IP Library › Granted Patent US 12,517,997
Granted Patent B2
US 12,517,997 · App. 18/509,616 · Granted Jan 6, 2026

Validation for an IHS with swappable hardware components

Inventors: A Anis Ahmed (Bangalore, IN); Jason Matthew Young (Round Rock, TX); Pallavi Satpathy (Bhubaneswar, IN); Kalyani Korubilli (Bangalore, IN)
Assignee: Dell Products, L.P.
G06F21/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,517,997
App. No.
18/509,616
Granted
Jan 6, 2026
Kind
B2
Abstract

Systems and methods are provided for supporting secure swapping of replaceable hardware components of IHSs (Information Handling Systems). During factory provisioning of an IHS, a factory-signed inventory certificate is uploaded to the IHS that identifies factory-installed hardware of the IHS. Factory provisioning also generates a ledger certificate that identifies replaceable hardware of the IHS that may occasionally be swapped from the IHS. Upon receipt of the IHS by the administrator, validation procedures use the inventory certificate to validate the detected IHS hardware as factory-installed. When discrepancies are identified in the detected hardware, the ledger certificate is retrieved and consulted to determine whether the discrepancy is due to movement of swappable hardware. The ledger certificate is then updated for use in validating the movement of the replaceable hardware.

Claims (43)

1 . An Information Handling System (IHS) comprising:

one or more processors; and

one or more memory devices coupled to the one or more processors, the one or more memory devices configured with computer-readable instructions stored thereon that, upon execution by the one or more processors, cause a validation process of the IHS to perform operations that comprise:

retrieve a factory-provisioned inventory certificate that specifies factory-installed hardware of the IHS;

determine whether the factory-provisioned inventory certificate is valid, based, at least in part, upon a public encryption key provided in the factory-provisioned inventory certificate; and

upon a determination the factory-provisioned inventory certificate is valid:

identify a discrepancy between hardware of the IHS detected by a Basic Input/Output System (BIOS), and the factory-installed hardware specified in the factory-provisioned inventory certificate;

retrieve a factory-provisioned ledger certificate that specifies replaceable hardware supported by the IHS;

determine when the discrepancy is due to movement of the replaceable hardware supported by the IHS; and

upon validation of the movement of the replaceable hardware, update the factory-provisioned ledger certificate to indicate the movement of the replaceable hardware supported by the IHS.

2 . The IHS of claim 1 , wherein updates to the factory-provisioned ledger certificate are blocked until the factory-provisioned inventory certificate is used to confirm the IHS as received included only the factory-installed hardware.

3 . The IHS of claim 2 , wherein updates to the factory-provisioned ledger certificate are blocked by a remote access controller of the IHS.

4 . The IHS of claim 1 , wherein the factory-provisioned inventory certificate is stored to a persistent memory of the IHS when the IHS is factory-provisioned.

5 . The IHS of claim 4 , wherein the factory-provisioned ledger certificate is also stored to the persistent memory of the IHS when the IHS is factory-provisioned.

6 . The IHS of claim 1 , wherein the replaceable hardware specified in the factory-provisioned ledger certificate comprises hardware that is not included in a hardware root-of-trust of the IHS.

7 . The IHS of claim 6 , wherein hardware included in the hardware root-of-trust of the IHS comprises at least one of a processor, remote access controller and TPM (Trusted Platform Module).

8 . The IHS of claim 1 , wherein validation of a modification specified in the factory-provisioned ledger certificate does not require validation of any prior modifications to the IHS.

9 . The IHS of claim 1 , wherein updates to the factory-provisioned ledger certificate specify whether a replaceable hardware component of the IHS is installed in the IHS.

10 . The IHS of claim 9 , wherein the factory-provisioned ledger certificate specifies all replaceable hardware components of the IHS that are installed in the IHS.

11 . The IHS of claim 1 , wherein updates to the factory-provisioned ledger certificate specify whether a replaceable hardware component of the IHS is not installed in the IHS.

12 . The IHS of claim 11 , wherein the factory-provisioned ledger certificate specifies a plurality of replaceable hardware components of the IHS that have been authorized for use by the IHS, but are not installed in the IHS.

