IP Library Granted Patent US 12,367,299
Granted Patent B2
US 12,367,299 · App. 17/863,095 · Granted Jul 22, 2025

Methods, systems, and program products for securely blocking access to system operations and data

Inventors: Robert J. Kapinos (Durham, NC); Scott Li (Cary, NC); Robert James Norton, Jr. (Raleigh, NC); Russell Speight VanBlon (Raleigh, NC)
Assignee: Lenovo (United States) Inc.
G06F21/62
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,367,299
App. No.
17/863,095
Granted
Jul 22, 2025
Kind
B2
Abstract

Methods, systems, and program products are disclosed for blocking input/output (I/O) access to a computing system. A method includes establishing a portion of the machine-readable instructions as sole controller of the system responsive to the machine-readable instructions and preventing unauthorized replacement of the machine-readable instructions. The method also includes blocking user access to internal resources of the computing system and preventing predefined input/output (I/O) of the computing system.

Claims (57)

1. A method performed on a computing system, the method comprising:

receiving a special capsule read-only memory (“ROM”) having a payload configured to block input/output (I/O) access, the payload comprising machine-readable instructions;

loading the special capsule ROM to a scratchpad memory using a flash ROM utility of the computing system;

performing a hard restart of the computing system;

flashing the special capsule ROM;

preventing unauthorized replacement of the machine-readable instructions;

blocking user access to internal resources of the computing system; and

preventing predefined input/output (I/O) of the computing system.

2. The method of claim 1 , further comprising establishing a portion of the machine-readable instructions as a sole controller of the computing system responsive to the machine-readable instructions and replacing previously stored instructions by a different, predefined set of machine-readable instructions through an authorized process internal to the computing system responsive to the machine-readable instructions.

3. The method of claim 2 , further comprising:

creating encryption keys at time of blocking predefined input/output (I/O) access; and

validating the payload of a recovery capsule ROM based on the encryption keys.

4. The method of claim 1 , further comprising installing the machine-readable instructions using a unified extensible firmware interface (UEFI) capsule update process.

5. The method of claim 1 , further comprising:

determining that the received special capsule ROM is an authorized recovery capsule ROM; and

restoring normal operation of the computing system upon the authorized recovery capsule ROM being flashed into the computing system.

6. The method of claim 5 , wherein the determining comprises determining if the authorized recovery capsule ROM is available at a previously designated port of the computing system.

7. The method of claim 1 , further comprising validating the payload based on previously created encryption keys, wherein the previously created encryption keys were generated by a manufacturer of the computing system.

8. A system comprising:

a processor; and

a storage device configured to store machine-readable instructions that, when executed by the processor, cause the processor to:

receive a special capsule read-only memory (“ROM”) having a payload configured to block input/output (I/O) access;

load the special capsule ROM to a scratchpad memory using a flash ROM utility of the system;

perform a hard restart of the system;

flash the special capsule ROM;

prevent unauthorized replacement of the machine-readable instructions;

block user access to internal resources of the system; and

prevent predefined input/output (I/O) of the system.

9. The system of claim 8 , wherein the machine-readable instructions further cause the processor to establish a portion of the machine-readable instructions as a sole controller of the system responsive to the machine readable instructions and replace previously stored instructions by a different, predefined set of machine-readable instructions through an authorized process internal to the system responsive to the machine-readable instructions.

10. The system of claim 8 , wherein the machine-readable instructions further cause the processor to install the machine-readable instructions using a unified extensible firmware interface (UEFI) capsule update process.

11. The system of claim 8 , wherein the machine-readable instructions further cause the processor to:

determine that the received special capsule ROM is an authorized recovery capsule ROM; and

restore normal operation of the system upon the authorized recovery capsule ROM being flashed into the system.

12. The system of claim 11 , wherein the machine-readable instructions further cause the processor to determine if the authorized recovery capsule ROM is available at a previously designated port of the system.

13. The system of claim 8 , wherein the machine-readable instructions further cause the processor to validate the payload based on previously created encryption keys.

14. The system of claim 13 , wherein the previously created encryption keys were previously generated by a manufacturer of the system.

