IP Library Granted Patent US 11,409,884
Granted Patent B2
US 11,409,884 · App. 16/176,096 · Granted Aug 9, 2022

Security profiling of system firmware and applications from an OOB appliance at a differentiated trust boundary

Inventors: Chitrak Gupta (Bangalore, IN); Rama Rao Bisa (Bangalore, IN); Elie A. Jreij (Pflugerville, TX); Sushma Basavarajaiah (Karnataka, IN); Kala Sampathkumar (Bangalore, IN); Mainak Roy (Kolkata, IN)
Assignee: Dell Products L.P.
G06F21/577G06F8/65G06F21/564G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,409,884
App. No.
16/176,096
Granted
Aug 9, 2022
Kind
B2
Abstract

A system, method, and computer-readable medium for a security vulnerability detection operation. The security vulnerability operation includes configuring a firmware security profiling environment with a trusted host and a trusted service processor; receiving a firmware update file via the trusted service processor; using the trusted service processor to identify a security vulnerability within the firmware update file; and, installing the firmware update file to the information handling system only when no security vulnerability is identified by the trusted service processor, the installing being performed by the trusted host.

Claims (52)

1. A computer-implementable method for performing a security vulnerability detection operation, comprising:

configuring a firmware security profiling environment with a trusted host and a trusted service processor, the trusted host comprising a host system configured to provide a trust boundary for data the trusted host provides to an associated sub-system, the trusted service processor comprising an out of band management controller, the trusted service processor being configured to provide a trust boundary for data the trusted service processor provides an information handling system;

receiving a firmware update file via the out of band management controller of the trusted service processor, the firmware update file including an associated digital signature attesting to validity of the firmware update file, the out of band management controller of the trusted service processor providing a dedicated channel for providing the firmware update file to the information handling system;

using the trusted service processor to identify a security vulnerability within the firmware update file; and,

installing the firmware update file to the information handling system only when no security vulnerability is identified by the trusted service processor, the installing being performed by the trusted host.

2. The method of claim 1 , wherein:

the firmware update file is used to update a sub-system of the information handling system.

3. The method of claim 1 , wherein:

the firmware update file is received via an externally provided firmware update package.

4. The method of claim 1 , wherein:

the identifying the security vulnerabilities comprises using a malware scanning application file and the digital signature, the identifying determining whether the digital signature deceptively attests to validity of the firmware update file.

5. The method of claim 4 , wherein:

the malware scanning application file and the digital signature are provided by the trusted host.

6. The method of claim 1 , further comprising:

mapping the firmware update file to a memory-mapped device contained within the trusted service processor.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

configuring a firmware security profiling environment with a trusted host and a trusted service processor, the trusted host comprising a host system configured to provide a trust boundary for data the trusted host provides to an associated sub-system, the trusted service processor comprising an out of band management controller, the trusted service processor being configured to provide a trust boundary for data the trusted service processor provides an information handling system;

receiving a firmware update file via the out of band management controller of the trusted service processor, the firmware update file including an associated digital signature attesting to validity of the firmware update file, the out of band management controller of the trusted service processor providing a dedicated channel for providing the firmware update file to the information handling system;

using the trusted service processor to identify a security vulnerability within the firmware update file; and,

installing the firmware update file to the information handling system only when no security vulnerability is identified by the trusted service processor, the installing being performed by the trusted host.

8. The system of claim 7 , wherein:

the firmware update file is used to update a sub-system of the information handling system.

9. The system of claim 7 , wherein:

the firmware update file is received via an externally provided firmware update package.

10. The system of claim 7 , wherein the instructions executable by the processor are further configured for:

the identifying the security vulnerabilities comprises using a malware scanning application file and the digital signature, the identifying determining whether the digital signature deceptively attests to validity of the firmware update file.

11. The system of claim 10 , wherein:

the malware scanning application file and the digital signature are provided by the trusted host.

12. The system of claim 7 , wherein the instructions executable by the processor are further configured for:

mapping the firmware update file to a memory-mapped device contained within the trusted service processor.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

configuring a firmware security profiling environment with a trusted host and a trusted service processor, the trusted host comprising a host system configured to provide a trust boundary for data the trusted host provides to an associated sub-system, the trusted service processor comprising an out of band management controller, the trusted service processor being configured to provide a trust boundary for data the trusted service processor provides an information handling system;

receiving a firmware update file via the out of band management controller of the trusted service processor, the firmware update file including an associated digital signature attesting to validity of the firmware update file, the out of band management controller of the trusted service processor providing a dedicated channel for providing the firmware update file to the information handling system;

using the trusted service processor to identify a security vulnerability within the firmware update file; and,

installing the firmware update file to the information handling system only when no security vulnerability is identified by the trusted service processor, the installing being performed by the trusted host.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the firmware update file is used to update a sub-system of the information handling system.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

the firmware update file is received via an externally provided firmware update package.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the identifying the security vulnerabilities comprises using a malware scanning application file and the digital signature, the identifying determining whether the digital signature deceptively attests to validity of the firmware update file.

17. The non-transitory, computer-readable storage medium of claim 16 , wherein:

the malware scanning application file and the digital signature are provided by the trusted host.

18. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

mapping the firmware update file to a memory-mapped device contained within the trusted service processor.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (6)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 052771 FRAME 0906 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0298 →
SECURITY AGREEMENT Recorded May 28, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052771/0906 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2018
From: GUPTA, CHITRAK; BISA, RAMA RAO; JREIJ, ELIE A.; BASAVARAJAIAH, SUSHMA; SAMAPATHUKUMAR, KALA; ROY, MAINAK
To: DELL PRODUCTS L.P.
Reel/Frame 047368/0645 →
Continuity (1)
Related Publication 20200134192A1 · Apr 30, 2020