IP Library Granted Patent US 11,500,994
Granted Patent B2
US 11,500,994 · App. 17/029,409 · Granted Nov 15, 2022

Communication system personality provisioning system

Inventors: Mukund P. Khatri (Austin, TX); Jimmy D. Pike (Georgetown, TX); Gaurav Chawla (Austin, TX); William Price Dawkins (Lakeway, TX); Elie Jreij (Pflugerville, TX); Mark Steven Sanders (Roanoke, VA); Walter A. O'Brien, III (Westborough, MA); Robert W. Hormuth (Cedar Park, TX)
Assignee: Dell Products L.P.
G06F21/575G06F8/63G06F9/547G06F21/44G06F21/572H04L9/30G06F9/4401G06F2221/033G06Q10/10G06Q30/0185
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,500,994
App. No.
17/029,409
Granted
Nov 15, 2022
Kind
B2
Abstract

A communication system personality provisioning system includes a communication system included in a computing system and coupled to a management system. The communication system stores authentication information in a UEFI database of a UEFI system in the communication system. The communication system receives a first operating software image and application/service from the management system, authenticates the first operating software image and application/service via first secure initialization operations performed by the UEFI system using the authentication information and, in response, installs the first operating software image and application/service on the communication system. The communication system subsequently receives a second operating software image and application/service from the management system, authenticates the second operating software image and application/service via second secure initialization operations performed by the UEFI system using the authentication information and, in response, installs the second operating software image and application/service on the communication system.

Claims (48)

1. A communication system personality provisioning system, comprising:

a management system;

a computing system; and

a communication system that is included in the computing system and that is coupled to the management system, wherein the communication system is configured to:

store authentication information in a Unified Extensible Firmware Interface (UEFI) database that is part of a UEFI system that is included in the communication system;

receive, from the management system, a first operating software image and at least one first application/service;

authenticate, via first secure initialization operations performed by the UEFI system using the authentication information, the first operating software image and the at least one first application/service and, in response, install the first operating software image and the at least one first application/service on the communication system;

receive, from the management system subsequent to installing the first operating software image and the at least one first application/service on the computing device, a second operating software image and at least one second application/service; and

authenticate, via second secure initialization operations performed by the UEFI system using the authentication information, the second operating software image and the at least one second application/service and, in response, install the second operating software image and the at least one second application/service on the communication system.

2. The system of claim 1 , wherein the management system includes a Baseboard Management Controller system that is included in the computing device and that is coupled to the communication system.

3. The system of claim 1 , wherein the management system is coupled to the communication system via a network.

4. The system of claim 1 , wherein the authentication information includes at least one public key, wherein the authenticating the first operating software image and the at least one first application/service includes determining that the first operating software image and the at least one first application/service have been signed with at least one private key corresponding to the at least one public key, and wherein the authenticating the second operating software image and the at least one second application/service includes determining that the second operating software image and the at least one second application/service have been signed with at least one private key corresponding to the at least one public key.

5. The system of claim 1 , wherein the first secure initialization operations and the second secure initialization operations include UEFI secure boot operations.

6. The system of claim 1 , wherein the communication system is configured to:

prevent, subsequent to installing the first operating software image on the computing system, storage of data on the communication system without operating software authorization; and

receive the operating software authorization to store the second operating software image and at least one second application/service on the communication system and, in response, store the second operating software image and at least one second application/service on the communication system.

7. A communication system, comprising:

a communication processing system; and

a communication memory system that is coupled to the communication processing system and that includes instructions that, when executed by the communication processing system, cause the communication processing system to provide a communication system personality provisioning engine that is configured to:

store authentication information in a Unified Extensible Firmware Interface (UEFI) database that is part of a UEFI system that is included in the communication system;

receive, from a management system, a first operating software image and at least one first application/service;

authenticate, via first secure initialization operations using the authentication information, the first operating software image and the at least one first application/service and, in response, install the first operating software image and the at least one first application/service on the communication system;

receive, from the management system subsequent to installing the first operating software image and the at least one first application/service on the computing device, a second operating software image and at least one second application/service; and

authenticate, via second secure initialization operations using the authentication information, the second operating software image and the at least one second application/service and, in response, install the second operating software image and the at least one second application/service on the communication system.

