IP Library Granted Patent US 9,742,568
Granted Patent B2
US 9,742,568 · App. 14/863,401 · Granted Aug 22, 2017

Trusted support processor authentication of host BIOS/UEFI

Inventors: Balaji Bapu Gururaja Rao (Austin, TX); Elie Antoun Jreij (Pflugerville, TX); Richard Lynn Hall (Cedar Park, TX); Mukund P. Khatri (Austin, TX)
Assignee: Dell Products, L.P.
H04L9/3234G06F3/0619G06F3/0632G06F3/0679G06F21/575H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,742,568
App. No.
14/863,401
Filed
Sep 23, 2015
Granted
Aug 22, 2017
Kind
B2
Art Unit
2115
USPC
713/2
Abstract

An information handling system (IHS) prevents execution of corrupted bootup instructions in flash memory. A memory component contains basic input/output system (BIOS) instructions to execute during boot up of the IHS. A host processor is in communication with the memory component via the system interconnect to execute the BIOS instructions to configure the IHS. A support processor executes instructions to configure the IHS to: (a) calculate a current hash value for the BIOS instructions; (b) access a trusted encrypted hash value and the unique key from a secure storage; (c) decrypt the trusted encrypted hash value using the unique key to obtain a trusted hash value; (d) determine whether the current hash value is identical to the trusted hash value; and (e) allow execution of the BIOS instructions by the host processor in response to determining that the encrypted current hash value is identical to the trusted hash value.

Claims (83)

1. An information handling system (IHS) for preventing execution of corrupted boot up instructions in flash memory, the IHS comprising:

a system interconnect;

a memory component containing basic input/output system (BIOS) instructions to execute during boot up of the IHS;

a host processor in communication with the memory component via the system interconnect and which executes the BIOS instructions to configure the IHS;

a support processor in communication via the system interconnection with the memory component and comprising an embedded memory containing a unique key that is assigned to the support processor and executing instructions to configure the IHS to:

calculate a current hash value for the BIOS instructions;

access a trusted encrypted hash value and the unique key from a secure storage;

decrypt the trusted encrypted hash value using the unique key to obtain a trusted hash value;

determine whether the current hash value is identical to the trusted hash value; and

allow execution of the BIOS instructions by the host processor in response to determining that the encrypted current hash value is identical to the trusted hash value;

wherein the system interconnect comprises a selected one of an inter-integrated circuit (I 2 C) bus, a Personal Computer Interconnect Express (PCIe) bus, and a Serial Peripheral Interface (SPI) bus, with selectively one of the host processor and the support processor in master communication control to read an entirety of the memory component.

2. The IHS of claim 1 , wherein the support processor executes instructions to configure the IHS to replace the BIOS instructions with trusted BIOS instructions in response to determining that the current hash value is not identical to the trusted hash value.

3. The IHS of claim 1 , wherein, in response to determining that the current hash value is not identical to the trusted hash value, the support processor executes instructions to configure the IHS to perform at least one of:

shut down the IHS;

send an alert to an administrator; and

invoke a BIOS recovery using a backup BIOS image.

4. The IHS of claim 1 , wherein the support processor executes instructions to configure the IHS during a first boot to:

determine whether the trusted hash value is stored in the secure storage;

in response to determining that the trusted hash value is not stored in the secure storage:

calculate a hash value from trusted BIOS instructions stored in the removable flash memory module;

encrypt the hash value using the unique key to create the trusted hash value; and

store the trusted hash value in the secure storage.

5. The IHS of claim 1 , wherein the support processor executes instructions to configure the IHS to:

receive an encrypted BIOS instruction update;

determine, via the support processor, whether a digital signature of a source of the encrypted BIOS instruction update is a trusted source; and

enable updating of the BIOS instructions in the removable flash memory module in response to determining that the digital signature of the source of the encrypted BIOS instruction update is a trusted source.

6. The IHS of claim 1 , wherein the IHS comprises a server and the support processor comprises a baseboard management controller.

7. The IHS of claim 1 , further comprising a controller of an array of replacement non-volatile storage devices, the controller executing instructions to:

calculate a current hash value for the memory content in the particular nonvolatile storage device;

access, from a secure storage, the unique key and a trusted encrypted hash value for the particular nonvolatile storage device encrypted with the unique key assigned to the controller;

decrypt the trusted encrypted hash value for the particular nonvolatile storage device using the unique key to obtain a trusted hash value;

determine whether the current hash value is identical to the trusted hash value for the particular nonvolatile storage device; and

allow access to the particular nonvolatile storage device in response to determining that the current hash value is identical to the trusted hash value for the particular nonvolatile storage device.

