IP Library › Granted Patent US 12,417,290
Granted Patent B2
US 12,417,290 · App. 17/869,848 · Granted Sep 16, 2025

Revoked firmware rollback prevention

Inventors: William C. Munger (Round Rock, TX); Mukund P. Khatri (Austin, TX)
Assignee: Dell Products L.P.
G06F21/572G06F8/65G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,417,290
App. No.
17/869,848
Granted
Sep 16, 2025
Kind
B2
Abstract

An information handling system includes multiple components including a first component. The first component includes a protected memory and a basic input/output system (BIOS). The protected memory stores a revoked versions list. The BIOS initializes a firmware update for a firmware image having a firmware version. The BIOS scans the revoked versions list for the firmware version of the firmware image. In response to the firmware version not being located within the revoked versions list, the BIOS completes the firmware update, and determines whether a revoked firmware version is included in the firmware update. In response to the revoked firmware version being included in the firmware update, the BIOS adds an entry in the revoked versions list. The entry is associated with the revoked firmware version included in the firmware update.

Claims (54)

1. An information handling system comprising:

a protected memory to store a revoked versions list;

a processor configured to modify a revoked firmware version of a first firmware image in the revoked versions list; and

a basic input/output system (BIOS), the BIOS configured to:

initialize a firmware update for a firmware image having a firmware version;

scan the revoked versions list for the firmware version of the firmware image; and

in response to the firmware version not being located within the revoked versions list, the BIOS further configured to:

complete the firmware update;

determine whether a firmware version number for a new revoked firmware version is included in the firmware update, wherein the new revoked firmware version is a previous firmware version, wherein multiple firmware updates occurred between the previous firmware version and the firmware update; and

in response to the firmware version number for the new revoked firmware version being included in the firmware update, add an entry in the revoked versions list, the entry being associated with the firmware version number for the new revoked firmware version included in the firmware update.

2. The information handling system of claim 1 , wherein the processor further configured to:

receive a notification of a firmware version vulnerability associated with a first firmware version;

create a new entry for the first firmware version; and

add the new entry to the revoked versions list.

3. The information handling system of claim 2 , wherein the new entry is signed by a private key prior to being added to the revoked versions list.

4. The information handling system of claim 1 , wherein the scan of the revoked versions list is performed by a signed update utility.

5. The information handling system of claim 1 , wherein the new revoked firmware version in the firmware update is for versions prior to a current firmware image.

6. The information handling system of claim 1 , wherein the new revoked firmware version has a security vulnerability.

7. The information handling system of claim 1 , wherein the new revoked firmware version is stored in a unified extensible firmware interface variable.

8. The information handling system of claim 1 , in response to the firmware version being located within the revoked versions list, the BIOS further configured to abort the firmware update.

9. A method comprising:

modifying, by a processor, a revoked firmware version of a first firmware image in a revoked versions list;

initializing, by a basic input/output system (BIOS), a firmware update for a firmware image having a firmware version;

scanning, by the BIOS, the revoked versions list for the firmware version of the firmware image; and

in response to the firmware version not being located within the revoked versions list:

completing the firmware update;

determining whether a firmware version number for a new revoked firmware version is included in the firmware update, wherein the new revoked firmware version is a previous firmware version, wherein multiple firmware updates occurred between the previous firmware version and the firmware update; and

in response to the firmware version number for the new revoked firmware version being included in the firmware update, adding an entry in the revoked versions list, the entry is associated with the firmware version number for the new revoked firmware version included in the firmware update.

10. The method of claim 9 , further comprising:

receiving, by the processor, a notification of a firmware version vulnerability associated with a first firmware version;

creating, by the processor, a new entry for the first firmware version; and

adding the new entry to the revoked versions list.

11. The method of claim 10 , wherein the new entry is signed by a private key prior to being added to the revoked versions list.

12. The method of claim 9 , wherein the scanning of the revoked versions list is performed by a signed update utility within the BIOS.

13. The method of claim 9 , wherein the new revoked firmware version in the firmware update is for a current firmware image.

14. The method of claim 9 , wherein the new revoked firmware version has a security vulnerability.

15. The method of claim 9 , wherein the new revoked firmware version is a unified extensible firmware interface variable.

16. The method of claim 9 , wherein in response to the firmware version being located within the revoked versions list:

aborting the firmware update.

17. A method comprising:

modifying, by a processor, a revoked firmware version of a first firmware image in a revoked versions list;

initializing, by a basic input/output system (BIOS), a firmware update for a firmware image having a firmware version;

scanning, by the BIOS, the revoked versions list for the firmware version of the firmware image;

if the firmware version is not within the revoked versions list, then:

completing the firmware update;

determining whether a firmware version number for a new revoked firmware version is included in the firmware update, wherein the new revoked firmware version is a previous firmware version, wherein multiple firmware updates occurred between the previous firmware version and the firmware update; and

if the firmware version number for the new revoked firmware version is in the firmware update, then adding an entry in the revoked versions list, the entry is associated with the firmware version number for the new revoked firmware version included in the firmware update, wherein the new revoked firmware version has a security vulnerability; and

if the firmware version is within the revoked versions list, then aborting the firmware update.

18. The method of claim 17 , further comprising:

receiving, by the processor, a notification of a firmware version vulnerability associated with a first firmware version;

creating, by the processor, a new entry for the first firmware version; and

adding the new entry to the revoked versions list.

19. The method of claim 18 , wherein the new entry is signed by a private key prior to being added to the revoked versions list.

20. The method of claim 17 , wherein the new revoked firmware version in the firmware update is for versions prior to a current firmware image.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2022
From: MUNGER, WILLIAM C.; KHATRI, MUKUND P.
To: DELL PRODUCTS L.P.
Reel/Frame 060576/0243 →
Continuity (1)
Related Publication 20240028730A1 · Jan 25, 2024
References Cited (16)
US 5742829A · Davis · 1998 [cited by examiner]
US 6996817B2 · Birum · 2006 [cited by examiner]
US 8745612B1 · Semenzato · 2014 [cited by examiner]
US 10003612B1 · Hocker · 2018 [cited by examiner]
US 20110154135A1 · Tyhurst · 2011 [cited by examiner]
US 20170103192A1 · Hussey · 2017 [cited by examiner]
US 20190179631A1 · Benedetti · 2019 [cited by examiner]
US 20200019397A1 · Duran · 2020 [cited by examiner]
US 20200356357A1 · Narasimhan · 2020 [cited by examiner]
US 20210004466A1 · Nadarajah · 2021 [cited by examiner]
US 20210048997A1 · Samuel et al. · 2021 [cited by applicant]
US 20210224061A1 · Pillilli · 2021 [cited by examiner]
US 20220083324A1 · Singh et al. · 2022 [cited by applicant]
US 20230315432A1 · Chabaud · 2023 [cited by examiner]
US 20240338197A1 · Horovitz · 2024 [cited by examiner]
Eizenhefer et al., “Secure CRTM/BIOS Update Through Allowed Versions List”, published by ip.com, an IP.com Prior Art Database Technical Disclosure, pp. 1-7 (Year: 2006). [cited by examiner]