IP Library Granted Patent US 11,016,755
Granted Patent B2
US 11,016,755 · App. 16/527,216 · Granted May 25, 2021

System and method to secure embedded controller flashing process

Inventors: Adolfo S. Montero (Pflugerville, TX); Richard M. Tonry (Austin, TX)
Assignee: Dell Products L.P.
G06F8/654G06F3/0607G06F3/0647G06F3/0652G06F3/0679G06F9/44589G06F13/1673G06F21/572H04L9/3236G06F3/0659G06F8/65G06F8/71G06F13/4027G06F13/4045G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,016,755
App. No.
16/527,216
Granted
May 25, 2021
Kind
B2
Abstract

Methods, systems, and computer programs for receiving, by an embedded controller (EC), an EC firmware update from a central processing unit (CPU); storing the EC firmware update into a buffer region of a flash memory medium via a first bus, the first bus communicatively coupling the EC and the flash memory medium; verifying the EC firmware update stored in the buffer region of the flash memory medium; and in response to verifying the EC firmware update: storing the verified EC firmware update into a primary region of the flash memory medium; and loading the verified EC firmware update from the primary region into an EC memory medium of the EC via the first bus.

Claims (71)

1. A method comprising:

receiving, by an embedded controller (EC), an EC firmware update from a central processing unit (CPU);

storing, by the EC, the EC firmware update into a buffer region of a flash memory medium via a first bus, the first bus communicatively coupling the EC and the flash memory medium, wherein storing the EC firmware update into the buffer region comprises:

causing, by the EC, a high impedance state in an output port of a platform controller hub (PCH);

bypassing, by the EC, a second bus communicatively coupling the EC and the PCH; and

accessing, by the EC, the buffer region of the flash memory medium via the first bus communicatively coupling the EC and the flash memory medium; and

verifying, by the EC, the EC firmware update stored in the buffer region of the flash memory medium; and

in response to verifying the EC firmware update:

storing, by the EC, the verified EC firmware update into a primary region of the flash memory medium; and

loading, by the EC, the verified EC firmware update from the primary region into an EC memory medium of the EC via the first bus.

2. The method of claim 1 , wherein causing the high impedance state in the output port of the PCH comprises resetting the PCH.

3. The method of claim 1 , wherein loading the verified EC firmware update from the primary region into the EC memory medium of the EC further comprises:

reverifying the verified EC firmware update, the reverifying responsive to an EC reboot.

4. The method of claim 3 , further comprising:

determining that the verified EC firmware update cannot be reverified; and

in response to determining that the verified EC firmware update cannot be reverified:

causing a recovery mode comprising:

loading recovery software stored in a secondary region of the flash memory medium;

accessing a copy of the verified EC firmware update stored in the buffer region of the flash memory medium using the recovery software;

reverifying the copy of the verified EC firmware update stored in the buffer region of the flash memory medium; and

storing the reverified copy of the verified EC firmware update into the primary region of the flash memory medium.

5. The method of claim 1 , further comprising:

determining that the EC firmware update in the buffer region of the flash memory medium cannot be verified; and

deleting the EC firmware update from the buffer region of the flash memory medium.

6. The method of claim 1 , wherein verifying the EC firmware update in the buffer region comprises performing a cryptographic function.

7. A system comprising a processor having access to memory media storing instructions executable by the processor to perform operations comprising:

receiving, by an embedded controller (EC), an EC firmware update from a central processing unit (CPU);

storing, by the EC, the EC firmware update into a buffer region of a flash memory medium via a first bus, the first bus communicatively coupling the EC and the flash memory medium, wherein storing the EC firmware update into the buffer region comprises:

causing, by the EC, a high impedance state in an output port of a platform controller hub (PCH);

bypassing, by the EC, a second bus communicatively coupling the EC and the PCH; and

accessing, by the EC, the buffer region of the flash memory medium via the first bus communicatively coupling the EC and the flash memory medium; and

verifying, by the EC, the EC firmware update stored in the buffer region of the flash memory medium; and

in response to verifying the EC firmware update:

storing, by the EC, the verified EC firmware update into a primary region of the flash memory medium; and

loading, by the EC, the verified EC firmware update from the primary region into an EC memory medium of the EC via the first bus.

8. The system of claim 7 , wherein causing the high impedance state in the output port of the PCH comprises resetting the PCH.

9. The system of claim 7 , wherein loading the verified EC firmware update from the primary region into the EC memory medium of the EC further comprises:

reverifying the verified EC firmware update, the reverifying responsive to an EC reboot.

10. The system of claim 9 , further comprising:

determining that the verified EC firmware update cannot be reverified; and

in response to determining that the verified EC firmware update cannot be reverified: causing a recovery mode comprising:

loading recovery software stored in a secondary region of the flash memory medium;

accessing a copy of the verified EC firmware update stored in the buffer region of the flash memory medium using the recovery software;

reverifying the copy of the verified EC firmware update stored in the buffer region of the flash memory medium; and

storing the reverified copy of the verified EC firmware update into the primary region of the flash memory medium.

11. The system of claim 7 , further comprising:

determining that the EC firmware update in the buffer region of the flash memory medium cannot be verified; and

deleting the EC firmware update from the buffer region of the flash memory medium.

12. The system of claim 7 , wherein verifying the EC firmware update in the buffer region comprises performing a cryptographic function.

13. A non-transitory computer-readable medium storing software comprising instructions executable by one or more computers which, upon such execution, cause the one or more computers to perform operations comprising:

receiving, by an embedded controller (EC), an EC firmware update from a central processing unit (CPU);

storing, by the EC, the EC firmware update into a buffer region of a flash memory medium via a first bus, the first bus communicatively coupling the EC and the flash memory medium, wherein storing the EC firmware update into the buffer region comprises:

causing, by the EC, a high impedance state in an output port of a platform controller hub (PCH);

bypassing, by the EC, a second bus communicatively coupling the EC and the PCH; and

accessing, by the EC, the buffer region of the flash memory medium via the first bus communicatively coupling the EC and the flash memory medium; and

verifying, by the EC, the EC firmware update stored in the buffer region of the flash memory medium; and

in response to verifying the EC firmware update:

storing, by the EC, the verified EC firmware update into a primary region of the flash memory medium; and

loading, by the EC, the verified EC firmware update from the primary region into an EC memory medium of the EC via the first bus.

14. The non-transitory computer-readable medium of claim 13 , wherein causing the high impedance state in the output port of the PCH comprises resetting the PCH.

15. The non-transitory computer-readable medium of claim 13 , wherein loading the verified EC firmware update from the primary region into the EC memory medium of the EC further comprises:

reverifying the verified EC firmware update, the reverifying responsive to an EC reboot.

16. The non-transitory computer-readable medium of claim 15 , further comprising:

determining that the verified EC firmware update cannot be reverified; and

in response to determining that the verified EC firmware update cannot be reverified:

causing a recovery mode comprising:

loading recovery software stored in a secondary region of the flash memory medium;

accessing a copy of the verified EC firmware update stored in the buffer region of the flash memory medium using the recovery software;

reverifying the copy of the verified EC firmware update stored in the buffer region of the flash memory medium; and

storing the reverified copy of the verified EC firmware update into the primary region of the flash memory medium.

17. The non-transitory computer-readable medium of claim 13 , wherein verifying the EC firmware update in the buffer region comprises performing a cryptographic function.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2019
From: MONTERO, ADOLFO S.
To: DELL PRODUCTS L.P.
Reel/Frame 049912/0634 →