IP Library Granted Patent US 12,632,580
Granted Patent B2
US 12,632,580 · App. 18/498,324 · Granted May 19, 2026

Managing sanitization of data processing systems using out-of-band methods

Inventors: Richard M. Tonry (Georgetown, TX); Abeye Teshome (Austin, TX); Bassem El-Azzami (Austin, TX); Mohit Arora (Frisco, TX); Vinodkumar Vasudev Ottar (Mckinney, TX); Luis Antonio Valencia Reyes (Waxahachie, TX); Adolfo Sandor Montero (Pflugerville, TX); Amy Christine Nelson (Round Rock, TX); Rajaravi Chandra Kollarapu (Allen, TX)
Assignee: Dell Products L.P.
G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,580
App. No.
18/498,324
Granted
May 19, 2026
Kind
B2
Abstract

Methods and systems for managing a data processing system are disclosed. A management controller of the data processing system may provide a sanitization request to a policy management server using an out-of-band communication channel. The management controller may obtain a response to the sanitization request from the policy management server via the out-of-band communication channel. The response may indicate whether performance of a sanitization process is authorized. The authorization may be based on a sanitization policy that governs sanitizations for the data processing system. If performance of the sanitization process is authorized, then the management controller may initiate and/or perform an action set based on the sanitization policy in order to complete the sanitization process, thereby placing the data processing system in a safe state.

Claims (48)

1 . A method for managing a data processing system, the method comprising:

providing, by a management controller of the data processing system and via an out-of-band communication channel that is provided by a network module of the data processing system that also provides in-band communication channels and the out-of-band communication channel also bypassing hardware resources of the data processing system that participate in performance of at least a portion of an action set, a sanitization request to a policy management server;

obtaining, by the management controller and via the out-of-band communication channel, a response to the sanitization request from the policy management server, the response indicating whether performance of a sanitization process is authorized based, at least in part, on a sanitization policy that, at least in part, governs sanitizations for the data processing system; and

in a first instance of the obtaining, where the performance of the sanitization process is authorized:

performing, by, at least in part, the management controller, the action set based on the sanitization policy in order to complete the performance of the sanitization process to place the data processing system in a safe state.

2 . The method of claim 1 , further comprising:

prior to providing the sanitization request:

obtaining, by the management controller, instructions to initiate the sanitization process from the hardware resources of the data processing system.

3 . The method of claim 1 , further comprising:

prior to providing the sanitization request:

obtaining, by the management controller and via the out-of-band communication channel, instructions to initiate the sanitization process from the policy management server.

4 . The method of claim 1 , wherein performing the action set comprises deleting a portion of data stored on the data processing system.

5 . The method of claim 4 , wherein performing the action set further comprises providing a sanitization status to the policy management server.

6 . The method of claim 1 , wherein after placing the data processing system in the safe state, sensitive data previously stored on the data processing system is unrecoverable from the data processing system.

7 . The method of claim 6 , wherein the sensitive data comprises at least one type of sensitive data from a list of types of sensitive data consisting of:

a fingerprint;

a password;

device-specific provisioning data; and

owner-specific provisioning data.

8 . The method of claim 1 , wherein the data processing system comprises a network module adapted to separately advertise network endpoints for the management controller and the hardware resources of the data processing system, the network endpoints being usable by the policy management server to address communications to the hardware resources and the management controller.

9 . The method of claim 8 , wherein the out-of-band communication channel runs through the network module, and an in-band communication channel that services the hardware resources also runs through the network module.

10 . The method of claim 9 , wherein the management controller and the network module are on separate power domains from the hardware resources so that the management controller and the network module are operable while the hardware resources are inoperable.

11 . The method of claim 10 , wherein the response is obtained while the hardware resources are inoperable due to being unpowered.

12 . The method of claim 10 , wherein the sanitization process is performed while at least a portion of the hardware resources are inoperable due to being unpowered.

13 . The method of claim 1 , wherein the hardware resources are adapted to provide desired computer implemented services using the in-band communication channels, the in-band communication channels bypassing the management controller, the in-band communication channels and the out-of-band communication channel facilitating separate addressing of the hardware resources and the management controller, and the in-band communication channels and the out-of-band communication channel being distinct physical layer channels.

14 . The method of claim 1 , wherein at least a portion of the hardware resources are unpowered when the response is obtained, and the at least the portion of the hardware resources are unpowered during performance of some of the action set.

15 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing a data processing system, the operations comprising:

providing, by a management controller of the data processing system and via an out-of-band communication channel that is provided by a network module of the data processing system that also provides in-band communication channels and the out-of-band communication channel also bypassing hardware resources of the data processing system that participate in performance of at least a portion of an action set, a sanitization request to a policy management server;

obtaining, by the management controller and via the out-of-band communication channel, a response to the sanitization request from the policy management server, the response indicating whether performance of a sanitization process is authorized based, at least in part, on a sanitization policy that, at least in part, governs sanitizations for the data processing system; and

in a first instance of the obtaining, where the performance of the sanitization process is authorized:

performing, by, at least in part, the management controller, the action set based on the sanitization policy in order to complete the performance of the sanitization process to place the data processing system in a safe state.

