IP Library Granted Patent US 11,347,858
Granted Patent B2
US 11,347,858 · App. 16/517,995 · Granted May 31, 2022

System and method to inhibit firmware downgrade

Inventors: Janardan Rajagopal Pradeep Gopal (Round Rock, TX); Sudhir Mathane (Leander, TX)
Assignee: Dell Products L.P.
G06F21/572G06F21/575H04L9/0897H04L9/3247G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,347,858
App. No.
16/517,995
Granted
May 31, 2022
Kind
B2
Abstract

A system initiates a boot operation that executes firmware, and retrieves an anti-roll back version table stored by a trusted platform module. The system determines that the firmware is invalid based on the anti-roll back version table retrieved from the trusted platform module, and aborts the boot operation in response to the determining that the firmware is invalid based on the anti-roll back version table.

Claims (39)

1. A method, comprising:

initiating, by a hardware processor, a boot operation that executes a first version of a firmware;

retrieving an anti-roll back version table stored by a trusted platform module, wherein the anti-roll back version table specifies which particular version of the firmware is allowed to execute;

subsequent to successfully verifying a cryptographic signature associated with the first version of the firmware, determining whether the first version of the firmware is valid or invalid;

determining that the first version of the firmware is invalid based on the anti-roll back version table retrieved from the trusted platform module when the first version of the firmware does not match the particular version specified in the anti-roll back version table that is allowed to execute;

aborting, by the hardware processor, the boot operation in response to the determining that the first version of the firmware is invalid based on the anti-roll back version table;

determining that the first version of the firmware is valid based on the anti-roll back version table when the first version of the firmware matches the particular version specified in the anti-roll back version table;

performing subsequent verification of other firmware versions in response to the determining that the first version of the firmware is valid based on the anti-roll back version table; and

performing secure boot operation when the subsequent verification of the other firmware versions is valid.

2. The method of claim 1 , further comprising storing the anti-roll back version table in a non-volatile memory of the trusted platform module.

3. The method of claim 1 , wherein the retrieving of the anti-roll back version table further comprises retrieving the anti-roll back version table from a non-volatile memory of the trusted platform module.

4. The method of claim 1 , further comprising generating a specific cryptographic signature representing the anti-roll back version table.

5. The method of claim 1 , further comprising reading the firmware from a memory device.

6. A system, comprising:

a hardware processor; and

a memory device accessible to the hardware processor, the memory device storing instructions that when executed cause the hardware processor to perform operations including:

initiating a boot operation that executes a first version of a firmware;

retrieving an anti-roll back version table stored by a trusted platform module, wherein the anti-roll back version table specifies which particular version of the firmware is allowed to execute;

determining that the first version of the firmware is invalid based on the anti-roll back version table retrieved from the trusted platform module when the first version of the firmware does not match the particular version specified in the anti-roll back version table that is allowed to execute;

aborting the boot operation in response to the determining that the first version of the firmware is invalid based on the anti-roll back version table;

determining that the first version of the firmware is valid based on the anti-roll back version table when the first version of the firmware matches the particular version specified in the anti-roll back version table;

performing subsequent verification of other firmware versions in response to the determining that the first version of the firmware is valid based on the anti-roll back version table; and

performing secure boot operation when the subsequent verification of the other firmware versions is valid.

7. The system of claim 6 , wherein the operations further comprise storing the anti-roll back version table in a non-volatile memory of the trusted platform module.

8. The system of claim 6 , wherein the operations further comprise retrieving the anti-roll back version table from a non-volatile memory of the trusted platform module.

9. The system of claim 6 , wherein the operations further comprise generating a cryptographic signature representing the anti-roll back version table.

10. The system of claim 6 , wherein the operations further comprise reading the firmware from the memory device.

11. A non-transitory memory device storing instructions that when executed cause a network interface card to perform operations comprising:

initiating a boot operation that executes a first version of a firmware;

retrieving an anti-roll back version table stored by a trusted platform module, wherein the anti-roll back version table specifies which particular version of the firmware is allowed to execute;

subsequent to successfully verifying a cryptographic signature associated with the first version of the firmware, determining whether the first version of the firmware is valid or invalid;

determining that the first version of the firmware is invalid based on the anti-roll back version table retrieved from the trusted platform module when the first version of the firmware does not match the particular version specified in the anti-roll back version table that is allowed to execute;

aborting the boot operation in response to the determining that the first version of the firmware is invalid based on the anti-roll back version table;

determining that the first version of the firmware is valid based on the anti-roll back version table when the first version of the firmware matches the particular version specified in the anti-roll back version table;

performing subsequent verification of other firmware versions in response to the determining that the first version of the firmware is valid based on the anti-roll back version table; and

performing secure boot operation when the subsequent verification of the other firmware versions is valid.

12. The non-transitory memory device of claim 11 , wherein the operations further comprise storing the anti-roll back version table in a non-volatile memory of the trusted platform module.

13. The non-transitory memory device of claim 11 , wherein the operations further comprise retrieving the anti-roll back version table from a non-volatile memory of the trusted platform module.

14. The non-transitory memory device of claim 11 , wherein the operations further comprise generating a specific cryptographic signature representing the anti-roll back version table.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2019
From: GOPAL, JANARDAN RAJAGOPAL PRADEEP; MATHANE, SUDHIR
To: DELL PRODUCTS, LP
Reel/Frame 049818/0150 →
Cited By (1)
US 12,602,217