Systems and methods for binding secondary operating system to platform basic input/output system
An information handling system may include a processor, non-transitory computer readable media communicatively coupled to the processor and having stored thereon a primary operating system of the information handling system and a secondary operating system of the information handling system, and a basic input/output system communicatively coupled to the processor and having provisioned thereon a signed signature of the secondary operating system signed with a private key of a public-private key pair and a public key of the public-private key pair. The basic input/output system is configured to, responsive to a determination to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system verify the secondary operating system using the signed signature of the secondary operating system and the public key and responsive to verifying the secondary operating system, allow the information handling system to boot to the secondary operating system.
1. An information handling system comprising:
a processor;
non-transitory computer readable media communicatively coupled to the processor and having stored thereon a primary operating system of the information handling system and a secondary operating system of the information handling system; and
a basic input/output system communicatively coupled to the processor and having provisioned thereon:
a signed signature of the secondary operating system signed with a private key of a public-private key pair; and
a public key of the public-private key pair;
wherein the basic input/output system is configured to, responsive to a determination to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
verify the secondary operating system using the signed signature of the secondary operating system and the public key;
responsive to verifying the secondary operating system, allow the information handling system to boot to the secondary operating system; and
responsive to failed verification of the secondary operating system:
download to the non-transitory computer readable media a replacement image of the secondary operating system;
verify the secondary operating system using the signed signature of the secondary operating system and the public key; and
responsive to verifying the replacement image of the secondary operating system, allow the information handling system to boot to the replacement image of the secondary operating system.
2. The information handling system of claim 1 , wherein the basic input/output system is configured to verify the secondary operating system by:
generating a signature of an image of the secondary operating system as stored within the non-transitory computer-readable media;
decrypting the signed signature of the secondary operating system to generate an unsigned signature; and
comparing the signature of an image of the secondary operating system as stored within the non-transitory computer-readable media with the unsigned signature.
3. The information handling system of claim 1 , wherein the signed signature of the secondary operating system is a hash of an image of the secondary operating system.
4. The information handling system of claim 1 , wherein the basic input/output system is further configured to, responsive to the determination to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
determine if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive; and
if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive, authenticate a namespace of a partition of the Non-Volatile Memory Enhanced hard drive having the secondary operating system stored therein.
5. The information handling system of claim 4 , the basic input/output system configured to authenticate the namespace based on the public key and an encryption of the partition using the private key.
6. A method, in an information handling system comprising non-transitory computer readable media having stored thereon a primary operating system of the information handling system and a secondary operating system of the information handling system and the information handling system further comprising a basic input/output system communicatively having provisioned thereon a signed signature of the secondary operating system signed with a private key of a public-private key pair and a public key of the public-private key pair, the method comprising:
responsive to a determination by the basic input/output system to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
verifying, with the basic input/output system, the secondary operating system using the signed signature of the secondary operating system and the public key;
responsive to verifying the secondary operating system, allowing, by the basic input/output system, the information handling system to boot to the secondary operating system; and
responsive to failed verification of the secondary operating system:
downloading, by the basic input/output system, to the non-transitory computer readable media a replacement image of the secondary operating system;
verifying, by the basic input/output system, the secondary operating system using the signed signature of the secondary operating system and the public key; and
responsive to verifying the replacement image of the secondary operating system, allowing, by the basic input/output system, the information handling system to boot to the replacement image of the secondary operating system.
7. The method of claim 6 , further comprising verifying the secondary operating system by:
generating a signature of an image of the secondary operating system as stored within the non-transitory computer-readable media;
decrypting the signed signature of the secondary operating system to generate an unsigned signature; and
comparing the signature of an image of the secondary operating system as stored within the non-transitory computer-readable media with the unsigned signature.
8. The method of claim 6 , wherein the signed signature of the secondary operating system is a hash of an image of the secondary operating system.
9. The method of claim 6 , further comprising, responsive to the determination to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
determining if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive; and
if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive, authenticating a namespace of a partition of the Non-Volatile Memory Enhanced hard drive having the secondary operating system stored therein.
10. The method of claim 9 , further comprising authenticating the namespace based on the public key and an encryption of the partition using the private key.
11. An article of manufacture comprising:
a computer readable medium; and
computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to, in an information handling system comprising non-transitory computer readable media having stored thereon a primary operating system of the information handling system and a secondary operating system of the information handling system and the information handling system further comprising a basic input/output system communicatively having provisioned thereon a signed signature of the secondary operating system signed with a private key of a public-private key pair and a public key of the public-private key pair:
responsive to a determination by the basic input/output system to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
verify, with the basic input/output system, the secondary operating system using the signed signature of the secondary operating system and the public key;
responsive to verifying the secondary operating system, allow, by the basic input/output system, the information handling system to boot to the secondary operating system; and
responsive to failed verification of the secondary operating system:
download, by the basic input/output system, to the non-transitory computer readable media a replacement image of the secondary operating system;
verify, by the basic input/output system, the secondary operating system using the signed signature of the secondary operating system and the public key; and
responsive to verifying the replacement image of the secondary operating system, allow, by the basic input/output system, the information handling system to boot to the replacement image of the secondary operating system.
