IP Library Granted Patent US 8,428,929
Granted Patent B2
US 8,428,929 · App. 12/894,876 · Granted Apr 23, 2013

Demand based USB proxy for data stores in service processor complex

Inventors: Palsamy Sakthikumar (Puyallup, WA); Michael A. Rothman (Puyallup, WA); Vincent J. Zimmer (Federal Way, WA); Robert C. Swanson (Olympia, WA); Mallik Bulusu (Olympia, WA)
Assignee: Intel Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,428,929
App. No.
12/894,876
Granted
Apr 23, 2013
Kind
B2
Abstract

A method, apparatus, system, and computer program product for secure server system management. A payload containing system software and/or firmware updates is distributed in an on-demand, secure I/O operation. The I/O operation is performed via a secured communication channel inaccessible by the server operating system to an emulated USB drive. The secure communication channel can be established for the I/O operation only after authenticating the recipient of the payload, and the payload can be protected from access by a potentially-infected server operating system. Furthermore, the payload can be delivered on demand rather than relying on a BIOS update schedule, and the payload can be delivered at speeds of a write operation to a USB drive.

Claims (58)

1. A computer-implemented method comprising:

in a system having a platform controller coupled to an I/O controller capable of generating a System Management Interrupt (SMI), performing the following:

in response to an event requiring secure access to data, generating an SMI to cause the system to enter System Management Mode;

using a resource of the platform controller to create an emulated USB device, wherein the resource stores the data;

copying the data from the resource using the emulated USB device via a connection inaccessible by an operating system of the system; and

processing the data prior to exiting System Management Mode.

2. The method of claim 1 , further comprising:

authenticating a recipient of the data while in System Management Mode.

3. The method of claim 1 wherein

the platform controller is a baseboard management controller.

4. The method of claim 1 wherein

the platform controller is provided by a manageability engine of a chipset of the system.

5. The method of claim 1 further comprising:

downloading the data from an enterprise server to the resource using the emulated USB device.

6. The method of claim 1 further comprising:

removing the emulated USB device from visibility by the operating system prior to exiting System Management Mode.

7. The method of claim 1 wherein

using the resource of the platform controller to create the emulated USB device is performed in response to a request to access the data.

8. A system comprising:

a processor;

a platform controller;

an I/O controller capable of generating a System Management Interrupt (SMI);

a memory coupled to the processor, the memory comprising instructions for performing the following:

in response to an event requiring secure access to data, generating an SMI to cause the system to enter System Management Mode;

using a resource of the platform controller to create an emulated USB device, wherein the resource stores the data;

copying the data from the resource using the emulated USB device via a connection inaccessible by an operating system of the system; and

processing the data prior to exiting System Management Mode.

9. The system of claim 8 , wherein the instructions further perform the following:

authenticating a recipient of the data while in System Management Mode.

10. The system of claim 8 wherein

the platform controller is a baseboard management controller.

11. The system of claim 8 wherein

the platform controller is provided by a manageability engine of a chipset of the system.

12. The system of claim 8 wherein the instructions further perform the following:

downloading the data from an enterprise server to the resource using the emulated USB device.

13. The system of claim 8 , wherein the instructions further perform the following:

removing the emulated USB device from visibility by the operating system prior to exiting System Management Mode.

14. The system of claim 8 wherein

using the resource of the platform controller to create the emulated USB device is performed in response to a request to access the data.

15. A computer program product comprising:

a non-transitory computer-readable storage medium; and

instructions in the non-transitory computer-readable storage medium, wherein the instructions, when executed in a processing system having a platform controller coupled to an I/O controller capable of generating a System Management Interrupt (SMI), cause the processing system to perform operations comprising:

in response to an event requiring secure access to data, generating an SMI to cause the system to enter System Management Mode;

using a resource of the platform controller to create an emulated USB device, wherein the resource stores the data;

copying the data from the resource using the emulated USB device via a connection inaccessible by an operating system of the system; and

processing the data prior to exiting System Management Mode.

16. The computer program product of claim 15 , wherein the instructions further perform the following:

authenticating a recipient of the data while in System Management Mode.

17. The computer program product of claim 15 wherein

the platform controller is a baseboard management controller.

18. The computer program product of claim 15 wherein

the platform controller is provided by a manageability engine of a chipset of the system.

19. The computer program product of claim 15 wherein the instructions further perform the following:

downloading the data from an enterprise server to the resource using the emulated USB device.

20. The computer program product of claim 15 , wherein the instructions further perform the following:

removing the emulated USB device from visibility by the operating system prior to exiting System Management Mode.

21. The computer program product of claim 15 wherein

using the resource of the platform controller to create the emulated USB device is performed in response to a request to access the data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2011
From: SAKTHIKUMAR, PALSAMY; SWANSON, ROBERT C.; ROTHMAN, MICHAEL A.; ZIMMER, VINCENT J.; BULUSU, MALLIK
To: INTEL CORPORATION
Reel/Frame 025960/0391 →
Continuity (1)
Related Publication 20120084552A1 · Apr 5, 2012