IP Library Granted Patent US 10,824,731
Granted Patent B2
US 10,824,731 · App. 15/971,166 · Granted Nov 3, 2020

Secure bios attribute system

Inventors: Wei G. Liu (Austin, TX); William Carl Munger (Round Rock, TX)
Assignee: Dell Products L.P.
G06F21/572G06F9/4401G06F21/44G06F21/575H04L9/0894H04L63/061H04L63/0823H04L63/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,824,731
App. No.
15/971,166
Granted
Nov 3, 2020
Kind
B2
Abstract

A secure Basic Input/Output System (BIOS) attribute system includes a secure server system coupled to a computing device through a network. The computing device receives a first BIOS attribute modification request, and authenticates the first BIOS attribute modification request using a first certificate that was previously stored in the computing device in response to validating the first certificate based on a key provided by the secure server system. In response to authenticating the first BIOS attribute modification request using the first certificate, the computing device modifies at least one BIOS attribute stored in the computing device.

Claims (80)

1. A secure Basic Input/Output System (BIOS) attribute system, comprising:

a secure server system; and

a computing device that is coupled to the secure server system through a network, wherein the computing device is configured to:

receive a first BIOS attribute modification request;

authenticate, using a first certificate that was stored in the computing device prior to the receiving the first BIOS attribute modification request and in response to validating the first certificate based on a key provided by the secure server system, the first BIOS attribute modification request; and

modify, in response to authenticating the first BIOS attribute modification request using the first certificate, at least one BIOS attribute stored in the computing device.

2. The system of claim 1 , wherein the computing device is configured to:

receive, through the network from the secure sever system, the key;

store the key in a BIOS storage that is included in the computing device;

receive the first certificate;

validate the first certificate using the key; and

store, in response to validating the first certificate, the first certificate in a secure storage subsystem in the computing device.

3. The system of claim 2 , wherein the secure storage subsystem is included in a remote access controller that is included in the computing device.

4. The system of claim 1 , wherein the computing device is configured to:

receive the first certificate;

provide, through the network to the secure server system, the first certificate;

receive, through the network from the secure server system, a validation of the first certificate that is based on the key that is stored in the secure server system; and

store, in response to receiving the validation, the first certificate in a secure storage subsystem in the computing device.

5. The system of claim 1 , wherein the computing device is configured to:

receive a second certificate;

determine that the second certificate cannot be validated using a key that is provided by the secure server system; and

ignore, in response to determining that the second certificate cannot be validated, the second certificate.

6. The system of claim 1 , wherein the computing device is configured to:

receive a second BIOS attribute modification request;

determine that the second BIOS attribute modification request cannot be authenticated using any certificates that were previously stored in the computing device; and

ignore, in response to determining that the second BIOS attribute modification request cannot be authenticated, the second BIOS attribute modification request.

7. An Information Handling System (IHS), comprising:

a processing system; and

a memory system that is coupled to the processing system and that includes instructions that, when executed by the processing system, cause the processing system to provide a Basic Input/Output System (BIOS) engine that is configured to:

receive a first BIOS attribute modification request;

authenticate, using a first certificate that was stored in a secure storage subsystem prior to the receiving the first BIOS attribute modification request and in response to validating the first certificate based on a key, the first BIOS attribute modification request; and

modify, in response to authenticating the first BIOS attribute modification request using the first certificate, at least one BIOS attribute stored in a BIOS storage.

8. The IHS of claim 7 , wherein the BIOS engine is configured to:

receive, through a network from a secure sever system, the key;

store the key in the BIOS storage;

receive the first certificate;

validate the first certificate using the key; and

store, in response to validating the first certificate, the first certificate in the secure storage subsystem.

9. The IHS of claim 8 , further comprising:

a remote access controller that is coupled to the processing system, wherein the secure storage subsystem is included in the remote access controller.

10. The IHS of claim 7 , wherein the BIOS engine is configured to:

receive the first certificate;

provide, through a network to a secure server system, the first certificate;

receive, through the network from the secure server system, a validation of the first certificate that is based on the key that is stored in the secure server system; and

store, in response to receiving the validation, the first certificate in the BIOS storage.

11. The IHS of claim 7 , wherein the BIOS engine is configured to:

receive a second certificate;

determine that the second certificate cannot be validated using a key; and

ignore, in response to determining that the second certificate cannot be validated, the second certificate.

12. The IHS of claim 7 , wherein the BIOS engine is configured to:

receive a second BIOS attribute modification request;

determine that the second BIOS attribute modification request cannot be authenticated using any certificates that were previously stored in the BIOS storage; and

ignore, in response to determining that the second BIOS attribute modification request cannot be authenticated, the second BIOS attribute modification request.

13. The IHS of claim 7 , further comprising:

a BIOS interface coupled to the processing system, wherein the first certificate is received from a runtime engine via the BIOS interface.

14. A method for securing Basic Input/Output System (BIOS) attributes, comprising:

receiving, by a BIOS engine, a first BIOS attribute modification request;

authenticating, by the BIOS engine using a first certificate that was previously stored in a secure storage subsystem prior to the receiving the first BIOS attribute modification request and in response to validating the first certificate based on a key, the first BIOS attribute modification request; and

modifying, by the BIOS engine in response to authenticating the first BIOS attribute modification request using the first certificate, at least one BIOS attribute stored in a BIOS storage.

15. The method of claim 14 , further comprising:

receiving, by the BIOS engine through a network from a secure sever system, the key;

storing, by the BIOS engine, the key in the BIOS storage;

receiving, by the BIOS engine, the first certificate;

validating, by the BIOS engine, the first certificate using the key; and

storing, by the BIOS engine in response to validating the first certificate, the first certificate in the secure storage subsystem.

16. The method of claim 15 , wherein the secure storage subsystem is included in the remote access controller.

17. The method of claim 14 , further comprising:

receiving, by the BIOS engine, the first certificate;

providing, by the BIOS engine through a network to a secure server system, the first certificate;

receiving, by the BIOS engine through the network from the secure server system, a validation of the first certificate that is based on the key that is stored in the secure server system; and

storing, by the BIOS engine in response to receiving the validation, the first certificate in the secure storage subsystem.

18. The method of claim 14 , further comprising:

receiving, by the BIOS engine, a second certificate;

determining, by the BIOS engine, that the second certificate cannot be validated using a key; and

ignoring, by the BIOS engine in response to determining that the second certificate cannot be validated, the second certificate.

19. The method of claim 14 , further comprising:

receiving, by the BIOS engine, a second BIOS attribute modification request;

determining, by the BIOS engine, that the second BIOS attribute modification request cannot be authenticated using any certificates that were previously stored in the BIOS storage; and

ignoring, by the BIOS engine in response to determining that the second BIOS attribute modification request cannot be authenticated, the second BIOS attribute modification request.

20. The method of claim 14 , wherein the first certificate is received from a runtime engine via a BIOS interface that is coupled to the BIOS engine.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060450/0306 →
RELEASE OF SECURITY INTEREST AT REEL 046286 FRAME 0653 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0093 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2018
From: LIU, WEI G.; MUNGER, WILLIAM CARL
To: DELL PRODUCTS L.P.
Reel/Frame 045716/0287 →
Continuity (1)
Related Publication 20190340364A1 · Nov 7, 2019