IP Library Granted Patent US 12,639,413
Granted Patent B2
US 12,639,413 · App. 18/177,226 · Granted May 26, 2026

Systems and methods for caching SPDM-based certificates

Inventors: Rama Rao Bisa (Bangalore, IN); Dharma Bhushan Ramaiah (Bangalore, IN); Vineeth Radhakrishnan (Palakkad, IN); Mini Thottunkal Thankappan (Bangalore, IN); Shinose Abdul Rahiman (Bangalore, IN)
Assignee: Dell Products L.P.
G06F21/33G06F12/0875G06F2212/1052G06F2212/45
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,639,413
App. No.
18/177,226
Granted
May 26, 2026
Kind
B2
Abstract

According to embodiments of the present disclosure, a certificate caching system and method is provided using Security Protocol and Data Model (SPDM)-enabled Baseboard Management Controller (BMC). The system time verification system and method include program instructions that may be executed on an Information Handling System (HIS) to obtain a certificate from a SPDM-enabled device configured in a target computing device, identify a cache associated with the target computing device, determine whether the certificate is a hardware bound certificate, and store the certificate in the cache based upon the determination.

Claims (60)

1 . An Information Handling System (IHS) comprising:

at least one memory coupled to at least one processor, the at least one memory having program instructions stored thereon that, upon execution by the at least one processor, cause the IHS to:

obtain a certificate from a Security Protocol and Data Model (SPDM)-enabled device configured in a target computing device;

identify a Certificate Transparency (CT) list associated with the target computing device;

determine whether the certificate is a hardware bound certificate; and

store the certificate in the CT list based upon the determination;

obtain data associated with how the certificate is obtained from an associated SPDM-enabled device, wherein the obtained data comprises at least one of a capacity of the CT list and a response time to obtain the certificate from the SPDM-enabled device;

generate a score based upon the obtained data; and

add the certificate to the CT list or remove the certificate from the CT list based upon the score.

2 . The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to:

for each SPDM-enabled device deployed in the target computing device, add a hardware bound certificate associated with the SPDM-enabled device to the CT list; and

when one of the SPDM-enabled devices is removed from the target computing device, remove its hardware bound certificate associated with the one SPDM-enabled device from the CT list.

3 . The IHS of claim 2 , wherein the program instructions, upon execution, further cause the IHS to:

at an ongoing basis, determine whether any of the certificates are valid or invalid; and

when one of the certificates is determined to be invalid, perform one or more remedial actions.

4 . The IHS of claim 3 , wherein the one or more remedial actions comprise at least one of;

stop communicating with the SPDM-enabled device associated with the one certificate, disable a slot associated with the SPDM-enabled device, and generate an alert message indicating the invalid certificate.

5 . The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to:

notify a SPDM daemon that the certificate is to be obtained from the CT list.

6 . The IHS of claim 5 , wherein the program instructions, upon execution, further cause the IHS to obtain the data during a SPDM authentication process.

7 . The IHS of claim 5 , wherein the program instructions, upon execution, further cause the IHS to remove the certificate from the CT list or replace another certificate with the certificate based upon the score.

8 . The IHS of claim 1 , wherein the program instructions are performed by a Baseboard Management Controller (BMC) configured in the IHS.

9 . A Security Protocol and Data Model (SPDM)-based certificate caching method comprising:

obtaining a certificate from a SPDM-enabled device configured in a target computing device;

identifying a Certificate Transparency (CT) list associated with the target computing device;

determining whether the certificate is a hardware bound certificate; and

storing the certificate in the CT list based upon the determination;

obtaining data associated with how the certificate is obtained from an associated SPDM-enabled device, wherein the obtained data comprises at least one of a capacity of the CT list and a response time to obtain the certificate from the SPDM-enabled device;

generating a score based upon the obtained data; and

adding the certificate to the CT list or removing the certificate from the CT list based upon the score.

10 . The SPDM-based certificate caching method of claim 9 , further comprising:

for each SPDM-enabled device deployed in the target computing device, adding a hardware bound certificate associated with the SPDM-enabled device to the CT list; and

when one of the SPDM-enabled devices is removed from the target computing device, removing its hardware bound certificate associated with the one SPDM-enabled device from the CT list.

11 . The SPDM-based certificate caching method of claim 10 , further comprising:

at an ongoing basis, determining whether any of the certificates are valid or invalid; and

when one of the certificates is determined to be invalid, performing one or more remedial actions comprising at least one of stopping communication with the SPDM-enabled device associated with the one certificate, disabling a slot associated with the SPDM-enabled device, and generating an alert message indicating the invalid certificate.

