IP Library Granted Patent US 11,809,851
Granted Patent B2
US 11,809,851 · App. 17/386,449 · Granted Nov 7, 2023

System and method for managing update installation lockdown policies for firmware devices and driver-managed devices

Inventors: Anusha Bhaskar (Bengaluru, IN); Santosh Gore (Bangalore, IN); Muniswamy Setty (Bengaluru, IN); Parmeshwr Prasad (Bangalore, IN); Chandrashekar Nelogal (Round Rock, TX)
Assignee: DELL PRODUCTS L.P.
G06F8/65
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,809,851
App. No.
17/386,449
Granted
Nov 7, 2023
Kind
B2
Abstract

A method for managing a resource system includes obtaining, by a hardware resource manager, a firmware update lockdown request for a lockdown for a firmware device of the resource system, in response to the firmware update lockdown request: identifying a firmware protocol corresponding to the firmware device, generating a firmware lockdown command corresponding to the firmware device based on the firmware protocol, and initiating updating of a lockdown policy based on the firmware lockdown command.

Claims (53)

1. A method for managing a resource system, the method comprising:

obtaining, by a hardware resource manager, a firmware update lockdown request for a lockdown for a first firmware device and a second firmware device of the resource system, wherein the hardware resource manager operates in a first computing device;

in response to the firmware update lockdown request:

identifying, based on first firmware operating on the first firmware device, a firmware protocol corresponding to the first firmware device, wherein the first firmware device is operatively connected to the computing device;

identifying, based on second firmware operating on the second firmware device, a second firmware protocol corresponding to the second firmware device, wherein the computing device comprises the second firmware device;

in parallel:

generating a first firmware lockdown command corresponding to the first firmware device based on the first firmware protocol; and

generating a second firmware lockdown command corresponding to the second firmware device based on the second firmware protocol;

in parallel:

sending, to the first firmware device, the first firmware lockdown command, wherein the first firmware device operates using a firmware management protocol (FMP), wherein the first firmware lockdown command is an FMP command that specifies updating a firmware lockdown policy of the first firmware device to specify a lockdown mode of a hardware device in the first firmware device, and wherein the first firmware device executes the first firmware lockdown command; and

sending, to the second firmware device, the second firmware lockdown command, wherein the second firmware device operates using a platform-level data model (PLDM) protocol, wherein the second firmware lockdown command is a PLDM command that specifies obtaining firmware parameters of the second firmware device for specifying a lockdown of a hardware device in the second firmware device, and wherein the second firmware device executes the second firmware lockdown command;

initiating updating the lockdown policies, wherein the lockdown policies are updated at the first and second devices based on the first firmware lockdown command and the second firmware lockdown command.

2. The method of claim 1 , further comprising:

obtaining, by the hardware resource manager, a driver update lockdown policy request for a driver-managed device of the resource system; in response to the driver update lockdown policy request:

identifying a set of hardware resources managed by the driver-managed device; and initiating an installation prevention for the set of hardware resources.

3. The method of claim 2 , wherein initiating the installation prevention comprises sending an installation prevention request to a device driver of the driver-managed device.

4. The method of claim 3 , wherein the installation prevention request specifies preventing an operating system of the driver-managed device from automatically updating.

5. A non-transitory computer readable medium comprising computer readable program code, which when executed by a computer processor enables the computer processor to perform a method for managing a resource system, the method comprising:

obtaining, by a hardware resource manager, a firmware update lockdown request for a lockdown for a first firmware device and a second firmware device, wherein the hardware resource manager operates in a first computing device;

in response to the firmware update lockdown request:

identifying, based on first firmware operating on the first firmware device, a firmware protocol corresponding to the first firmware device, wherein the first firmware device is operatively connected to the computing device;

identifying, based on second firmware operating on the second firmware device, a second firmware protocol corresponding to the second firmware device, wherein the computing device comprises the second firmware device;

in parallel:

generating a first firmware lockdown command corresponding to the first firmware device based on the first firmware protocol; and

generating a second firmware lockdown command corresponding to the second firmware device based on the second firmware protocol;

in parallel:

