IP Library Granted Patent US 11,630,898
Granted Patent B2
US 11,630,898 · App. 17/132,783 · Granted Apr 18, 2023

Systems and methods for providing secure logic device authentication, update, and recovery

Inventors: Timothy M. Lambert (Austin, TX); Milton Olavo Decarvalho Taveira (Round Rock, TX); Jeffrey L. Kennedy (Austin, TX)
Assignee: Dell Products L.P.
G06F21/572G06F8/65G06F12/1433G06F21/44G06F2212/1052G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,630,898
App. No.
17/132,783
Granted
Apr 18, 2023
Kind
B2
Abstract

An information handling system may include a host system comprising a host system processor, a logic device configured to perform a functionality of the information handling system in accordance with code stored on non-transitory computer-readable media of the logic device, and a management controller communicatively coupled to the host system processor and the logic device and configured to perform out-of-band management of the information handling system. The management controller may be further configured to: during a boot of the management controller, perform an initial authentication of the code via an immutable interface of the logic device, after the initial authentication and prior to completion of boot of the management controller, enable a hardware lock to prevent write access to the logic device via the immutable interface, and in response to a power on request of the host system, perform a second authentication of the code via a mutable interface of the logic device.

Claims (44)

1. An information handling system comprising:

a host system comprising a host system processor;

a logic device configured to perform a functionality of the information handling system in accordance with code stored on non-transitory computer-readable media of the logic device; and

a management controller communicatively coupled to the host system processor and the logic device and configured to perform out-of-band management of the information handling system, and further configured to:

during a boot of the management controller, perform an initial authentication of the code via an immutable interface of the logic device;

after the initial authentication and prior to completion of boot of the management controller, enable a hardware lock to prevent write access to the logic device via the immutable interface; and

in response to a power on request of the host system, perform a second authentication of the code via a mutable interface of the logic device.

2. The information handling system of claim 1 , wherein the management controller is further configured to perform a runtime authentication of the code via the mutable interface of the logic device during runtime of an operating system of the host system.

3. The information handling system of claim 2 , wherein the management controller is further configured to queue a recovery of the code on a subsequent power on request of the host system in response to failure of the runtime authentication of the code.

4. The information handling system of claim 1 , wherein the management controller is further configured to perform an automatic recovery of the code in response to one or both of a failure of the initial authentication of the code or the second authentication of the code.

5. The information handling system of claim 1 , wherein the management controller is further configured to, during the boot of the management controller, perform an update of the code via the immutable interface of the logic device.

6. The information handling system of claim 1 , further comprising a second logic device communicatively coupled to the logic device such that the logic device is communicatively interfaced between the management controller and the second logic device, and wherein the management controller is configured to:

during a boot of the management controller, perform an initial authentication of second code of the second logic device via the mutable interface of the logic device and a second immutable interface of the second logic device;

after the initial authentication and prior to completion of boot of the management controller, enable, via the mutable interface of the logic device, a second hardware lock to prevent write access to the second logic device via the second immutable interface; and

in response to a power on request of the host system, perform a second authentication of the second code via the mutable interface of the logic device and a second mutable interface of the second logic device.

7. The information handling system of claim 6 , wherein the management controller is further configured to perform a runtime authentication of the second code via the mutable interface of the logic device and the second mutable interface of the second logic device during runtime of the operating system of the host system.

8. A method comprising, in an information handling system comprising a host system comprising a host system processor and a logic device configured to perform a functionality of the information handling system in accordance with code stored on non-transitory computer-readable media of the logic device:

during a boot of a management controller communicatively coupled to the host system processor and the logic device and configured to perform out-of-band management of the information handling system, performing, by the management controller, an initial authentication of the code via an immutable interface of the logic device;

after the initial authentication and prior to completion of boot of the management controller, enabling, by the management controller, a hardware lock to prevent write access to the logic device via the immutable interface; and

in response to a power on request of the host system, performing, by the management controller, a second authentication of the code via a mutable interface of the logic device.

9. The method of claim 8 , the method further comprising performing, by the management controller, a runtime authentication of the code via the mutable interface of the logic device during runtime of an operating system of the host system.

10. The method of claim 9 , further comprising queuing, by the management controller, a recovery of the code on a subsequent power on request of the host system in response to failure of the runtime authentication of the code.

11. The method of claim 8 , further comprising performing, by the management controller, an automatic recovery of the code in response to one or both of a failure of the initial authentication of the code or the second authentication of the code.

12. The method of claim 8 , further comprising, during the boot of the management controller, performing, by the management controller, an update of the code via the immutable interface of the logic device.

13. The method of claim 8 , wherein the information handling system further comprises a second logic device communicatively coupled to the logic device such that the logic device is communicatively interfaced between the management controller and the second logic device, the method further comprising:

during a boot of the management controller, performing, by the management controller, an initial authentication of second code of the second logic device via the mutable interface of the logic device and a second immutable interface of the second logic device;

after the initial authentication and prior to completion of boot of the management controller, enabling, by the management controller and via the mutable interface of the logic device, a second hardware lock to prevent write access to the second logic device via the second immutable interface; and

in response to a power on request of the host system, performing, by the management controller, a second authentication of the second code via the mutable interface of the logic device and a second mutable interface of the second logic device.

14. The method of claim 13 , further comprising performing, by the management controller, a runtime authentication of the second code via the mutable interface of the logic device and the second mutable interface of the second logic device during runtime of the operating system of the host system.

15. An article of manufacture comprising:

a non-transitory computer-readable medium; and

computer-executable instructions carried on the computer-readable medium, the instructions readable by a processing device, the instructions, when read and executed, for causing the processing device to, in an information handling system comprising a host system comprising a host system processor and a logic device configured to perform a functionality of the information handling system in accordance with code stored on non-transitory computer-readable media of the logic device:

during a boot of a management controller communicatively coupled to the host system processor and the logic device and configured to perform out-of-band management of the information handling system, perform, by the management controller, an initial authentication of the code via an immutable interface of the logic device;

after the initial authentication and prior to completion of boot of the management controller, enable, by the management controller, a hardware lock to prevent write access to the logic device via the immutable interface; and

in response to a power on request of the host system, perform, by the management controller, a second authentication of the code via a mutable interface of the logic device.

16. The article of claim 15 , the instructions for further causing the processing device to perform, by the management controller, a runtime authentication of the code via the mutable interface of the logic device during runtime of an operating system of the host system.

17. The article of claim 16 , the instructions for further causing the processing device to queue, by the management controller, a recovery of the code on a subsequent power on request of the host system in response to failure of the runtime authentication of the code.

18. The article of claim 15 , the instructions for further causing the processing device to perform, by the management controller, an automatic recovery of the code in response to one or both of a failure of the initial authentication of the code or the second authentication of the code.

19. The article of claim 15 , the instructions for further causing the processing device to, during the boot of the management controller, perform, by the management controller, an update of the code via the immutable interface of the logic device.

20. The article of claim 15 , wherein the information handling system further comprises a second logic device communicatively coupled to the logic device such that the logic device is communicatively interfaced between the management controller and the second logic device, the instructions for further causing the processing device to:

during a boot of the management controller, perform, by the management controller, an initial authentication of second code of the second logic device via the mutable interface of the logic device and a second immutable interface of the second logic device;

after the initial authentication and prior to completion of boot of the management controller, enable, by the management controller and via the mutable interface of the logic device, a second hardware lock to prevent write access to the second logic device via the second immutable interface; and

in response to a power on request of the host system, perform, by the management controller, a second authentication of the second code via the mutable interface of the logic device and a second mutable interface of the second logic device.

21. The article of claim 20 , the instructions for further causing the processing device to perform, by the management controller, a runtime authentication of the second code via the mutable interface of the logic device and the second mutable interface of the second logic device during runtime of the operating system of the host system.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2020
From: LAMBERT, TIMOTHY M.; TAVEIRA, MILTON OLAVO DECARVALHO; KENNEDY, JEFFREY L.
To: DELL PRODUCTS L.P.
Reel/Frame 054741/0700 →
Continuity (1)
Related Publication 20220198016A1 · Jun 23, 2022