8. The IHS of claim 1 , further comprising a controller of an array of replacement non-volatile storage devices, the controller executing instructions to:

determine whether a trusted encrypted hash value for a particular nonvolatile storage device is stored in the secure storage;

in response to determining that the trusted encrypted hash value for the particular nonvolatile storage device is not stored in the secure storage:

calculate a hash value from trusted memory content stored in the particular nonvolatile storage device;

encrypt the hash value using a unique key that is assigned to the controller to create a trusted hash value; and

store the trusted encrypted hash value for the particular nonvolatile storage device in the secure storage.

9. A method of authenticating Basic Input/Output System (BIOS) of an information handling system (IHS) for preventing execution of corrupted boot up instructions, the method comprising:

calculating, by a support processor, a current hash value for the BIOS instructions;

accessing, by the support processor, a trusted encrypted hash value and the unique key from a secure storage;

decrypting, by the support processor, the trusted encrypted hash value using the unique key to obtain a trusted hash value;

determining, by the support processor, whether the current hash value is identical to the trusted hash value; and

allowing execution of the BIOS instructions by the host processor in response to determining that the encrypted current hash value is identical to the trusted hash value; and

the support processor selectively communicating over a system interconnection shared with the host processor and comprising a selected one of an inter-integrated circuit (I 2 C) bus, a Personal Computer Interconnect Express (PCIe) bus, and a Serial Peripheral Interface (SPI) bus in master communication control to read an entirety of the memory component.

10. The method of claim 9 , further comprising replacing the BIOS instructions with trusted BIOS instructions in response to determining that the current hash value is not identical to the trusted hash value.

11. The method of claim 9 , wherein, in response to determining that the current hash value is not identical to the trusted hash value, the support processor performing at least one of:

shutting down the IHS;

sending an alert to an administrator; and

invoking a BIOS recovery using a backup BIOS image.

12. The method of claim 9 , further comprising configuring the IHS during a first boot by:

determining whether the trusted encrypted hash value is stored in the secure storage;

in response to determining that the trusted hash value is not stored in the secure storage:

calculating a hash value from trusted BIOS instructions stored in the removable flash memory module;

encrypting the hash value using the unique key to create the trusted hash value; and

storing the trusted hash value in the secure storage.

13. The method of claim 9 , further comprising:

receiving an encrypted BIOS instruction update;

determining whether a digital signature of a source of the encrypted BIOS instruction update is a trusted source; and

enabling update of the BIOS instructions in the removable flash memory module in response to determining that the digital signature of the source of the encrypted BIOS instruction update is a trusted source.

14. The method of claim 9 , further comprising:

a controller:

determining whether a trusted encrypted hash value for a particular nonvolatile storage device of an array of replacement non-volatile storage devices is stored in the secure storage;

in response to determining that the trusted encrypted hash value for the particular nonvolatile storage device is not stored in the secure storage:

calculating a hash value from trusted memory content stored in the particular nonvolatile storage device;

encrypting the hash value using a unique key that is assigned to the controller and stored in the secure storage to create a trusted encrypted hash value; and

storing the trusted encrypted hash value for the particular nonvolatile storage device in the secure storage.

15. A method of authenticating a memory device of an information handling system (IHS), the method comprising:

accessing, by a processor, current memory contents of a memory device;

calculating, by the processor, a current hash value for the current memory content memory device;

accessing, by the processor, a trusted encrypted hash value and the unique key from a secure storage;

decrypting, by the processor, the trusted encrypted hash value using the unique key to obtain a trusted hash value;

determining, by the processor, whether the current hash value is identical to the trusted hash value; and

allowing, by the processor, access to the current memory contents of the memory device by another processor in response to determining that the encrypted current hash value is identical to the trusted hash value.

16. The method of claim 15 , further comprising the processor disabling access to the memory device in response to determining that the current hash value is not identical to the trusted hash value for the memory device.

17. The method of claim 15 , further comprising the processor preparing the memory device for use by:

calculating a hash value from memory content stored in the memory device;

encrypting the hash value using a unique key that is assigned to the processor and stored in the secure storage to create the trusted encrypted hash value; and

storing the trusted encrypted hash value for the memory device in the secure storage.

18. The method of claim 15 , further comprising:

the processor selecting master control of a system interconnect in slaved communication with the storage device to read the current memory contents; and

the processor allowing another processor to select master control of the system interconnect in response to determining that the current hash value is identical to the trusted hash value for the memory device.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 037160 FRAME 0142 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0812 →
RELEASE OF REEL 037160 FRAME 0239 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0115 →
RELEASE OF REEL 037160 FRAME 0171 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0253 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - NOTES Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 037160/0142 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - TERM LOAN Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037160/0239 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - ABL Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037160/0171 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2015
From: RAO, BALAJI BAPU GURURAJA; JREIJ, ELIE ANTOUN; HALL, RICHARD LYNN; KHATRI, MUKUND P.
To: DELL PRODUCTS L.P.
Reel/Frame 036639/0681 →
Continuity (1)
Related Publication 20170085383A1 · Mar 23, 2017