IP Library › Granted Patent US 12,724,864
Granted Patent B2
US 12,724,864 · App. 18/637,527 · Granted Sep 1, 2026

Remote secure boot verification service for secure deployment of virtual machines

Inventors: Ankit Singh (Bangalore, IN); Shrikant U. Hallur (Bangalore, IN); Naveen Awasthy (Bangalore, IN)
Assignee: Dell Products L.P.
G06F21/33G06F21/554G06F21/575G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,724,864
App. No.
18/637,527
Granted
Sep 1, 2026
Kind
B2
Abstract

Disclosed systems and methods for authenticating virtual machines, upon detecting a virtual machine launch (VML) request associated with a hypervisor and an unconfirmed VM, request a VM signing (VMS) certificate from a deployment/verification cloud server. The VMS certificate is forwarded to a certificate store of the hypervisor. After an unconfirmed VM is successfully authenticated, the VMS certificate may be deleted from the hypervisor certificate store. If an alert indicating a failed authentication associated is detected, termination operations are performed to prevent the unconfirmed VM from running under the hypervisor. The termination operations may include identifying a suspect key or signature associated with the unconfirmed VM and recording the suspect key or signature in a prohibited database store, such as a UEFI Secure Boot DBX variable store. For example, a suspect key or signature may be a key used to sign the unconfirmed VM.

Claims (30)

1 . A method for authenticating virtual machine, the method comprising: detecting, by a lightweight secure operating system (LSOS) running on an information handling system, a virtual machine launch (VML) request associated with an unconfirmed virtual machine (VM) and a hypervisor, wherein the LSOS resides on an original equipment manufacturer (OEM)-protected nonvolatile memory express (NVMe) partition and is communicatively coupled to a VM deployment/verification cloud service server; activating, by the LSOS, a digital certificate checker (DCC) in response to detecting the VML request; requesting, by the DCC, a VM signing (VMS) certificate from the cloud service server, wherein the VMS certificate is stored in an authenticated variable store; receiving the VMS certificate and forwarding it to a certificate store of the hypervisor; executing, by the hypervisor, Secure Boot authentication of the unconfirmed VM using the VMS certificate; responsive to successful authentication, permitting the VM to launch and deleting the VMS certificate from the certificate store; and responsive to failed authentication, terminating the unconfirmed VM and copying, by the LSOS, a suspect certificate to a prohibited database (DBX) variable store of the cloud service server to prevent future unauthorized VM launches.

2 . The method of claim 1 , wherein the suspect certificate comprises a key or signature stored in an authenticated variable store of the hypervisor.

3 . The method of claim 2 , wherein the hypervisor comprises a Universal Extensible Firmware Interface (UEFI) compliant hypervisor.

4 . The method of claim 1 , further comprising, after successfully authenticating the unconfirmed VM, deleting the VMS certificate from the hypervisor certificate store.

5 . The method of claim 1 , wherein the LSOS performs one or more of:

detecting the VML request;

requesting the VMS certificate from the cloud service server; and

forwarding the VMS certificate to the certificate store of the hypervisor.

6 . The method of claim 1 , further comprising, enabling, by the LSOS, an original equipment manufacturer (OEM) communication channel for connecting an OEM information handling system with an OEM cloud.

7 . An information handling system, comprising: a central processing unit (CPU); and a memory, including processor executable instructions that, when executed by the CPU, cause the system to perform virtual machine authentication operations, wherein the virtual machine authentication operations include: detecting, by a lightweight secure operating system (LSOS) running on an information handling system, a virtual machine launch (VML) request associated with an unconfirmed virtual machine (VM) and a hypervisor, wherein the LSOS resides on an original equipment manufacturer (OEM)-protected nonvolatile memory express (NVMe) partition and is communicatively coupled to a VM deployment/verification cloud service server; activating, by the LSOS, a digital certificate checker (DCC) in response to detecting the VML request; requesting, by the DCC, a VM signing (VMS) certificate from the cloud service server, wherein the VMS certificate is stored in an authenticated variable store; receiving the VMS certificate and forwarding it to a certificate store of the hypervisor; executing, by the hypervisor, Secure Boot authentication of the unconfirmed VM using the VMS certificate; responsive to successful authentication, permitting the VM to launch and deleting the VMS certificate from the certificate store; and responsive to failed authentication, terminating the unconfirmed VM and copying, by the LSOS, a suspect certificate to a prohibited database (DBX) variable store of the cloud service server to prevent future unauthorized VM launches.

