IP Library Granted Patent US 11,347,856
Granted Patent B2
US 11,347,856 · App. 16/422,667 · Granted May 31, 2022

Bios method to block compromised preboot features

Inventors: Ibrahim Sayyed (Georgetown, TX); Alok Pant (Austin, TX); Anand Prakash Joshi (Round Rock, TX)
Assignee: Dell Products L.P.
G06F21/572G06F9/4406G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,347,856
App. No.
16/422,667
Granted
May 31, 2022
Kind
B2
Abstract

An information handling system may include at least one processor, a memory coupled to the at least one processor, and an information handling resource including a firmware. The information handling system may be configured to: boot into an operating system stored on the memory; after booting into the operating system, receive, from at least one remote server, information regarding a vulnerability associated with the firmware; based on a security policy, determine a resolution for mitigation of the vulnerability; and store information regarding the resolution in a storage location accessible to a preboot environment of the information handling system, wherein the preboot environment is configured to apply the resolution upon a subsequent boot of the information handling system.

Claims (41)

1. An information handling system comprising:

at least one processor;

a memory coupled to the at least one processor; and

an information handling resource including a firmware;

wherein the information handling system is configured to:

boot an operating system stored on the memory;

after booting the operating system, receive, from at least one remote server, information regarding a vulnerability associated with the firmware;

create a firmware-specific feature flag based on the information regarding the vulnerability;

store the firmware-specific feature flag in a cryptographically signed policy table with identifying information for the information handling resource;

based on the cryptographically signed policy table, determine a resolution for mitigation of the vulnerability, wherein the resolution includes allowing the information handling resource to operate but disabling a particular feature of the information handling resource; and

store information regarding the resolution in a storage location accessible to a preboot environment of the information handling system, wherein the preboot environment is configured to apply the resolution upon a subsequent boot of the information handling system.

2. The information handling system of claim 1 , wherein the resolution includes preventing loading a driver associated with the information handling resource that includes the firmware.

3. The information handling system of claim 2 , wherein the driver is a Unified Extensible Firmware Interface (UEFI) driver.

4. The information handling system of claim 1 , wherein the preboot environment is a Basic Input/Output System of the information handling system.

5. The information handling system of claim 1 , wherein storing the information regarding the resolution in the storage location accessible to the preboot environment includes:

the operating system of the information handling system executing a persistent agent that has been presented to the operating system via a Windows Platform Binary Table (WPBT) channel; and

the persistent agent storing the information regarding the resolution in a designated storage space accessible to the preboot environment.

6. The information handling system of claim 1 , wherein the receiving, determining, and storing are carried out by a software agent executing on the operating system.

7. A method comprising:

booting an information handling system an operating system, wherein the information handling system comprises an information handling resource that includes a firmware;

after booting the operating system, the information handling system receiving, from at least one remote server, information regarding a vulnerability associated with the firmware;

creating a firmware-specific feature flag based on the information regarding the vulnerability;

storing the firmware-specific feature flag in a cryptographically signed policy table with identifying information for the information handling resource;

based on the cryptographically signed policy table, the information handling system determining a resolution for mitigation of the vulnerability, wherein the resolution includes allowing the information handling resource to operate but disabling a particular feature of the information handling resource; and

the information handling system storing information regarding the resolution in a storage location accessible to a preboot environment of the information handling system, wherein the preboot environment is configured to apply the resolution upon a subsequent boot of the information handling system.

8. The method of claim 7 , further comprising the information handling system requesting the information regarding the vulnerability.

9. The method of claim 7 , further comprising the information handling system receiving the information regarding the vulnerability without requesting such information.

10. An article of manufacture comprising a non-transitory, computer-readable medium having computer-executable code thereon that is executable by a processor of an information handling system for:

booting an operating system;

after booting the operating system, receiving, from at least one remote server, information regarding a vulnerability associated with a firmware of an information handling resource of the information handling system;

creating a firmware-specific feature flag based on the information regarding the vulnerability;

storing the firmware-specific feature flag in a cryptographically signed policy table with identifying information for the information handling resource;

based on the cryptographically signed policy table, determining a resolution for mitigation of the vulnerability, wherein the resolution includes allowing the information handling resource to operate but disabling a particular feature of the information handling resource; and

storing information regarding the resolution in a storage location accessible to a preboot environment of the information handling system, wherein the preboot environment is configured to apply the resolution upon a subsequent boot of the information handling system.

11. The article of claim 10 , wherein the resolution includes preventing loading a driver associated with the information handling resource that includes the firmware.

12. The article of claim 11 , wherein the driver is a Unified Extensible Firmware Interface (UEFI) driver.

13. The article of claim 10 , wherein the preboot environment is a Basic Input/Output System of the information handling system.

14. The article of claim 10 , wherein storing the information regarding the resolution in the storage location accessible to the preboot environment includes:

the operating system of the information handling system executing a persistent agent that has been presented to the operating system via a Windows Platform Binary Table (WPBT) channel; and

the persistent agent storing the information regarding the resolution in a designated storage space accessible to the preboot environment.

15. The article of claim 10 , wherein the receiving, determining, and storing are carried out by a software agent executing on the operating system.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2019
From: SAYYED, IBRAHIM; PANT, ALOK; JOSHI, ANAND PRAKASH
To: DELL PRODUCTS L.P.
Reel/Frame 049301/0882 →