IP Library Granted Patent US 11,803,667
Granted Patent B2
US 11,803,667 · App. 17/225,026 · Granted Oct 31, 2023

Overlay ownership certificates including hardware inventory profiles

Inventors: Ankit Singh (Bangalore, IN); Deepaganesh Paulraj (Bangalore, IN); Vaideeswaran Ganesan (Bangalore, IN)
Assignee: Dell Products L.P.
G06F21/73G06F9/4411G06F21/64G06F21/72G06F2221/2129
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,803,667
App. No.
17/225,026
Filed
Apr 7, 2021
Granted
Oct 31, 2023
Kind
B2
Examiner
SUH, ANDREW
Art Unit
2493
USPC
726/26
Abstract

An information handling system includes a provisioning server and a server. The server includes a baseboard management controller (BMC) to determine a first hardware inventory profile for the server. The BMC provides the first hardware inventory profile to the provisioning server. The BMC stores first signed provisioning configuration content that is based on a first ownership certificate for a first owner of the server. The BMC determines a second hardware inventory profile for the server, and provides the second hardware inventory profile to the provisioning server. The BMC stores second signed provisioning configuration content that is based on a second ownership certificate for a second owner of the server. In response to an expiration of the second ownership certificate, the BMC removes the second signed provisioning configuration content, compares a current hardware inventory profile to the first hardware inventory profile, and generates a report to indicate any hardware changes.

Claims (60)

1. An information handling system comprising:

a provisioning server; and

a server including a baseboard management controller, the baseboard management controller to:

determine a first hardware inventory profile for the server;

provide the first hardware inventory profile to the provisioning server, wherein the first hardware inventory profile is included within first provisioning configuration content;

store first signed provisioning configuration content, wherein the first signed provisioning configuration content is based on a first ownership certificate for a first owner of the server, wherein the first signed provisioning configuration content is stored in an encrypted memory;

determine a second hardware inventory profile for the server;

provide the second hardware inventory profile to the provisioning server, wherein the second hardware inventory profile is included within second provisioning configuration content;

store second signed provisioning configuration content, wherein the second signed provisioning configuration content is based on a second ownership certificate for a second owner of the server;

lock the second signed provisioning configuration content on top of the first signed provisioning configuration content in the encrypted memory; and

in response to an expiration of the second ownership certificate:

remove the second signed provisioning configuration content;

compare a current hardware inventory profile for the server to the first hardware inventory profile; and

generate a report to indicate any hardware changes between the current hardware inventory profile and the first hardware inventory profile.

2. The information handling system of claim 1 , wherein the indication of hardware changes includes the baseboard management controller further to include a replacement hardware device in the report without flagging the replacement hardware device when the replacement hardware device is a verified device.

3. The information handling system of claim 1 , wherein the baseboard management controller further to flag unidentified hardware devices in the report.

4. The information handling system of claim 1 , wherein the baseboard management controller further to embed the first hardware inventory profile and the first provisioning configuration content within the first ownership certificate.

5. The information handling system of claim 4 , wherein the baseboard management controller further to encode the first provisioning configuration content with a private key of the first ownership certificate, and to provide the encoded first provisioning configuration content to the provisioning server.

6. The information handling system of claim 1 , wherein prior to the removal of the second signed provisioning configuration content, the baseboard management controller to unlock the second signed provisioning configuration content.

7. A method comprising:

determining, by a baseboard management controller of a server, a first hardware inventory profile for the server;

providing the first hardware inventory profile to the provisioning server, wherein the first hardware inventory profile is included within first provisioning configuration content;

storing first signed provisioning configuration content, wherein the first signed provisioning configuration content is based on a first ownership certificate for a first owner of the server, wherein the first signed provisioning configuration content is stored in an encrypted memory;

determining a second hardware inventory profile for the server;

providing the second hardware inventory profile to the provisioning server, wherein the second hardware inventory profile is included within second provisioning configuration content;

storing second signed provisioning configuration content, wherein the second signed provisioning configuration content is based on a second ownership certificate for a second owner of the server;

locking the second signed provisioning configuration content on top of the first signed provisioning configuration content in the encrypted memory; and

in response to an expiration of the second ownership certificate:

removing the second signed provisioning configuration content;

comparing a current hardware inventory profile for the server to the first hardware inventory profile; and

generating a report to indicate any hardware changes between the current hardware inventory profile and the first hardware inventory profile.

8. The method of claim 7 , wherein the indicating of hardware changes, the method further comprises:

including a replacement hardware device in the report without flagging the replacement hardware device when the replacement hardware device is a verified device.

9. The method of claim 7 , further comprising:

flagging unidentified hardware devices in the report.

10. The method of claim 7 , further comprising:

embedding the first hardware inventory profile and the first provisioning configuration content within the first ownership certificate.

11. The method of claim 10 , further comprising:

encoding the first provisioning configuration content with a private key of the first ownership certificate; and

providing the encoded first provisioning configuration content to the provisioning server.

12. The method of claim 7 , prior to the removing of the second signed provisioning configuration content, the method further comprising:

unlocking the second signed provisioning configuration content.

13. A method comprising:

determining, by a first baseboard management controller of a server, a first hardware inventory profile for the server;

providing the first hardware inventory profile to the provisioning server, wherein the first hardware inventory profile is included within first provisioning configuration content;

storing first signed provisioning configuration content, wherein the first signed provisioning configuration content is based on a first ownership certificate for a first owner of the server, wherein the first signed provisioning configuration content is stored in an encrypted memory;

providing a second hardware inventory profile for the server to the provisioning server, wherein the second hardware inventory profile is included within second provisioning configuration content;

storing second signed provisioning configuration content, wherein the second signed provisioning configuration content is based on a second ownership certificate for a second owner of the server;

locking the second signed provisioning configuration content on top of the first signed provisioning configuration content in the encrypted memory;

synchronizing, by a second baseboard management controller, the first and second signed provisioning configuration contents with the provisioning server, wherein the first baseboard management controller is replaced by the second baseboard management controller in the server; and

in response to an expiration of the second ownership certificate:

removing, by the second baseboard management controller, the second signed provisioning configuration content;

comparing a current hardware inventory profile for the server to the first hardware inventory profile; and

generating, by the second baseboard management controller, a report to indicate any hardware changes between the current hardware inventory profile and the first hardware inventory profile.

14. The method of claim 13 , wherein the indicating of hardware changes, the method further comprises:

including a replacement hardware device in the report without flagging the replacement hardware device when the replacement hardware device is a verified device.

15. The method of claim 13 , further comprising:

flagging unidentified hardware devices in the report.

16. The method of claim 13 , further comprising:

embedding the first hardware inventory profile and the first provisioning configuration content within the first ownership certificate.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2021
From: SINGH, ANKIT; PAULRAJ, DEEPAGANESH; GANESAN, VAIDEESWARAN
To: DELL PRODUCTS, LP
Reel/Frame 055858/0627 →
Continuity (1)
Related Publication 20220327243A1 · Oct 13, 2022
Cited By (3)
US 12,211,021 US 12,561,180 US 12,579,084