8. The communication system of claim 7 , wherein the management system includes a Baseboard Management Controller system that is included in the computing device and that is coupled to the communication system.

9. The communication system of claim 7 , wherein the management system is coupled to the communication system via a network.

10. The communication system of claim 7 , wherein the authentication information includes at least one public key, wherein the authenticating the first operating software image and the at least one first application/service includes determining that the first operating software image and the at least one first application/service have been signed with at least one private key corresponding to the at least one public key, and wherein the authenticating the second operating software image and the at least one second application/service includes determining that the second operating software image and the at least one second application/service have been signed with at least one private key corresponding to the at least one public key.

11. The communication system of claim 7 , wherein the first secure initialization operations and the second secure initialization operations include UEFI secure boot operations.

12. The communication system of claim 7 , wherein the personality provisioning engine is configured to:

prevent, subsequent to installing the first operating software image on the computing system, storage of data on the communication system without operating software authorization; and

receive the operating software authorization to store the second operating software image and at least one second application/service on the communication system and, in response, store the second operating software image and at least one second application/service on the communication system.

13. The communication system of claim 12 , wherein the preventing the storage of data on the communication system without operating software authorization includes:

locking each Application Programming Interface (API) that allows the storage of data on the communication system, wherein the operating software authorization is configured to provide for the unlocking of each API that allows the storage of data on the communication system.

14. A method for providing personalities on a communication system, comprising:

storing, by a communication system, authentication information in a Unified Extensible Firmware Interface (UEFI) database that is part of a UEFI system that is included in the communication system;

receiving, by the communication system from a management system, a first operating software image and at least one first application/service;

authenticating, by the communication system via first secure initialization operations using the authentication information, the first operating software image and the at least one first application/service and, in response, installing the first operating software image and the at least one first application/service on the communication system;

receiving, by the communication system from the management system subsequent to installing the first operating software image and the at least one first application/service on the computing device, a second operating software image and at least one second application/service;

authenticating, by the communication system via second secure initialization operations using the authentication information, the second operating software image and the at least one second application/service and, in response, install the second operating software image and the at least one second application/service on the communication system.

15. The method of claim 14 , wherein the management system includes a Baseboard Management Controller system that is included in the computing device and that is coupled to the communication system.

16. The method of claim 14 , wherein the management system is coupled to the communication system via a network.

17. The method of claim 14 , wherein the authentication information includes at least one public key, wherein the authenticating the first operating software image and the at least one first application/service includes determining that the first operating software image and the at least one first application/service have been signed with at least one private key corresponding to the at least one public key, and wherein the authenticating the second operating software image and the at least one second application/service includes determining that the second operating software image and the at least one second application/service have been signed with at least one private key corresponding to the at least one public key.

18. The method of claim 14 , wherein the first secure initialization operations and the second secure initialization operations include UEFI secure boot operations.

19. The method of claim 14 , further comprising:

preventing, by the communication system subsequent to installing the first operating software image on the computing system, storage of data on the communication system without operating software authorization; and

receiving, by the communication system, the operating software authorization to store the second operating software image and at least one second application/service on the communication system and, in response, store the second operating software image and at least one second application/service on the communication system.

20. The method of claim 19 , wherein the preventing the storage of data on the communication system without operating software authorization includes:

locking each Application Programming Interface (API) that allows the storage of data on the communication system, wherein the operating software authorization is configured to provide for the unlocking of each API that allows the storage of data on the communication system.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2020
From: KHATRI, MUKUND P.; PIKE, JIMMY D.; CHAWLA, GAURAV; DAWKINS, WILLIAM PRICE; JREIJ, ELIE; SANDERS, MARK STEVEN; O'BRIEN, WALTER A., III; HORMUTH, ROBERT W.
To: DELL PRODUCTS L.P.
Reel/Frame 053859/0363 →