IP Library Granted Patent US 11,481,497
Granted Patent B2
US 11,481,497 · App. 17/018,416 · Granted Oct 25, 2022

Systems and methods for hardware attestation in an information handling system

Inventors: Anantha K. Boyapalle (Cedar Park, TX); Charles D. Robison (Buford, GA); Amy C. Nelson (Round Rock, TX)
Assignee: Dell Products L.P.
G06F21/572G06F21/554G06F21/72H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,481,497
App. No.
17/018,416
Granted
Oct 25, 2022
Kind
B2
Abstract

A method may include, during execution of a basic input/output system comprising boot firmware configured to be the first code executed by the processor when the information handling system is booted and/or powered on and execute prior to execution of an operating system of the information handling system, executing a hardware attestation verification application configured to: (i) read a platform certificate comprising information associated with one or more information handling resources of the information handling system recorded during creation of the platform certificate; (ii) perform hardware attestation of the information handling system by comparing information associated with the one or more information handling resources and the information stored within the platform certificate; and (iii) generate a log indicative of the results of the hardware attestation.

Claims (43)

1. An information handling system comprising:

a processor; and

a basic input/output system including boot firmware comprising the first code executed by the processor when the information handling system is booted and/or powered on and executed prior to execution of an operating system of the information handling system, the basic input/output system embodied in non-transitory computer-readable media communicatively coupled to the processor and configured, when loaded and executed by the processor, to execute a hardware attestation verification application prior to execution of an operating system of the information handling system wherein the hardware attestation verification application, when executed, performs operations including:

reading a platform certificate comprising identifying information associated with one or more hardware resources of the information handling system recorded during creation of the platform certificate;

comparing the identifying information associated with the one or more hardware resources and the information stored within the platform certificate; and

generating a log indicative of the comparing.

2. The information handling system of claim 1 , wherein the hardware attestation verification application performs the operations in accordance with a hardware attestation policy wherein the hardware attestation policy includes configuration parameters indicative of at least one of:

one of a plurality of selectable levels of attestation; and

a frequency parameter indicative of how often the operations are performed.

3. The information handling system of claim 2 , wherein the plurality of selectable levels of attestation include:

a first level for performing attestation of each of the one or more hardware resources; and

a second level for performing attestation of less than all of the one or more hardware resources.

4. The information handling system of claim 1 , wherein the platform certificate is created by a manufacturer of the information handling system prior to delivery of the information handling system to its intended end user.

5. The information handling system of claim 1 , wherein the information handling system comprises a cryptoprocessor and the platform certificate is bound to the information handling system by the cryptoprocessor.

6. The information handling system of claim 1 , wherein the platform certificate is cryptographically signed with a signature and the hardware attestation verification application is configured to verify the signature when performing hardware attestation.

7. A method comprising, during execution of a basic input/output system comprising boot firmware configured to be the first code executed by the processor when the information handling system is booted and/or powered on and execute prior to execution of an operating system of the information handling system, executing a hardware attestation verification application configured to perform operations including:

reading a platform certificate comprising identifying information associated with one or more hardware resources of the information handling system recorded during creation of the platform certificate;

comparing the identifying information associated with the one or more hardware resources and the information stored within the platform certificate; and

generating a log indicative of the results of the comparing.

8. The method of claim 7 , wherein the hardware attestation verification application performs the operations in accordance with a hardware attestation policy wherein the hardware attestation policy includes configuration parameters indicative of at least one of:

one of a plurality of selectable levels of attestation; and

a frequency parameter indicative of how often the operations are performed.

9. The method of claim 8 , wherein the plurality of selectable levels of attestation include:

a first level for performing attestation of each of the one or more hardware resources; and

a second level for performing attestation of less than all of the one or more hardware resources.

10. The method of claim 7 , wherein the platform certificate is created by a manufacturer of the information handling system prior to delivery of the information handling system to its intended end user.

11. The method of claim 7 , wherein the information handling system comprises a cryptoprocessor and the platform certificate is bound to the information handling system by the cryptoprocessor.

12. The method of claim 7 , wherein the platform certificate is cryptographically signed with a signature and the hardware attestation verification application is configured to verify the signature when performing hardware attestation.

13. An article of manufacture comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to, during execution of a basic input/output system comprising boot firmware configured to be the first code executed by the processor when the information handling system is booted and/or powered on and executed prior to execution of an operating system of the information handling system, executing a hardware attestation verification application configured to perform operations including:

reading a platform certificate comprising identifying information associated with one or more hardware resources of the information handling system recorded during creation of the platform certificate;

comparing the identifying information associated with the one or more hardware resources and the information stored within the platform certificate; and

generating a log indicative of the results of the comparing.

14. The article of claim 13 , wherein the hardware attestation verification application performs the operations in accordance with a hardware attestation policy wherein the hardware attestation policy includes configuration parameters indicative of at least one of:

one of a plurality of selectable levels of attestation; and

a frequency parameter indicative of how often the operations are performed.

15. The article of claim 14 , wherein the plurality of selectable levels of attestation include:

a first level for performing attestation of each of the one or more hardware resources; and

a second level for performing attestation of less than all of the one or more hardware resources.

16. The article of claim 13 , wherein the platform certificate is created by a manufacturer of the information handling system prior to delivery of the information handling system to its intended end user.

17. The article of claim 13 , wherein the information handling system comprises a cryptoprocessor and the platform certificate is bound to the information handling system by the cryptoprocessor.

18. The article of claim 13 , wherein the platform certificate is cryptographically signed with a signature and the hardware attestation verification application is configured to verify the signature when performing hardware attestation.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2020
From: BOYAPALLE, ANANTHA K.; ROBISON, CHARLES D.; NELSON, AMY C.
To: DELL PRODUCTS L.P.
Reel/Frame 053748/0396 →