IP Library Granted Patent US 11,496,325
Granted Patent B2
US 11,496,325 · App. 17/189,886 · Granted Nov 8, 2022

Information handling system with overlay ownership certificates for ownership chaining

Inventors: Ankit Singh (Bangalore, IN); Deepaganesh Paulraj (Bangalore, IN)
Assignee: Dell Products L.P.
H04L9/3268H04L9/3265H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,496,325
App. No.
17/189,886
Granted
Nov 8, 2022
Kind
B2
Abstract

An information handling system includes a provisioning server and a server. The server includes a baseboard management controller (BMC) that configures a first ownership certificate for the server, and provides it to the provisioning server. The first ownership certificate is associated with a first owner. The BMC receives a first signed provisioning configuration content, and stores the first signed provisioning configuration content in an encrypted memory. The BMC configures a second ownership certificate for the server, and provides it to the provisioning server. The second ownership certificate is associated with a second owner. The BMC receives a second signed provisioning configuration content, and stores the second signed provisioning configuration content on top of the first signed provisioning configuration content in the encrypted memory. In response to an expiration of the second ownership certificate, the BMC removes the first signed provisioning configuration content, and applies the second signed provisioning configuration content.

Claims (66)

1. An information handling system comprising:

a provisioning server; and

a server including a baseboard management controller, the baseboard management controller to:

configure a first ownership certificate for the server, wherein the first ownership certificate is associated with a first owner;

provide the first ownership certificate to the provisioning server;

receive a first signed provisioning configuration content, wherein the first signed provisioning configuration content is based on the first ownership certificate;

store the first signed provisioning configuration content in an encrypted memory;

configure a second ownership certificate for the server, wherein the second ownership certificate is associated with a second owner;

provide the second ownership certificate to the provisioning server;

receive a second signed provisioning configuration content, wherein the second signed provisioning configuration content is based on the second ownership certificate;

store the second signed provisioning configuration content on top of the first signed provisioning configuration content in the encrypted memory; and

in response to an expiration of the second ownership certificate:

remove the second signed provisioning configuration content; and

apply the first signed provisioning configuration content.

2. The information handling system of claim 1 , wherein the baseboard management controller further to export a current server profile, and to update a configuration content for the server.

3. The information handling system of claim 2 , wherein the configuration content includes an administrator user name and an administrator password.

4. The information handling system of claim 2 , wherein the baseboard management controller further to encode the updated configuration content with a private key, and to provide the encoded updated configuration content to the provisioning server.

5. The information handling system of claim 1 , the baseboard management controller further to transfer ownership of the server to the second user in the provisioning server, and to provide a signed ownership transfer certificate.

6. The information handling system of claim 5 , wherein the baseboard management controller further to provide a countersigned ownership transfer certificate along with the second ownership certificate to the provisioning server.

7. The information handling system of claim 5 , wherein the baseboard management controller further to lock the second signed provisioning configuration content on top of the first signed provisioning configuration content.

8. The information handling system of claim 1 , wherein prior to the removal of the second signed provisioning configuration content, the baseboard management controller to unlock the second signed provisioning configuration content.

9. A method comprising:

configuring, by a baseboard management controller of a server, a first ownership certificate for the server, wherein the first ownership certificate is associated with a first owner;

providing the first ownership certificate to a provisioning server;

receiving a first signed provisioning configuration content, wherein the first signed provisioning configuration content is based on the first ownership certificate;

storing the first signed provisioning configuration content in an encrypted memory;

configuring a second ownership certificate for the server, wherein the second ownership certificate is associated with a second owner;

providing the second ownership certificate to the provisioning server;

receiving a second signed provisioning configuration content, wherein the second signed provisioning configuration content is based on the second ownership certificate;

storing, by the baseboard management controller, the second signed provisioning configuration content on top of the first signed provisioning configuration content in the encrypted memory; and

in response to an expiration of the second ownership certificate:

removing, by the baseboard management controller, the second signed provisioning configuration content; and

applying, by the baseboard management controller, the first signed provisioning configuration content.

10. The method of claim 9 , further comprising:

exporting a current server profile; and

updating a configuration content for the server.

11. The method of claim 10 , wherein the configuration content includes an administrator user name and an administrator password.

12. The method of claim 10 , further comprising:

encoding the updated configuration content with a private key; and

providing the encoded updated configuration content to the provisioning server.

13. The method of claim 9 , further comprising:

transferring ownership of the server to the second user in the provisioning server; and

providing a signed ownership transfer certificate.

14. The method of claim 13 , further comprising:

providing a countersigned ownership transfer certificate along with the second ownership certificate to the provisioning server.

15. The method of claim 13 , further comprising:

locking the second signed provisioning configuration content on top of the first signed provisioning configuration content.

16. The method of claim 9 , prior to the removing of the second signed provisioning configuration content, the method further comprising:

unlocking the second signed provisioning configuration content.

17. A non-transitory computer-readable medium including code that when executed performs a method, the method comprising:

configuring first ownership certificate for a server, wherein the first ownership certificate is associated with a first owner;

providing the first ownership certificate to a provisioning server;

receiving a first signed provisioning configuration content, wherein the first signed provisioning configuration content is based on the first ownership certificate;

storing the first signed provisioning configuration content in an encrypted memory;

configuring second ownership certificate for the server, wherein the second ownership certificate is associated with a second owner;

providing the second ownership certificate to the provisioning server;

receiving a second signed provisioning configuration content, wherein the second signed provisioning configuration content is based on the second ownership certificate;

storing the second signed provisioning configuration content on top of the first signed provisioning configuration content in the encrypted memory; and

in response to an expiration of the second ownership certificate:

removing the second signed provisioning configuration content; and

applying the first signed provisioning configuration content.

18. The non-transitory computer-readable medium of claim 17 , wherein the method further comprises:

transferring ownership of the server to the second user in the provisioning server; and

providing a signed ownership transfer certificate.

19. The non-transitory computer-readable medium of claim 17 , wherein the method further comprises providing a countersigned ownership transfer certificate along with the second ownership certificate to the provisioning server.

20. The non-transitory computer-readable medium of claim 19 , wherein the method further comprises locking the second signed provisioning configuration content on top of the first signed provisioning configuration content.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2021
From: SINGH, ANKIT; PAULRAJ, DEEPAGANESH
To: DELL PRODUCTS, LP
Reel/Frame 055460/0547 →
Continuity (1)
Related Publication 20220286302A1 · Sep 8, 2022