IP Library Granted Patent US 11,194,588
Granted Patent B2
US 11,194,588 · App. 16/030,456 · Granted Dec 7, 2021

Information handling systems and method to provide secure shared memory access at OS runtime

Inventors: Shekar B. Suryanarayana (Bangalore, IN); Chandrasekhar Puthillanthe (Bangalore, IN)
Assignee: Dell Products L.P.
G06F9/4411G06F9/44505G06F21/44G06F21/52G06F21/78G06F9/4401G06F9/4406
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,194,588
App. No.
16/030,456
Granted
Dec 7, 2021
Kind
B2
Abstract

The present disclosure provides an information handling system (IHS) and related methods that provide secure shared memory access (SMA) to shared memory locations within a Peripheral Component Interconnect (PCI) device of an IHS. The IHS and methods disclosed herein provide secure SMA to one or more operating system (OS) applications that are granted access to the shared memory. According to one embodiment, the disclosed method provides secure SMA to one or more OS applications by receiving a secure runtime request from at least one OS application to access shared memory locations within a PCI device, authenticating the secure runtime request received from the OS application, creating a secure session for communicating with the OS application, and providing the OS application secure runtime access to the shared memory locations within the PCI device.

Claims (29)

1. An information handling system (IHS), comprising:

a non-transitory computer readable storage medium storing an operating system (OS) and at least one OS application;

a baseboard management controller (BMC) comprising non-volatile memory configured to store BMC firmware, and a processor configured to execute the BMC Firmware during OS runtime to:

receive a secure runtime request from the at least one OS application to access shared memory locations within the non-volatile memory, wherein access to the shared memory locations is disabled prior to the received secure runtime request;

authenticate the secure runtime request received from the at least one OS application, wherein the received secure runtime request is authenticated upon receiving a secure runtime authenticated handshake;

create a secure session for communicating with the at least one OS application after the secure runtime request is authenticated; and

provide the at least one OS application secure runtime access to the shared memory locations within the non-volatile memory.

2. The information handling system as recited in claim 1 , further comprising a non-transitory computer readable memory storing boot firmware and Advanced Configuration and Power Interface (ACPI) firmware, wherein the boot firmware includes boot services and runtime services, and wherein the ACPI firmware includes ACPI runtime services and ACPI tables.

3. The information handling system as recited in claim 2 , further comprising a host processing device coupled to the non-transitory computer readable storage medium and to the non-transitory computer readable memory, wherein during a pre-boot phase of the boot firmware, the host processing device executes one or more boot services of the boot firmware to configure Peripheral Component Interconnect (PCI) configuration registers contained within the BMC and store configuration space information within an ACPI table of the ACPI firmware.

4. The information handling system as recited in claim 3 , wherein during the pre-boot phase of the boot firmware, the host processing device executes one or more additional boot services to disable the PCI configuration registers contained within the BMC to disable access to the shared memory locations.

5. The information handling system as recited in claim 3 , wherein during OS runtime, a first ACPI runtime service is executed by the host processing device to receive the secure runtime request from the at least one OS application and communicate the secure runtime request to the BMC.

6. The information handling system as recited in claim 3 , wherein during OS runtime, a second ACPI runtime service is executed by the host processing device to provide the secure runtime authenticated handshake to the BMC, and wherein the BMC firmware is executed by the processor to authenticate the secure runtime request upon receiving the secure runtime authenticated handshake.

7. The information handling system as recited in claim 3 , wherein during OS runtime, a third ACPI runtime service is executed by the host processing device to access the configuration space information stored within the ACPI table and use the configuration space information to locate a device path access service, which points to runtime services of the boot firmware.

8. The information handling system as recited in claim 7 , wherein during OS runtime, the third ACPI runtime service is further executed by the host processing device to call the runtime services of the boot firmware, wherein the runtime services include methods to open a shared memory access (SMA) channel to the shared memory locations and begin communication over the SMA channel.

9. The information handling system as recited in claim 8 , further comprising an SMA service table that includes entries for mapping the methods included within the runtime services of the boot firmware to a BMC access service, and wherein the BMC access service includes methods to directly call functions that are executable to access the shared memory locations within the non-volatile memory.

10. The information handling system as recited in claim 9 , wherein the first ACPI runtime service, the second ACPI runtime service, the third ACPI runtime service, the device path access service, the SMA service table and the BMC access service are constructed and stored within a boot table of the boot firmware during the pre-boot phase of the boot firmware.

11. A method to provide an operating system (OS) application, during OS runtime, with secure shared memory access (SMA) to shared memory locations within a Peripheral Component Interconnect (PCI) device, the method comprising, during the OS runtime:

receiving a secure runtime request from the OS application to access shared memory locations within a PCI device, wherein access to the shared memory locations is disabled prior to the step of receiving;

authenticating the secure runtime request received from the OS application, wherein the received secure runtime request is authenticated upon receiving a secure runtime authenticated handshake;

creating a secure session for communicating with the OS application after the secure runtime request is authenticated; and

providing the OS application secure runtime access to the shared memory locations within the PCI device.

12. The method as recited in claim 11 , wherein the step of receiving comprising receiving the secure runtime request from the OS application via a first Advanced Configuration and Power Interface (ACPI) runtime service.

13. The method as recited in claim 11 , wherein the step of authenticating comprises authenticating the secure runtime request upon receiving the secure runtime authenticated handshake from a second Advanced Configuration and Power Interface (ACPI) runtime service.

14. The method as recited in claim 11 , wherein prior to the step of receiving, the method comprises configuring PCI configuration registers of the PCI device and storing configuration space information within an Advanced Configuration and Power Interface (ACPI) table.

15. The method as recited in claim 14 , wherein prior to the step of receiving, the method comprises disabling the PCI configuration registers of the PCI device to disable access to the shared memory locations.

16. The method as recited in claim 14 , wherein the step of providing comprises accessing the configuration space information stored within the ACPI table and using the configuration space information to locate the shared memory locations within the non-volatile memory.

17. The method as recited in claim 14 , wherein the step of providing comprises executing a third ACPI runtime service to call boot firmware runtime services.

18. The method as recited in claim 17 , further comprising executing methods within the boot firmware runtime services to open an SMA channel to the shared memory locations and begin communication over the SMA channel.

19. The method as recited in claim 18 , further comprising mapping the methods within the boot firmware runtime services to an access service comprising methods to directly call functions, which are executable to access the shared memory locations.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (047648/0422) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060160/0862 →
RELEASE OF SECURITY INTEREST AT REEL 047648 FRAME 0346 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0510 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 047648/0422 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047648/0346 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2018
From: PUTHILLANTHE, CHANDRASKHAR; SURYANARAYANA, SHEKAR B.
To: DELL PRODUCTS L.P.
Reel/Frame 046543/0774 →