IP Library Granted Patent US 11,126,725
Granted Patent B2
US 11,126,725 · App. 16/438,807 · Granted Sep 21, 2021

Secure firmware capsule update using NVMe storage and method therefor

Inventors: Shekar Babu Suryanarayana (Bangalore, IN); Sumanth Vidyadhara (Bangalore, IN)
Assignee: Dell Products L.P.
G06F21/572G06F8/654
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,126,725
App. No.
16/438,807
Granted
Sep 21, 2021
Kind
B2
Abstract

A method includes receiving a firmware update package at an information handling system, the package including a payload containing a first firmware image. In response to executing the firmware update package while the information handling system is under control of an operating system, identifying a non-volatile storage device; authenticating the first firmware image; and storing the first firmware image at the non-volatile storage device. In response to successfully authenticating the first firmware image, initiating a reboot of the information handling system to invoke an initialization routine. The initialization routine includes retrieving the first firmware image from the non-volatile storage device and installing the first firmware image at a first device.

Claims (54)

1. A method comprising:

receiving a firmware update package at an information handling system (IHS), the package including a payload containing a first firmware image;

in response to executing the firmware update package while the IHS is under control of an operating system,

initiating an Advanced Configuration and Power Interface (ACPI) runtime service dynamic handler event;

identifying a non-volatile memory express (NVMe) storage device;

authenticating the first firmware image; and

storing the first firmware image at the NVMe storage device; and

in response to successfully authenticating the first firmware image, initiating a reboot of the IHS to invoke an initialization routine, the routine including:

retrieving the first firmware image from the NVMe storage device; and

installing the first firmware image at a first device.

2. The method of claim 1 , wherein the ACPI runtime service dynamic handler event identifies an ACPI firmware interface table corresponding to the NVMe storage device.

3. The method of claim 2 , wherein the ACPI firmware interface table includes a runtime system firmware handler entry identifying system firmware namespace included at the NVMe storage device.

4. The method of claim 3 , wherein the system firmware namespace includes a Unified Extensible Firmware Interface firmware management protocol.

5. The method of claim 1 , wherein the first firmware image includes firmware to be stored at a serial peripheral interface flash memory device.

6. The method of claim 1 , further comprising:

determining that a first firmware configuration option is enabled at a basic input/output system setup interface, the configuration option specifying use of the NVMe storage device to provide temporary storage of the first firmware image prior to installing the first firmware image at the first device.

7. The method of claim 1 , further comprising:

determining that a first firmware configuration option is enabled at a basic input/output system setup interface, the configuration option specifying runtime authentication of the first firmware image.

8. The method of claim 1 , further comprising verifying that a global unique identifier associated with the first firmware image is included at an extensible firmware interface system resource table.

9. An information handling system comprising:

a non-volatile memory express (NVMe) device;

a first device supporting updatable firmware;

a basic input/output system setup interface including a configuration option specifying use of the NVMe device to provide temporary storage of the first firmware image prior to installing the first firmware image at the first device; and

a central processing unit (CPU) configured to execute instructions during a run-time mode of operation and to execute instructions during a boot-time mode of operation,

wherein during the run-time mode of operation, the CPU is configured to execute instructions to:

receive a firmware update package, the package including a payload containing a first firmware image;

identify the NVMe device;

authenticate the first firmware image; and

store the first firmware image at the NVMe device; and

wherein during the boot-time mode of operation, the CPU is configured to execute instructions to:

retrieve the first firmware image from the NVMe device; and

install the first firmware image at the first device.

10. The information handling system of claim 9 , wherein executing the firmware update package initiates an Advanced Configuration and Power Interface (ACPI) runtime service dynamic handler event.

11. The information handling system of claim 10 , wherein the ACPI runtime service dynamic handler event identifies an ACPI firmware interface table corresponding to the NVMe device.

12. The information handling system of claim 11 , wherein the ACPI firmware interface table includes a runtime system firmware handler entry identifying system firmware namespace included at the NVMe storage device.

13. The information handling system of claim 12 , wherein the system firmware namespace includes a Unified Extensible Firmware Interface firmware management protocol.

14. The information handling system of claim 9 , further comprising a serial peripheral interface (SPI) flash memory device, wherein the first firmware image includes firmware to be stored at the flash memory device.

15. The information handling system of claim 9 , further comprising system firmware instruction executable by the CPU to provide a basic input/output system setup interface including a configuration option specifying runtime authentication of the first firmware image.

16. A method comprising:

receiving a firmware update package at an information handling system (IHS), the package including a payload containing a first firmware image to update firmware at a first device;

verifying that a global unique identifier associated with the first firmware image is included at an extensible firmware interface system resource table;

in response to executing the firmware update package while the IHS is under control of an operating system:

identifying a non-volatile memory express (NVMe) device;

authenticating the first firmware image; and

storing the first firmware image at the NVMe device; and

in response to successfully authenticating the first firmware image, initiating a reboot of the IHS to invoke an initialization routine, the routine including:

retrieving the first firmware image from the NVMe device; and

installing the first firmware image at the first device.

17. The method of claim 16 , wherein executing the firmware update package initiates an Advanced Configuration and Power Interface (ACPI) runtime service dynamic handler event.

18. The method of claim 17 , wherein the ACPI runtime service dynamic handler event identifies an ACPI firmware interface table corresponding to the NVMe storage device, and wherein the ACPI firmware interface table includes a runtime system firmware handler entry identifying system firmware namespace included at the NVMe storage device.

19. The method of claim 16 , further comprising:

determining that a first firmware configuration option is enabled at a basic input/output system setup interface, the configuration option specifying runtime authentication of the first firmware image.

20. The method of claim 16 , further comprising:

determining that a first firmware configuration option is enabled at a basic input/output system setup interface, the configuration option specifying use of the NVMe storage device to provide temporary storage of the first firmware image prior to installing the first firmware image at the first device.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2019
From: SURYANARAYANA, SHEKAR BABU; VIDYADHARA, SUMANTH
To: DELL PRODUCTS, LP
Reel/Frame 049454/0485 →
Cited By (1)
US 12,236,087