IP Library Granted Patent US 12,197,556
Granted Patent B2
US 12,197,556 · App. 17/135,252 · Granted Jan 14, 2025

Secure data collection for validation of installed components of information handling systems

Inventors: Jason Matthew Young (Round Rock, TX); A Anis Ahmed (Bangalore, IN)
Assignee: Dell Products, L.P.
G06F21/44H04L9/3247H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,197,556
App. No.
17/135,252
Granted
Jan 14, 2025
Kind
B2
Abstract

Methods and system are provided for validating the secure assembly and delivery of an IHS (Information Handling System). During factory provisioning of the IHS, an inventory certificate is uploaded to the IHS. The certificate includes: an inventory of hardware components installed during factory assembly of the IHS, validation schemas the provide instructions for identifying the hardware components, and digital signatures used to confirm the integrity of the validation schemas. Upon delivery of the IHS, a validation process retrieves the inventory certificate and confirms the integrity of the validation schemas. Based on validation schema instructions, the validation process collects an inventory of the detected IHS hardware. The validation schema instructions are further used to compare the collected inventory against the inventory from the inventory certificate in order to validate the detected hardware components of the IHS as the same hardware components installed during factory assembly of the IHS.

Claims (35)

1. A method for validating secure assembly of an Information Handling System (IHS), the method comprising:

retrieving an inventory certificate uploaded to the IHS during factory provisioning of the IHS, wherein the inventory certificate includes an inventory identifying a plurality of factory installed hardware components installed during a factory assembly of the IHS, wherein the inventory certificate further includes a plurality of validation schemas that comprise instructions for identifying the plurality of factory installed hardware components of the IHS, wherein at least one of the validation schemas specifies whether a given hardware component is identifiable via a Basic Input/Output System (BIOS) query, and wherein the inventory certificate further includes a plurality of respective digital signatures corresponding to the validation schemas for identifying the plurality of factory installed hardware components of the IHS;

confirming the integrity of the plurality of validation schemas included in the inventory certificate based, at least in part, on the plurality of respective digital signatures in the inventory certificate;

collecting an inventory of detected hardware components of the IHS, wherein the inventory is collected based on the instructions for identifying the plurality of factory installed hardware components of the IHS comprised in the plurality of validation schemas included in the inventory certificate; and

comparing the collected inventory of detected components against the inventory from the inventory certificate in order to validate the detected hardware components of the IHS as the same plurality of factory installed hardware components installed during the factory assembly of the IHS.

2. The method of claim 1 , wherein the inventory certificate is signed using a keypair of a certificate authority and wherein a private key of the keypair is used to generate the respective digital signatures corresponding to the validation schemas.

3. The method of claim 2 , wherein the integrity of validation schemas is determined using a public key of the keypair of the certificate authority.

4. The method of claim 1 , further comprising retrieving a component certificate uploaded to the IHS upon a first hardware component being supplied for installation in the IHS, wherein the component certificate includes an inventory identifying the first hardware component, a first validation schema that comprises instructions for identifying the first hardware component, and a first digital signature corresponding to the first validation schema.

5. The method of claim 4 , further comprising confirming the integrity of the first validation schema included in the component certificate based on the first digital signature in the component certificate.

6. The method of claim 5 , wherein the inventory is further collected based on the instructions comprised in the first validation schema included in the component certificate.

7. The method of claim 6 , further comprising comparing the collected inventory of detected components against the inventory from the component certificate in order to identify the first hardware component supplied for installation in the IHS in collected inventory.

8. The method of claim 1 , wherein the comparisons are conducted based on the instructions comprised in the plurality of validation schemas included in the inventory certificate.

9. The method of claim 8 , wherein the inventory certificate further includes a digital signature corresponding to validation logic for use in evaluating the instructions comprised in the plurality of validation schemas.

10. An Information Handling System (IHS), comprising:

a processor; and

a plurality of hardware components coupled to the processor, wherein during factory provisioning of the IHS a signed inventory certificate is uploaded to the IHS that includes an inventory identifying a plurality of factory installed hardware components installed during a factory assembly of the IHS, wherein the inventory certificate further includes a plurality of validation schemas that comprise instructions for identifying the plurality of factory installed hardware components of the IHS, and wherein the inventory certificate further includes a plurality of respective digital signatures corresponding to the validation schemas for identifying the plurality of factory installed hardware components of the IHS, and wherein the plurality of hardware components comprise:

one or more processors; and

one or more memory devices coupled to the processors, the memory devices storing computer-readable instructions that, upon execution by the processors, cause a validation process of the IHS to:

confirm the integrity of the plurality of validation schemas included in the inventory certificate based, at least in part, on the plurality of respective digital signatures in the inventory certificate;

collect an inventory of the plurality of hardware components, wherein the inventory is collected based on the instructions for identifying the plurality of factory installed hardware components of the IHS comprised in the plurality of validation schemas included in the inventory certificate, wherein at least one of the validation schemas specifies whether a given hardware component is identifiable via a Trusted Platform Module (TPM) query; and

compare the collected inventory against the inventory from the inventory certificate in order to validate the plurality of hardware components of the IHS as the same plurality of factory installed hardware components installed during the factory assembly of the IHS.

