IP Library Granted Patent US 11,429,288
Granted Patent B1
US 11,429,288 · App. 17/184,641 · Granted Aug 30, 2022

System and method to secure ports on a computer

Inventors: Craig Lawrence Chaiken (Pflugerville, TX); Siva Subramaniam Rajan (Austin, TX)
Assignee: Dell Products L.P.
G06F3/0619G06F3/067G06F3/0629G06F13/4081
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,429,288
App. No.
17/184,641
Granted
Aug 30, 2022
Kind
B1
Abstract

A system, method, and computer-readable medium are disclosed for securing hot-pluggable ports, such as USB ports, of an information handling system, by isolating a dedicated controller from the operating system of the information handling system. Devices that are to be allowed to be enabled at the ports are determined. A hash signature is created and saved to verify the devices. The controller and ports are held in reset until the devices are authenticated.

Claims (38)

1. A computer-implementable method of securing hot-pluggable ports of an information handling system comprising:

isolating from an operating system of the information handling system a controller configured to the hot-pluggable ports;

determining devices to be enabled at the hot-pluggable ports;

creating a hash signature for the hot-pluggable ports;

saving the hash signature for device verification;

holding the controller and the hot-pluggable ports in reset if no devices are plugged at the hot-pluggable ports; and

taking the controller and the hot-pluggable ports out of reset by a system management interrupt (SMI) handler when devices are authenticated.

2. The method of claim 1 , wherein the controller is a universal serial bus (USB) controller, and the hot-pluggable ports are USB ports.

3. The method of claim 1 , wherein the determining is based on one or more of the following: device type, class code, descriptors returned by devices.

4. The method of claim 1 , wherein the creating the hash signature comprises concatenated descriptors returned by a device, and signed by a private key.

5. The method of claim 1 , wherein the creating the hash signature is performed when a device is plugged into a hot-pluggable port to create the hash signature based on descriptors.

6. The method of claim 1 , wherein the hash signature is used by other information handling systems.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

isolating from an operating system of the information handling system a controller configured to the hot-pluggable ports;

determining devices to be enabled at the hot-pluggable ports;

creating a hash signature for the hot-pluggable ports;

saving the hash signature for device verification;

holding the controller and the hot-pluggable ports in reset if no devices are plugged at the hot-pluggable ports; and

taking the controller and the hot-pluggable ports out of reset by a system management interrupt (SMI) handler when devices are authenticated.

8. The system of claim 7 , wherein the controller is a universal serial bus (USB) controller, and the hot-pluggable ports are USB ports.

9. The system of claim 7 , wherein the determining is based on one or more of the following: device type, class code, descriptors returned by devices.

10. The system of claim 7 , wherein the creating the hash signature comprises concatenated descriptors returned by a device, and signed by a private key.

11. The system of claim 7 , wherein the creating the hash signature is performed when a device is plugged into a hot-pluggable port to create the hash signature based on descriptors.

12. The system of claim 7 , wherein the hash signature is used by other information handling systems.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

isolating from an operating system of the information handling system a controller configured to the hot-pluggable ports;

determining devices to be enabled at the hot-pluggable ports;

creating a hash signature for the hot-pluggable ports;

saving the hash signature for device verification;

holding the controller and the hot-pluggable ports in reset if no devices are plugged at the hot-pluggable ports; and

taking the controller and the hot-pluggable ports out of reset by a system management interrupt (SMI) handler when devices are authenticated.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein the controller is a universal serial bus (USB) controller, and the hot-pluggable ports are USB ports.

15. The non-transitory, computer-readable storage medium of claim 13 , wherein the determining is based on one or more of the following: device type, class code, descriptors returned by devices.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein the creating the hash signature comprises concatenated descriptors returned by a device, and signed by a private key.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein the hash signature is used by other information handling systems.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2021
From: CHAIKEN, CRAIG LAWRENCE; RAJAN, SIVA SUBRAMANIAM
To: DELL PRODUCTS L.P.
Reel/Frame 055403/0302 →