IP Library Granted Patent US 11,803,454
Granted Patent B2
US 11,803,454 · App. 17/246,378 · Granted Oct 31, 2023

Chained loading with static and dynamic root of trust measurements

Inventors: Sumanth Vidyadhara (Bangalore, IN); Nicholas D. Grobelny (Austin, TX); Lip Vui Kan (Singapore, SG); Ricardo L. Martinez (Leander, TX)
Assignee: Dell Products L.P.
G06F11/26G06F8/60G06F9/4401G06F9/445G06F11/2284G06F21/575G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,803,454
App. No.
17/246,378
Filed
Apr 30, 2021
Granted
Oct 31, 2023
Kind
B2
Art Unit
2114
USPC
714/37
Abstract

Establishing a diagnostic OS for an information handling system platform performing a UEFI BIOS boot to place the platform in a pre-OS state. Upon detecting a particular POST error and/or a platform configuration policy, an embedded OS kernel may be launched into a DRTM-authenticated measured launch environment (MLE). Additional objects for the diagnostic OS may be downloaded. The additional objects may include an initial ramdisk (initrd) module and one or more applications specific to the particular diagnostic OS. The diagnostic OS may be launched as follows: for each diagnostic OS application, launching the application and extending a measurement of the application into a DRTM PCR. Launching the diagnostic OS may include launching an initrd module and extending a measurement of the initrd module into the DRTM PCR. A measurement of embedded OS kernel may be extended into the TPM and the embedded OS kernel may validate the UEFI BIOS sequence.

Claims (30)

1. A method of establishing a diagnostic operating system (OS) module for an information handling system platform, comprising:

performing a unified extensible firmware interface (UEFI) basic input/output system (BIOS) boot to place the platform in a pre-OS state;

responsive to detecting either a particular platform configuration policy or a particular power on self test (POST) error, launching the diagnostic OS module into a measured launch environment (MLE);

based at least in part on the particular platform configuration policy, downloading additional objects for the diagnostic OS module, wherein the additional objects include one or more diagnostic OS-specific applications; and

launching the diagnostic OS module, wherein said launching includes:

for each diagnostic OS-specific application, launching the application and extending a measurement of the application into at least one dynamic root of trust measurement (DRTM) platform control register (PCR) of a trusted platform module (TPM).

2. The method of claim 1 , wherein the UEFI BIOS boot includes one or more UEFI BIOS modules and further wherein the UEFI BIOS boot comprises a measured boot wherein a measurement of each UEFI BIOS module is extended into the TPM.

3. The method of claim 2 , wherein the measurements of the UEFI BIOS modules are extended into one or more static root of trust measurement (SRTM) platform control registers (PCRs) of the TPM.

4. The method of claim 3 , wherein the UEFI BIOS modules include a core root of trust measurement (CRTM) module and wherein a measurement of the CRTM module establishes a CRTM.

5. The method of claim 2 , further comprising, validating, by an embedded OS kernel, the measured boot.

6. The method of claim 2 , wherein launching an embedded OS kernel includes extending a measurement of the embedded OS kernel into the trusted platform module (TPM).

7. The method of claim 1 , wherein the additional objects include an initial ramdisk (initrd) module and wherein launching the diagnostic OS module includes:

launching the initrd module and extending a measurement of the initrd module into the at least one dynamic PCR of the TPM.

8. The method of claim 1 , wherein the MLE comprises a dynamic root of trust measurement (DRTM)-authenticated MLE.

9. An information handling system platform, comprising:

a central processing unit; and

a nontransitory computer readable medium including processor executable instructions that, when executed, cause the system to perform operations for establishing a diagnostic operating system (OS), the operations comprising:

performing a unified extensible firmware interface (UEFI) basic input/output system (BIOS) boot to place the platform in a pre-OS state;

responsive to detecting either a particular platform configuration policy or a particular power on self test (POST) error, launching a diagnostic OS module into a measured launch environment (MLE);

based at least in part on the particular platform configuration policy, downloading additional objects for the diagnostic OS module, wherein the additional objects include one or more diagnostic OS-specific applications; and

launching the diagnostic OS module, wherein said launching includes:

for each diagnostic OS-specific application, launching the application and extending a measurement of the application into at least one dynamic root of trust measurement (DRTM) platform control register (PCR) of a trusted platform module (TPM).

10. The information handling system of claim 9 , wherein the UEFI BIOS boot includes one or more UEFI BIOS modules and further wherein the UEFI BIOS boot comprises a measured boot wherein a measurement of each UEFI BIOS module is extended into the TPM.

11. The information handling system of claim 10 , wherein the measurements of the UEFI BIOS modules are extended into one or more static root of trust measurement (SRTM) platform control registers (PCRs) of the TPM.

12. The information handling system of claim 11 , wherein the UEFI BIOS modules include a core root of trust measurement (CRTM) module and wherein a measurement of the CRTM module establishes a CRTM.

13. The information handling system of claim 10 , further comprising, validating, by an embedded OS kernel, the measured boot.

14. The information handling system of claim 10 , wherein launching an embedded OS kernel includes extending a measurement of the embedded OS kernel into the trusted platform module (TPM).

15. The information handling system of claim 9 , wherein the additional objects include an initial ramdisk (initrd) module and wherein launching the diagnostic OS module includes:

launching the initrd module and extending a measurement of the initrd module into the at least one dynamic PCR of the TPM.

16. The information handling system of claim 9 , wherein the MLE comprises a dynamic root of trust measurement (DRTM)-authenticated MLE.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2021
From: VIDYADHARA, SUMANTH; GROBELNY, NICHOLAS D.; KAN, LIP VUI; MARTINEZ, RICARDO L.
To: DELL PRODUCTS L.P.
Reel/Frame 056333/0945 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →