IP Library › Granted Patent US 9,589,139
Granted Patent B2
US 9,589,139 · App. 14/669,641 · Granted Mar 7, 2017

Method and device for altering a unified extensible firmware interface (UEFI) secure boot process in a computing device

Inventor: Jeffery Jay Bobzin (Harvard, MA)
Assignee: Insyde Software Corp.
G06F21/575G06F9/4401G06F15/177G06F2221/034G06F2221/2105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,589,139
App. No.
14/669,641
Granted
Mar 7, 2017
Kind
B2
Abstract

Firmware in a computing device is used to administer and alter a Secure Boot process for the computing device while continuing to provide protection from unauthorized third-party code.

Claims (48)

1. A method for altering a secure boot process in a computing device equipped with Unified Extensible Firmware Interface (UEFI)-compliant firmware, comprising:

identifying an interrupt command during a UEFI secure boot process for the computing device, the secure boot process interrupted in response to the command;

displaying to a user, following the interruption of the secure boot process, a listing of at least one task related to altering the secure boot process;

receiving a selection of a listed task;

invoking System Management Mode (SMM) in response to the selection of the listed task;

performing the selected task in SMM using a firmware module executable only within SMM;

exiting SMM after the performing of the task, and

booting the computing device after the exiting.

2. The method of claim 1 wherein the performing of the selected task further comprises:

enrolling a hash of unsigned executable code in a system security database.

3. The method of claim 1 wherein the performing of the selected task further comprises:

turning off a requirement to enforce the secure boot so as to allow all code to run during a boot sequence.

4. The method of claim 1 wherein the performing of the selected task further comprises:

clearing a system security database of all certificates and disabling the secure boot.

5. The method of claim 1 wherein the performing of the selected task further comprises:

restoring a system security database from a backup location or resetting the system security database to a factory setting.

6. The method of claim 1 wherein the interrupt command may only be received from a physically present user who is physically accessing the computing device.

7. The method of claim 1 wherein the interrupt command may be received from a user who is accessing the computing device from a remote location.

8. The method of claim 1 wherein the secure boot process is interrupted when a previously recorded request to alter the secure boot process is identified during the boot sequence.

9. The method of claim 8 wherein the request is recorded in a UEFI-defined variable by an operating system process.

10. A non-transitory computer-readable medium holding computer-executable instructions for altering a secure boot process in a computing device equipped with Unified Extensible Firmware Interface (UEFI)-compliant firmware, the instructions when executed causing the computing device to:

identify an interrupt command during a UEFI secure boot process for the computing device, the secure boot process interrupted in response to the command;

display to a user, following the interruption of the boot process, a listing of at least one task related to altering the secure boot process;

receive a selection of a listed task;

invoke System Management Mode (SMM) in response to the selection of the listed task;

perform the selected task in SMM using a firmware module executable only within SMM;

exit SMM after the performing of the task, and

boot the computing device after the exiting.

11. The medium of claim 10 wherein the performing of the selected task enrolls a hash of unsigned executable code in a system security database.

12. The medium of claim 10 wherein the performing of the selected task turns off a requirement to enforce the secure boot so as to allow all code to run during a boot sequence.

13. The medium of claim 10 wherein the performing of the selected task clears a system security database of all certificates and disabling the secure boot.

14. The medium of claim 10 wherein the performing of the selected task restores a system security database from a backup location or resetting the system security database to a factory setting.

15. The medium of claim 10 wherein the interrupt command may only be received from a physically present user who is physically accessing the computing device.

16. The medium of claim 10 wherein the interrupt command may be received from a user who is accessing the computing device from a remote location.

17. The medium of claim 10 wherein the secure boot process is interrupted when a previously recorded request to alter the secure boot process is identified during the boot sequence.

18. The medium of claim 17 wherein the request is recorded in a UEFI-defined variable by an operating system process.

19. A computing device equipped with Unified Extensible Firmware Interface (UEFI)-compliant firmware for altering a UEFI secure boot process, comprising:

a processor, the processor supporting System Management Mode (SMM);

a display surface in communication with the computing device;

an input mechanism; and

at least one firmware module, the firmware module when executed:

identifying an interrupt command during a UEFI secure boot process for the computing device, the secure boot process interrupted in response to the command;

displaying to a user, following the interruption of the boot process, a listing of at least one task related to altering the secure boot process;

receiving a selection of a listed task;

invoking System Management Mode (SMM) in response to the selection of the listed task;

performing the selected task in SMM using a firmware module executable only within SMM; and

booting the computing device after exiting SMM.

20. The computing device of claim 19 in which the task performed is to enroll a hash of executable code to be launched in the boot process into a system security database.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2015
From: BOBZIN, JEFFERY JAY
To: INSYDE SOFTWARE CORP.
Reel/Frame 035270/0882 →
Continuity (3)
Continuation 13668757 · Nov 5, 2012
Provisional Application 61555851 · Nov 4, 2011
Related Publication 20150199521A1 · Jul 16, 2015