IP Library Granted Patent US 11,977,640
Granted Patent B2
US 11,977,640 · App. 17/372,806 · Granted May 7, 2024

Systems and methods for authenticating the identity of an information handling system

Inventors: Mukund P. Khatri (Austin, TX); Eugene David Cho (Austin, TX)
Assignee: Dell Products, L.P.
G06F21/575G06F21/33G06F21/602G06F21/64G06F21/73G06Q30/0645G06F21/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,977,640
App. No.
17/372,806
Granted
May 7, 2024
Kind
B2
Abstract

Systems and methods are provided for validating components of an Information Handling System (IHS). During factory provisioning of the IHS, an owner certificate is stored that specifies an identity of a motherboard installed during manufacture of the IHS. The owner certificate is signed by a certificate authority of an owner of the IHS that retains capabilities for specifying the use of boot code provided by successive renters of the IHS. A renter certificate is also stored that specifies an identity of a chassis to which the motherboard is installed during manufacture of the IHS. Upon a transfer of control or ownership of the IHS, boot code operations by the security processor identify a motherboard and chassis in use by the IHS and utilize the motherboard and chassis certificates to validate that the identified motherboard and chassis are the same motherboard and chassis installed during manufacture of the IHS.

Claims (43)

1. A security processor installed in an IHS (Information Handling System), the security processor comprising:

a logic unit; and

a memory coupled to the logic unit, the memory having program instructions stored thereon that, upon execution by the logic unit, cause the security processor to:

as part of a factory provisioning of the IHS:

retrieve owner boot code from a memory device that is fixed to a motherboard installed during manufacture of the IHS;

use the retrieved owner boot code to store a signed owner certificate specifying an identity of the motherboard, wherein the owner certificate comprises a public key of an owner keypair that is derived by the retrieved owner boot code from immutable specifications of the motherboard of the IHS and is signed by a certificate authority of an owner of the IHS; and

use the retrieved owner boot code to store a signed renter certificate specifying an identity of a chassis to which the motherboard was installed during manufacture of the IHS; and

upon a transfer of control or ownership of the security processor:

retrieve renter boot code from the memory device that is fixed to the motherboard; and

use the retrieved renter boot code to validate a detected motherboard as the motherboard installed during manufacture of the IHS and to validate a detected chassis as the chassis to which the motherboard was installed during manufacture of the IHS.

2. The security processor of claim 1 , wherein the signed renter certificate comprises a public key of a renter keypair that is derived by the retrieved owner boot code from immutable specifications of the chassis of the IHS.

3. The security processor of claim 2 , wherein the immutable specifications of the chassis comprise a unique identifier of a memory device that is fixed to the chassis.

4. The security processor of claim 1 , wherein, upon the transfer of control or ownership of the security processor, the execution of the instructions by the logic unit further causes the security processor to use the retrieved renter boot code to: identify a chassis in use by the IHS and utilize the signed renter certificate to validate that the identified chassis in use by the IHS is the same chassis to which the motherboard was installed during manufacture of the IHS.

5. The security processor of claim 1 , wherein the signed renter certificate obtained during the factory provisioning of the IHS further specifies an identity of a renter of the IHS.

6. The security processor of claim 5 , wherein, upon the transfer of control or ownership of the security processor, the execution of the instructions by the logic unit further causes the security processor to: identify an entity that has received the transfer of the security processor and utilize the signed renter certificate to validate that the identified entity is the renter specified during the factory provisioning of the IHS.

7. The security processor of claim 5 , wherein the identity of the renter specified in the signed renter certificate comprises a name of a company that contracts for the manufacture of the IHS.

8. The security processor of claim 1 , wherein, upon the transfer of control or ownership of the security processor, the execution of the instructions by the logic unit further causes the security processor to: use the retrieved renter boot code to: identify a motherboard in use by the IHS and utilize the signed owner certificate to validate that the identified motherboard in use by the IHS is the same motherboard installed during manufacture of the IHS.

9. The security processor of claim 1 , wherein the immutable specifications of the motherboard comprise unique identifiers of at least one of a processor and a memory device that are each fixed to the motherboard.

10. The security processor of claim 1 , wherein the renter certificate is signed by an embedded certificate authority of the security processor.

11. The security processor of claim 1 , wherein the identity of the motherboard specified in the signed owner certificate comprises a part number assigned to the motherboard.

