IP Library Granted Patent US 12,072,982
Granted Patent B2
US 12,072,982 · App. 17/837,329 · Granted Aug 27, 2024

Pre-authorized virtualization engine for dynamic firmware measurement

Inventors: Shekar Babu Suryanarayana (Bangalore, IN); Anand Prakash Joshi (Round Rock, TX); Amy Christine Nelson (Round Rock, TX); Nicholas D. Grobelny (Evergreen, CO)
Assignee: Dell Products L.P.
G06F21/572G06F21/54G06F21/575G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,072,982
App. No.
17/837,329
Granted
Aug 27, 2024
Kind
B2
Abstract

A virtual BIOS engine may be configured to, during runtime of an operating system, in response to an operating system event for updating firmware, load onto an isolated compute domain of the processor to emulate firmware update processes of a non-transitory computer-readable media with a virtual non-transitory computer-readable media and emulate the firmware update processes of the cryptoprocessor with a virtual cryptoprocessor, extract a firmware payload to the virtual non-transitory computer-readable media, and execute a virtual trust chain to measure the firmware payload in the virtual non-transitory computer-readable media.

Claims (40)

1. An information handling system comprising:

a processor;

first non-transitory computer-readable media communicatively coupled to the processor and having stored thereon a basic input/output system (BIOS);

a cryptoprocessor; and

second non-transitory computer-readable media communicatively coupled to the processor and having stored thereon:

an operating system; and

a virtual BIOS engine configured to, during runtime of the operating system:

in response to an operating system event for updating firmware, load onto an isolated compute domain of the processor to emulate firmware update processes of the first non-transitory computer-readable media with a virtual non-transitory computer-readable media and emulate the firmware update processes of the cryptoprocessor with a virtual cryptoprocessor;

extract a firmware payload to the virtual non-transitory computer-readable media; and

execute a virtual trust chain to measure the firmware payload in the virtual non-transitory computer-readable media.

2. The information handling system of claim 1 , wherein the first non-transitory computer-readable media is a Serial Peripheral Interface flash storage device.

3. The information handling system of claim 1 , wherein the cryptoprocessor is implemented in accordance with a Trusted Platform Module specification.

4. The information handling system of claim 1 , the virtual BIOS engine further configured to extend measurements of the firmware payload into a configuration register of the cryptoprocessor after measuring the firmware payload, such that the configuration register includes a signature of an old firmware image to be replaced and the firmware payload.

5. The information handling system of claim 4 , the virtual BIOS engine further configured to perform a quote of a configuration register.

6. The information handling system of claim 5 , wherein the virtual BIOS engine is further configured to commit a new firmware image to the first non-transitory computer-readable media in response to verifying information stored in the configuration register relating to the old firmware image to be replaced and the firmware payload.

7. The information handling system of claim 1 , wherein the isolated compute domain is instantiated on a securely-isolated hybrid processing core of the processor.

8. A method, in an information handling system having a processor, first non-transitory computer-readable media communicatively coupled to the processor and having stored thereon a basic input/output system (BIOS), a cryptoprocessor, and second non-transitory computer-readable media communicatively coupled to the processor and having stored thereon an operating system, the method comprising:

executing a virtual BIOS engine configured to, during runtime of the operating system:

in response to an operating system event for updating firmware, load onto an isolated compute domain of the processor to emulate firmware update processes of the first non-transitory computer-readable media with a virtual non-transitory computer-readable media and emulate the firmware update processes of the cryptoprocessor with a virtual cryptoprocessor;

extract a firmware payload to the virtual non-transitory computer-readable media; and

execute a virtual trust chain to measure the firmware payload in the virtual non-transitory computer-readable media.

9. The method of claim 8 , wherein the first non-transitory computer-readable media is a Serial Peripheral Interface flash storage device.

10. The method of claim 8 , wherein the cryptoprocessor is implemented in accordance with a Trusted Platform Module specification.

11. The method of claim 8 , wherein the virtual BIOS engine is further configured to extend the firmware payload into a configuration register of the cryptoprocessor after measuring the firmware payload, such that the configuration register includes a signature of an old firmware image to be replaced and the firmware payload.

12. The method of claim 11 , the virtual BIOS engine further configured to perform a quote of a configuration register.

13. The method of claim 12 , wherein the virtual BIOS engine is further configured to commit a new firmware image to the first non-transitory computer-readable media in response to verifying information stored in the configuration register relating to the old firmware image to be replaced and the firmware payload.

14. The method of claim 8 , wherein the isolated compute domain is instantiated on a securely-isolated hybrid processing core of the processor.

15. An article of manufacture comprising:

a first non-transitory computer-readable medium having stored thereon an operating system; and

computer-executable instructions carried on the first computer-readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to, in an information handling system having a processor, the first non-transitory computer-readable media communicatively coupled to the processor, second non-transitory computer-readable media communicatively coupled to the processors and having stored thereon a basic input/output system (BIOS), and a cryptoprocessor:

execute a virtual BIOS engine configured to, during runtime of the operating system:

in response to an operating system event for updating firmware, load onto an isolated compute domain of the processor to emulate firmware update processes of the second non-transitory computer-readable media with a virtual non-transitory computer-readable media and emulate the firmware update processes of the cryptoprocessor with a virtual cryptoprocessor;

extract a firmware payload to the virtual non-transitory computer-readable media; and

execute a virtual trust chain to measure the firmware payload in the virtual non-transitory computer-readable media.

16. The article of claim 15 , wherein the first non-transitory computer-readable media is a Serial Peripheral Interface flash storage device.

17. The article of claim 15 , wherein the cryptoprocessor is implemented in accordance with a Trusted Platform Module specification.

18. The article of claim 15 , the virtual BIOS engine further configured to extend the firmware payload into a configuration register of the cryptoprocessor after measuring the firmware payload, such that the configuration register includes a signature of an old firmware image to be replaced and the firmware payload.

19. The article of claim 18 , the virtual BIOS engine further configured to perform a quote of the configuration register.

20. The article of claim 19 , wherein the virtual BIOS engine further is configured to commit a new firmware image to the first non-transitory computer-readable media in response to verifying information stored in the configuration register relating to the old firmware image to be replaced and the firmware payload.

21. The article of claim 15 , wherein the isolated compute domain is instantiated on a securely-isolated hybrid processing core of the processor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2022
From: SURYANARAYANA, SHEKAR BABU; JOSHI, ANAND PRAKASH; NELSON, AMY CHRISTINE; GROBELNY, NICHOLAS D.
To: DELL PRODUCTS L.P.
Reel/Frame 060164/0039 →
Continuity (1)
Related Publication 20230401316A1 · Dec 14, 2023
Cited By (1)
US 12,339,969