IP Library › Granted Patent US 8,528,046
Granted Patent B2
US 8,528,046 · App. 12/762,671 · Granted Sep 3, 2013

Selective management controller authenticated access control to host mapped resources

Inventors: Timothy M. Lambert (Austin, TX); Mukund P. Khatri (Austin, TX)
Assignee: Dell Products, LP
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,528,046
App. No.
12/762,671
Filed
Apr 19, 2010
Granted
Sep 3, 2013
Kind
B2
Art Unit
2438
USPC
726/2
Abstract

An information handling system includes a host mapped general purpose input output (GPIO), a shared memory, a board management controller, and a cryptography engine. The host mapped GPIO includes a plurality of registers. The board management controller is in communication with the host mapped GPIO and with the shared memory, and is configured to control accessibility to the plurality of registers in the GPIO, and to control write accessibility of the shared memory based on a private key received from a basic input output system requesting accessibility to the plurality of registers and write accessibility of the shared memory. The cryptography engine is in communication with the board memory controller, and is configured to authenticate the private key received from the board management controller.

Claims (46)

1. An information handling system comprising:

a host mapped general purpose input output (GPIO) including a plurality of registers, wherein a first register includes a system service tag associate with the information handling system;

a shared memory;

a host processor in communication with the host mapped GPIO and with the shared memory, the host processor including a basic input output system;

a board management controller separate from the host processor and in communication with the host mapped GPIO and with the shared memory, the board management controller configured to control accessibility to the plurality of registers in the GPIO, and to control write accessibility of the shared memory based on a private key received from the basic input output system requesting accessibility to the plurality of registers and write accessibility of the shared memory, wherein the private key is based on the system service tag;

a cryptography engine in communication with the board management controller, the cryptography engine configured to authenticate the private key received from the board management controller; and

wherein the board management controller is further configured to provide accessibility to the host mapped GPIO and the write ability to the shared memory for a specific number of transactions of the basic input output system when the private key is authenticated.

2. The information handling system of claim 1 further comprising:

a keyboard controller style in communication with the board management controller, the keyboard controller style configured to pass the private key from the basic input output system to the board management controller.

3. The information handling system of claim 1 wherein the specific number of transactions of the basic input output system is a programmable number of transactions.

4. The information handling system of claim 1 wherein the board management controller provides accessibility to the host mapped GPIO and the write ability to the shared memory for a specific amount of time when the private key is authenticated.

5. The information handling system of claim 4 wherein the specific amount of time is a programmable amount of time.

6. The information handling system of claim 1 wherein the board management controller provides accessibility to the host mapped GPIO and the write ability to the shared memory until the basic input output system explicitly locks the host mapped GPIO and write protects the shared memory.

7. The information handling system of claim 1 wherein the plurality of registers is locked upon an end of a power-on self-test of the system.

8. The information handling system of claim 1 wherein the shared memory is write-protected upon an end of a power-on self-test.

9. An information handling system comprising:

a host mapped general purpose input output (GPIO) including a plurality of registers, wherein a first register includes a system service tag associated with the information handling system;

a shared memory;

a host processor in communication with the host mapped GPIO and with the shared memory, the host processor including a basic input output system;

a board management controller separate from the host processor and in communication with the host mapped GPIO and with the shared memory, the board management controller configured to operate as a proxy for the basic input output system, and to change an input/output state of one of the plurality of registers of the host mapped GPIO based on a state change request and to write data to the shared memory based on a write request received from the basic input output system and when a private key from the basic input output system is authenticated, wherein the private key is based on the system service tag; and

a cryptography engine in communication with the board management controller, the cryptography engine configured to authenticate the private key received from the board management controller.

10. The information handling system of claim 9 further comprising:

a keyboard controller style in communication with the board management controller, the keyboard controller style configured to pass the private key, the state change request, and the write request from the basic input output system to the board management controller.

11. The information handling system of claim 9 wherein the plurality of registers is locked upon an end of a power-on self-test of the system.

12. The information handling system of claim 9 wherein the shared memory is write-protected upon an end of a power-on self-test.

13. A method comprising:

detecting, at a host processor of an information handling system, at least one of an end of a power-on self-test and completion of a runtime write;

setting, by a board management controller of the information handling system, a host mapped general purpose input output (GPIO) register in a locked state in response to the end of the power-on self-test or to the completion of the runtime write, wherein the GPIO register includes a system service tag associated with the information handling system, and wherein the board management controller is separate from the host processor;

setting, by the board management controller, a shared memory to a write protected state in response to the end of the power-on self-test or to the completion of the runtime write;

receiving a first request to change an input/output state of the host mapped GPIO register, or a second request to write to the shared memory;

receiving, at the board management controller, a private key with the first request or with the second request, wherein the private key is received from a basic input output system of the host processor and is generated based upon the system service tag;

passing the private key to a cryptography engine;

receiving an indication that the private key is authenticated from the cryptography engine;

setting, by the board management controller, the host mapped GPIO register to an unlock state when the private key is authenticated; and

setting, by the board management controller, the shared memory to a full read and write accessible state when the private key is authenticated.

14. The method of claim 13 further comprising:

determining that a specific number of transactions have occurred;

setting the host mapped GPIO register in the locked state when the specific number of transactions have occurred; and

setting a shared memory to a write protected state when the specific number of transactions have occurred.

15. The method of claim 13 further comprising:

determining that a specific amount of time has occurred;

setting the host mapped GPIO register in the locked state when the specific amount of time has occurred; and

setting a shared memory to a write protected state when the specific amount of time has occurred.

16. The method of claim 13 wherein the host mapped GPIO register and the shared memory are located on a remote access controller.

17. The method of claim 13 wherein the authentication of the private key is performed on a remote access controller.

18. The method of claim 13 wherein the first request and the second request are received from the basic input output system.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2010
From: LAMBERT, TIMOTHY M.; KHATRI, MUKUND P.
To: DELL PRODUCTS, LP
Reel/Frame 024255/0085 →
Continuity (1)
Related Publication 20110258410A1 · Oct 20, 2011