12 . The SPDM-based certificate caching method of claim 9 , further comprising:

notifying a SPDM daemon that the certificate is to be obtained from the CT list.

13 . The SPDM-based certificate caching method of claim 12 , further comprising obtaining the data during a SPDM authentication process.

14 . The SPDM-based certificate caching method of claim 12 , further comprising removing the certificate from the CT list or replacing another certificate with the certificate based upon the score.

15 . A computer program product comprising a non-transitory computer readable storage medium having program instructions stored thereon that, upon execution by a Baseboard Management Controller (BMC), cause the BMC to:

obtain a certificate from a Security Protocol and Data Model (SPDM)-enabled device configured in a target computing device;

identify a Certificate Transparency (CT) list associated with the target computing device;

determine whether the certificate is a hardware bound certificate; and

store the certificate in the CT list based upon the determination;

obtain data associated with how the certificate is obtained from an associated SPDM-enabled device, wherein the obtained data comprises at least one of a capacity of the CT list and a response time to obtain the certificate from the SPDM-enabled device;

generate a score based upon the obtained data; and

add the certificate to the CT list or remove the certificate from the CT list based upon the score.

16 . The computer program product of claim 15 , wherein the program instructions, upon execution, further cause the BMC to:

for each SPDM-enabled device deployed in the target computing device, add a hardware bound certificate associated with the SPDM-enabled device to the CT list; and

when one of the SPDM-enabled devices is removed from the target computing device, remove its associated hardware bound certificate associated with the one SPDM-enabled device from the CT list.

17 . The computer program product of claim 16 , wherein the program instructions, upon execution, further cause the BMC to:

at an ongoing basis, determine whether any of the certificates are valid or invalid; and

when one of the certificates is determined to be invalid, perform one or more remedial actions comprising at least one of stopping communication with the SPDM-enabled device associated with the one certificate, disabling a slot associated with the SPDM-enabled device, and generating an alert message indicating the invalid certificate.

18 . The computer program product of claim 15 , wherein the program instructions, upon execution, further cause an Information Handling System (IHS) to:

obtain data associated with how the certificate is obtained from an associated SPDM-enabled device;

generate a score based upon the obtained data;

add the certificate to the CT list or remove the certificate from the CT list based upon the score; and

notify a SPDM daemon that the certificate is to be obtained from the CT list.

19 . The computer program product of claim 18 , wherein the program instructions, upon execution, further cause the IHS to obtain the data during a SPDM authentication process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2023
From: BISA, RAMA RAO; RAMAIAH, DHARMA BHUSHAN; RADHAKRISHNAN, VINEETH; THANKAPPAN, MINI THOTTUNKAL; RAHIMAN, SHINOSE ABDUL
To: DELL PRODUCTS, L.P.
Reel/Frame 062853/0499 →
Continuity (1)
Related Publication 20240296214A1 · Sep 5, 2024
References Cited (17)
US 11609980B2 · Benedict · 2023 [cited by examiner]
US 20190065072A1 · Dirik · 2019 [cited by examiner]
US 20210312044A1 · Berger · 2021 [cited by examiner]
US 20210342836A1 · Cella · 2021 [cited by examiner]
US 20220012187A1 · Contreras Munoz · 2022 [cited by examiner]
US 20220124118A1 · Bangalore Sathyanarayana · 2022 [cited by examiner]
US 20220292203A1 · Severns-Williams · 2022 [cited by examiner]
US 20230103368A1 · Vergis · 2023 [cited by examiner]
US 20230173395A1 · Cella · 2023 [cited by examiner]
US 20230205562A1 · Basak · 2023 [cited by examiner]
US 20230367575A1 · Izzo · 2023 [cited by examiner]
US 20230394140A1 · Orlando · 2023 [cited by examiner]
US 20240220298A1 · Powell · 2024 [cited by examiner]
US 20240220639A1 · Sahu · 2024 [cited by examiner]
US 20250141926A1 · Jain · 2025 [cited by examiner]
Diaz-Sanchez, Daniel et al. TLS/PKI Challenges and Certificate Pinning Techniques for IoT and M2M Secure Communications. IEEE Communications Surveys & Tutorials, vol. 21, Issue: 4. https://ieeexplore.ieee.org/stamp/stam… [cited by examiner]
Hinarejos, M. Francisca et al. RiskLaine: A Probabilistic Approach for Assessing Risk in Certificate-Based Security. IEEE Transactions on Information Forensics and Security, vol. 13, Issue: 8. https://ieeexplore.ieee.or… [cited by examiner]