IP Library Granted Patent US 9,183,395
Granted Patent B2
US 9,183,395 · App. 14/739,519 · Granted Nov 10, 2015

System and method for secure information handling system flash memory access

Inventors: Terry Wayne Liles (Round Rock, TX); Charles T. Perusse, Jr. (Pflugerville, TX); Yong Cao (Cedar Park, TX); Abhay Arjun Salunke (Austin, TX); Marshal F. Savage (Austin, TX)
Assignee: Dell Products L.P.
G06F21/572G06F8/67
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,183,395
App. No.
14/739,519
Filed
Jun 15, 2015
Granted
Nov 10, 2015
Kind
B2
Art Unit
3621
USPC
726/22
Abstract

Firmware updates at an information handling system flash memory device, such as provisioning information stored on a USB device, are securely performed by using a buffer memory and a secured code. An application running on a CPU generates a firmware update and a security code, such as a ciphered hash code based on the firmware update, stores the firmware update and security code in a buffer, and informs a management processor of the update. The management processor analyzes the firmware update to authorize copying of the update from the buffer to the flash memory device. For instance, the management processor creates the security code from the firmware update and compares the created code with the security code stored in the buffer to validate the firmware update.

Claims (32)

1. An information handling system comprising:

a central processing unit (CPU);

a management processor (MP) having a firmware manager, the firmware manager configured to execute on the MP;

random access memory (RAM) operable to store information, the RAM interfaced with the CPU and the MP;

flash memory operable to store firmware; and

a firmware updater stored in non-transitory memory and configured to execute on the CPU to prepare a firmware update, determine a security code for the firmware update, store the firmware update and the security code in a configuration file in a buffer defined in the RAM by the MP, and send a command over a management bus to execute a task list in the configuration file;

wherein the firmware manager in response to the command, finds a command in the task list to copy the firmware update to the flash memory after verification of the security code, authorizes copying of the firmware update from the buffer to the flash memory by verifying the security code, and performs the firmware update to be copied from the buffer to the flash memory over a system bus.

2. The information handling system of claim 1 wherein the system bus comprises a USB and the management bus comprises an IPMI.

3. The information handling system of claim 1 wherein:

the firmware updater comprises a first security module configured to generate a first security code from the firmware update for storage in the buffer with the firmware update;

the firmware manager comprises a second security module configured to retrieve the firmware update to generate a second security code; and

the firmware manager is further configured to compare the first and second security codes to authorize copying of the firmware update from the buffer to the flash memory.

4. The information handling system of claim 3 wherein the first and second security codes comprise a cryptographic hash algorithm.

5. The information handling system of claim 1 wherein the buffer is defined in hard disk drive memory.

6. The information handling system of claim 1 wherein the management processor comprises a baseboard management processor.

7. The information handling system of claim 1 wherein the firmware update comprises provisioning information.

8. A method for updating firmware, the method comprising:

generating a firmware update with an application stored in a random access memory (RAM) and running on a central processing unit (CPU), the firmware update having a security code, and storing the firmware update and the security code in a configuration file;

copying with the application the configuration file to a buffer memory defined in the RAM by a management processor (MP);

commanding the MP over a management bus to execute a task list in the configuration file;

in response to a command in the task list, authorizing by the MP copying of the firmware update from the buffer memory to the flash memory by verifying the security code; and

copying, in response to the authorizing, the firmware update from the buffer memory to the flash memory with the management processor through a system bus separate from the management bus.

9. The method of claim 8 wherein the system bus comprises USB and the management bus comprises IPMI.

10. The method of claim 9 wherein the generating a firmware update having a security code further comprises generating a hash code with a cryptographic hash algorithm.

11. The method of claim 8 wherein the firmware comprises provisioning information.

12. The method of claim 8 wherein the firmware update comprises a destination and a copy mode.

13. A system for updating firmware stored in flash memory of an information handling system, the system comprising:

a firmware updater stored in non-transitory memory and configured to execute on the CPU to prepare a firmware update, determine a security code for the firmware update, store the firmware update and the security code in a configuration file in a buffer defined in the RAM by the MP, and send a command over a management bus to execute a task list in the configuration file; and

a firmware manager operable to run on a management processor, the firmware manager in response to the command from the firmware updater, finds a command in the task list to copy the firmware update to the flash memory after verification of the security code, authorizes copying of the firmware update from the buffer to the flash memory by verifying the security code, and performs the firmware update to be copied from the buffer to the flash memory over a system bus.

14. The system of claim 13 wherein the security code comprises a hash code generated from the firmware update.

15. The system of claim 14 wherein the firmware manager authorizes copying of the firmware update by generating a hash code from the firmware update and comparing the generated hash code with the hash code stored in the buffer.

16. The system of claim 13 wherein the flash memory comprises a USB device.

Assignments (14)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 036502 FRAME 0291 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0637 →
RELEASE OF REEL 036502 FRAME 0237 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0088 →
RELEASE OF REEL 036502 FRAME 0206 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0204 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Aug 27, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 036502/0206 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Aug 27, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 036502/0237 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Aug 27, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 036502/0291 →
Continuity (2)
Continuation 12198236 · Aug 26, 2008
Related Publication 20150278524A1 · Oct 1, 2015