13 . A method for validating replaceable hardware components of an Information Handling System (IHS), the method comprising:

retrieving, by a pre-boot validation process of the IHS, a factory-provisioned inventory certificate that specifies factory-installed hardware of the IHS;

determining whether the factory-provisioned inventory certificate is valid, based, at least in part, upon a public encryption key provided in the factory-provisioned inventory certificate; and

upon determining the factory-provisioned inventory certificate is valid:

identifying a discrepancy between hardware of the IHS detected by a Basic Input/Output System (BIOS), and the factory-installed hardware specified in the factory-provisioned inventory certificate;

retrieving a factory-provisioned ledger certificate that specifies replaceable hardware supported by the IHS;

determining when the discrepancy is due to movement of the replaceable hardware supported by the IHS; and

upon validating the movement of the replaceable hardware, updating the factory-provisioned ledger certificate to indicate the movement of the replaceable hardware supported by the IHS.

14 . The method of claim 13 , wherein the factory-provisioned inventory certificate is stored to a persistent memory of the IHS during factory-provisioning of the IHS.

15 . The method of claim 14 , wherein the factory-provisioned ledger certificate is also stored to the persistent memory of the IHS during the factory-provisioning of the IHS.

16 . The method of claim 13 , wherein the replaceable hardware specified in the factory-provisioned ledger certificate comprises hardware not included in a hardware root-of-trust of the IHS.

17 . The method of claim 13 , wherein updating the factory-provisioned ledger certificate specifies whether a replaceable hardware component of the IHS is installed in the IHS.

18 . The method of claim 13 , wherein updating the factory-provisioned ledger certificate specifies whether a replaceable hardware component of the IHS is not installed in the IHS.

19 . A computer-readable storage device configured with instructions stored thereon to provide validation of replaceable hardware components of an Information Handling System (IHS), wherein execution of the instructions by one or more processors of the IHS causes a pre-boot validation process of the IHS to perform operations that comprise:

retrieve a factory-provisioned inventory certificate that specifies factory-installed hardware of the IHS;

determine whether the factory-provisioned inventory certificate is valid, based, at least in part, upon a public encryption key provided in the factory-provisioned inventory certificate; and

upon a determination the factory-provisioned inventory certificate is valid:

identify a discrepancy between hardware of the IHS detected by a Basic Input/Output System (BIOS), and the factory-installed hardware specified in the factory-provisioned inventory certificate;

retrieve a factory-provisioned ledger certificate that specifies replaceable hardware supported by the IHS;

determine when the discrepancy is due to movement of the replaceable hardware supported by the IHS; and

upon validation of the movement of the replaceable hardware, update the factory-provisioned ledger certificate to indicate the movement of the replaceable hardware supported by the IHS.

20 . The computer-readable storage device of claim 19 , wherein the factory-provisioned inventory certificate and the factory-provisioned ledger certificate are both stored to a persistent memory of the IHS when the IHS is factory-provisioned.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2023
From: AHMED, A ANIS; YOUNG, JASON MATTHEW; SATPATHY, PALLAVI; KORUBILLI, KALYANI
To: DELL PRODUCTS, L.P.
Reel/Frame 065569/0311 →
Continuity (1)
Related Publication 20250156519A1 · May 15, 2025
References Cited (17)
US 9544294B2 · Srinivasan · 2017 [cited by examiner]
US 10311224B1 · Farhan · 2019 [cited by examiner]
US 10489339B2 · Srivastava · 2019 [cited by examiner]
US 11810062B2 · Young · 2023 [cited by examiner]
US 11836544B2 · Sayyed · 2023 [cited by examiner]
US 11838113B2 · Munoz · 2023 [cited by examiner]
US 12206798B2 · Savage · 2025 [cited by examiner]
US 12229241B2 · Young · 2025 [cited by examiner]
US 20050086468A1 · Meandzija · 2005 [cited by examiner]
US 20160078213A1 · Rooyakkers · 2016 [cited by examiner]
US 20190018966A1 · Khatri · 2019 [cited by examiner]
US 20220004640A1 · Jacobs · 2022 [cited by examiner]
US 20220067139A1 · Rodriguez Bravo · 2022 [cited by examiner]
US 20220385483A1 · Tschofenig · 2022 [cited by examiner]
US 20220391235A1 · Ghetie · 2022 [cited by examiner]
US 20230126538A1 · Savage · 2023 [cited by examiner]
US 20230127882A1 · Young · 2023 [cited by examiner]