IP Library › Granted Patent US 11,915,015
Granted Patent B2
US 11,915,015 · App. 17/459,557 · Granted Feb 27, 2024

Systems and methods for use of pre-boot resources by modern workspaces

Inventors: Balasingh P. Samuel (Round Rock, TX); Vivek Viswanathan Iyer (Austin, TX)
Assignee: Dell Products, L.P.
G06F9/44505G06F1/26G06F13/4068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,915,015
App. No.
17/459,557
Granted
Feb 27, 2024
Kind
B2
Abstract

Systems and methods provide isolated workspaces operating on an IHS (Information Handling System) with use of pre-boot resources of the IHS that are not directly accessible by the workspaces. Upon notification of a workspace initialization, a segregated variable space, such as a segregated memory utilized by a UEFI (Unified Extensible Firmware Interface) of the IHS, is specified for use by the workspace. The segregated variable space is initialized and populated with pre-boot variables, such as UEFI variables, that are allowed for configuration by the workspace. Upon a workspace issuing a request to configure a pre-boot variable, the segregated variable space is identified that was mapped for use by the workspace. The requested pre-boot variable configuration is allowed based on whether the pre-boot variable is populated in the segregated variable space. When the requested pre-boot variable configuration is allowed, the pre-boot variable is configured on behalf of the workspace.

Claims (41)

1. An Information Handling System (IHS) supporting use of pre-boot resources of the IHS by a plurality of workspaces operating on the IHS, the IHS comprising:

processors;

a first memory coupled to the processors, the first memory storing program instructions that, upon execution by the processors, cause the IHS to run an operating system; and

a second memory coupled to the processors, the second memory storing program instructions that, upon execution by the processors, cause the IHS to:

receive a notification of an initialization of a first workspace on the IHS, wherein the notification specifies a segregated variable space for use by the first workspace;

initialize the segregated variable space and populate the segregated variable space with a plurality of pre-boot variables allowed for configuration by the first workspace, wherein the segregated variable space is populated with the pre-boot variables based on an access control list that specifies the plurality of pre-boot variables allowed for configuration by the first workspace, and wherein an update key is stored in the segregated variable space during initialization of the segregated variable space, and wherein a modification to the pre-boot variables allowed for configuration by the first workspace is decrypted using the update key;

receive, from the first workspace, a request to configure a pre-boot variable of the IHS;

identify the segregated variable space as being mapped for use by the first workspace;

determine whether the requested pre-boot variable configuration is allowed based on the pre-boot variables that are populated in the segregated variable space; and

when the requested pre-boot variable configuration is allowed, configure the requested pre-boot variable on behalf of the first workspace.

2. The IHS of claim 1 , wherein the segregated variable space comprises a segregated memory utilized by a UEFI (Unified Extensible Firmware Interface) of the IHS.

3. The IHS of claim 1 , wherein the first workspace is limited to accessing variable information provided in the segregated variable space, and wherein other workspaces are unable to access the variable information provided in the segregated variable space.

4. The IHS of claim 2 , wherein the segregated UEFI memory comprises a partition of an NVRAM (nonvolatile random-access memory) utilized by the UEFI.

5. The IHS of claim 1 , wherein the configuration of the pre-boot variable requested by the first workspace comprises initiating a power mode supported by the IHS.

6. The IHS of claim 1 , wherein the configuration of the pre-boot variable requested by the first workspace comprises disabling an I/O port of the IHS.

7. The IHS of claim 1 , wherein the configuration of the pre-boot variable requested by the first workspace comprises initiating a privacy capability implemented by an I/O device of the IHS.

8. The IHS of claim 1 , wherein the modification to the pre-boot variables allowed for configuration by the first workspace is received from a remote workspace orchestration service that initialized the first workspace on the IHS.

9. A method for supporting use of pre-boot resources of an Information Handling System (IHS) by a plurality of workspaces operating on the IHS, the method comprising:

receiving, from a remote workspace orchestration service, a notification of an initialization of a first workspace on the IHS, wherein the notification specifies a segregated variable space for use by the first workspace;

initializing the segregated variable space and populating the segregated variable space with a plurality of pre-boot variables allowed for configuration by the first workspace, wherein the segregated variable space is populated with the pre-boot variables based on an access control list that specifies the plurality of pre-boot variables allowed for configuration by the first workspace, and wherein an update key is stored in the segregated variable space during initialization of the segregated variable space, and wherein a modification to the pre-boot variables allowed for configuration by the first workspace is decrypted using the update key;

receiving, from the first workspace, a request to configure use of a pre-boot variable of the IHS;

identifying the segregated variable space as being mapped for use by the first workspace;

determining whether the first workspace is allowed to configure the requested pre-boot variable based on the pre-boot variables that are populated in the segregated variable space; and

when the requested pre-boot variable configuration is allowed, configuring the requested pre-boot variable on behalf of the first workspace.

10. The method of claim 9 , wherein the segregated variable space comprises a segregated memory utilized by a UEFI (Unified Extensible Firmware Interface) of the IHS.

11. The method of claim 9 , further comprising: limiting the first workspace to variable information provided in the segregated variable space, and preventing other workspaces from accessing the variable information provided in the segregated variable space.

12. The method of claim 9 , wherein the configuration of the pre-boot variable requested by the first workspace comprises initiating a power mode supported by the IHS.

13. The method of claim 9 , wherein the configuration of the pre-boot variable requested by the first workspace comprises disabling an I/O port of the IHS.

14. The method of claim 9 , wherein the configuration of the pre-boot variable requested by the first workspace comprises initiating a privacy capability implemented by an I/O device of the IHS.

15. A system supporting use of pre-boot resources of an Information Handling System (IHS) by a plurality of workspaces operating on the IHS, the system comprising:

a workspace orchestration service that is remote from the IHS and that manages deployment of workspaces on the IHS; and

the IHS comprising:

a processor; and

a memory coupled to the processor, the memory storing program instructions that, upon execution by the processor, cause the IHS to:

receive, from the remote workspace orchestration service, a notification of an initialization of a first workspace on the IHS, wherein the notification specifies a segregated variable space for use by the first workspace;

initialize the segregated variable space and populate the segregated variable space with a plurality of pre-boot variables allowed for configuration by the first workspace, wherein the segregated variable space is populated with the pre-boot variables based on an access control list that specifies the plurality of pre-boot variables allowed for configuration by the first workspace, and wherein an update key is stored in the segregated variable space during initialization of the segregated variable space, and wherein a modification to the pre-boot variables allowed for configuration by the first workspace is decrypted using the update key;

receive, from the first workspace, a request to configure a pre-boot resource of the IHS;

identify the segregated variable space as being mapped for use by the first workspace;

determine whether the first workspace is allowed to configure the requested pre-boot variable based on the pre-boot variables that are populated in the segregated variable space; and

when access to the requested pre-boot variable is allowed, configure the requested pre-boot variable on behalf of the first workspace.

16. The system of claim 15 , wherein the segregated variable space comprises a segregated memory utilized by a UEFI (Unified Extensible Firmware Interface) of the IHS.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2021
From: SAMUEL, BALASINGH P.; IYER, VIVEK VISWANATHAN
To: DELL PRODUCTS, L.P.
Reel/Frame 057313/0764 →
Continuity (1)
Related Publication 20230067647A1 · Mar 2, 2023