IP Library Granted Patent US 8,589,702
Granted Patent B2
US 8,589,702 · App. 13/104,685 · Granted Nov 19, 2013

System and method for pre-boot authentication of a secure client hosted virtualization in an information handling system

Inventors: Yuan-Chang Lo (Austin, TX); Shree Dandekar (Round Rock, TX)
Assignee: Dell Products, LP
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,589,702
App. No.
13/104,685
Filed
May 10, 2011
Granted
Nov 19, 2013
Kind
B2
Art Unit
2439
USPC
713/193
Abstract

A client hosted virtualization system (CHVS) includes a processor to execute code, a component, and a non-volatile memory. The non volatile memory includes BIOS code and code to implement a virtualization manager. The virtualization manager is operable to initialize the CHVS, launch a virtual machine on the CHVS, and assign the component to the virtual machine, such that the virtual machine has control of the component. The CHVS is configurable to execute the BIOS and not the virtualization manager, or to execute the virtualization manager and not the BIOS.

Claims (72)

1. A client hosted virtualization system (CHVS) comprising:

a processor to execute code;

a first component;

a second component; and

a non-volatile memory including:

first code to implement a basic input/output system to initialize the CHVS; and

second code to implement a virtualization manager to:

initialize the CHVS;

launch a first virtual machine on the CHVS;

assign the first component to the first virtual machine, such that the first virtual machine has control of the first component;

assign the second component to the first virtual machine, such that the first virtual machine has control of the second component;

determine a first digital signature for the CHVS based on the first component and the second component; and

provide the first digital signature to the first virtual machine;

wherein the CHVS operates in a first mode to execute the first code to initialize the CHVS and to not execute the second code to initialize the CHVS, and operates in a second mode to execute the second code to initialize the CHVS and to not execute the first code to initialize the CHVS.

2. The CHVS of claim 1 , wherein:

the virtualization manager is further to launch a second virtual machine on the CHVS; and

the first virtual machine assigns the first component to the second virtual machine, such that the second virtual machine has access to the first component.

3. The CHVS of claim 2 , wherein:

the virtualization manager is further to authenticate a user of the CHVS prior to assigning the first component to the first virtual machine; and

assigning the first component to the first virtual machine is in response to authenticating the user.

4. The CHVS of claim 3 , wherein assigning the first component to the second virtual machine is in response to authenticating the user.

5. The CHVS of claim 1 , wherein the first component is a select one of a trusted platform module, a general purpose encryption engine, a universal security hub, and a combination thereof.

6. The CHVS of claim 1 , wherein:

the first virtual machine compares the first digital signature with a second digital signature to determine if the CHVS has been tampered with; and

the virtualization manager is further to provide an indication that the CHVS has been tampered with in response to the comparison.

7. The CHVS of claim 6 , wherein the indication includes shutting off the CHVS.

8. A method of providing a client hosted virtualization system (CHVS), comprising:

storing first code in a non-volatile memory of the CHVS to implement a basic input/output system to initialize the CHVS;

storing second code in the non-volatile memory to implement a virtualization manager for the CHVS;

determining if a switch of the CHVS is in a first state or a second state;

executing the first code to the exclusion of the second code if the switch is in the first state; and

executing the second code to the exclusion of the first code if the switch is in the second state;

wherein in executing the second code, the method further comprises:

initializing the CHVS;

launching a first virtual machine on the CHVS;

assigning a first component to the first virtual machine, such that the first virtual machine has control of the first component;

assigning a second component to the first virtual machine, such that the first virtual machine has control of the second component;

determining a first digital signature for the CHVS based on the first component and the second component; and

providing the first digital signature to the first virtual machine.

9. The method of claim 8 , further comprising:

launching a second virtual machine on the CHVS; and

assigning by the first virtual machine the first component to the second virtual machine, such that the second virtual machine has access to the first component.

10. The method of claim 9 , further comprising:

authenticating a user of the CHVS prior to assigning the first component to the first virtual machine;

wherein assigning the first component to the first virtual machine is in response to authenticating the user.

11. The method of claim 10 , wherein assigning the first component to the second virtual machine is in response to authenticating the user.

12. The method of claim 8 , wherein the first component is a select one of a trusted platform module, a general purpose encryption engine, a universal security hub, and a combination thereof.

13. The method of claim 8 , further comprising:

comparing at the first virtual machine the first digital signature with a second digital signature to determine if the CHVS has been tampered with; and

providing an indication that the CHVS has been tampered with in response to the comparison.

14. Machine-executable code for an information handling system, wherein the machine-executable code is embedded in a non-transitory storage medium and includes instructions for carrying out a method, the method comprising:

storing first code in a non-volatile memory of the CHVS to implement a basic input/output system to initialize the CHVS;

storing second code in the non-volatile memory to implement a virtualization manager for the CHVS;

determining if a switch of the CHVS is in a first state or a second state;

executing the first code to the exclusion of the second code in response to determining that the switch is in the first state; and

executing the second code to the exclusion of the first code in response to determining that the switch is in the second state;

wherein in executing the second code, the method further comprises:

initializing the CHVS;

launching a first virtual machine on the CHVS;

assigning a first component to the first virtual machine, such that the first virtual machine has control of the first component;

assigning a second component to the first virtual machine, such that the first virtual machine has control of the second component;

determining a first digital signature for the CHVS based on the first component and the second component; and

providing the first digital signature to the first virtual machine.

15. The machine-executable code of claim 14 , the method further comprising:

launching a second virtual machine on the CHVS; and

assigning by the first virtual machine the first component to the second virtual machine, such that the second virtual machine has access to the first component.

16. The machine-executable code of claim 15 , the method further comprising:

authenticating a user of the CHVS prior to assigning the first component to the first virtual machine;

wherein assigning the first component to the first virtual machine is in response to authenticating the user.

17. The machine-executable code of claim 14 , the method further comprising:

comparing at the first virtual machine the first digital signature with a second digital signature to determine if the CHVS has been tampered with; and

providing an indication that the CHVS has been tampered with in response to the comparison.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2011
From: LO, YUAN-CHANG; DANDEKAR, SHREE
To: DELL PRODUCTS, LP
Reel/Frame 026614/0311 →
Continuity (2)
Continuation In Part 12790545 · May 28, 2010
Related Publication 20110296409A1 · Dec 1, 2011