IP Library Granted Patent US 9,916,451
Granted Patent B2
US 9,916,451 · App. 14/877,242 · Granted Mar 13, 2018

Information handling system boot pre-validation

Inventors: Jonathan B. Barkelew (Austin, TX); Kurt D. Gillespie (Pflugerville, TX)
Assignee: Dell Products L.P.
G06F21/572G06F9/4401G06F21/575H04L9/3268G06F2221/031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,916,451
App. No.
14/877,242
Filed
Oct 7, 2015
Granted
Mar 13, 2018
Kind
B2
Art Unit
2438
USPC
713/2
Abstract

Pre-validation of bootloader certificates for firmware bootloaders of an operating system boot list during a setup mode of BIOS boot initiation provides the end user with a tool to address boot certification problems associated with the firmware bootloaders before the operating system boot precludes execution of bootloaders that lack a valid certificate. For example, re-configuration of a boot list to address certification problems before exit of boot setup prevents boot to an inoperative state caused by lack of firmware execution during boot due to a failed certificate, such as a failure to load an unsigned option ROM.

Claims (47)

1. An information handling system comprising:

a processor executing instructions that process information;

memory interfaced with the processor, the memory storing the instructions and information;

a display interfaced with the processor and presenting the information as visual images;

plural components interfaced with the processor and performing functions with firmware instructions loaded at boot of an operating system on the processor;

initiation firmware stored in the memory and initiating boot of the operating system at power on of the processor;

a secure boot module associated with the initiation firmware and comparing bootloader certificates for bootloaders of firmware instructions for the plural components with valid certificates to validate the firmware instructions, the secure boot module further preventing execution of firmware that lacks a valid certificate; and

a pre-validation module associated with the initiation firmware and performing a pre-validation by comparing the bootloader certificates with the valid certificates before the comparison performed by the secure boot module, presenting the pre-validation at the display during a setup routine of the initiation firmware, initiating transition to a boot mode of the initiation firmware if the bootloader certificates are valid, and initiating transition to a modified boot mode of the initiation firmware if the bootloader certificates are not valid, the modified boot mode launching a firmware update function of the operating system to update the invalid firmware.

2. The information handling system of claim 1 wherein the plural components comprise a graphics subsystem and the firmware instructions comprise an option ROM to execute on the graphics subsystem.

3. The information handling system of claim 2 wherein the pre-validation module presents an alternative graphics subsystem to use at boot instead of a graphics subsystem having an invalid certificate, the alternative graphics subsystem selectable by an end user for use in boot through the display.

4. The information handling system of claim 3 wherein the graphics system is a graphics card and the alternative graphics system is a chipset-based graphics system.

5. The information handling system of claim 1 wherein the pre-validation module performs pre-validation during an initiation firmware set-up state to accept end user setting inputs to the initiation firmware based upon the pre-validation.

6. The information handling system of claim 5 wherein the secure boot module validates firmware instructions for the plural components after completion of boot services performed by the initiation firmware.

7. The information handling system of claim 1 wherein the pre-validation module further:

initiates transition to a boot mode of the initiation firmware if the bootloader certificates are valid; and

establishes a network interface to update the bootloader certificates if the bootloader certificates are not valid.

8. The system of claim 1 wherein the firmware loaded on the components at boot of the information handling system comprises option ROMs.

9. A method for booting an information handling system, the method comprising:

initiating firmware instructions to bring an operating system from persistent memory to an operational state;

executing a set-up state of the firmware instructions, the set-up state accepting end user inputs;

while in the set-up state, validating certificates of option ROM bootloaders in a boot list of the firmware; and

applying corrective action for invalid certificates in the set-up state before transition to a boot state, the corrective actions including at least presenting invalid certificates at a display while in the set-up state, and accepting end user inputs in response to the presenting invalid certificates.

10. The method of claim 9 further comprising:

transitioning to the boot state to prepare execution of the operating system;

exiting the boot state to initiate execution of the operating system; and

in response to exiting the boot state, validating the certificates of the option ROM bootloaders before executing the option ROM bootloaders.

11. The method of claim 9 wherein accepting end user inputs in response to the presenting invalid certificates further comprises accepting an end user selection of an alternative option ROM to execute instead of an option ROM having an invalid certificate.

12. The method of claim 9 wherein accepting end user inputs in response to the presenting invalid certificates further comprises accepting an end user selection of an alternative component to use on boot from a component having an invalid certificate.

13. The method of claim 12 wherein the component having an invalid certificate is a graphics card and the alternative component to use on boot is a chipset-based graphics system.

14. The method of claim 9 wherein accepting end user inputs in response to the presenting invalid certificates further comprises establishing a network interface to retrieve an option ROM having a valid certificate to replace the option ROM having the invalid certificate.

15. The method of claim 14 wherein accepting end user inputs in response to the presenting invalid certificates further comprises accepting an end user override of the invalid certificate to permit operating system use of the bootloader associated with the invalid certificate.

16. A system for booting an information handling system, the system comprising:

non-transitory memory storing:

an operating system having instructions that execute on a processor to coordinate execution of applications on the information handling system, the operating system having a secure boot mode that validates bootloader certificates and precludes execution of bootloaders that lack a valid bootloader certificate;

initiation firmware having instructions that coordinate boot of the operating system, the initiation firmware having a setup mode, a boot mode and an exit boot services that transitions control of the information handling system from the initiation firmware to the operating system; and

a pre-validation module having instructions that determine the validity of the bootloader certificates during the initiation firmware setup mode, present invalid bootloader certificates at a display while in the set-up state, and accept end user inputs in response to the presenting invalid certificates to alter the operating system boot based on the invalid bootloader certificates.

17. The system of claim 16 wherein the end user input comprises a change to a boot list of bootloaders to replace the invalid bootloader with a valid bootloader.

18. An information handling system comprising:

a processor executing instructions that process information;

memory interfaced with the processor, the memory storing the instructions and information;

a display interfaced with the processor and presenting the information as visual images;

plural components interfaced with the processor and performing functions with firmware instructions loaded at boot of an operating system on the processor;

initiation firmware stored in the memory and initiating boot of the operating system at power on of the processor;

a secure boot module associated with the initiation firmware and comparing bootloader certificates for bootloaders of firmware instructions for the plural components with valid certificates to validate the firmware instructions, the secure boot module further preventing execution of firmware that lacks a valid certificate; and

a pre-validation module associated with the initiation firmware and performing a pre-validation by comparing the bootloader certificates with the valid certificates before the comparison performed by the secure boot module, presenting the pre-validation at the display during a setup routine of the initiation firmware;

wherein the plural components comprise a graphics subsystem and the firmware instructions comprise an option ROM to execute on the graphics subsystem; and

wherein the pre-validation module presents an alternative graphics subsystem to use at boot instead of a graphics subsystem having an invalid certificate, the alternative graphics subsystem selectable by an end user for use in boot through the display.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 037160 FRAME 0142 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0812 →
RELEASE OF REEL 037160 FRAME 0239 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0115 →
RELEASE OF REEL 037160 FRAME 0171 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0253 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - NOTES Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 037160/0142 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - TERM LOAN Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037160/0239 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - ABL Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037160/0171 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2015
From: BARKELEW, JONATHAN B.; GILLESPIE, KURT D.
To: DELL PRODUCTS L.P.
Reel/Frame 036749/0170 →
Continuity (2)
Provisional Application 62113758 · Feb 9, 2015
Related Publication 20160232356A1 · Aug 11, 2016