IP Library Granted Patent US 11,445,027
Granted Patent B2
US 11,445,027 · App. 17/068,407 · Granted Sep 13, 2022

System and method for platform session management using device integrity measurements

Inventors: Viswanath Ponnuru (Bangalore, IN); Lee Eric Ballard (Georgetown, TX); Chandrasekhar Mugunda (Austin, TX); Rama Rao Bisa (Bangalore, IN); Chandrashekar Nelogal (Round Rock, TX)
Assignee: Dell Products L.P.
H04L67/141G06F8/65G06F8/71H04L9/3263H04L67/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,445,027
App. No.
17/068,407
Granted
Sep 13, 2022
Kind
B2
Abstract

A management controller sends a first firmware measurement request to verify integrity of a device. The first firmware measurement request is sent at initial power on of the device, and is sent subsequent to negotiating a secure session between the management controller and the device. The management controller verifies a first firmware measurement in a first firmware measurement response to the first firmware measurement request prior to storing the first firmware measurement, and sends a heartbeat request to the device to monitor for a device state change. The management controller may receive a heartbeat acknowledgement from the device in response to the heartbeat request, wherein the heartbeat acknowledgement includes an indication of the device state change. In response to the receipt of the heartbeat acknowledgment that includes the device state change, the management controller sends a second firmware measurement request to the device. The management controller may also verify a second firmware measurement included in a second firmware measurement response to the second firmware measurement request that includes a comparison of the first firmware measurement and the second firmware measurement; and apply a security policy to the device based on the device state change.

Claims (43)

1. A method comprising:

sending, by a management controller, a first firmware measurement request to a device to verify integrity of the device, wherein the first firmware measurement request is sent at initial power on of the device, wherein the sending the first firmware measurement request is subsequent to negotiating a secure session between the management controller and the device, and wherein the management controller and the device are components of a platform system;

verifying a first firmware measurement included in a first firmware measurement response to the first firmware measurement request prior to storing the first firmware measurement in a measurement manifest;

monitoring the device to detect a device state change by periodically sending a heartbeat request to the device;

receiving a heartbeat acknowledgement from the device in response to the heartbeat request, wherein the heartbeat acknowledgement includes an indication of the device state change during the secure session between the management controller and the device;

in response to the receiving the heartbeat acknowledgment that include the indication of the device state change, sending a second firmware measurement request to the device;

verifying a second firmware measurement included in a second firmware measurement response to the second firmware measurement request, wherein the verifying includes comparing the second firmware measurement with the first firmware measurement according to the measurement manifest; and

applying a security policy to the device based on the device state change.

2. The method of claim 1 , further comprising subseuqent to indication of the device state change, re-negotiating the secure session between the management controller and the device.

3. The method of claim 1 , wherein the indication of the device state change includes a change in the first firmware measurement of the device.

4. The method of claim 1 , wherein the indication of the device state change includes a change in a firmware certificate of the device.

5. The method of claim 1 , wherein the indication of the device state change includes a bit zero that is set to a value of one from an initial value of zero to indicate a change in the first firmware measurement of the device.

6. The method of claim 1 , wherein the indication of the device state change includes a bit one that is set to a value of one from an initial value of zero to indicate a change in a firmware certificate of the device.

7. The method of claim 1 , wherein the verifying the second firmware measurement includes decrypting the second firmware measurement using a public key associated with the device.

8. The method of claim 1 , further comprising terminating the secure session and marking the secure session for quarantine if the device is in an administrative lockdown mode.

9. The method of claim 1 , further comprising re-negotiating the secure session if the device is in an administrative non-lockdown mode.

10. An information handling system, comprising:

a device managed by a management controller; and

the management controller configured to communicate with the device, and to:

send a first firmware measurement request to the device to verify integrity of the device, wherein the first firmware measurement request is sent at initial power on of the device, wherein the first firmware measurement request is sent subsequent to negotiating a secure session between the management controller and the device and wherein the management controller and the device are components of a platform system;

verify a first firmware measurement in a first firmware measurement response to the first firmware measurement request prior to storing the first firmware measurement in a measurement manifest;

send a heartbeat request to the device to monitor for a device state change;

receive a heartbeat acknowledgement from the device in response to the heartbeat request, wherein the heartbeat acknowledgement includes an indication of the device state change;

in response to the receipt of the heartbeat acknowledgment that includes the device state change, sending a second firmware measurement request to the device during the secure session between the management controller and the device;

verify a second firmware measurement included in a second firmware measurement response to the second firmware measurement request that includes a comparison of the first firmware measurement and the second firmware measurement according to the measurement manifest; and

apply a security policy to the device based on the device state change.

11. The information handling system of claim 10 , wherein the management controller is further configured to re-negotiate the secure session between the management controller and the device.

12. The information handling system of claim 10 , wherein the heartbeat acknowledgment response includes a field associated with a change in the first firmware measurement of the device.

13. The information handling system of claim 10 , wherein the heartbeat acknowledgement response includes a field associated with a change in a firmware certificate of the device.

14. The information handling system of claim 10 , wherein the management controller is further configured to re-negotiate the secure session if the management controller is in administrative non-lockdown mode.

15. The information handling system of claim 10 , wherein the management controller is further configured terminate the secure session and puts the secure session in quarantine.

16. A non-transitory computer-readable medium including code that when executed performs a method, the method comprising:

sending a first firmware measurement request to a device to verify integrity of the device, wherein the first firmware measurement request is sent to the device at initial power on of the device, and wherein the sending the first firmware measurement request is subsequent to negotiating a secure session between a management controller and the device, wherein the management controller and the device are components of a platform subsystem;

verifying a first firmware measurement included in a first firmware measurement response to the first firmware measurement request prior to storing the first firmware measurement in a measurement manifest;

monitoring the device to detect a device state change by sending a heartbeat request to the device periodically;

receiving a heartbeat acknowledgement response from the device in response to the heartbeat request, wherein the heartbeat acknowledgement response includes an indication of the device state change during the secure session between the management controller and the device;

in response to the receiving the heartbeat acknowledgment response that include the indication of the device state change, sending a second firmware measurement request to the device;

verifying a second firmware measurement included in a second firmware measurement response to the second firmware measurement request, wherein the verifying includes comparing the second firmware measurement with the first firmware measurement according to the measurement manifest; and

applying a security policy to the device based on the device state change.

17. The method of claim 16 , further comprising re-negotiating the secure session if the device is in an administrative non-lockdown mode.

18. The method of claim 16 , further comprising terminating the secure session and marking the secure session for quarantine if the device is in an administrative lockdown mode.

19. The method of claim 16 , wherein the indication of the device state change includes a change in a firmware certificate of the device.

20. The method of claim 16 , wherein the indication of the device state change includes a change in the first firmware measurement of the device.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2020
From: PONNURU, VISWANATH; BALLARD, LEE ERIC; MUGUNDA, CHANDRASEKHAR; BISA, RAMA RAO; NELOGAL, CHANDRASHEKAR
To: DELL PRODUCTS, LP
Reel/Frame 054029/0811 →