IP Library Granted Patent US 11,422,788
Granted Patent B2
US 11,422,788 · App. 16/995,561 · Granted Aug 23, 2022

Deploying firmware updates

Inventors: Balasingh P. Samuel (Round Rock, TX); Sungsup Lee (Pflugerville, TX)
Assignee: Dell Products L.P.
G06F8/65G06F8/71G06F9/4401
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,422,788
App. No.
16/995,561
Granted
Aug 23, 2022
Kind
B2
Abstract

Firmware updates are packaged in a manner that enables a firmware update utility to be executed to provide control functionality for deployment of the firmware updates while leveraging an operating system provided update framework to deliver the firmware updates to pre-boot environment. Accordingly, control over the deployment of the firmware updates is provided without difficulties and security risks of employing a custom kernel-mode driver to deliver the firmware updates.

Claims (51)

1. A method for deploying firmware updates on a computing device that includes an operating system (OS), the method comprising:

creating, by an update provider, a firmware update package executable by:

creating a capsule that contains one or more firmware updates;

creating a firmware update package that includes the capsule;

submitting the firmware update package to an OS provider for signing;

receiving the signed firmware update package from the OS provider; and

wrapping the signed firmware update package with a firmware update utility;

receiving, at an agent executing on the computing device, the firmware update package executable that includes the signed firmware update package that was wrapped with the firmware update utility;

initiating, by the agent, execution of the firmware update package executable to thereby cause the firmware update utility to be launched on the computing device;

providing, by the firmware update utility that has been launched on the computing device and prior to delivering the signed firmware update package that was wrapped with the firmware update utility to an OS-provided update framework, control functionality for deployment of the one or more firmware updates contained in the signed firmware update package that was wrapped with the firmware update utility, the control functionality including one or more of:

displaying a user interface on the computing device;

executing one or more scripts before delivering the signed firmware update package that was wrapped with the firmware update utility to the OS-provided update framework; and

performing one or more prerequisite checks before delivering the signed firmware update package that was wrapped with the firmware update utility to the OS-provided update framework; and

after providing the control functionality, delivering, by the firmware update utility, the signed firmware update package that was wrapped with the firmware update utility to the OS-provided update framework to thereby cause the capsule containing the one or more firmware updates to be conveyed from an OS context to a pre-boot context on the computing device only after providing the control functionality.

2. The method of claim 1 , wherein the one or more scripts are dynamically generated.

3. The method of claim 1 , wherein the OS provider is Microsoft and the OS-provided update framework is Windows Update.

4. The method of claim 1 , wherein the update provider signs each of the one or more firmware updates in the capsule and creates a capsule header.

5. The method of claim 4 , wherein the update provider also signs the firmware update package using an extended validation code signing certificate before submitting the firmware update package to the OS provider for signing.

6. The method of claim 5 , wherein the update provider includes metadata in the firmware update package, the metadata including an INF file that defines an EFI System Resource Table (ESRT) globally unique identifier (GUID) for a class of firmware to which the one or more firmware updates in the capsule pertain.

7. One or more computer storage media storing computer executable instructions, which when executed, implement a method for deploying firmware updates on a computing device that includes an operating system (OS), the method comprising:

creating, by an update provider, a firmware update package executable by:

creating a capsule that contains one or more firmware updates;

creating a firmware update package that includes the capsule;

submitting the firmware update package to an OS provider for signing;

receiving the signed firmware update package from the OS provider; and

wrapping the signed firmware update package with a firmware update utility;

delivering, to an agent that is executing on the computing device, the firmware update package executable that includes the signed firmware update package that was wrapped with the firmware update utility;

initiating, by the agent on the computing device, execution of the firmware update package executable to thereby cause the firmware update utility to be launched on the computing device;

providing, by the firmware update utility that has been launched on the computing device and prior to delivering the signed firmware update package that was wrapped with the firmware update utility to an OS-provided update framework, control functionality for deployment of the one or more firmware updates contained in the signed firmware update package that was wrapped with the firmware update utility, the control functionality including each of:

displaying a user interface on the computing device;

executing one or more scripts before delivering the signed firmware update package that was wrapped with the firmware update utility to the OS-provided update framework; and

performing one or more prerequisite checks before delivering the signed firmware update package that was wrapped with the firmware update utility to the OS-provided update framework; and

after providing the control functionality, delivering, by the firmware update utility, the signed firmware update package that was wrapped with the firmware update utility to the OS-provided update framework to thereby cause the one or more firmware updates to be conveyed from an OS context to a pre-boot context on the computing device only after providing the control functionality.

8. The computer storage media of claim 7 , wherein the one or more scripts are dynamically generated.

9. The computer storage media of claim 7 , wherein the firmware update utility does not include a kernel-mode driver.

10. A method for deploying firmware updates on a computing device that includes an operating system (OS), the method comprising:

creating, by an update provider, a firmware update package executable by:

signing each of one or more firmware updates;

creating a capsule that contains the one or more signed firmware updates and a capsule header;

creating a firmware update package that includes the capsule and metadata, the metadata including an INF file that defines an Extensible Firmware Interface (EFI) System Resource Table (ESRT) globally unique identifier (GUID) for a class of firmware to which the one or more signed firmware updates in the capsule pertain;

signing, by the update provider, the firmware update package using an extended validation code signing certificate;

submitting the firmware update package that is signed using the extended validation code signing certificate to an OS provider for signing with a security catalog;

receiving the signed firmware update package that has been signed by the update provider using the extended validation code signing certificate and has been signed by the OS provider using the security catalog; and

wrapping the signed firmware update package with a firmware update utility;

receiving, at an agent executing on the computing device, the firmware update package executable that includes the signed firmware update package that was wrapped with the firmware update utility;

initiating, by the agent, execution of the firmware update package executable to thereby cause the firmware update utility to be launched on the computing device;

providing, by the firmware update utility that has been launched on the computing device and prior to delivering the signed firmware update package that was wrapped with the firmware update utility to an OS-provided update framework, control functionality for deployment of the one or more signed firmware updates contained in the signed firmware update package that was wrapped with the firmware update utility, the control functionality including one or more of:

displaying a user interface on the computing device;

executing one or more scripts before delivering the signed firmware update package that was wrapped with the firmware update utility to the OS-provided update framework; and

performing one or more prerequisite checks before delivering the signed firmware update package that was wrapped with the firmware update utility to the OS-provided update framework; and

after providing the control functionality, delivering, by the firmware update utility, the signed firmware update package that was wrapped with the firmware update utility to the OS-provided update framework to thereby cause the capsule containing the one or more signed firmware updates to be conveyed from an OS context to a pre-boot context on the computing device only after providing the control functionality.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2020
From: SAMUEL, BALASINGH P.; LEE, SUNGSUP
To: DELL PRODUCTS L.P.
Reel/Frame 053516/0428 →
Cited By (2)
US 12,293,182 US 12,530,279