8 . The information handling system of claim 7 , wherein the suspect key or signature comprises a key or signature stored in an authorized database store of the hypervisor.

9 . The information handling system of claim 8 , wherein the hypervisor comprises a Universal Extensible Firmware Interface (UEFI) compliant hypervisor.

10 . The information handling system of claim 7 , further comprising, after successfully authenticating the unconfirmed VM, deleting the VMS certificate from the hypervisor certificate store.

11 . The information handling system of claim 7 , wherein the LSOS performs one or more of:

detecting the VML request;

requesting the VMS certificate from the cloud service server; and

requesting the VMS certificate from a cloud server; and

forwarding the VMS certificate to the certificate store of the hypervisor.

12 . The information handling system of claim 7 , further comprising, enabling, by the LSOS, an original equipment manufacturer (OEM) communication channel for connecting an OEM information handling system with an OEM cloud.

13 . A method for authenticating virtual machines, the method comprising:

detecting, by a lightweight secure operating system (LSOS) running on an information handling system, a virtual machine launch (VML) request associated with an unconfirmed virtual machine (VM) and a hypervisor running on the information handling system, wherein the LSOS resides on an original equipment manufacturer (OEM)-protected nonvolatile memory express (NVMe) partition and is communicatively coupled to a VM deployment/verification cloud service server via a secure connection;

activating, by the LSOS, a digital certificate checker (DCC) in response to detecting the VML request;

requesting, by the DCC, a VM signing (VMS) certificate from the VM deployment/verification cloud service server, wherein the VMS certificate is stored in an authenticated variable store of the cloud service server;

receiving, from the VM deployment/verification cloud service server, the VMS certificate;

forwarding, by the DCC, the VMS certificate to a certificate store of the hypervisor;

executing, by the hypervisor, a Secure Boot authentication of the unconfirmed, VM using the VMS certificate;

responsive to successful authentication of the unconfirmed VM, permitting the unconfirmed VM to launch and deleting the VMS certificate from the certificate store of the hypervisor; and

responsive to receiving an alert from the hypervisor indicating a failed authentication associated with the unconfirmed VM, performing one or more termination operations, wherein the one or more termination operations include:

terminating the unconfirmed VM to prevent the unconfirmed VM from running under the hypervisor; and

copying, by the LSOS, a suspect certificate associated with the unconfirmed VM to a prohibited database (DBX) variable store of the VM deployment/verification cloud service server to prevent future unauthorized VM launches using the suspect certificate.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2024
From: SINGH, ANKIT; HALLUR, SHRIKANT U.; AWASTHY, NAVEEN
To: DELL PRODUCTS L.P.
Reel/Frame 067130/0631 →
Continuity (1)
Related Publication 20250328621A1 · Oct 23, 2025
References Cited (8)
US 8949825B1 · Fitzgerald · 2015 [cited by examiner]
US 10528736B1 · Sobel · 2020 [cited by examiner]
US 20120054744A1 · Singh · 2012 [cited by examiner]
US 20130061293A1 · Mao · 2013 [cited by examiner]
US 20160274933A1 · Paolino · 2016 [cited by examiner]
US 20180268146A1 · Suryanarayana · 2018 [cited by examiner]
US 20190012271A1 · Avoinne · 2019 [cited by examiner]
US 20200213112A1 · Singleton, IV · 2020 [cited by examiner]