IP Library › Granted Patent US 10,013,563
Granted Patent B2
US 10,013,563 · App. 14/040,995 · Granted Jul 3, 2018

Systems and methods for binding a removable cryptoprocessor to an information handling system

Inventors: Johan Rahardjo (Austin, TX); Mukund Purshottam Khatri (Austin, TX); Vaden Albert Mohrmann (Cedar Park, TX)
Assignee: Dell Products L.P.
G06F21/602G06F9/4403G06F21/445G06F21/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,013,563
App. No.
14/040,995
Filed
Sep 30, 2013
Granted
Jul 3, 2018
Kind
B2
Art Unit
2495
USPC
713/189
Abstract

In accordance with these and other embodiments of the present disclosure, an information handling system may include a processor and a basic input/output system (BIOS) including a program of instructions. The BIOS may be configured to, when read and executed by the processor, calculate a binding secret for binding a cryptoprocessor to a motherboard of the information handling system, the binding secret based on unique identifying information of both the cryptoprocessor and the motherboard, store the binding secret in a non-volatile memory integral to the cryptoprocessor, and validate binding of the cryptoprocessor to the motherboard by comparing a subsequently-calculated binding secret to the binding secret.

Claims (96)

1. An information handling system, comprising:

a microprocessor coupled to a motherboard;

a random access memory coupled to the microprocessor;

a basic input/output system (BIOS) comprising a program of BIOS instructions, embodied in non-transitory computer readable media; and

a cryptoprocessor, comprising a cryptographic processor, coupled to the microprocessor and the BIOS;

wherein the BIOS instructions, when read and executed by a processor, cause the processor to perform BIOS operations comprising:

calculating a cryptoprocessor identifier based on a hash of:

a serial number of the cryptoprocessor; and

a random number generated by the cryptoprocessor;

calculating a binding secret value based on:

a unique identifier of the motherboard; and

the cryptoprocessor identifier;

creating a binding secret index to receive and store the binding secret value in a portion of a non-volatile memory integral to the cryptoprocessor;

determining whether the cryptoprocessor is bound to the motherboard;

responsive to determining that the cryptoprocessor is bound to the motherboard, performing validation operations comprising:

reading a previous binding secret value stored in the non-volatile memory using the binding secret index;

comparing the binding secret value and the previous binding secret value; and

responsive to detecting a match between the binding secret value and the previous binding secret value, validating a binding of the cryptoprocessor to the motherboard.

2. The information handling system of claim 1 , wherein the previous binding secret value is permanently locked in the binding secret index.

3. The information handling system of claim 1 , wherein determining whether the cryptoprocessor is bound to the motherboard includes:

determining whether a value read from the binding secret index has any one of one or more predetermined values, wherein the one or more predetermined values include an all 0 value, in which all bits of the value read from the binding secret index are 0, and an all 1 value, in which all bits of the value read from the binding secret index are 1.

4. The information handling system of claim 1 , wherein the BIOS operations include:

responsive to determining that the cryptoprocessor is not bound to the motherboard, performing binding activation operations comprising:

writing the binding secret value to the binding secret index;

write and read protecting the binding secret index by a physical presence provision in the cryptoprocessor; and

determining whether the writing of the binding secret value was successful.

5. The information handling system of claim 4 , wherein the BIOS operations include:

responsive to determining that either the writing of the binding secret value was unsuccessful or the binding secret value did not match the previous binding secret value, performing disabling operations comprising:

disabling the cryptoprocessor;

rebooting the information handling system; and

generating a binding error alert.

6. The information handling system of claim 5 , wherein rebooting the information handling system includes:

rebooting the information handling system without cryptoprocessor support.

7. The information handling system of claim 1 , wherein the cryptoprocessor comprises a Trusted Platform Module compliant with a Trusted Computing Group standard.

8. A method comprising BIOS operations performed by a basic input output system (BIOS) of an information handling system, wherein the BIOS operations include:

calculating a cryptoprocessor identifier based on a hash of:

a serial number of the cryptoprocessor; and

a random number generated by the cryptoprocessor;

calculating a binding secret value based on:

a unique identifier of the motherboard; and

the cryptoprocessor identifier;

creating a binding secret index to receive and store the binding secret value in a portion of a non-volatile memory integral to the cryptoprocessor;

determining whether the cryptoprocessor is bound to the motherboard;

responsive to determining that the cryptoprocessor is bound to the motherboard, performing validation operations comprising:

reading a previous binding secret value stored in the non-volatile memory using the binding secret index;

comparing the binding secret value and the previous binding secret value; and

responsive to detecting a match between the binding secret value and the previous binding secret value, validating a binding of the cryptoprocessor to the motherboard.

