IP Library › Granted Patent US 12,437,116
Granted Patent B2
US 12,437,116 · App. 18/298,977 · Granted Oct 7, 2025

Multi-path zero trust boot method to support context-specific OEM rebranding

Inventor: Shekar Babu Suryanarayana (Bangalore, IN)
Assignee: Dell Products L.P.
G06F21/64G06F21/575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,116
App. No.
18/298,977
Granted
Oct 7, 2025
Kind
B2
Abstract

Disclosed methods enable a mutable OEM identity to dynamically perform context-specific rebranding as part of a zero trust platform boot. This zero trust rebrand (ZTR) boot may implement an OEM security context identity method to fully ensure trusted rebrand boot paths against tampered, vulnerable, or corrupted payloads while leveraging existing customer-agnostic secure boot flow. Disclosed platforms may implement context-specific mutable entities via multiple boot paths to support the dynamic rebranding. A factory deploy engine may perform a bare metal deploy with a disclosed OEM security identity protocol, initialized by enumerating, for each of one or more OEMs, all OEM context attributes required for dynamic rebrand support. The rebrand protocol may create a protected namespace in non-volatile storage, e.g., a serial peripheral interface (SPI) flash area, to perform a once-only store of all OEM-specific mutable entities.

Claims (28)

1. A method, comprising:

for each of one or more original equipment manufacturers (OEMs), enumerating all OEM context (OC) attributes associated with a dynamic rebrand protocol and storing OEM-specific mutable entities for each of the OEM context attributes in an OEM context (OC) namespace;

storing one or more OC-specific signatures per OEM in a platform store;

applying an OEM-specific index key determined based on a current boot context; and

loading one or more of the OEM-specific mutable entities based on the current boot context before continuing in regular secure boot path.

2. The method of claim 1 , wherein the storing of the one or more mutable entities comprises performing a one-time-only factory mode storing of the one or more mutable entities.

3. The method of claim 1 , wherein the platform store comprises a platform nonvolatile (NV) store.

4. The method of claim 3 , wherein the platform NV store comprises a serial peripheral interface (SPI) flash memory store.

5. The method of claim 4 , wherein the OC namespace comprises a protected namespace.

6. The method of claim 1 , further comprising:

publishing an OEM context boot policy to ensure an existing secure boot path is unaltered.

7. The method of claim 1 , further comprising:

performing a customer agnostic secure boot flow to boot a customer agnostic firmware image.

8. An information handling system, comprising:

a central processing unit (CPU);

a computer readable memory, accessible to the CPU, including processor executable instructions that, when executed by the CPU, cause the system to perform operations comprising:

for each of one or more original equipment manufacturers (OEMs), enumerating all OEM context (OC) attributes associated with a dynamic rebrand protocol and storing OEM-specific mutable entities for each of the OC attributes in an OEM context (OC) namespace;

storing one or more OC specific signatures per OEM in a platform store;

applying an OEM-specific index key determined based on a current boot context; and

loading one or more of the OEM-specific mutable entities based on the current boot context before continuing in regular secure boot path.

9. The information handling system of claim 8 , wherein the storing of the one or more mutable entities comprises performing a one-time-only factory mode storing of the one or more mutable entities.

10. The information handling system of claim 8 , wherein the platform store comprises a platform nonvolatile (NV) store.

11. The information handling system of claim 10 , wherein the platform NV store comprises a serial peripheral interface (SPI) flash memory store.

12. The information handling system of claim 11 , wherein the OC namespace comprises a protected namespace.

13. The information handling system of claim 8 , wherein the operations further comprise:

publishing an OEM context boot policy to ensure an existing secure boot path is unaltered.

14. The information handling system of claim 8 , wherein the operations further comprise:

performing a customer agnostic secure boot flow to boot a customer agnostic firmware image.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2023
From: SURYANARAYANA, SHEKAR BABU
To: DELL PRODUCTS L.P.
Reel/Frame 063487/0953 →
Continuity (1)
Related Publication 20240346184A1 · Oct 17, 2024
References Cited (5)
US 20140075567A1 · Raleigh · 2014 [cited by examiner]
US 20140380425A1 · Lockett · 2014 [cited by examiner]
US 20190339888A1 · Sasidharan · 2019 [cited by examiner]
US 20200364040A1 · Chao · 2020 [cited by examiner]
US 20210103661A1 · Wu · 2021 [cited by examiner]