16 . The non-transitory machine-readable medium of claim 15 , wherein the operations further comprise:

prior to providing the sanitization request:

obtaining, by the management controller, instructions to initiate the sanitization process from the hardware resources of the data processing system.

17 . The non-transitory machine-readable medium of claim 15 , wherein the operations further comprise:

prior to providing the sanitization request:

obtaining, by the management controller and via the out-of-band communication channel, instructions to initiate the sanitization process from the policy management server.

18 . The non-transitory machine-readable medium of claim 17 , wherein in the first instance of the obtaining, where the performance of the sanitization process is authorized, the response confirming, to the management controller, that the instructions have been authenticated by the policy management server.

19 . A data processing system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing the data processing system, the operations comprising:

providing, by a management controller of the data processing system and via an out-of-band communication channel that is provided by a network module of the data processing system that also provides in-band communication channels and the out-of-band communication channel also bypassing hardware resources of the data processing system that participate in performance of at least a portion of an action set, a sanitization request to a policy management server;

obtaining, by the management controller and via the out-of-band communication channel, a response to the sanitization request from the policy management server, the response indicating whether performance of a sanitization process is authorized based, at least in part, on a sanitization policy that, at least in part, governs sanitizations for the data processing system; and

in a first instance of the obtaining, where the performance of the sanitization process is authorized:

performing, by, at least in part, the management controller, the action set based on the sanitization policy in order to complete the performance of the sanitization process to place the data processing system in a safe state.

20 . The data processing system of claim 19 , wherein the operations further comprise:

prior to providing the sanitization request:

obtaining, by the management controller, instructions to initiate the sanitization process from the hardware resources of the data processing system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2023
From: TONRY, RICHARD M.; TESHOME, ABEYE; EL-AZZAMI, BASSEM; ARORA, MOHIT; OTTAR, VINODKUMAR VASUDEV; VALENCIA REYES, LUIS ANTONIO; MONTERO, ADOLFO SANDOR; NELSON, AMY CHRISTINE; KOLLARAPU, RAJARAVI CHANDRA
To: DELL PRODUCTS L.P.
Reel/Frame 065568/0303 →
Continuity (1)
Related Publication 20250139271A1 · May 1, 2025
References Cited (34)
US 7599907B2 · Havewala et al. · 2009 [cited by applicant]
US 8020192B2 · Wright et al. · 2011 [cited by applicant]
US 8490163B1 · Harsell et al. · 2013 [cited by applicant]
US 8738935B1 · Brooker · 2014 [cited by examiner]
US 8850186B2 · Yamauchi · 2014 [cited by applicant]
US 9165931B1 · Schmit · 2015 [cited by examiner]
US 9191781B2 · Kumar · 2015 [cited by applicant]
US 9246678B2 · Nayshtut et al. · 2016 [cited by applicant]
US 9349009B2 · Rivera · 2016 [cited by applicant]
US 9721111B2 · Cavanaugh · 2017 [cited by applicant]
US 9721175B2 · Kursun et al. · 2017 [cited by applicant]
US 9785491B2 · Cilfone et al. · 2017 [cited by applicant]
US 10021669B2 · George · 2018 [cited by applicant]
US 10163105B1 · Ziraknejad et al. · 2018 [cited by applicant]
US 10169571B1 · Attfield et al. · 2019 [cited by applicant]
US 10395039B2 · Khatri et al. · 2019 [cited by applicant]
US 10630489B2 · Hughes · 2020 [cited by applicant]
US 10678555B2 · Johansson et al. · 2020 [cited by applicant]
US 10841295B1 · Pecen et al. · 2020 [cited by applicant]
US 11563565B2 · Yang et al. · 2023 [cited by applicant]
US 11704384B2 · Murphy et al. · 2023 [cited by applicant]
US 20130227634A1 · Pal · 2013 [cited by examiner]
US 20150271207A1 · Jaiswal · 2015 [cited by applicant]
US 20170277876A1 · Alameh et al. · 2017 [cited by applicant]
US 20170289197A1 · Mandyam et al. · 2017 [cited by applicant]
US 20180006829A1 · Kravitz et al. · 2018 [cited by applicant]
US 20180255080A1 · Paine · 2018 [cited by applicant]
US 20180341773A1 · Khatri · 2018 [cited by examiner]
US 20190156019A1 · Chen · 2019 [cited by applicant]
US 20190207980A1 · Sarin · 2019 [cited by applicant]
US 20190312887A1 · Grimm · 2019 [cited by applicant]
US 20200195433A1 · Collier · 2020 [cited by examiner]
US 20210099467A1 · March · 2021 [cited by applicant]
US 20220222328A1 · Talib et al. · 2022 [cited by applicant]