IP Library Granted Patent US 11,281,471
Granted Patent B2
US 11,281,471 · App. 16/791,843 · Granted Mar 22, 2022

Systems and methods for minimizing boot time and minimizing unauthorized access and attack surface in basic input/output system

Inventors: Balasingh P. Samuel (Round Rock, TX); Anand Prakash Joshi (Round Rock, TX)
Assignee: Dell Products L.P.
G06F9/441G06F21/572G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,281,471
App. No.
16/791,843
Granted
Mar 22, 2022
Kind
B2
Abstract

An information handling system may include a processor and a basic input/output system communicatively coupled to the processor and comprising a plurality of firmware volumes embodied in non-transitory computer readable media, each firmware volume comprising executable code for a respective functionality of the basic input/output system, wherein the basic input/output system is configured to, based on the presence or absence of an action or event associated with the basic input/output system, select a boot path for execution from a plurality of boot paths, each of the plurality of boot paths comprising a respective trust chain of a subset of the plurality of firmware volumes and execute the boot path selected.

Claims (31)

1. An information handling system comprising:

a processor; and

a basic input/output system communicatively coupled to the processor and comprising a plurality of firmware volumes embodied in non-transitory computer readable media, each firmware volume comprising executable code for a respective functionality of the basic input/output system, wherein the basic input/output system is configured to, based on the presence or absence of an action or event associated with the basic input/output system:

select a boot path for execution from a plurality of boot paths, each of the plurality of boot paths comprising a respective trust chain for a subset of the plurality of firmware volumes wherein each firmware volume prior to a last firmware volume in each subset of the plurality of firmware volumes includes a hash value for verifying a next firmware volume in the respective trust chain; and

execute the boot path selected.

2. The information handling system of claim 1 , wherein the plurality of boot paths comprises an accelerated boot path for booting to an operating system of the information handling system.

3. The information handling system of claim 2 , wherein the accelerated boot path excludes firmware volumes of the plurality of firmware volumes for performing configuration of the basic input/output system.

4. The information handling system of claim 2 , wherein the accelerated boot path excludes firmware volumes of the plurality of firmware volumes for performing diagnostics of the information handling system.

5. The information handling system of claim 1 , wherein the plurality of boot paths comprises an exception boot path for performing configuration of the basic input/output system.

6. The information handling system of claim 1 , wherein the plurality of boot paths comprises an exception boot path for performing diagnostics of the information handling system.

7. The information handling system of claim 1 , wherein the plurality of firmware volumes comprises a base firmware volume configured to, based on the presence or absence of the action or event associated with the basic input/output system, select another firmware volume for execution from a plurality of other firmware volumes and wherein each of the plurality of boot paths includes the base volume within its subset of firmware volumes.

8. A method comprising, in a basic input/output system communicatively coupled to a processor and comprising a plurality of firmware volumes embodied in non-transitory computer readable media, each firmware volume comprising executable code for a respective functionality of the basic input/output system, wherein the basic input/output system is configured to, based on the presence or absence of an action or event associated with the basic input/output system:

selecting a boot path for execution from a plurality of boot paths, each of the plurality of boot paths comprising a respective trust chain of a subset of the plurality of firmware volumes wherein each firmware volume prior to a last firmware volume in each subset of the plurality of firmware volumes includes a hash value for verifying a next firmware volume in the respective trust chain; and

executing the boot path selected.

9. The method of claim 8 , wherein the plurality of boot paths comprises an accelerated boot path for booting to an operating system of an information handling system.

10. The method of claim 9 , wherein the accelerated boot path excludes firmware volumes of the plurality of firmware volumes for performing configuration of the basic input/output system.

11. The method of claim 9 , wherein the accelerated boot path excludes firmware volumes of the plurality of firmware volumes for performing diagnostics of the information handling system.

12. The method of claim 8 , wherein the plurality of boot paths comprises an exception boot path for performing configuration of the basic input/output system.

13. The method of claim 8 , wherein the plurality of boot paths comprises an exception boot path for performing diagnostics of the information handling system.

14. The method of claim 8 , wherein the plurality of firmware volumes comprises a base firmware volume configured to, and the method further comprises, based on the presence or absence of the action or event associated with the basic input/output system, selecting, by the base firmware volume, another firmware volume for execution from a plurality of other firmware volumes and wherein each of the plurality of boot paths includes the base volume within its subset of firmware volumes.

15. An article of manufacture comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to, in a basic input/output system communicatively coupled to the processor and comprising a plurality of firmware volumes embodied in non-transitory computer readable media, each firmware volume comprising executable code for a respective functionality of the basic input/output system, wherein the basic input/output system is configured to, based on the presence or absence of an action or event associated with the basic input/output system:

select a boot path for execution from a plurality of boot paths, each of the plurality of boot paths comprising a respective trust chain of a subset of the plurality of firmware volumes wherein each firmware volume prior to a last firmware volume in each subset of the plurality of firmware volumes includes a hash value for verifying a next firmware volume in the respective trust chain; and

execute the boot path selected.

16. The article of claim 15 , wherein the plurality of boot paths comprises an accelerated boot path for booting to an operating system of an information handling system.

17. The article of claim 16 , wherein the accelerated boot path excludes firmware volumes of the plurality of firmware volumes for performing configuration of the basic input/output system.

18. The article of claim 16 , wherein the accelerated boot path excludes firmware volumes of the plurality of firmware volumes for performing diagnostics of the information handling system.

19. The article of claim 15 , wherein the plurality of boot paths comprises an exception boot path for performing configuration of the basic input/output system.

20. The article of claim 15 , wherein the plurality of boot paths comprises an exception boot path for performing diagnostics of the information handling system.

21. The article of claim 15 , wherein the plurality of firmware volumes comprises a base firmware volume configured to, and the instructions further cause the processor to, based on the presence or absence of the action or event associated with the basic input/output system, select, by the base firmware volume, another firmware volume for execution from a plurality of other firmware volumes and wherein each of the plurality of boot paths includes the base volume within its subset of firmware volumes.

Assignments (13)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0081) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0441 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0917) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0509 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052852/0022) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0582 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 052771 FRAME 0906 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0298 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0081 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0917 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052852/0022 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded May 28, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052771/0906 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2020
From: SAMUEL, BALASINGH P.; JOSHI, ANAND P.
To: DELL PRODUCTS L.P.
Reel/Frame 051826/0225 →