IP Library Granted Patent US 11,748,485
Granted Patent B2
US 11,748,485 · App. 17/443,979 · Granted Sep 5, 2023

System and method for booting using HSM integrated chain of trust certificates

Inventors: Christopher Campetti (Holden, MA); Huijun Xie (Hopkinton, MA); Antonio L. Fontes (Northbridge, MA); Azzam Tannous (Framingham, MA); Anoop Gulati (Pflugerville, TX)
Assignee: Dell Products L.P.
G06F21/575G06F21/572H04L9/0897H04L9/3268G06F2221/033H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,748,485
App. No.
17/443,979
Granted
Sep 5, 2023
Kind
B2
Abstract

A system for secure booting of an information handling system stores a Root of Trust private key in a hardware security module (HSM). A HSM-Integrated certificate creation utility receives inputs such as bin files for each firmware volume associated with a boot sequence. The HSM-Integrated certificate creation utility loads the correct extensions for the firmware volume, generates a certificate signing request (CSR) and generates a certificate based on the CSR. The certificates can be provided to a boot sequence for processing in a trusted firmware implementation without a certificate creation utility consuming the Hardware Root of Trust private key as a file that could be compromised.

Claims (42)

1. A method for generating a set of certificates for secure booting of an information handling system, the method comprising:

storing, in a Hardware Security Module, a Hardware Root of Trust private key;

for each firmware volume:

loading information associated with a certificate for the firmware volume into a hardware security module (HSM)-Integrated certificate creation utility;

generating, by a script generating engine executing in the (HSM)-Integrated certificate creation utility, a script for generating a Certificate Signing Request (CSR);

generating, by a CSR engine executing in the (HSM)-Integrated certificate creation utility, the CSR; and

generating, by a certificate creation engine executing in the (HSM)-Integrated certificate creation utility, a certificate based on the CSR.

2. The method of claim 1 , wherein the script comprises an OpenSSL script and one or more of the script generating engine, the CSR generating engine and the certificate creation engine comprises an OpenSSL gem engine.

3. The method of claim 1 , further comprising verifying, by a CSR verification engine executing in the (HSM)-Integrated certificate creation utility, the CSR was generated successfully before generating the certificate.

4. The method of claim 1 , further comprising verifying, by a certificate verification engine executing in the (HSM)-Integrated certificate creation utility, the certificate was generated successfully before implementing the certificate in a boot sequence.

5. The method of claim 4 , wherein the boot sequence comprises an ARM trusted firmware boot sequence.

6. A system for secure booting of an information handling system, the system comprising:

a hardware security module (HSM) storing a Root of Trust private key; and

a Hardware Security Module-Integrated certificate creation utility comprising instructions executable to:

determine, from a plurality of firmware volumes, a set of firmware volumes associated with a boot sequence;

for each firmware volume in the set of firmware volumes:

load information associated with a certificate for the firmware volume;

generate a script for a Certificate Signing Request (CSR);

generate the CSR;

generate a certificate based on the CSR; and

store the certificate.

7. The system of claim 6 , wherein the script comprises an OpenSSL script and one or more of the script generating engine, the CSR generating engine and the certificate creation engine comprises an OpenSSL gem engine.

8. The system of claim 6 , wherein the Hardware Security Module-Integrated certificate creation utility comprises a CSR verification engine configured to verify the CSR was generated successfully before generating the certificate.

9. The system of claim 6 , wherein the Hardware Security Module-Integrated certificate creation utility comprises a certificate verification engine configured to verify the certificate was generated successfully before implementing the certificate in a boot sequence.

10. The system of claim 9 , wherein the boot sequence comprises an ARM trusted firmware boot sequence.

11. An information handling system, comprising:

a processor subsystem;

a memory subsystem comprising a plurality of firmware volumes; and

a system for secure booting of the information handling system, the system comprising:

a hardware security module (HSM) storing a Root of Trust private key; and

a Hardware Security Module-Integrated certificate creation utility comprising instructions executable to:

determine, from the plurality of firmware volumes, a set of firmware volumes associated with a boot sequence;

for each firmware volume in the set of firmware volumes:

load information associated with a certificate for the firmware volume;

generate a script for a Certificate Signing Request (CSR);

generate the CSR;

generate a certificate based on the CSR; and

store the certificate.

12. The information handling system of claim 11 , wherein the script comprises an OpenSSL script and one or more of a script generating engine, a CSR generating engine and a certificate creation engine comprises an OpenSSL gem engine.

13. The information handling system of claim 12 , wherein a CSR verification engine is configured to verify the CSR was generated successfully before the certificate is generated.

14. The information handling system of claim 11 , wherein a certificate verification engine is configured to verify the certificate was generated successfully before implementing the certificate in a boot sequence.

15. The information handling system of claim 14 , wherein the boot sequence comprises an ARM trusted firmware boot sequence.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2021
From: CAMPETTI, CHRISTOPHER; XIE, HUIJUN; FONTES, ANTONIO L.; TANNOUS, AZZAM; GULATI, ANOOP
To: DELL PRODUCTS L.P.
Reel/Frame 057020/0603 →
Continuity (1)
Related Publication 20230035801A1 · Feb 2, 2023