IP Library Granted Patent US 10,853,088
Granted Patent B2
US 10,853,088 · App. 15/981,370 · Granted Dec 1, 2020

Tamper-proof, dual-boot information handling system having operating system-specific hardware and/or firmware components

Inventors: Geroncio Ong Tan (Austin, TX); Adolfo S. Montero (Pflugerville, TX); Alok Pant (Austin, TX); Ray Vivian Kacelenga (Cedar Park, TX)
Assignee: Dell Products, L.P.
G06F9/441G06F1/14G06F21/575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,853,088
App. No.
15/981,370
Granted
Dec 1, 2020
Kind
B2
Abstract

Systems and methods for providing a tamper-proof, dual-boot Information Handling System (IHS) having Operating System (OS)-specific hardware and/or firmware components. In some embodiments, a method may include: producing, by an Embedded Controller (EC) of an IHS, a Real-Time Clock (RTC) battery-powered General-Purpose Input/Output (GPIO) control or external latch; applying the RTC battery-powered GPIO control to a chip select circuit; and selecting, via the chip select circuit: (i) a first flash memory configured to boot the IHS into a diagnostic mode or first OS, or (ii) a second flash memory configured to boot the IHS into a native OS.

Claims (32)

1. A method, comprising:

producing, by an Embedded Controller (EC) of an Information Handling System (IHS), a Real-Time Clock (RTC) battery-powered General-Purpose Input/Output (GPIO) control or external latch;

applying the RTC battery-powered GPIO control to a chip select circuit; and

selecting, via the chip select circuit: (i) a first flash memory configured to boot the IHS into a diagnostic mode or first Operating System (OS), or (ii) a second flash memory configured to boot the IHS into a native OS.

2. The method of claim 1 , further comprising holding a security chip in reset using the RTC battery-powered GPIO control while in the diagnostic mode.

3. The method of claim 1 , further comprising using a tamper-proof circuit to allow the selecting to take place before the Central Processing Unit (CPU) is powered on.

4. The method of claim 3 , wherein the tamper-proof circuit is configured to isolate the RTC battery-powered GPIO control from the chip select circuit after booting of the EC.

5. The method of claim 4 , wherein the tamper-proof circuit is configured to maintain a value of the RTC battery-powered GPIO control applied to the chip select circuit in response to tampering with the chip select circuit.

6. The method of claim 5 , wherein the tamper-proof circuit is configured to cause an IHS shutdown in response to tampering with the chip select circuit.

7. The method of claim 1 , further comprising using a security chip of the IHS to apply an override control to the chip select circuit in response to a transition of a Central Processing Unit (CPU) voltage regulator.

8. An Information Handling System (IHS), comprising:

a chip select circuit;

a first flash memory coupled to the chip select circuit;

a second flash memory coupled to the chip select circuit; and

an Embedded Controller (EC) coupled to the chip select circuit, wherein the EC is configured to:

in a default mode of operation, (a) use the chip select circuit to set the second flash memory active and set the first flash memory inactive, and (b) perform a default boot procedure using the second flash memory; and

in an alternate mode of operation, (a) use the chip select circuit to set the second flash memory inactive and set the first flash memory active, and (b) perform an alternate boot procedure using the first flash memory, wherein to use the chip select circuit, the EC is configured to apply a Real-Time Clock (RTC) battery-powered General-Purpose Input/Output (GPIO) control or external latch circuit to the chip select circuit.

9. The IHS of claim 8 , wherein while in the alternate mode of operation, the chip select circuit is further configured to maintain a security chip in reset.

10. The IHS of claim 8 , further comprising a tamper protection circuit coupled to the chip select circuit, wherein the tamper protection circuit is configured to, in response to a power-on event, pass the RTC battery-powered GPIO control to the output of a logic gate until a Central Processing Unit (CPU) voltage regulator is enabled.

11. The IHS of claim 10 , wherein the tamper protection circuit is further configured to isolate the RTC battery-powered GPIO control from an input of the logic gate in response to a CPU voltage regulator transition.

12. The IHS of claim 11 , wherein the EC is further configured to apply an alternate control to the tamper protection circuit via a flip-flop, and wherein an output of the flip-flop is applied to the logic gate.

13. The IHS of claim 12 , wherein the flip-flop is configured to latch the alternate control to an output of the flip-flop in response to a rising edge of the CPU voltage regulator transition.

14. The IHS of claim 8 , further comprising a security chip coupled to the chip select circuit, wherein the security chip outputs an override control configured to disable the RTC battery-powered GPIO control after the default boot procedure.

15. The IHS of claim 8 , further comprising a flip-flop configured to latch the override control to an output of the flip-flop in response to a rising edge of a CPU voltage regulator transition.

16. A hardware memory device having program instructions stored thereon that, upon execution by an Embedded Controller (EC) of an Information Handling System (IHS), cause the IHS to:

apply a Real-Time Clock (RTC) battery-powered General-Purpose Input/Output (GPIO) control to the chip select circuit;

in a default mode of operation, (a) use a chip select circuit to set a second flash memory active and set a first flash memory inactive, and (b) perform a default boot procedure using the second flash memory; and

in a diagnostic mode of operation, (a) use the chip select circuit to set the second flash memory inactive and set the first flash memory active, and (b) perform a diagnostic boot procedure using the first flash memory.

17. The hardware memory device of claim 16 , wherein the program instructions, upon execution by the EC, further cause the IHS to hold a security chip in reset using the RTC battery-powered GPIO control, latching and isolating the control while in the diagnostic mode.

18. The hardware memory device of claim 16 , wherein the program instructions, upon execution by the EC, further cause the IHS to:

isolate the RTC battery-powered GPIO control from the chip select circuit after the default boot procedure; and

at least one of: (a) maintain a value of the RTC battery-powered GPIO control applied to the chip select circuit in response to tampering with the chip select circuit; or (b) initiate an IHS shutdown in response to tampering with the chip select circuit.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (047648/0422) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060160/0862 →
RELEASE OF SECURITY INTEREST AT REEL 047648 FRAME 0346 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0510 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047648/0346 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 047648/0422 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2018
From: TAN, GERONCIO ONG; MONTERO, ADOLFO S.; PANT, ALOK; KACELENGA, RAY VIVIAN
To: DELL PRODUCTS. L.P.
Reel/Frame 045822/0448 →
Continuity (1)
Related Publication 20190354377A1 · Nov 21, 2019