9. The method of claim 8 , wherein the previous binding secret value is permanently locked in the binding secret index.

10. The method of claim 8 , wherein determining whether the cryptoprocessor is bound to the motherboard includes:

determining whether a value read from the binding secret index has any one of one or more predetermined values, wherein the one or more predetermined values include an all-0 value in which all bits of the value read from the binding secret index are 0 and an all-1 value in which all bits of the value read from the binding secret index are 1.

11. The method of claim 10 , wherein the BIOS operations include:

responsive to determining that the cryptoprocessor is not bound to the motherboard, performing binding activation operations comprising:

writing the binding secret value to the binding secret index;

write and read protecting the binding secret index by a physical presence provision in the cryptoprocessor; and

determining whether the writing of the binding secret value was successful.

12. The method of claim 11 , wherein the BIOS operations include:

responsive to determining that either the writing of the binding secret value was unsuccessful or the binding secret value did not match the previous binding secret value, performing disabling operations comprising:

disabling the cryptoprocessor;

rebooting the information handling system; and

generating a binding error alert.

13. The method of claim 12 , wherein rebooting the information handling system includes:

rebooting the information handling system without cryptoprocessor support.

14. The method of claim 8 , wherein the cryptoprocessor is a modular component readily removable from the motherboard once coupled to the motherboard.

15. The method of claim 8 , wherein the cryptoprocessor comprises a Trusted Platform Module compliant with a Trusted Computing Group standard.

16. An article of manufacture comprising:

a non-transitory computer-readable medium; and

processor-executable basic input output system (BIOS) instructions carried on the non-transitory computer-readable medium, wherein the BIOS instructions, when read and executed by a processor, cause the microprocessor to perform BIOS operations comprising:

calculating a cryptoprocessor identifier based on a hash of:

a serial number of the cryptoprocessor; and

a random number generated by the cryptoprocessor;

calculating a binding secret value based on:

a unique identifier of the motherboard; and

the cryptoprocessor identifier;

creating a binding secret index to receive and store the binding secret value in a portion of a non-volatile memory integral to the cryptoprocessor;

determining whether the cryptoprocessor is bound to the motherboard;

responsive to determining that the cryptoprocessor is bound to the motherboard, performing validation operations comprising:

reading a previous binding secret value stored in the non-volatile memory using the binding secret index;

comparing the binding secret value and the previous binding secret value; and

responsive to detecting a match between the binding secret value and the previous binding secret value, validating a binding of the cryptoprocessor to the motherboard.

17. The article of claim 16 , wherein the previous binding secret value is permanently locked in the binding secret index.

18. The article of claim 16 , wherein determining whether the cryptoprocessor is bound to the motherboard includes:

determining whether a value read from the binding secret index has any one of one or more predetermined values, wherein the one or more predetermined values include an all-0 value in which all bits of the value read from the binding secret index are 0 and an all-1 value in which all bits of the value read from the binding secret index are 1.

19. The article of claim 18 , wherein the BIOS operations include:

responsive to determining that the cryptoprocessor is not bound to the motherboard, performing binding activation operations comprising:

writing the binding secret value to the binding secret index;

write and read protecting the binding secret index by a physical presence provision in the cryptoprocessor; and

determining whether the writing of the binding secret value was successful.

20. The article of claim 19 , wherein the BIOS operations include:

responsive to determining that either the writing of the binding secret value was unsuccessful or the binding secret value did not match the previous binding secret value, performing disabling operations comprising:

disabling the cryptoprocessor;

rebooting the information handling system; and

generating a binding error alert.

21. The article of claim 20 , wherein rebooting the information handling system includes:

rebooting the information handling system without cryptoprocessor support.

22. The article of claim 16 , wherein the cryptoprocessor is a modular component readily removable from the motherboard once coupled to the motherboard.

23. The article of claim 16 , wherein the cryptoprocessor comprises a Trusted Platform Module compliant with a Trusted Computing Group standard.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2013
From: RAHARDJO, JOHAN; KHATRI, MUKUND PURSHOTTAM; MOHRMANN, VADEN ALBERT
To: DELL PRODUCTS L.P.
Reel/Frame 031389/0204 →
Continuity (1)
Related Publication 20150095631A1 · Apr 2, 2015