12. The article of claim 11 , the instructions for further causing the processor to verify the secondary operating system by:
generating a signature of an image of the secondary operating system as stored within the non-transitory computer-readable media;
decrypting the signed signature of the secondary operating system to generate an unsigned signature; and
comparing the signature of an image of the secondary operating system as stored within the non-transitory computer-readable media with the unsigned signature.
13. The article of claim 11 , wherein the signed signature of the secondary operating system is a hash of an image of the secondary operating system.
14. The article of claim 11 , the instructions for further causing the processor to, responsive to the determination to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
determining if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive; and
if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive, authenticating a namespace of a partition of the Non-Volatile Memory Enhanced hard drive having the secondary operating system stored therein.
15. The article of claim 14 , the instructions for further causing the processor to authenticate the namespace based on the public key and an encryption of the partition using the private key.
16. An information handling system comprising:
a processor;
non-transitory computer readable media communicatively coupled to the processor and having stored thereon a primary operating system of the information handling system and a secondary operating system of the information handling system; and
a basic input/output system communicatively coupled to the processor and having provisioned thereon:
a signed signature of the secondary operating system signed with a private key of a public-private key pair; and
a public key of the public-private key pair;
wherein the basic input/output system is configured to, responsive to a determination to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
verify the secondary operating system using the signed signature of the secondary operating system and the public key by:
generating a signature of an image of the secondary operating system as stored within the non-transitory computer-readable media;
decrypting the signed signature of the secondary operating system to generate an unsigned signature; and
comparing the signature of an image of the secondary operating system as stored within the non-transitory computer-readable media with the unsigned signature; and
responsive to verifying the secondary operating system, allow the information handling system to boot to the secondary operating system.
17. The information handling system of claim 16 , wherein the signed signature of the secondary operating system is a hash of an image of the secondary operating system.
18. The information handling system of claim 16 , wherein the basic input/output system is further configured to, responsive to the determination to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
determine if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive; and
if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive, authenticate a namespace of a partition of the Non-Volatile Memory Enhanced hard drive having the secondary operating system stored therein.
19. The information handling system of claim 18 , the basic input/output system configured to authenticate the namespace based on the public key and an encryption of the partition using the private key.
20. A method, in an information handling system comprising non-transitory computer readable media having stored thereon a primary operating system of the information handling system and a secondary operating system of the information handling system and the information handling system further comprising a basic input/output system communicatively having provisioned thereon a signed signature of the secondary operating system signed with a private key of a public-private key pair and a public key of the public-private key pair, the method comprising:
responsive to a determination by the basic input/output system to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
verifying, with the basic input/output system, the secondary operating system using the signed signature of the secondary operating system and the public key by:
generating a signature of an image of the secondary operating system as stored within the non-transitory computer-readable media;
decrypting the signed signature of the secondary operating system to generate an unsigned signature; and
comparing the signature of an image of the secondary operating system as stored within the non-transitory computer-readable media with the unsigned signature; and
responsive to verifying the secondary operating system, allowing, by the basic input/output system, the information handling system to boot to the secondary operating system.
21. The method of claim 20 , wherein the signed signature of the secondary operating system is a hash of an image of the secondary operating system.
22. The method of claim 20 , further comprising, responsive to the determination to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
determining if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive; and
if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive, authenticating a namespace of a partition of the Non-Volatile Memory Enhanced hard drive having the secondary operating system stored therein.
23. The method of claim 22 , further comprising authenticating the namespace based on the public key and an encryption of the partition using the private key.
24. An article of manufacture comprising:
a computer readable medium; and
computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to, in an information handling system comprising non-transitory computer readable media having stored thereon a primary operating system of the information handling system and a secondary operating system of the information handling system and the information handling system further comprising a basic input/output system communicatively having provisioned thereon a signed signature of the secondary operating system signed with a private key of a public-private key pair and a public key of the public-private key pair:
responsive to a determination by the basic input/output system to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
verify, with the basic input/output system, the secondary operating system using the signed signature of the secondary operating system and the public key by:
generating a signature of an image of the secondary operating system as stored within the non-transitory computer-readable media;
decrypting the signed signature of the secondary operating system to generate an unsigned signature; and
comparing the signature of an image of the secondary operating system as stored within the non-transitory computer-readable media with the unsigned signature; and
responsive to verifying the secondary operating system, allow, by the basic input/output system, the information handling system to boot to the secondary operating system.
25. The article of claim 24 , wherein the signed signature of the secondary operating system is a hash of an image of the secondary operating system.
26. The article of claim 24 , the instructions for further causing the processor to, responsive to the determination to boot to the secondary operating system in lieu of booting to the primary operating system of the information handling system:
determining if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive; and
if the secondary operating system is stored on a Non-Volatile Memory Enhanced hard drive, authenticating a namespace of a partition of the Non-Volatile Memory Enhanced hard drive having the secondary operating system stored therein.
27. The article of claim 26 , the instructions for further causing the processor to authenticate the namespace based on the public key and an encryption of the partition using the private key.