IP Library Granted Patent US 10,853,498
Granted Patent B2
US 10,853,498 · App. 16/135,291 · Granted Dec 1, 2020

Secure boot orchestration device in a virtual desktop infrastructure

Inventors: John Bosco Kelly (Mallow, IE); Ricardo L. Martinez (Leander, TX)
Assignee: Dell Products L.P.
G06F21/575G06F9/452G06F21/604H04L9/3234
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,853,498
App. No.
16/135,291
Granted
Dec 1, 2020
Kind
B2
Abstract

Methods, systems, and computer programs encoded on computer storage medium, for identifying a virtual desktop infrastructure (VDI) that includes a plurality of components; identifying a secure boot state of each of the components; aggregating the secure boot state of each of the components to define an aggregated secure boot state of the VDI; comparing the aggregated secure boot state of the VDI with a secure boot lookup table to identify a measure of trust of the VDI; identifying access control policies for the VDI for the identified measure of trust of the VDI; and enabling access to one or more resources based on the identified access control policies for the VDI.

Claims (18)

1. A computer-implemented method, comprising: identifying a virtual desktop infrastructure (VDI) that includes a plurality of components and sources of certifications corresponding to the plurality of components; identifying a secure boot state of each of the components; aggregating the secure boot state of each of the components to define an aggregated secure boot state of the VDI; identifying, for each component of the plurality of components, a source of a certification signature corresponding to the secure boot state of the component, the source including a self-signed signature and a known certificate authority; identifying, for the aggregated secure boot state, a particular combination of the sources of the certifications corresponding to each of the components defining the secure boot state; comparing i) the aggregated secure boot state of the VDI and ii) the particular combination of the sources of the certifications for the aggregated secure boot state with a secure boot lookup table to identify a measure of trust of the VDI; identifying access control policies for the VDI for the identified measure of trust of the VDI; and enabling access to one or more resources based on the identified access control policies for the VDI.

2. The computer-implemented method of claim 1 , wherein the plurality of components includes at least a hypervisor, a virtual desktop, and a virtual desktop access device.

3. The computer-implemented method of claim 1 , wherein identifying the secure boot state of each of the components includes querying, for each of the components, a secure boot database corresponding to the component.

4. The computer-implemented method of claim 1 , wherein the secure boot state of each of the components can include one of the following: i) a secure boot enabled state, ii) a secure boot capable state, iii) a secure boot not supported state, and iv) an unable to detect secure boot state.

5. The computer-implemented method of claim 1 , wherein identifying, for each component of the plurality of components, the source of the certificate signature corresponding to the secure boot state of the component includes only identifying the certification signature corresponding to a secure boot enabled state of the component.

6. The computer-implemented method of claim 1 , further comprising: receiving, from a trusted platform module (TPM), secure boot state data associated each of the components; comparing, for each of the components, the received secure boot state data with the identified secure boot state; matching, based on the comparing and for each of the components, the received secure boot state data with the identified secure boot state; and in response to matching the received secure boot state data with the identified secure boot state, enabling access to the one or more resources based on the identified access control policies for the VDI.

7. The computer-implemented method of claim 1 , further comprising: in response to comparing i) the aggregated secure boot state of the VDI and ii) the particular combination of the sources of the certifications for the aggregated secure boot state with the secure boot lookup table to identify a measure of trust of the VDI, increasing the measure of trust of the VDI by providing a notification to a virtual desktop access device of the VDI indicating that at least one of the components of the VDI does not include a secure boot enabled state.

8. The computer-implemented method of claim 1 , further comprising: in response to comparing i) the aggregated secure boot state of the VDI and ii) the particular combination of the sources of the certifications for the aggregated secure boot state with the secure boot lookup table to identify a measure of trust of the VDI, updating a secure boot policy of one or more of the components of the VDI.

9. The computer-implemented method of claim 1 , wherein the secure boot state of each of the components is identified when one or more of the components of the VDI is booted.

10. The computer-implemented method of claim 1 , wherein the secure boot state of each of the components is identified periodically.

11. A system comprising a processor having access to memory media storing instructions executable by the processor to perform operations comprising: identifying a virtual desktop infrastructure (VDI) that includes a plurality of components and sources of certifications corresponding to the plurality of components; identifying a secure boot state of each of the components; aggregating the secure boot state of each of the components to define an aggregated secure boot state of the VDI; identifying, for each component of the plurality of components, a source of a certification signature corresponding to the secure boot state of the component, the source including a self-signed signature and a known certificate authority; identifying, for the aggregated secure boot state, a particular combination of the sources of the certifications corresponding to each of the components defining the secure boot state; comparing i) the aggregated secure boot state of the VDI and ii) the particular combination of the sources of the certifications for the aggregated secure boot state with a secure boot lookup table to identify a measure of trust of the VDI; identifying access control policies for the VDI for the identified measure of trust of the VDI; and enabling access to one or more resources based on the identified access control policies for the VDI.

12. The system of claim 11 , wherein the plurality of components includes at least a hypervisor, a virtual desktop, and a virtual desktop access device.

13. The system of claim 11 , wherein identifying the secure boot state of each of the components includes querying, for each of the components, a secure boot database corresponding to the component.

14. The system of claim 11 , wherein the secure boot state of each of the components can include one of the following: i) a secure boot enabled state, ii) a secure boot capable state, iii) a secure boot not supported state, and iv) an unable to detect secure boot state.

15. The system of claim 11 , wherein identifying, for each component of the plurality of components, the source of the certificate signature corresponding to the secure boot state of the component includes only identifying the certification signature corresponding to a secure boot enabled state of the component.

16. The system of claim 11 , the operations further comprising: receiving, from a trusted platform module (TPM), secure boot state data associated each of the components; comparing, for each of the components, the received secure boot state data with the identified secure boot state; matching, based on the comparing and for each of the components, the received secure boot state data with the identified secure boot state; and in response to matching the received secure boot state data with the identified secure boot state, enabling access to the one or more resources based on the identified access control policies for the VDI.

17. The system of claim 11 , the operations further comprising: in response to comparing i) the aggregated secure boot state of the VDI and ii) the particular combination of the sources of the certifications for the aggregated secure boot state with the secure boot lookup table to identify a measure of trust of the VDI, increasing the measure of trust of the VDI by providing a notification to a virtual desktop access device of the VDI indicating that at least one of the components of the VDI does not include a secure boot enabled state.

18. A non-transitory computer-readable medium storing software comprising instructions executable by one or more computers which, upon such execution, cause the one or more computers to perform operations comprising: identifying a virtual desktop infrastructure (VDI) that includes a plurality of components and sources of certifications corresponding to the plurality of components; identifying a secure boot state of each of the components; aggregating the secure boot state of each of the components to define an aggregated secure boot state of the VDI; identifying, for each component of the plurality of components, a source of a certification signature corresponding to the secure boot state of the component, the source including a self-signed signature and a known certificate authority; identifying, for the aggregated secure boot state, a particular combination of the sources of the certifications corresponding to each of the components defining the secure boot state; comparing i) the aggregated secure boot state of the VDI and ii) the particular combination of the sources of the certifications for the aggregated secure boot state with a secure boot lookup table to identify a measure of trust of the VDI; identifying access control policies for the VDI for the identified measure of trust of the VDI; and enabling access to one or more resources based on the identified access control policies for the VDI.

Assignments (5)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2018
From: KELLY, JOHN; MARTINEZ, RICARDO L.
To: DELL PRODUCTS L.P.
Reel/Frame 046910/0882 →