IP Library Granted Patent US 11,593,490
Granted Patent B2
US 11,593,490 · App. 17/386,826 · Granted Feb 28, 2023

System and method for maintaining trusted execution in an untrusted computing environment using a secure communication channel

Inventors: Eugene David Cho (Austin, TX); Mario Alberto Sanchez (Austin, TX); Akkiah Choudary Maddukuri (Austin, TX); Marshal F. Savage (Austin, TX); Paul W. Vancil (Austin, TX)
Assignee: Dell Products, L.P.
G06F21/575G06F21/52G06F21/572G06F21/606H04L9/0822H04L25/0204
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,593,490
App. No.
17/386,826
Granted
Feb 28, 2023
Kind
B2
Abstract

An Information Handling System (IHS) includes multiple hardware devices, and a baseboard Management Controller (BMC) in communication with the plurality of hardware devices. The BMC includes instructions for executing an assistance application (APP) in an untrusted domain of the BMC. The assistance APP configured to monitor a custom BMC firmware stack executed in the untrusted domain. The instructions are further executed to verify an integrity of the assistance APP from a trusted domain of the BMC by encrypting communications between the trusted and untrusted domains using an encryption key that comprises a function of a time counter value.

Claims (48)

1. An information handling system (IHS) comprising:

a plurality of hardware devices; and

a baseboard management controller (BMC) in communication with the plurality of hardware devices, the BMC comprising one or more processors and one or more memory units including instructions that, upon execution by the processors, are executed to:

execute an assistance application (APP) in an untrusted domain of the BMC, the assistance APP configured to monitor a custom BMC firmware stack executed in the untrusted domain;

verify an integrity of the assistance APP from a trusted domain of the BMC by encrypting communications between the trusted and untrusted domains using an encryption key that comprises a function of a time counter value.

2. The IHS of claim 1 , wherein the instructions are further executed to:

split the communications into a plurality of blocks; and

encrypt each block using the encryption key, wherein the encryption key comprises a function of a block counter value comprising a quantity of the blocks that have been previously sent.

3. The IHS of claim 1 , wherein the instructions are further executed to update the encryption key at ongoing intervals.

4. The IHS of claim 3 , wherein the updated encryption key comprises a function of the encryption key of the previous interval.

5. The IHS of claim 1 , wherein the instructions are further executed to repeatedly verify the integrity of the assistance APP at ongoing intervals.

6. The IHS of claim 1 , wherein the BMC comprises a baseboard processor and a coprocessor configured in a system on chip (SoC), a memory space of the baseboard processor comprising the untrusted domain, and the memory space of the coprocessor comprising the trusted domain.

7. The IHS of claim 6 , wherein the BMC comprises a hardware encryption engine, wherein the baseboard processor and the coprocessor are configured to access the hardware encryption engine for encrypting the communications.

8. The IHS of claim 6 , wherein the instructions comprise a bootloader that is executed to:

provide a single storage source key to the coprocessor, wherein the coprocessor is configured to generate the encryption key from the single storage source key;

generate the encryption key;

send the generated encryption key to the baseboard processor, wherein the baseboard processor and coprocessor are configured to use their respective encryption keys for encrypting the communications.

9. The IHS of claim 8 , wherein the instructions are further executed to inhibit any processes executed on the baseboard processor from accessing the single storage source key.

10. The IHS of claim 8 , wherein the bootloader is further executed to perform the steps of providing a single storage source key, generating the encryption key, and sending the generated encryption key to the baseboard processor when the BMC is booted.

11. A trust verification method comprising:

executing, using instructions stored in at least one memory and executed by at least one processor, an assistance application (APP) in an untrusted domain of a baseboard management controller (BMC), the assistance APP configured to monitor a custom BMC firmware stack executed in the untrusted domain, the BMC in communication with a plurality of hardware devices of an information handling system (IHS);

verifying, using the instructions, an integrity of the assistance APP from a trusted domain of the BMC by encrypting communications between the trusted and untrusted domains using an encryption key that comprises a function of a time counter value.

12. The trust verification method of claim 11 , further comprising wherein the instructions are further executed to:

split the communications into a plurality of blocks; and

encrypt each block using the encryption key, wherein the encryption key comprises a function of a block counter value comprising a quantity of the blocks that have been previously sent.

13. The trust verification method of claim 11 , further comprising updating the encryption key at ongoing intervals, wherein the updated encryption key comprises a function of the encryption key of the previous interval.

14. The trust verification method of claim 11 , further comprising repeatedly verifying the integrity of the assistance APP at ongoing intervals.

15. The trust verification method of claim 11 , further comprising accessing a hardware encryption engine for encrypting the communications, the hardware engine in communication with a baseboard processor and a coprocessor configured in a system on chip (SoC), a memory space of the baseboard processor comprising the untrusted domain, and the memory space of the coprocessor comprising the trusted domain.

16. The trust verification method of claim 15 , further comprising, using a bootloader:

providing a single storage source key to the coprocessor, wherein the coprocessor is configured to generate the encryption key from the single storage source key;

generating the encryption key;

sending the generated encryption key to the baseboard processor, wherein the baseboard processor and coprocessor are configured to use their respective encryption keys for encrypting the communications.

17. The trust verification method of claim 16 , further comprising inhibiting any processes executed on the baseboard processor from accessing the single storage source key.

18. The trust verification method of claim 16 , further comprising performing the steps of providing a single storage source key, generating the encryption key, and sending the generated encryption key to the baseboard processor when the BMC is booted.

19. A baseboard management controller (BMC) comprising:

one or more processors and one or more memory units including instructions that, upon execution by the processors, are executed to:

execute an assistance application (APP) in an untrusted domain of the BMC, the assistance APP configured to monitor a custom BMC firmware stack executed in the untrusted domain;

verify an integrity of the assistance APP from a trusted domain of the BMC by encrypting communications between the trusted and untrusted domains using an encryption key that comprises a function of a time counter value.

20. The BMC of claim 19 , wherein the instructions are further executed to:

split the communications into a plurality of blocks; and

encrypt each block using the encryption key, wherein the encryption key comprises a function of a block counter value comprising a quantity of the blocks that have been previously sent,

wherein the instructions are further executed to update the encryption key at ongoing intervals,

wherein the updated encryption key comprises a function of the encryption key of the previous interval, and

wherein the BMC comprises a baseboard processor and a coprocessor configured in a system on chip (SoC), a memory space of the baseboard processor comprising the untrusted domain, and the memory space of the coprocessor comprising the trusted domain;

wherein the instructions comprise a bootloader that is executed to:

provide a single storage source key to the coprocessor, wherein the coprocessor is configured to generate the encryption key from the single storage source key;

generate the encryption key; and

send the generated encryption key to the baseboard processor, wherein the baseboard processor and coprocessor are configured to use their respective encryption keys for encrypting the communications.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2021
From: CHO, EUGENE DAVID; SANCHEZ, MARIO ALBERTO; MADDUKURI, AKKIAH CHOUDARY; SAVAGE, MARSHAL F.; VANCIL, PAUL W.
To: DELL PRODUCTS, L.P.
Reel/Frame 057001/0886 →
Continuity (1)
Related Publication 20230030501A1 · Feb 2, 2023