sending, to the first firmware device, the first firmware lockdown command, wherein the first firmware device operates using a firmware management protocol (FMP), wherein the first firmware lockdown command is an FMP command that specifies updating a firmware lockdown policy of the first firmware device to specify a lockdown mode of a hardware device in the first firmware device, and wherein the first firmware device executes the first firmware lockdown command; and

sending, to the second firmware device, the second firmware lockdown command, wherein the second firmware device operates using a platform-level data model (PLDM) protocol, wherein the second firmware lockdown command is a PLDM command that specifies obtaining firmware parameters of the second firmware device for specifying a lockdown of a hardware device in the second firmware device, and wherein the second firmware device executes the second firmware lockdown command;

initiating updating the lockdown policies, wherein the lockdown policies are updated at the first and second devices based on the first firmware lockdown command and the second firmware lockdown command.

6. The non-transitory computer readable medium of claim 5 , the method further comprising:

obtaining, by the hardware resource manager, a driver update lockdown policy request for a driver-managed device;

in response to the driver update lockdown policy request: identifying a set of hardware resources managed by the driver-managed device; and initiating an installation prevention for the set of hardware resources.

7. The non-transitory computer readable medium of claim 6 , wherein initiating the installation prevention comprises sending an installation prevention request to a device driver of the driver-managed device.

8. The non-transitory computer readable medium of claim 7 , wherein the installation prevention request specifies preventing an operating system of the driver-managed device from automatically updating.

9. A system comprising:

a processor; and

memory comprising instructions, which when executed by the processor, perform a method comprising:

obtaining, by a hardware resource manager, a firmware update lockdown request for a lockdown for a first firmware device and a second firmware device, wherein the hardware resource manager operates in a first computing device;

in response to the firmware update lockdown request:

identifying, based on first firmware operating on the first firmware device, a firmware protocol corresponding to the first firmware device, wherein the first firmware device is operatively connected to the computing device;

identifying, based on second firmware operating on the second firmware device, a second firmware protocol corresponding to the second firmware device, wherein the computing device comprises the second firmware device;

in parallel:

generating a first firmware lockdown command corresponding to the first firmware device based on the first firmware protocol; and

generating a second firmware lockdown command corresponding to the second firmware device based on the second firmware protocol;

in parallel:

sending, to the first firmware device, the first firmware lockdown command, wherein the first firmware device operates using a firmware management protocol (FMP), wherein the first firmware lockdown command is an FMP command that specifies updating a firmware lockdown policy of the first firmware device to specify a lockdown mode of a hardware device in the first firmware device, and wherein the first firmware device executes the first firmware lockdown command;

sending, to the second firmware device, the second firmware lockdown command, wherein the second firmware device operates using a platform-level data model (PLDM) protocol, wherein the second firmware lockdown command is a PLDM command that specifies obtaining firmware parameters of the second firmware device for specifying a lockdown of a hardware device in the second firmware device, and wherein the second firmware device executes the second firmware lockdown command;

initiating updating the lockdown policies, wherein the lockdown policies are updated at the first and second devices based on the first firmware lockdown command and the second firmware lockdown command.

10. The system of claim 9 , further comprising:

obtaining, by the hardware resource manager, a driver update lockdown policy request for a driver-managed device;

in response to the driver update lockdown policy request: identifying a set of hardware resources managed by the driver-managed device; and initiating an installation prevention for the set of hardware resources.

11. The system of claim 10 , wherein initiating the installation prevention comprises sending an installation prevention request to a device driver of the driver-managed device.

12. The system of claim 11 , wherein the installation prevention request specifies preventing an operating system of the driver-managed device from automatically updating.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2021
From: BHASKAR, ANUSHA; GORE, SANTOSH; SETTY, MUNISWAMY; PRASAD, PARMESHWR; NELOGAL, CHANDRASHEKAR
To: DELL PRODUCTS L.P.
Reel/Frame 057424/0576 →
Priority Claims (1)
IN 202111025909 · Jun 10, 2021 · national
Continuity (1)
Related Publication 20220398088A1 · Dec 15, 2022