IP Library Granted Patent US 12,277,229
Granted Patent B2
US 12,277,229 · App. 18/452,024 · Granted Apr 15, 2025

Pre-calculation of cryptoprocessor control register

Inventors: Robert Kliewer (Wylie, TX); Darrel Goeddel (Urbana, IL); Ted Pacyga (St. Louis, MO)
Assignee: EVERFOX HOLDINGS LLC
G06F21/575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,277,229
App. No.
18/452,024
Granted
Apr 15, 2025
Kind
B2
Abstract

A computer-implementable method may include, during execution of an installation image for installing an operating system on an information handling system performing mock measurements for one or more configuration registers of a cryptoprocessor of the information handling system based on values for the one or more configuration registers that will exist for a boot session of the information handling system immediately following installation of the operating system, extending the mock measurements into the one or more mock configuration registers, and storing an encryption key to the cryptoprocessor such that the encryption key is accessible to a subsequent boot session of the information handling system if the contents of the one or more configuration registers are equal to measurements performed by firmware of the information handling system during the subsequent boot session.

Claims (26)

1. A computer-implementable method comprising, during execution of an installation image for installing an operating system on an information handling system:

performing mock measurements for one or more configuration registers of a cryptoprocessor of the information handling system based on values for the one or more configuration registers that will exist for a boot session of the information handling system immediately following installation of the operating system;

extending the mock measurements into one or more mock configuration registers; and

storing an encryption key to the cryptoprocessor such that the encryption key is accessible to a subsequent boot session of the information handling system if the contents of the one or more mock configuration registers are equal to measurements performed by firmware of the information handling system during the subsequent boot session.

2. The computer-implementable method of claim 1 , wherein the cryptoprocessor comprises a Trusted Platform Module.

3. The computer-implementable method of claim 2 , wherein the one or more configuration registers comprise one or more Platform Configuration Registers of the Trusted Platform Module.

4. The computer-implementable method of claim 1 , wherein the one or more configuration registers comprise a Platform Configuration Register associated with a secure boot assurance executed by a basic input/output system of the information handling system.

5. The computer-implementable method of claim 1 , wherein the encryption key is used in connection with encryption or decryption of data stored to a hard disk drive of the information handling system.

6. A system comprising:

a processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for, when read and executed by the processor:

performing mock measurements for one or more configuration registers of a cryptoprocessor of the information handling system based on values for one or more configuration registers that will exist for a boot session of the information handling system immediately following installation of the operating system;

extending the mock measurements into one or more mock configuration registers; and

storing an encryption key to the cryptoprocessor such that the encryption key is accessible to a subsequent boot session of the information handling system if the contents of the one or more mock configuration registers are equal to measurements performed by firmware of the information handling system during the subsequent boot session.

7. The system of claim 6 , wherein the cryptoprocessor comprises a Trusted Platform Module.

8. The system of claim 7 , wherein the one or more configuration registers comprise one or more Platform Configuration Registers of the Trusted Platform Module.

9. The system of claim 6 , wherein the one or more configuration registers comprise a Platform Configuration Register associated with a secure boot assurance executed by a basic input/output system of the information handling system.

10. The system of claim 6 , wherein the encryption key is used in connection with encryption or decryption of data stored to a hard disk drive of the information handling system.

11. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

performing mock measurements for one or more configuration registers of a cryptoprocessor of an information handling system based on values for the one or more configuration registers that will exist for a boot session of the information handling system immediately following installation of the operating system;

extending the mock measurements into one or more mock configuration registers; and

storing an encryption key to the cryptoprocessor such that the encryption key is accessible to a subsequent boot session of the information handling system if the contents of the one or more mock configuration registers are equal to measurements performed by firmware of the information handling system during the subsequent boot session.

12. The storage medium of claim 11 , wherein the cryptoprocessor comprises a Trusted Platform Module.

13. The storage medium of claim 12 , wherein the one or more configuration registers comprise one or more Platform Configuration Registers of the Trusted Platform Module.

14. The storage medium of claim 11 , wherein the one or more configuration registers comprise a Platform Configuration Register associated with a secure boot assurance executed by a basic input/output system of the information handling system.

15. The storage medium of claim 11 , wherein the encryption key is used in connection with encryption or decryption of data stored to a hard disk drive of the information handling system.

Assignments (2)
CHANGE OF NAME Recorded Feb 13, 2024
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 066582/0531 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2023
From: KLIEWER, ROBERT; GOEDDEL, DARREL; PACYGA, TED
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 064635/0092 →
Continuity (1)
Related Publication 20250061205A1 · Feb 20, 2025
References Cited (6)
US 20020194389A1 · Worley, Jr. · 2002 [cited by examiner]
US 20030115445A1 · Heller · 2003 [cited by examiner]
US 20180365422A1 · Callaghan · 2018 [cited by examiner]
US 20230252172A1 · Mink · 2023 [cited by examiner]
US 20230261866A1 · Roper · 2023 [cited by examiner]
US 20240086543A1 · Hwang · 2024 [cited by examiner]