12. The security processor of claim 1 , wherein the immutable specifications of the motherboard of the IHS are accessible to the owner boot code during pre-boot operations of the IHS and not accessible during post-boot operations of the IHS.

13. A memory storage device having program instructions stored thereon that, upon execution by an Information Handling System (IHS), cause the IHS to:

as part of a factory provisioning of the IHS:

retrieve owner boot code from a memory device that is fixed to a motherboard installed during manufacture of the IHS;

use the retrieved owner boot code to store a signed owner certificate specifying an identity of the motherboard, wherein the owner certificate comprises a public key of an owner keypair that is derived by the retrieved owner boot code from immutable specifications of the motherboard of the IHS and is signed by a certificate authority of an owner of the IHS; and

use the retrieved owner boot code to store a signed renter certificate specifying an identity of a chassis to which the motherboard was installed during manufacture of the IHS; and

upon a transfer of control or ownership of the IHS:

retrieve renter boot code from the memory device that is fixed to the motherboard; and

use the retrieved renter boot code to validate a detected motherboard as the motherboard installed during manufacture of the IHS and to validate a detected chassis as the chassis to which the motherboard was installed during manufacture of the IHS.

14. The memory storage device of claim 13 , wherein, upon the transfer of control or ownership of the IHS, the execution of the instructions by the logic unit further causes the security processor to: use the retrieved renter boot code to identify a chassis in use by the IHS and utilize the signed renter certificate to validate that the identified chassis in use by the IHS is the same chassis to which the motherboard was installed during manufacture of the IHS.

15. The memory storage device of claim 13 , wherein the signed renter certificate obtained during the factory provisioning of the IHS further specifies an identity of a renter of the IHS and wherein, upon a transfer of control or ownership of the IHS, the execution of the instructions by the logic unit further causes the security processor to: identify an entity that has received the transfer of the security processor and utilize the signed renter certificate to validate that the identified entity is the renter specified during the factory provisioning of the IHS.

16. The memory storage device of claim 13 , wherein, upon a transfer of control or ownership of the IHS, the execution of the instructions by the logic unit further causes the security processor to: use the retrieved renter boot code to identify a motherboard in use by the IHS and utilize the signed owner certificate to validate that the identified motherboard in use by the IHS is the same motherboard installed during manufacture of the IHS.

17. A method for validating components of an Information Handling System (IHS), the method comprising:

as part of a factory provisioning of the IHS:

retrieving owner boot code from a memory device that is fixed to a motherboard installed during manufacture of the IHS;

using the retrieved owner boot code to generate and store a signed owner certificate specifying an identity of the motherboard, wherein the owner certificate is signed by a certificate authority of an owner of the IHS; and

using the retrieved owner boot code to generate and store a signed renter certificate specifying an identity of a chassis to which the motherboard was installed during manufacture of the IHS, wherein the renter certificate is signed by an embedded certificate authority of a security processor of the IHS, wherein the owner of the IHS maintains a restricted access to the security processor upon a transfer of control or ownership of the IHS; and

upon a transfer of control or ownership of the IHS:

retrieve renter boot code from the memory device that is fixed to the motherboard; and

use the retrieved renter boot code to validate a detected motherboard as the motherboard installed during manufacture of the IHS and to validate a detected chassis as the chassis to which the motherboard was installed during manufacture of the IHS.

18. The method of claim 17 , wherein, upon the transfer of control or ownership of the IHS, the execution of the instructions by the logic unit further causes the security processor to: use the retrieved renter boot code to identify a chassis in use by the IHS and utilize the signed renter certificate to validate that the identified chassis in use by the IHS is the same chassis to which the motherboard was installed during manufacture of the IHS.

19. The method of claim 17 , wherein, upon a transfer of control or ownership of the IHS, the execution of the instructions by the logic unit further causes the security processor to: use the retrieved renter boot code to identify a motherboard in use by the IHS and utilize the signed owner certificate to validate that the identified motherboard in use by the IHS is the same motherboard installed during manufacture of the IHS.

20. The method of claim 17 , wherein the owner of the IHS comprises a manufacturer of the IHS.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2021
From: KHATRI, MUKUND P.; CHO, EUGENE DAVID
To: DELL PRODUCTS, L.P.
Reel/Frame 056822/0559 →
Continuity (1)
Related Publication 20230009032A1 · Jan 12, 2023