IP Library › Patent Application 19062673
Patent Application
App. No. 19/062,673

MANAGING STARTUP OF A DATA PROCESSING SYSTEM USING TRUST STORES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/062,673
Abstract

Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, during a startup of the data processing system, an entity may obtain, using a security protocol and data model (SDPM) security standard, at least a first device certificate of a certificate chain for a device. Using the at least the first device certificate and a store of trusted device certificates, the entity may perform a first analysis process to determine a level of trust in the device. If the level of trust is indeterminate, the entity may use the certificate chain and a store of trusted root certificates to perform a second analysis process to determine the level of trust in the device. Operation of the data processing system may be managed based on the level of trust in the device.

Claims (69)

1 . A method for managing operation of a data processing system, the method comprising:

during a startup of the data processing system:

obtaining, by an entity of the data processing system and using a security protocol and data model (SPDM) security standard, at least a first device certificate of a certificate chain for a device of the data processing system, the certificate chain comprising the at least the first device certificate and a root certificate;

performing, by the entity and using the at least the first device certificate and a store of trusted device certificates, a first analysis process to determine a level of trust in the device;

in a first instance of the performing in which the level of trust in the device is indeterminate:

performing, by the entity and using the certificate chain and a store of trusted root certificates, a second analysis process to determine the level of trust in the device; and

managing operation of the data processing system based on the level of trust in the device to reduce a likelihood of the data processing system being compromised.

2 . The method of claim 1 , wherein the store of trusted device certificates comprises device certificates and/or digests of device certificates.

3 . The method of claim 2 , wherein performing the first analysis process comprises:

obtaining a digest of the at least the first device certificate; and

identifying, based on the digest of the at least the first device certificate and the digests of device certificates in the store of trusted device certificates, the level of trust in the device.

4 . The method of claim 1 , wherein performing the second analysis process comprises:

performing a signature verification process to establish trust in each portion of the certificate chain;

identifying, using the store of trusted root certificates, whether a root certificate authority for the root certificate is trusted by the entity to obtain the level of trust in the device; and

in an instance of the identifying in which the level of trust is trusted:

updating the store of trusted device certificates for use during future startups of the data processing system.

5 . The method of claim 1 , further comprising:

in a second instance of the performing the first analysis process in which the level of trust in the device is trusted:

performing, by the entity, a measurement process using the SPDM security standard for the device to obtain at least one measurement; and

managing operation of the device based on the at least one measurement.

6 . The method of claim 5 , wherein the at least one measurement comprises security data usable to validate authenticity and/or integrity of software hosted by the device.

7 . The method of claim 1 , wherein no other portions of the certificate chain other than the first device certificate are used during the first analysis process.

8 . The method of claim 1 , further comprising:

in a third instance of the performing the first analysis process in which the level of trust in the device is untrusted:

preventing the device from performing at least a portion of its functionality, and/or logging information regarding trustworthiness of the device.

9 . The method of claim 1 , wherein the SPDM security standard is a data model for devices of data processing systems, the SPDM security standard specifying, at least, methods of security communication between the devices, minimum standards of data to be made available to other devices, and security information to be made available to the other devices.

10 . The method of claim 1 , wherein the entity of the data processing system is a basic input-output system (BIOS).

11 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing operation of a data processing system, the operations comprising:

during a startup of the data processing system:

obtaining, by an entity of the data processing system and using a security protocol and data model (SPDM) security standard, at least a first device certificate of a certificate chain for a device of the data processing system, the certificate chain comprising the at least the first device certificate and a root certificate;

performing, by the entity and using the at least the first device certificate and a store of trusted device certificates, a first analysis process to determine a level of trust in the device;

in a first instance of the performing in which the level of trust in the device is indeterminate:

performing, by the entity and using the certificate chain and a store of trusted root certificates, a second analysis process to determine the level of trust in the device; and

managing operation of the data processing system based on the level of trust in the device to reduce a likelihood of the data processing system being compromised.

12 . The non-transitory machine-readable medium of claim 11 , wherein the store of trusted device certificates comprises device certificates and/or digests of device certificates.

13 . The non-transitory machine-readable medium of claim 12 , wherein performing the first analysis process comprises:

obtaining a digest of the at least the first device certificate; and

identifying, based on the digest of the at least the first device certificate and the digests of device certificates in the store of trusted device certificates, the level of trust in the device.

14 . The non-transitory machine-readable medium of claim 11 , wherein performing the second analysis process comprises:

performing a signature verification process to establish trust in each portion of the certificate chain;

identifying, using the store of trusted root certificates, whether a root certificate authority for the root certificate is trusted by the entity to obtain the level of trust in the device; and

in an instance of the identifying in which the level of trust is trusted:

updating the store of trusted device certificates for use during future startups of the data processing system.

15 . The non-transitory machine-readable medium of claim 11 , further comprising:

in a second instance of the performing the first analysis process in which the level of trust in the device is trusted:

performing, by the entity, a measurement process using the SPDM security standard for the device to obtain at least one measurement; and

managing operation of the device based on the at least one measurement.

16 . A data processing system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing operation of a data processing system, the operations comprising:

during a startup of the data processing system:

obtaining, by an entity of the data processing system and using a security protocol and data model (SPDM) security standard, at least a first device certificate of a certificate chain for a device of the data processing system, the certificate chain comprising the at least the first device certificate and a root certificate;

performing, by the entity and using the at least the first device certificate and a store of trusted device certificates, a first analysis process to determine a level of trust in the device;

in a first instance of the performing in which the level of trust in the device is indeterminate:

performing, by the entity and using the certificate chain and a store of trusted root certificates, a second analysis process to determine the level of trust in the device; and

managing operation of the data processing system based on the level of trust in the device to reduce a likelihood of the data processing system being compromised.

17 . The data processing system of claim 16 , wherein the store of trusted device certificates comprises device certificates and/or digests of device certificates,

18 . The data processing system of claim 17 , wherein performing the first analysis process comprises:

obtaining a digest of the at least the first device certificate; and

identifying, based on the digest of the at least the first device certificate and the digests of device certificates in the store of trusted device certificates, the level of trust in the device.

19 . The data processing system of claim 16 , wherein performing the second analysis process comprises:

performing a signature verification process to establish trust in each portion of the certificate chain;

identifying, using the store of trusted root certificates, whether a root certificate authority for the root certificate is trusted by the entity to obtain the level of trust in the device; and

in an instance of the identifying in which the level of trust is trusted:

updating the store of trusted device certificates for use during future startups of the data processing system.

20 . The data processing system of claim 16 , further comprising:

in a second instance of the performing the first analysis process in which the level of trust in the device is trusted:

performing, by the entity, a measurement process using the SPDM security standard for the device to obtain at least one measurement; and

managing operation of the device based on the at least one measurement.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2026
From: MONOGRAM TECHNOLOGIES, LLC
To: ZIMMER, INC.
Reel/Frame 075391/0294 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2025
From: GROBELNY, NICHOLAS D.; NELSON, AMY CHRISTINE; CONSOLVER, DAVID ALBERT; SHARMA, RAMAN; TONRY, RICHARD M.
To: DELL PRODUCTS L.P.
Reel/Frame 070383/0711 →