IP Library Patent Application 17372582
Patent Application
App. No. 17/372,582

DERIVING DEPENDENT SYMMETRIC ENCRYPTION KEYS BASED UPON A TYPE OF SECURE BOOT USING A SECURITY PROCESSOR

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/372,582
Abstract

Embodiments of systems and methods for deriving dependent symmetric encryption keys based upon a type of secure boot using a security processor are described. In some embodiments, a security processor may include: a core; and a memory coupled to the core, the memory having program instructions stored thereon that, upon execution by the core, cause the security processor to: retrieve a first symmetric key based, at least in part, upon a type of secure boot performed to bootstrap an Information Handling System (IHS); and derive a second symmetric key based, at least in part, upon the first symmetric key.

Claims (28)

1 . A security processor, comprising:

a core; and

a memory coupled to the core, the memory having program instructions stored thereon that, upon execution by the core, cause the security processor to:

retrieve a first symmetric key based, at least in part, upon a type of secure boot performed to bootstrap an Information Handling System (IHS); and

derive a second symmetric key based, at least in part, upon the first symmetric key.

2 . The security processor of claim 1 , wherein the type of secure boot performed comprises the type of secure boot last performed.

3 . The security processor of claim 1 , wherein the program instructions, upon execution by the core, further cause the security processor to identify the type of secure boot corresponding to a secure boot public key used to bootstrap the IHS.

4 . The security processor of claim 3 , wherein to identify the type of secure boot, the program instructions, upon execution, further cause the security processor to read a value of a counter configured to be incremented upon an eviction of a customer or brand of an Original Equipment Manufacturer (OEM) from the security processor.

5 . The security processor of claim 4 , wherein the eviction of the customer or brand is associated with a return, service, or warranty claim.

6 . The security processor of claim 4 , wherein the value of the counter is usable by the security processor to identify a number of times the security processor has been shipped to a plurality of customers or brands.

7 . The security processor of claim 4 , wherein the value of the counter is usable by the security processor to identify a number of times the IHS has been returned to the OEM.

8 . The security processor of claim 4 , wherein the value of the counter is usable by the security processor to identify or a number of times the security processor has been provisioned or reprovisioned by the OEM.

9 . The security processor of claim 1 , wherein the first symmetric key is usable by a first Advanced Encryption Standard (AES) hardware engine within a Baseboard Management Controller (BMC).

10 . The security processor of claim 9 , wherein the first symmetric key is fused into the security processor.

11 . The security processor of claim 9 , wherein the second symmetric key is usable by a second AES hardware engine within the security processor.

12 . The security processor of claim 11 , wherein the second symmetric key is fused into the security processor.

13 . The security processor of claim 11 , wherein the program instructions, upon execution by the core, further cause the security processor to encrypt and decrypt data usable to authenticate a user with the second symmetric key.

14 . The security processor of claim 1 , wherein the program instructions, upon execution by the core, further cause the security processor to, in response to a rekeying command from the customer or brand, derive the second symmetric key further based, at least in part, upon at least one additional input.

15 . A memory storage device having program instructions stored thereon that, upon execution by an Information Handling System (IHS), cause the IHS to:

retrieve a first symmetric key fused into a security processor based, at least in part, upon the value of a counter configured to be incremented upon eviction of a customer of an Original Equipment Manufacturer (OEM) from the security processor, wherein the first symmetric key is usable by a first encryption engine within an external processor; and

derive a second symmetric key based, at least in part, upon the first symmetric key, wherein the second symmetric key is usable by a second encryption engine within the security processor.

16 . The memory storage device of claim 15 , wherein the second symmetric key is further derived based, at least in part, upon a seed fused into the security processor, and wherein the seed is selected based upon the value of the counter.

17 . The memory storage device of claim 15 , wherein the program instructions, upon execution by the IHS, further cause the IHS to encrypt and decrypt data usable to authenticate a user with the second symmetric key.

18 . A method, comprising:

retrieving a first symmetric key based, at least in part, upon the value of a counter, wherein the first symmetric key is usable by a first encryption engine within a security processor; and

deriving a second symmetric key based, at least in part, upon the first symmetric key, wherein the second symmetric key is usable by a second encryption engine within an external processor.

19 . The method of claim 18 , wherein the second symmetric key is further derived based, at least in part, upon a seed selected based upon the value.

20 . The method of claim 18 , further comprising encrypting and decrypting data usable to authenticate a user with the second symmetric key.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2021
From: KHATRI, MUKUND P.; CHO, EUGENE DAVID
To: DELL PRODUCTS, L.P.
Reel/Frame 056831/0228 →