11. The IHS of claim 10 , wherein the given hardware component comprises a secure memory module.

12. The IHS of claim 10 , wherein the inventory certificate is signed using a keypair of a certificate authority and wherein a private key of the keypair is used to generate the respective digital signatures corresponding to the validation schemas, and wherein the integrity of validation schemas is determined using a public key of the keypair of the certificate authority.

13. The IHS of claim 10 , wherein the validation process additionally retrieves a component certificate uploaded to the IHS upon a first hardware component being supplied for installation in the IHS, wherein the component certificate includes an inventory identifying the first hardware component, a first validation schema that comprises instructions for identifying the first hardware component, and a first digital signature corresponding to the first validation schema.

14. The IHS of claim 13 , wherein the validation process additionally confirms the integrity of the first validation schema included in the component certificate based on the first digital signature in the component certificate.

15. The IHS of claim 14 , wherein the validation process additionally further collects the inventory based on the instructions comprised in the first validation schema included in the component certificate.

16. The IHS of claim 15 , wherein the validation process additionally compares the collected inventory of detected components against the inventory from the component certificate in order to identify the first hardware component supplied for installation in the IHS in collected inventory.

17. The IHS of claim 10 , wherein the validation process comprises a pre-boot process of the IHS.

18. A computer-readable storage device having instructions stored thereon for validating secure assembly of an Information Handling System (IHS), wherein execution of the instructions by one or more processors of the IHS causes a validation process of the IHS to:

retrieve an inventory certificate uploaded to the IHS during factory provisioning of the IHS, wherein the inventory certificate includes an inventory identifying a plurality of factory installed hardware components installed during a factory assembly of the IHS, wherein the inventory certificate further includes a plurality of validation schemas that comprise instructions for identifying the plurality of factory installed hardware components of the IHS, wherein at least one of the validation schemas specifies whether a given hardware component is identifiable via a Basic Input/Output System (BIOS) query or a Trusted Platform Module (TPM) query, and wherein the inventory certificate further includes a plurality of respective digital signatures corresponding to the validation schemas for identifying the plurality of factory installed hardware components of the IHS;

confirm the integrity of plurality of validation schemas included in the inventory certificate based, at least in part, on the plurality of respective digital signatures in the inventory certificate;

collect an inventory of detected hardware components of the IHS, wherein the inventory is collected based on the instructions for identifying the plurality of factory installed hardware components of the IHS comprised in the plurality of validation schemas included in the inventory certificate; and

compare the collected inventory of detected hardware components against the inventory from the inventory certificate in order to validate the detected hardware components of the IHS as the same plurality of factory installed hardware components installed during the factory assembly of the IHS.

19. The storage device of claim 18 , wherein the inventory certificate is signed using a keypair of a certificate authority and wherein a private key of the keypair is used to generate the respective digital signatures corresponding to the validation schemas, and wherein the integrity of validation schemas is determined using a public key of the keypair of the certificate authority.

20. The storage device of claim 19 , wherein the comparisons are conducted based on the instructions comprised in the plurality of validation schemas included in the inventory certificate.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2020
From: YOUNG, JASON MATTHEW; AHMED, A ANIS
To: DELL PRODUCTS, L.P.
Reel/Frame 054756/0209 →
Continuity (1)
Related Publication 20220207125A1 · Jun 30, 2022
References Cited (9)
US 6968373B1 · Norris · 2005 [cited by examiner]
US 7162635B2 · Bisbee · 2007 [cited by examiner]
US 8171296B2 · Vion-Dury · 2012 [cited by examiner]
US 10311224B1 · Farhan · 2019 [cited by examiner]
US 10320922B1 · Hussain · 2019 [cited by examiner]
US 20150012623A1 · Jubran · 2015 [cited by examiner]
US 20190042707A1 · Young · 2019 [cited by examiner]
US 20190042753A1 · Jreij · 2019 [cited by examiner]
CN 112084484A · 2020 [cited by examiner]