IP Library Granted Patent US 11,627,468
Granted Patent B2
US 11,627,468 · App. 16/780,321 · Granted Apr 11, 2023

Connecting securely to a wireless display from BIOS

Inventors: Shekar Babu Suryanarayana (Bangalore, IN); Sumanth Vidyadhara (Bangalore, IN)
Assignee: Dell Products L.P.
H04W12/50G06F9/4401G06F21/84H04N21/2347H04N21/25816H04W12/04H04W12/041H04W12/069
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,627,468
App. No.
16/780,321
Granted
Apr 11, 2023
Kind
B2
Abstract

During the boot process, a secure wireless display connect module of the BIOS can authenticate a wireless display and determine whether the wireless display can comply with the HDCP. When the secure wireless display connect module determines that the wireless display is HDCP compliant, the secure wireless display connect module can create an ACPI secure blob in which is stored a shared session key generated as part of determining that the wireless display is HDCP compliant. A video authentication session module of the BIOS can then retrieve this shared session key from the ACPI secure blob and use it to encrypt video frames that are to be sent to the wireless display. The video authentication session module may additionally embed a session ID and a timeout into each video frame which the wireless display can employ to detect when the video frame should no longer be displayed.

Claims (52)

1. A method, implemented by BIOS during a boot process on a computing system, for connecting securely to a wireless display, the method comprising:

performing, by the BIOS, the boot process prior to loading an operating system on the computing system;

during the boot process, detecting the wireless display;

during the boot process, authenticating with the wireless display;

while performing the boot process, detecting that the wireless display is compliant with High-Bandwidth Digital Content Protection (HDCP) by receiving a certificate from the wireless display and verifying the certificate against a BIOS-based certificate store;

generating encrypted video frames that comply with the HDCP using a shared session key that is generated as part of authenticating with the wireless display during the boot process; and

wirelessly sending the encrypted video frames to the wireless display during the boot process.

2. The method of claim 1 , wherein authenticating with the wireless display comprises performing WPA3-Personal-based authentication.

3. The method of claim 1 , further comprising:

storing the shared session key in a data structure.

4. The method of claim 3 , wherein the data structure is an Advanced Configuration and Power Interface (ACPI) secure blob.

5. The method of claim 4 , further comprising:

generating an ACPI node that includes the ACPI secure blob and enables the operating system to cause the ACPI secure blob to be employed to encrypt the encrypted video frames that are sent to the wireless display.

6. The method of claim 1 , further comprising:

embedding a timeout in the encrypted video frames, each timeout defining when the wireless display should prevent the corresponding video frame from being displayed.

7. The method of claim 1 , further comprising:

embedding a session identifier in the encrypted video frames.

8. One or more computer storage media storing BIOS which when executed during a boot process on a computing system perform a method for connecting securely to a wireless display during the boot process, the method comprising:

performing, by the BIOS, the boot process prior to loading an operating system on the computing system;

during the boot process, detecting the wireless display;

during the boot process, authenticating with the wireless display;

while performing the boot process, detecting that the wireless display is compliant with High-Bandwidth Digital Content Protection (HDCP) by receiving a certificate from the wireless display and verifying the certificate against a BIOS-based certificate store;

generating encrypted video frames that comply with the HDCP using a shared session key that is generated as part of authenticating with the wireless display during the boot process; and

wirelessly sending the encrypted video frames to the wireless display during the boot process.

9. The computer storage media of claim 8 , wherein the method further comprises:

storing the shared session key in an Advanced Configuration and Power Interface (ACPI) data structure.

10. The computer storage media of claim 8 , wherein the method further comprises:

including a timeout in the encrypted video frames.

11. The computer storage media of claim 8 ,

wherein authenticating with the wireless display comprises performing WPA3-Personal-based authentication with the wireless display.

12. A computing system comprising:

one or more processors; and

computer storage media storing BIOS which when executed by the one or more processors during a boot process on the computing system perform a method for connecting securely to a wireless display during the boot process, the method comprising:

performing, by the BIOS, the boot process prior to loading an operating system on the computing system;

during the boot process, detecting the wireless display;

during the boot process, authenticating with the wireless display;

while performing the boot process, detecting that the wireless display is compliant with High-Bandwidth Digital Content Protection (HDCP) by receiving a certificate from the wireless display and verifying the certificate against a BIOS-based certificate store;

generating encrypted video frames that comply with the HDCP using a shared session key that is generated as part of authenticating with the wireless display during the boot process; and

wirelessly sending the encrypted video frames to the wireless display during the boot process.

13. The computing system of claim 12 , wherein the method further comprises:

including a timeout in the encrypted video frames.

14. The computing system of claim 12 , wherein the shared session key is stored in an Advanced Configuration and Power Interface (ACPI) data structure.

15. The method of claim 1 , further comprising:

storing the shared session key in an Advanced Configuration and Power Interface (ACPI) secure blob;

generating an ACPI node that includes the ACPI secure blob; and

loading the operating system;

wherein the operating system is enabled to access the shared session key in the ACPI secure blob stored in the ACPI node to continue generating and sending encrypted video frames to the wireless display after the boot process.

16. The method of claim 1 , wherein the BIOS generates and sends the encrypted video frames during a Driver Execution Environment (DXE) phase of the boot process.

17. The method of claim 1 , wherein the BIOS includes a BIOS network communication platform, a video authentication session module, a video frame buffer, a group of pictures, and an ACPI secure blob by which the encrypted video frames that comply with the HDCP are generated and sent to the wireless display.

18. The method of claim 1 , wherein authenticating with the wireless display comprises receiving input from a third device and using the input as part of authenticating with the wireless display.

19. The method of claim 18 , wherein the third device is a mobile phone and the input is a password.

20. The method of claim 1 , wherein authenticating with the wireless display comprises establishing a secure Wi-Fi connection between the BIOS and the wireless display, and wherein detecting that the wireless display is compliant with the HDCP is performed via the secure Wi-Fi connection.

Assignments (13)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0917) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0509 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052852/0022) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0582 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0081) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0441 →
RELEASE OF SECURITY INTEREST AT REEL 052771 FRAME 0906 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0298 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0081 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0917 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052852/0022 →
SECURITY AGREEMENT Recorded May 28, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052771/0906 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2020
From: SURYANARAYANA, SHEKAR BABU; VIDYADHARA, SUMANTH
To: DELL PRODUCTS L.P.
Reel/Frame 051703/0344 →