IP Library Granted Patent US 11,301,567
Granted Patent B2
US 11,301,567 · App. 16/779,864 · Granted Apr 12, 2022

Systems and methods for automatic boot to authenticated external device

Inventors: Puri R. Malluru (Round Rock, TX); Daniel L. Smythia (Austin, TX); Ibrahim Sayyed (Georgetown, TX); Chris C. Griffin (Cedar Park, TX); Anand P. Joshi (Round Rock, TX)
Assignee: Dell Products L.P.
G06F21/575G06F8/65G06F9/4406G06F21/34G06F21/572G06F21/577G06F21/602G06F2221/0751
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,301,567
App. No.
16/779,864
Granted
Apr 12, 2022
Kind
B2
Abstract

An information handling system may include a processor, an external port communicatively coupled to the processor and configured to receive an external information handling resource and couple the external information handling resource to the processor, and a basic input/output system comprising a program of instructions executable by the processor. The program of instructions may be configured to cause the processor to: (i) determine if the external information handling resource coupled via the external port has a signed payload manifest stored thereon, the signed payload manifest comprising information regarding files of a bootable payload stored on the external information handling resource; (ii) if the external information handling resource has a signed payload manifest stored thereon, attempt to authenticate the signed payload manifest; (iii) if the signed payload manifest is authenticated, attempt to verify the files of the bootable payload based on the information with the signed payload manifest regarding files of the bootable payload; (iv) if the files of the bootable payload are verified, attempt to verify a bootable image of the bootable payload; and (v) if the bootable image is verified, cause the information handling system to boot from the bootable payload.

Claims (62)

1. An information handling system comprising:

a processor;

an external port communicatively coupled to the processor and configured to receive an external information handling resource and couple the external information handling resource to the processor; and

a basic input/output system comprising a program of instructions executable by the processor and configured to cause the processor to:

determine if the external information handling resource coupled via the external port has a bootable payload and a signed payload manifest stored thereon, the signed payload manifest comprising:

a payload manifest signature;

information regarding one or more key files of the bootable payload; and

signatures for each of the one or more key files of the bootable payload;

if the external information handling resource has a signed payload manifest stored thereon, attempt to authenticate the signed payload manifest based on the payload manifest signature;

if the signed payload manifest is authenticated, attempt to verify the one or more key files of the bootable payload based on the signatures for each of the one or more key files of the bootable payload;

if the files of the bootable payload are verified, attempt to verify an external boot agent; and

if the external boot agent is verified, cause the information handling system to boot from the bootable payload.

2. The information handling system of claim 1 , wherein the external information handling resource is an external storage resource.

3. The information handling system of claim 1 , wherein:

the signed payload manifest is signed with a private cryptographic key; and

attempting to authenticate the signed payload manifest comprises authenticating the signed payload manifest using a public cryptographic key stored upon or otherwise accessible to the basic input/output system.

4. The information handling system of claim 1 , wherein:

information regarding files of a bootable payload stored on the external information handling resource comprises cryptographic signatures of the files; and

attempting to verify the files of the bootable payload comprises determining if the files within the bootable payload match the cryptographic signatures of the files.

5. The information handling system of claim 1 , wherein the bootable payload comprises a program of instructions for recovering an operating system of the information handling system.

6. The information handling system of claim 1 , wherein the bootable payload comprises an update package for the basic input/output system.

7. The information handling system of claim 1 , wherein the bootable payload comprises an automated and uninterruptable process.

8. A method comprising:

determining, with a basic input/output system of an information handling system, if an external information handling resource coupled to the information handling system via an external port of the information handling system has a bootable payload and a signed payload manifest stored thereon, the signed payload manifest comprising:

a payload manifest signature;

information regarding files one or more key files of the bootable payload; and

signatures for each of the one or more key files of the bootable payload;

if the external information handling resource has a signed payload manifest stored thereon, attempting, with the basic input/output system, to authenticate the signed payload manifest;

if the signed payload manifest is authenticated, attempting to verify, with the basic input/output system, the one or more key files of the bootable payload based on the signatures for each of the one or more key files of the bootable payload;

if the files of the bootable payload are verified, attempting to verify, with the basic input/output system, an external boot agent; and

if the external boot agent is verified, cause the information handling system to boot from the bootable payload.

9. The method of claim 8 , wherein the external information handling resource is an external storage resource.

10. The method of claim 8 , wherein:

the signed payload manifest is signed with a private cryptographic key; and

attempting to authenticate the signed payload manifest comprises authenticating the signed payload manifest using a public cryptographic key stored upon or otherwise accessible to the basic input/output system.

11. The method of claim 8 , wherein:

information regarding files of a bootable payload stored on the external information handling resource comprises cryptographic signatures of the files; and

attempting to verify the files of the bootable payload comprises determining if the files within the bootable payload match the cryptographic signatures of the files.

12. The method of claim 8 , wherein the bootable payload comprises a program of instructions for recovering an operating system of the information handling system.

13. The method of claim 8 , wherein the bootable payload comprises an update package for the basic input/output system.

14. The method of claim 8 , wherein the bootable payload comprises an automated and uninterruptable process.

15. An article of manufacture comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

determine, with a basic input/output system of an information handling system, if an external information handling resource coupled to the information handling system via an external port of the information handling system has a bootable payload and a signed payload manifest stored thereon, the signed payload manifest comprising;

a payload manifest signature;

information regarding one or more key files of the bootable payload stored on the external information handling resource; and

signatures for each of the one or more key files of the bootable payload;

if the external information handling resource has a signed payload manifest stored thereon, attempt, with the basic input/output system, to authenticate the signed payload manifest based on the payload manifest signature;

if the signed payload manifest is authenticated, attempt to verify, with the basic input/output system, the files of the bootable payload based on the signatures for each of the one or more key files of the bootable payload;

if the files of the bootable payload are verified, attempt to verify, with the basic input/output system, an external boot agent; and

if the external boot agent is verified, cause the information handling system to boot from the bootable payload.

16. The article of claim 15 , wherein the external information handling resource is an external storage resource.

17. The article of claim 15 , wherein:

the signed payload manifest is signed with a private cryptographic key; and

attempting to authenticate the signed payload manifest comprises authenticating the signed payload manifest using a public cryptographic key stored upon or otherwise accessible to the basic input/output system.

18. The article of claim 15 , wherein:

information regarding files of a bootable payload stored on the external information handling resource comprises cryptographic signatures of the files; and

attempting to verify the files of the bootable payload comprises determining if the files within the bootable payload match the cryptographic signatures of the files.

19. The article of claim 15 , wherein the bootable payload comprises a program of instructions for recovering an operating system of the information handling system.

20. The article of claim 15 , wherein the bootable payload comprises an update package for the basic input/output system.

21. The article of claim 15 , wherein the bootable payload comprises an automated and uninterruptable process.

Assignments (13)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0917) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0509 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052852/0022) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0582 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0081) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0441 →
RELEASE OF SECURITY INTEREST AT REEL 052771 FRAME 0906 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0298 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0081 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0917 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052852/0022 →
SECURITY AGREEMENT Recorded May 28, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052771/0906 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2020
From: MALLURU, PURI R.; SMYTHIA, DANIEL L.; SAYYED, IBRAHIM; GRIFFIN, CHRIS C.; JOSHI, ANAND P.
To: DELL PRODUCTS L.P.
Reel/Frame 051699/0365 →