IP Library Granted Patent US 11,669,618
Granted Patent B2
US 11,669,618 · App. 17/236,399 · Granted Jun 6, 2023

Systems and methods for securing and loading bios drivers and dependencies in a predefined and measured load order

Inventors: Balasingh P. Samuel (Round Rock, TX); Richard M. Tonry (Austin, TX); Jonathan D. Samuel (Round Rock, TX)
Assignee: Dell Products L.P.
G06F21/572G06F9/4401G06F9/44505H04L9/3236G06F11/1417G06F21/57G06F21/575G06F21/64G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,669,618
App. No.
17/236,399
Granted
Jun 6, 2023
Kind
B2
Abstract

An information handling system may include a processor and a basic input/output system (BIOS) comprising a program of instructions comprising boot firmware configured to be the first code executed by the processor when the information handling system is booted or powered on, the BIOS configured to, during boot of the information handling system: (i) read a predefined measurement of an order of loading of BIOS drivers configured to execute during execution of the BIOS, such predefined measurement made during build of the BIOS; (ii) perform a runtime measurement of an order of loading of the BIOS drivers during actual runtime of the information handling system; (iii) compare the predefined measurement to the runtime measurement; and (iv) responsive to a mismatch between the predefined measurement and the runtime measurement, respond with a remedial action.

Claims (46)

1. An information handling system comprising:

a processor; and

a basic input/output system (BIOS) comprising a program of instructions comprising boot firmware configured to be the first code executed by the processor when the information handling system is booted or powered on, the BIOS configured to, during boot of the information handling system:

read a predefined measurement of an order of loading of BIOS drivers configured to execute during execution of the BIOS, such predefined measurement made during build of the BIOS wherein the predefined measurement is determined in accordance with content of each BIOS driver and a sequence in which the BIOS drivers were loaded;

perform a runtime measurement of an order of loading of the BIOS drivers during actual runtime of the information handling system;

compare the predefined measurement to the runtime measurement; and

responsive to a mismatch between the predefined measurement and the runtime measurement, respond with a remedial action.

2. The information handling system of claim 1 , wherein:

the predefined measurement is a cryptographic hash of the order of loading of the BIOS drivers during the predefined measurement made during build of the BIOS; and

the runtime measurement is a cryptographic hash of the order of loading of the BIOS drivers during actual runtime of the information handling system.

3. The information handling system of claim 2 , wherein the predefined measurement is a level-based driver load order list, wherein each level represents a particular phase, step, and/or priority of BIOS execution.

4. The information handling system of claim 1 , wherein:

the predefined measurement is signed with a private key; and

the BIOS is further configured to apply a public key associated with the private key to the predefined measurement.

5. The information handling system of claim 1 , wherein the remedial action comprises one of shutting down the information handling system, rebooting the information handling system, booting to a diagnostic operating system of the information handling system, and performing a recovery operation.

6. The information handling system of claim 1 , wherein the remedial action comprises one of restoring a safe configuration of the information handling system and restoring a safe firmware revision of the BIOS.

7. A method comprising, in an information handling system comprising a processor and a basic input/output system (BIOS) comprising a program of instructions comprising boot firmware configured to be the first code executed by the processor when the information handling system is booted or powered on, during boot of the information handling system by the BIOS:

reading a predefined measurement of an order of loading of BIOS drivers configured to execute during execution of the BIOS, such predefined measurement made during build of the BIOS wherein the predefined measurement is determined in accordance with content of each BIOS driver and a sequence in which the BIOS drivers were loaded;

performing a runtime measurement of an order of loading of the BIOS drivers during actual runtime of the information handling system;

comparing the predefined measurement to the runtime measurement; and

responsive to a mismatch between the predefined measurement and the runtime measurement, responding with a remedial action.

8. The method of claim 7 , wherein:

the predefined measurement is a cryptographic hash of the order of loading of the BIOS drivers during the predefined measurement made during build of the BIOS; and

the runtime measurement is a cryptographic hash of the order of loading of the BIOS drivers during actual runtime of the information handling system.

9. The method of claim 8 , wherein the predefined measurement is a level-based driver load order list, wherein each level represents a particular phase, step, and/or priority of BIOS execution.

10. The method of claim 7 , wherein:

the predefined measurement is signed with a private key; and

the method further comprises applying a public key associated with the private key to the predefined measurement.

11. The method of claim 7 , wherein the remedial action comprises one of shutting down the information handling system, rebooting the information handling system, booting to a diagnostic operating system of the information handling system, and performing a recovery operation.

12. The method of claim 7 , wherein the remedial action comprises one of restoring a safe configuration of the information handling system and restoring a safe firmware revision of the BIOS.

13. An article of manufacture comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the non-transitory computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to, in a basic input/output system (BIOS) of an information handling system:

read a predefined measurement of an order of loading of BIOS drivers configured to execute during execution of the BIOS, such predefined measurement made during build of the BIOS wherein the predefined measurement is determined in accordance with content of each BIOS driver and a sequence in which the BIOS drivers were loaded;

perform a runtime measurement of an order of loading of the BIOS drivers during actual runtime of the information handling system;

compare the predefined measurement to the runtime measurement; and

responsive to a mismatch between the predefined measurement and the runtime measurement, respond with a remedial action.

14. The article of claim 13 , wherein:

the predefined measurement is a cryptographic hash of the order of loading of the BIOS drivers during the predefined measurement made during build of the BIOS; and

the runtime measurement is a cryptographic hash of the order of loading of the BIOS drivers during actual runtime of the information handling system.

15. The article of claim 14 , wherein the predefined measurement is a level-based driver load order list, wherein each level represents a particular phase, step, and/or priority of BIOS execution.

16. The article of claim 13 , wherein:

the predefined measurement is signed with a private key; and

the instructions are for further causing the processor to apply a public key associated with the private key to the predefined measurement.

17. The article of claim 13 , wherein the remedial action comprises one of shutting down the information handling system, rebooting the information handling system, booting to a diagnostic operating system of the information handling system, and performing a recovery operation.

18. The article of claim 13 , wherein the remedial action comprises one of restoring a safe configuration of the information handling system and restoring a safe firmware revision of the BIOS.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2021
From: SAMUEL, BALASINGH P.; TONRY, RICHARD M.; SAMUEL, JONATHAN D.
To: DELL PRODUCTS L.P.
Reel/Frame 055990/0331 →