15. A non-transitory computer-readable medium storing machine-readable instructions that, when executed by a processor of a computing system, cause the processor to:

receive a special capsule read-only memory (“ROM”) having a payload configured to block input/output (I/O) access, the payload comprising machine-readable instructions;

load the special capsule ROM to a scratchpad memory using a flash ROM utility of the computing system;

perform a hard restart of the computing system;

flash the special capsule ROM;

prevent unauthorized replacement of the machine-readable instructions;

block user access to internal resources of the computing system; and

prevent predefined input/output (I/O) of the computing system.

16. The non-transitory computer-readable medium of claim 15 ,

wherein the machine-readable instructions further cause the processor to establish a portion of the machine-readable instructions as a sole controller of the computing system responsive to the machine-readable instructions and replace previously stored instructions by a different, predefined set of machine-readable instructions through an authorized process internal to the computing system responsive to the machine-readable instructions.

17. The non-transitory computer-readable medium of claim 15 , wherein the machine-readable instructions further cause the processor to install the machine-readable instructions using a unified extensible firmware interface (UEFI) capsule update process.

18. The non-transitory computer-readable medium of claim 15 ,

wherein the machine-readable instructions further cause the processor to:

determine that the loaded special capsule ROM is an authorized recovery capsule ROM; and

restore normal operation of the computing system upon the authorized recovery capsule ROM being flashed into the computing system.

19. The non-transitory computer-readable medium of claim 18 ,

wherein the machine-readable instructions further cause the processor to determine if the authorized recovery capsule ROM is available at a previously designated port of the computing system.

20. The non-transitory computer-readable medium of claim 18 ,

wherein the machine-readable instructions further cause the processor to:

manipulate a version of basic input/output system (BIOS) firmware to be lower than a version associated with the recovery capsule ROM; and

validate the payload based on previously created encryption keys, wherein the previously created encryption keys were previously generated by a manufacturer of the computing system.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2022
From: LENOVO (UNITED STATES) INC.
To: LENOVO (SINGAPORE) PTE. LTD
Reel/Frame 062078/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2022
From: KAPINOS, ROBERT J; LI, SCOTT; NORTON, ROBERT JAMES, JR.; VANBLON, RUSSELL SPEIGHT
To: LENOVO (UNITED STATES) INC.
Reel/Frame 060565/0379 →
Continuity (1)
Related Publication 20240020395A1 · Jan 18, 2024
References Cited (24)
US 7860097B1 · Lovett · 2010 [cited by examiner]
US 11531760B1 · Righi · 2022 [cited by examiner]
US 20050235135A1 · Dao · 2005 [cited by examiner]
US 20090327684A1 · Zimmer · 2009 [cited by examiner]
US 20160202964A1 · Butcher · 2016 [cited by examiner]
US 20160241398A1 · Lewis · 2016 [cited by examiner]
US 20170109235A1 · Hung · 2017 [cited by examiner]
US 20170286086A1 · Narasimhan · 2017 [cited by examiner]
US 20190243634A1 · Lewis · 2019 [cited by examiner]
US 20200082090A1 · Samuel · 2020 [cited by examiner]
US 20200310774A1 · Zhu · 2020 [cited by examiner]
US 20200310824A1 · Atta · 2020 [cited by examiner]
US 20210232384A1 · Lewis · 2021 [cited by examiner]
US 20210240489A1 · Xie · 2021 [cited by examiner]
US 20210240831A1 · Oncale · 2021 [cited by examiner]
US 20220050671A1 · Samuel · 2022 [cited by examiner]
US 20220292203A1 · Severns-Williams · 2022 [cited by examiner]
US 20220334825A1 · Swirydczuk · 2022 [cited by examiner]
US 20230083979A1 · Mitchell · 2023 [cited by examiner]
US 20240193309A1 · Wagner · 2024 [cited by examiner]
WO WO2021221602A1 · 2021 [cited by examiner]
Cooper, David, et al. “BIOS protection guidelines.” NIST Special Publication 800.2011 (2011): 147. (Year: 2011). [cited by examiner]
Yao, Jiewen, and Vincent Zimmer. “A Tour Beyond BIOS-Capsule Update and Recovery in EDK II.” Intel whitepaper (2016). (Year: 2016). [cited by examiner]
Yao, Jiewen, and Vincent Zimmer. “Building secure firmware.” Apress: New York, NY, USA (2020): 18-48. (Year: 2020). [cited by examiner]