IP Library Granted Patent US 12,373,569
Granted Patent B2
US 12,373,569 · App. 17/868,543 · Granted Jul 29, 2025

Pre-operating system embedded controller hardening based on operating system security awareness

Inventors: Ibrahim Sayyed (Georgetown, TX); Adolfo Montero (Pflugerville, TX); Laxmi Medicherla (Austin, TX)
Assignee: Dell Products L.P.
G06F21/577G06F21/54G06F21/572
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,569
App. No.
17/868,543
Granted
Jul 29, 2025
Kind
B2
Abstract

An information handling system includes an embedded controller and a memory device storing code that when executed causes the embedded controller to perform operations that includes receiving a request to change a security setting, determining a security policy associated with the security setting, and determining whether the change to the security setting deviates from the security policy. In addition, the embedded controller in response to determining that the change to the security setting deviates from the security policy, denying the request and reverting the change to the security setting.

Claims (33)

1. A method comprising:

receiving, by an embedded controller, a request to change a security setting;

determining a security policy associated with the security setting;

determining whether the request to change to the security setting adheres to the security policy; and

in response to determining that the request to change to the security setting is authorized but the change to the security setting does not adhere with the security policy, denying the request and overwriting the change to the security setting with a previous value using a secured memory-mapped input/output command.

2. The method of claim 1 , further comprising in response to determining that the change to the security setting adheres to the security policy, authorizing the request and applying the change to the security setting.

3. The method of claim 1 , wherein the security setting is an operating system level security setting.

4. The method of claim 1 , wherein the security setting is a system basic input-output system (BIOS) security setting.

5. The method of claim 1 , further comprising restricting access to a locked controller device.

6. The method of claim 1 , wherein the embedded controller is provisioned with the security policy.

7. The method of claim 1 , further comprising logging the request to change the security setting.

8. The method of claim 1 , wherein the embedded controller is communicatively coupled to a software service via a secured memory-mapped input/output bus.

9. An information handling system, comprising:

an embedded controller; and

a memory device storing code that when executed causes the embedded controller to perform operations, the operations including:

receiving, by the embedded controller, a write operation request to change an operating system level security setting;

determining a security policy associated with the operating system level security setting;

determining whether the change to the operating system level security setting deviates from the security policy; and

in response to determining that the write operation request to change to the operating system level security setting deviates from the security policy, denying the write operation request and overwriting the change to the operating system level security setting with a previous value.

10. The information handling system of claim 9 , the operations further comprising in response to determining that the change to the operating system level security setting adheres to the security policy, authorizing the write operation request and applying the change to the operating system level security setting.

11. The information handling system of claim 9 , wherein the operating system level security setting is an operating system security setting.

12. The information handling system of claim 9 , wherein the operating system level security setting is an information technology decision maker (ITDM) security setting.

13. The information handling system of claim 9 , wherein the security policy is a corporate policy.

14. The information handling system of claim 9 , wherein the embedded controller is provisioned with the security policy.

15. The information handling system of claim 9 , wherein the embedded controller is communicatively coupled to a software service via a secured memory-mapped input/output.

16. A non-transitory computer-readable media to store instructions that are executable to perform operations, the operations comprising:

receiving, by an embedded controller, a write operation request to change a pre-operating system level security setting;

determining a security policy associated with the write operation request to change the pre-operating system level security setting; and

if the write operation request to change to the pre-operating system level security setting is unauthorized, then restricting access to the pre-operating system level security setting based on the security policy.

17. The non-transitory computer-readable media of claim 16 , wherein the operations further comprise if the change to the pre-operating system level security setting adheres to the security policy, then authorizing the write operation request, and applying the change to the pre-operating system level security setting.

18. The non-transitory computer-readable media of claim 16 , wherein the pre-operating system level security setting is basic input/output system (BIOS) security setting.

19. The non-transitory computer-readable media of claim 16 , wherein the restricting access to the pre-operating system level security setting includes greying out the pre-operating system level security setting.

20. The non-transitory computer-readable media of claim 16 , wherein the pre-operating system level security setting is a hardware security setting.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2022
From: SAYYED, IBRAHIM; MONTERO, ADOLFO; MEDICHERLA, LAXMI
To: DELL PRODUCTS L.P.
Reel/Frame 060553/0543 →
Continuity (1)
Related Publication 20240028739A1 · Jan 25, 2024
References Cited (19)
US 6748544B1 · Challener · 2004 [cited by examiner]
US 9880908B2 · Jeansonne · 2018 [cited by examiner]
US 10091112B1 · Sharma · 2018 [cited by examiner]
US 10289832B2 · Page · 2019 [cited by examiner]
US 10949540B2 · Andrews et al. · 2021 [cited by applicant]
US 11113403B2 · Sella · 2021 [cited by examiner]
US 11169818B2 · Suryanarayana et al. · 2021 [cited by applicant]
US 11347856B2 · Sayyed et al. · 2022 [cited by applicant]
US 20040078591A1 · Teixeira · 2004 [cited by examiner]
US 20080276059A1 · Horiuchi · 2008 [cited by examiner]
US 20120179802A1 · Narasimhan · 2012 [cited by examiner]
US 20140230078A1 · Graham · 2014 [cited by examiner]
US 20160316005A1 · Thirumurthi · 2016 [cited by examiner]
US 20160328555A1 · Page · 2016 [cited by examiner]
US 20210034756A1 · Vichare · 2021 [cited by examiner]
US 20210240567A1 · Hsu et al. · 2021 [cited by applicant]
US 20220156378A1 · Eguchi · 2022 [cited by examiner]
US 20220391545A1 · Stewart · 2022 [cited by examiner]
WO WO2018190846A1 · 2018 [cited by examiner]