IP Library Granted Patent US 11,010,478
Granted Patent B2
US 11,010,478 · App. 16/404,278 · Granted May 18, 2021

Method and system for management of secure boot certificates

Inventors: Deepaganesh Paulraj (Bangalore, IN); Vinod Parackal Saby (Bangalore, IN); Ankit Singh (Bangalore, IN); Shinose Abdul Rahiman (Bangalore, IN)
Assignee: Dell Products L.P.
G06F21/575G06F9/45558H04L63/0823G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,010,478
App. No.
16/404,278
Granted
May 18, 2021
Kind
B2
Abstract

Methods, systems, and computer programs encoded on computer storage medium, for providing, by a client computing node, an interface identifying a secure boot certificate namespace hierarchy including a plurality of namespaces; in response to providing the interface, receiving, by the client computing node, a request to create a new namespace within the secure boot namespace hierarchy; configuring the new namespace, including adding a certificate that is to be included by the new namespace, the certificate associated with a server computing system; and assigning the new namespace to the server computing system.

Claims (54)

1. A computer-implemented method, comprising:

providing, by a client computing node, an interface identifying a secure boot certificate namespace hierarchy including a plurality of namespaces;

in response to providing the interface, receiving, by the client computing node, a request to create a new namespace within the secure boot namespace hierarchy;

configuring the new namespace, including adding a certificate that is to be included by the new namespace, the certificate associated with a server computing system; and

assigning the new namespace to the server computing system.

2. The computer-implemented method of claim 1 , further comprising:

in response to the request, forwarding, by the client computing node, the request to a mining computing node.

3. The computer-implemented method of claim 2 , further comprising:

querying, by the server computing system, an effective certificate for the new namespace;

receiving, by the mining computing node, the query for the effective certificate for the new namespace;

recursively obtaining, by the mining computing node, a set of secure boot certificates of the secure boot namespace hierarchy; and

deriving, by the mining computing node, the effective certificate from the set of secure boot certificates.

4. The computer-implemented method of claim 3 , further comprising:

providing, by the mining computing node, the effective certificate to the client computing node;

providing, by the client computing node, the effective certificate to the server computing system; and

in response to receiving the effective certificate, validating, by the server computing system, drivers against the effective certificate and boot an operating system of the server computing system.

5. The computer-implemented method of claim 3 , wherein the effective certificate is derived based on a cardinality value and an override procedure of the secure boot certificate namespace hierarchy.

6. The computer-implemented method of claim 1 , wherein the request can include a request to update certificates within the secure boot namespace hierarchy.

7. The computer-implemented method of claim 1 , further comprising:

configuring the new namespace, including adding a certificate that is to be included by the new namespace, the certificate associated with a virtual machine; and

assigning the new namespace to the virtual machine.

8. A system comprising a processor having access to memory media storing instructions executable by the processor to perform operations comprising:

providing an interface identifying a secure boot certificate namespace hierarchy including a plurality of namespaces;

in response to providing the interface, receiving a request to create a new namespace within the secure boot namespace hierarchy;

configuring the new namespace, including adding a certificate that is to be included by the new namespace, the certificate associated with a server computing system; and

assigning the new namespace to the server computing system.

9. The system of claim 8 , the operations further comprising:

querying an effective certificate for the new namespace;

receiving the query for the effective certificate for the new namespace;

recursively obtaining a set of secure boot certificates of the secure boot namespace hierarchy; and

deriving the effective certificate from the set of secure boot certificates.

10. The system of claim 9 , the operations further comprising:

providing the effective certificate to the server computing system; and

in response to receiving the effective certificate, validating drivers against the effective certificate and boot an operating system of the server computing system.

11. The system of claim 9 , wherein the effective certificate is derived based on a cardinality value and an override procedure of the secure boot certificate namespace hierarchy.

12. The system of claim 8 , wherein the request can include a request to update certificates within the secure boot namespace hierarchy.

13. The system of claim 8 , the operations further comprising:

configuring the new namespace, including adding a certificate that is to be included by the new namespace, the certificate associated with a virtual machine; and

assigning the new namespace to the virtual machine.

14. A non-transitory computer-readable medium storing software comprising instructions executable by one or more computers which, upon such execution, cause the one or more computers to perform operations comprising:

providing an interface identifying a secure boot certificate namespace hierarchy including a plurality of namespaces;

in response to providing the interface, receiving a request to create a new namespace within the secure boot namespace hierarchy;

configuring the new namespace, including adding a certificate that is to be included by the new namespace, the certificate associated with a server computing system; and

assigning the new namespace to the server computing system.

15. The computer-readable medium of claim 14 , the operations further comprising:

querying an effective certificate for the new namespace;

receiving the query for the effective certificate for the new namespace;

recursively obtaining a set of secure boot certificates of the secure boot namespace hierarchy; and

deriving the effective certificate from the set of secure boot certificates.

16. The computer-readable medium of claim 15 , the operations further comprising:

providing the effective certificate to the server computing system; and

in response to receiving the effective certificate, validating drivers against the effective certificate and boot an operating system of the server computing system.

17. The computer-readable medium of claim 15 , wherein the effective certificate is derived based on a cardinality value and an override procedure of the secure boot certificate namespace hierarchy.

18. The computer-readable medium of claim 14 , wherein the request can include a request to update certificates within the secure boot namespace hierarchy.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: EMC CORPORATION; DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2019
From: PAULRAJ, DEEPAGANESH; SABY, VINOD PARACKAL; SINGH, ANKIT; RAHIMAN, SHINOSE ABDUL
To: DELL PRODUCTS L.P.
Reel/Frame 049093/0641 →
Continuity (1)
Related Publication 20200356672A1 · Nov 12, 2020
Cited By (1)
US 12,223,054