IP Library Granted Patent US 11,409,883
Granted Patent B1
US 11,409,883 · App. 17/152,314 · Granted Aug 9, 2022

Binding customer-signed image to a specific platform

Inventors: Balaji Bapu Gururaja Rao (Austin, TX); Elie Jreij (Pflugerville, TX); Paul Vancil (Austin, TX); Marshal Savage (Austin, TX)
Assignee: Dell Products L.P.
G06F21/575G06F13/4282G06F15/7807
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,409,883
App. No.
17/152,314
Granted
Aug 9, 2022
Kind
B1
Abstract

An information handling system may include a circuit board; a processor disposed on the circuit board, wherein the processor includes a media access control (MAC) address and a hidden root key (HRK) encoded therein; and a memory not disposed on the circuit board. The information handling system may be configured to: determine a customer public key (CPK); create a data structure comprising the CPK and the MAC address; encrypt the data structure using the HRK to generate an encrypted structure; and store the encrypted structure in the memory.

Claims (46)

1. An information handling system comprising:

a circuit board;

a processor disposed on the circuit board, wherein the processor includes a media access control (MAC) address and a hidden root key (HRK) encoded therein; and

a memory not disposed on the circuit board;

wherein the information handling system is configured to:

determine a customer public key (CPK);

create a data structure comprising the CPK and the MAC address;

encrypt the data structure using the HRK to generate an encrypted structure; and

store the encrypted structure in the memory.

2. The information handling system of claim 1 , wherein the information handling system comprises a management controller.

3. The information handling system of claim 2 , wherein the management controller is configured to carry out the determining, the creating, the encrypting, and the storing.

4. The information handling system of claim 1 , wherein the memory is an integral part of a chassis of the information handling system.

5. The information handling system of claim 1 , wherein the memory is a front-panel flash memory.

6. The information handling system of claim 5 , wherein the front-panel flash memory is coupled to the processor via a serial peripheral interface (SPI) bus.

7. The information handling system of claim 1 , wherein the data structure further comprises an initialization vector (IV), and wherein the information handling system is further configured to store the IV in the memory.

8. The information handling system of claim 1 , wherein, during a subsequent boot process, the information handling system is further configured to:

read the encrypted structure from the memory;

decrypt the encrypted structure with the HRK to determine a potential MAC address and a potential CPK;

perform a first comparison between the potential MAC address and the MAC address;

perform a second comparison between the potential CPK and the CPK; and

in response to a mismatch in either the first comparison or the second comparison, disable execution of a customer-signed firmware image.

9. A method executed in an information handling system including a circuit board; a processor disposed on the circuit board, wherein the processor includes a media access control (MAC) address and a hidden root key (HRK) encoded therein; and a memory not disposed on the circuit board, the method comprising:

determining a customer public key (CPK);

creating a data structure comprising the CPK and the MAC address;

encrypting the data structure using the HRK to generate an encrypted structure; and

storing the encrypted structure in the memory.

10. The method of claim 9 , wherein the CPK is encoded into a vendor boot loader of the information handling system.

11. The method of claim 9 , wherein the processor is a system-on-chip (SoC) of a management controller.

12. The method of claim 9 , wherein the method is performed in response to an instruction to enable execution of a customer-signed firmware image.

13. An article of manufacture comprising a non-transitory, computer-readable medium having computer-executable instructions thereon that are executable by a processor of an information handling system that includes a circuit board; a processor disposed on the circuit board, wherein the processor includes a media access control (MAC) address and a hidden root key (HRK) encoded therein; and a memory not disposed on the circuit board, the instructions executable for:

determining a customer public key (CPK);

creating a data structure comprising the CPK and the MAC address;

encrypting the data structure using the HRK to generate an encrypted structure; and

storing the encrypted structure in the memory.

14. The article of claim 13 , wherein the information handling system comprises a management controller.

15. The article of claim 14 , wherein the management controller is configured to carry out the determining, the creating, the encrypting, and the storing.

16. The article of claim 13 , wherein the memory is an integral part of a chassis of the information handling system.

17. The article of claim 13 , wherein the memory is a front-panel flash memory.

18. The article of claim 17 , wherein the front-panel flash memory is coupled to the processor via a serial peripheral interface (SPI) bus.

19. The article of claim 13 , wherein the data structure further comprises an initialization vector (IV), and wherein the information handling system is further configured to store the IV in the memory.

20. The article of claim 19 , wherein the instructions are further executable for, during a subsequent boot process:

reading the encrypted structure from the memory;

decrypting the encrypted structure with the HRK to determine a potential MAC address and a potential CPK;

performing a first comparison between the potential MAC address and the MAC address;

performing a second comparison between the potential CPK and the CPK; and

in response to a mismatch in either the first comparison or the second comparison, disabling execution of a customer-signed firmware image.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2021
From: RAO, BALAJI BAPU GURURAJA; JREIJ, ELIE; VANCIL, PAUL; SAVAGE, MARSHAL
To: DELL PRODUCTS L.P.
Reel/Frame 054956/0049 →