11 , further comprising generating a boot firmware token if the physical presence of the user is verified.

16. The method as recited in claim 15 , further comprising opening a secure communication tunnel between the boot firmware and the at least one application.

17. The method as recited in claim 15 , further comprising generating a physical presence (PP) bind token including at least a subset of information included within the application token and the boot firmware token.

18. The method as recited in claim 17 , further comprising establishing a trust relationship between the boot firmware and the at least one application using the PP bind token.

19. The method as recited in claim 17 , wherein the PP bind token includes any permissions granted by the user.

20. The method as recited in claim 19 , further comprising performing application accesses per the permissions included within the PP bind token.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060450/0306 →
RELEASE OF SECURITY INTEREST AT REEL 046286 FRAME 0653 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0093 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2018
From: PANT, ALOK; MARTINEZ, RICARDO L.
To: DELL PRODUCTS L.P.
Reel/Frame 045671/0551 →