IP Library Granted Patent US 12,003,960
Granted Patent B2
US 12,003,960 · App. 17/397,944 · Granted Jun 4, 2024

Booting and operating computing devices at designated locations

Inventor: Jens Reimann (Grasbrunn, DE)
Assignee: Red Hat, Inc.
H04W12/06G06F21/575H04L9/14H04W12/04H04W12/63G06F2221/031H04L2209/805
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,003,960
App. No.
17/397,944
Granted
Jun 4, 2024
Kind
B2
Abstract

Aspects of the disclosure provide for mechanisms for booting and operating a computing device at a target location. A method of the disclosure includes determining, at a startup process of a computing device, whether the computing device is present at a designated target location by checking, using a first near-field communication (NFC) device associated with the computing device, presence of a second NFC device positioned at the target location. The method further includes in response to detecting the presence of the second NFC device, acquiring a cryptographic key from the second NFC device. The method also includes decrypting contents associated with the computing device using the cryptographic key, and performing, using the decrypted contents, a boot process for the computing device in response to determining that the computing device is at the target location.

Claims (49)

1. A method comprising:

determining, at a startup process of a computing device, whether the computing device is present at a designated target location by:

checking, using a first near-field communication (NFC) device associated with the computing device, presence of a second NFC device positioned at the target location,

acquiring, from the second NFC device, an identifier of the second NFC device,

comparing the received identifier of the second NFC device with an identifier of an authenticated NFC device, wherein the identifier of the authenticated NFC device comprises a stored identifier stored in a memory associated with firmware of the computing device, and

in response to the received identifier matching the stored identifier, authenticating the second NFC device;

in response to authenticating the second NFC device, acquiring a cryptographic key from the second NFC device;

decrypting, using the cryptographic key, contents of a storage device of the computing device; and

performing, using the decrypted contents, a boot process for the computing device in response to determining that the computing device is at the target location.

2. The method of claim 1 , further comprising performing a validation process to authenticate the second NFC device using credential information obtained from the second NFC device.

3. The method of claim 1 , wherein authenticating the second NFC device further comprises determining that the second NFC device is in a predetermined proximity of the first NFC device.

4. The method of claim 3 , wherein authenticating the second NFC device further comprises performing a handshaking process via the first NFC device.

5. The method of claim 2 , wherein performing the validation process comprises comparing the credential information with known credential information of an authenticated NFC device positioned at the target location.

6. The method of claim 2 , further comprising performing the validation process using the firmware of the computing device.

7. The method of claim 2 , further comprising: in response to failing to authenticate the second NFC device, shutting down the computing device.

8. The method of claim 1 , further comprising:

checking the presence of the second NFC device after completion of the boot process; and

in response to detecting absence of the second NFC device, shutting down the computing device.

9. A system comprising:

a memory; and

a processing device operatively coupled to the memory, wherein the processing device is configured to:

determine, at a startup process of a computing device, whether the computing device is present at a designated target location by:

checking, using a first near-field communication (NFC) device associated with the computing device, presence of a second NFC device positioned at the target location,

acquiring, from the second NFC device, an identifier of the second NFC device,

comparing the received identifier of the second NFC device with an identifier of an authenticated NFC device, wherein the identifier of the authenticated NFC device comprises a stored identifier stored in a memory associated with firmware of the computing device, and

in response to the received identifier matching the stored identifier, authenticating the second NFC device;

in response to authenticating the second NFC device, acquire a cryptographic key from the second NFC device;

decrypt, using the cryptographic key, contents of a storage device of the computing device; and

perform, using the decrypted contents, a boot process for the computing device in response to determining that the computing device is at the target location.

10. The system of claim 9 , wherein the processing device is further to perform a validation process to authenticate the second NFC device using credential information obtained from the second NFC device.

11. The system of claim 9 , wherein to authenticate the second NFC device, the processing device is to determine that the second NFC device is in a predetermined proximity of the first NFC device.

12. The system of claim 11 , wherein to authenticate the second NFC device, the processing device is to perform a handshaking process via the first NFC device.

13. A non-transitory machine-readable storage medium including instructions that, when accessed by a processing device, cause the processing device to:

determine, at a startup process of a computing device, whether the computing device is present at a designated target location by:

checking, using a first near-field communication (NFC) device associated with the computing device, presence of a second NFC device positioned at the target location,

acquiring, from the second NFC device, an identifier of the second NFC device,

comparing the received identifier of the second NFC device with an identifier of an authenticated NFC device, wherein the identifier of the authenticated NFC device comprises a stored identifier stored in a memory associated with firmware of the computing device, and

in response to the received identifier matching the stored identifier, authenticating the second NFC device;

in response to authenticating the second NFC device, acquire a cryptographic key from the second NFC device;

decrypt, using the cryptographic key, contents of a storage device of the computing device; and

perform, using the decrypted contents, a boot process for the computing device in response to determining that the computing device is at the target location.

14. The non-transitory machine-readable storage medium of claim 13 , wherein the processing device is further to perform a validation process to authenticate the second NFC device using credential information obtained from the second NFC device.

15. The non-transitory machine-readable storage medium of claim 13 , wherein to authenticate the second NFC device, the processing device is to determine that the second NFC device is in a predetermined proximity of the first NFC device.

16. The non-transitory machine-readable storage medium of claim 13 , wherein to authenticate the second NFC device, the processing device is to perform a handshaking process via the first NFC device.

17. The method of claim 1 , wherein:

acquiring the cryptographic key from the second NFC device is in further response to determining whether a predetermined policy is satisfied; and

the predetermined policy comprises that a platform configuration register (PCR) of a trusted platform module of the computing device is in a predetermined state.

18. The method of claim 17 , wherein the predetermined state comprises a predetermined value of the PCR.

19. The method of claim 8 , wherein checking the presence of the second NFC device after completion of the boot process comprises checking the presence of the second NFC device a random amount of time after completion of the boot process.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2021
From: REIMANN, JENS
To: RED HAT, INC.
Reel/Frame 057166/0733 →