Information handling apparatus and method for unlocking a persistent region in memory
Methods, systems, and apparatuses for unlocking a persistent region in memory are disclosed. An information handling apparatus includes a controller, a memory coupled to the controller, the memory having a persistent region that can either be locked or unlocked, and a firmware configured to determine whether the persistent region of the memory is locked, obtain a stored passphrase from a storage device if the persistent region is locked, and use the passphrase to unlock the persistent region of the memory.
1. A method for unlocking a persistent region in a memory of an information handling apparatus, the method comprising:
during a boot process of the information handling apparatus, automatically performing:
configuring a firmware of the information handling apparatus to determine whether the persistent region in the memory is locked;
when the persistent region is locked, instructing a controller of the information handling apparatus to obtain a stored passphrase from a storage device, wherein the controller and the storage device are external to the memory; and
using the passphrase to unlock the persistent region in the memory of the information handling apparatus.
2. The method according to claim 1 , wherein the firmware is a unified extensible firmware interface (UEFI).
3. The method according to claim 1 , further comprising:
accessing, by the controller, the storage device for the passphrase; and
returning, by a processor of the information handling apparatus, the passphrase to the firmware.
4. The method according to claim 3 , wherein the controller is a baseboard management controller (BMC) of the information handling apparatus.
5. The method according to claim 1 , wherein the persistent region is formed in a non-volatile dual in-line memory module (NVDIMM).
6. The method according to claim 5 , wherein the persistent region is interleaved on a plurality of NVDIMMs.
7. The method according to claim 1 , wherein the storage device is at least one of a local server and a remote server connected to the information handling apparatus.
8. The method according to claim 1 , wherein the storage device is formed as part of a baseboard management controller (BMC) of the information handling apparatus.
9. The method according to claim 1 , further comprising, prior to determining, by the firmware, whether the persistent region in the memory is locked, storing the passphrase to the storage device.
10. The method according to claim 9 , wherein storing the passphrase to the storage device further comprises:
receiving the passphrase from a user input;
setting the passphrase to the persistent region in the memory of the information handling apparatus; and
saving the passphrase to the storage device.
11. An information handling apparatus, comprising:
a controller;
a memory coupled to the controller, the memory having a persistent region that can either be locked or unlocked; and
a firmware configured to, automatically during a boot process of the information handling apparatus:
determine whether the persistent region of the memory is locked;
instruct the controller to obtain a stored passphrase from a storage device when the persistent region is locked, wherein the controller and the storage device are external to the memory; and
use the passphrase to unlock the persistent region of the memory.
12. The information handling apparatus according to claim 11 , wherein the firmware is a unified extensible firmware interface (UEFI).
13. The information handling apparatus according to claim 11 , wherein the controller is a baseboard management controller (BMC).
14. The information handling apparatus of claim 13 , wherein the storage device is formed as part of the BMC.
15. The information handling apparatus according to claim 11 , wherein the persistent region is formed in a non-volatile dual in-line memory module (NVDIMM).
16. The information handling apparatus according to claim 11 , wherein the persistent region is interleaved on a plurality of NVDIMMs.
17. The information handling apparatus according to claim 11 , wherein the storage device is at least one of a local server and a remote server connected to the information handling apparatus.