IP Library › Granted Patent US 10,037,201
Granted Patent B2
US 10,037,201 · App. 15/054,630 · Granted Jul 31, 2018

Secure live media boot system

Inventor: Dirie N. Herzi (Round Rock, TX)
Assignee: Dell Products L.P.
G06F8/63G06F9/4408G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,037,201
App. No.
15/054,630
Filed
Feb 26, 2016
Granted
Jul 31, 2018
Kind
B2
Examiner
LUU, BINH K
Art Unit
2191
USPC
717/174
Abstract

A secure live media boot system includes a BIOS that is coupled to a storage subsystem and a non-volatile memory system. The BIOS receives an operating system image. Prior to installing an operating system on a computing device using with the operating system image, the BIOS performs a first measurement action on the operating system image to produce a first operating system measurement that it stores in the non-volatile memory system. The BIOS also stores a read-only version of the operating system image on the storage subsystem. The BIOS subsequently receives a request to install the operating system on the computing device and, in response, performs a second measurement action on the operating system image in order to produce a second operating system measurement. If the BIOS determines that the second operating system measurement matches the first operating system measurement, the BIOS installs the operating system on the computing device.

Claims (60)

1. A secure live media boot system, comprising:

a storage subsystem;

a Trusted Platform Module (TPM);

a non-volatile memory system that is separate from the storage subsystem and that is included in a Trusted Platform Module (TPM);

at least one external device connector; and

a Basic Input/Output System (BIOS) that is coupled to the at least one external device connector, the storage subsystem, and the TPM, wherein the BIOS is configured to:

receive, during a BIOS boot process, an operating system image from an external device that is coupled to the external device connector and, in response, perform, during the BIOS boot process, a first measurement action on the operating system image prior to performing an installation of an operating system associated with the operating system image on a computing device that includes the BIOS, wherein the performance of the first measurement action produces a first operating system image measurement;

provide, during the BIOS boot process, the first operating system image measurement to the TPM, wherein the TPM is configured to encrypt and store the first operating system measurement in the non-volatile memory system;

store, during the BIOS boot process, the operating system image as a read-only operating system image on the storage subsystem;

receive a request to install the operating system provided by the operating system image on the computing device subsequent to storing the first operating system image measurement in the non-volatile memory system and, in response, perform a second measurement action on the operating system image stored as a read-only operating system image on the storage subsystem in order to produce a second operating system measurement; and

determine that the second operating system measurement matches the first operating system measurement and, in response, perform an installation of the operating system associated with the operating system image on the computing device.

2. The system of claim 1 , wherein the non-volatile memory system is included in the BIOS.

3. The system of claim 1 , wherein each of the first measurement action and the second measurement action are performed on all of a plurality of data that provides the operating system image.

4. The system of claim 1 , wherein the BIOS is configured to:

encrypt the read-only operating system image that is stored on the storage subsystem, wherein the performing the installation of the operating system associated with the operating system image on the computing device includes decrypting the read-only operating system image.

5. The system of claim 1 , wherein the TPM includes a cryptoprocessor that is configured to encrypt the first operating system measurement with a key.

6. The system of claim 1 , wherein the BIOS is configured to perform the installation of the operating system associated with the operating system image on the computing device by:

creating a Random Access Memory (RAM) drive;

copying the operating system image from the storage subsystem to the RAM drive;

disabling at least a portion of the storage subsystem and the at least one external device connector from accessing at least one component in the computing device; and

installing the operating system associated with the operating system image on the computing device using the operating system image that was copied to the RAM drive.

7. An Information Handling System (IHS), comprising:

a mass storage device;

a Trusted Platform Module (TPM);

a non-volatile memory subsystem that is separate from the mass storage device and that is included in the TPM;

an external device connector; and

a Basic Input/Output System (BIOS) that is coupled to the mass storage device, the TPM, and the external device connector, wherein the BIOS is configured to:

receive, during a BIOS boot process, an operating system image from an external device that is coupled to the external device connector and, in response, perform, during the BIOS boot process, a first measurement action on the operating system image prior to performing an installation of an operating system associated with the operating system image to produce a first operating system image measurement;

provide, during the BIOS boot process, the first operating system image measurement to the TPM, wherein the TPM is configured to encrypt and store the first operating system measurement in the non-volatile memory subsystem;

store, during the BIOS boot process, the operating system image as a read-only operating system image on the mass storage device;

receive a request to install the operating system provided by the operating system image subsequent to storing the first operating system image measurement in the non-volatile memory subsystem and, in response, perform a second measurement action on the operating system image in order to produce a second operating system measurement; and

determine that the second operating system measurement matches the first operating system measurement and, in response, perform an installation of the operating system associated with the operating system image.

8. The IHS of claim 7 , wherein the non-volatile memory subsystem is included in the BIOS.

9. The IHS of claim 7 , wherein each of the first measurement action and the second measurement action are performed on all of a plurality of data that provides the operating system image.

10. The IHS of claim 7 , wherein the BIOS is configured to:

encrypt the read-only operating system image that is stored on the mass storage device, wherein the performing the installation of the operating system associated with the operating system image includes decrypting the read-only operating system image.

11. The IHS of claim 7 , wherein the TPM includes a cryptoprocessor that is configured to encrypt the first operating system measurement with a key.

12. The IHS of claim 7 , wherein the BIOS is configured to perform the installation of the operating system associated with the operating system image by:

creating a Random Access Memory (RAM) drive;

copying the operating system image from the mass storage device to the RAM drive;

disabling the mass storage device and the external device connector; and

installing the operating system associated with the operating system image using the operating system image that was copied to the RAM drive.

13. The IHS of claim 7 , wherein the BIOS is provided by a Unified Extensible Firmware Interface (UEFI).

14. A method for providing secure live media booting, comprising:

receiving, during a Basic Input/Output System (BIOS) boot process by a BIOS through at least one external device connector, an operating system image and, in response, performing, by the BIOS during the BIOS boot process and prior to performing an installation of an operating system associated with the operating system image on a computing device, a first measurement action on the operating system image to produce a first operating system image measurement;

providing, by the BIOS during the BIOS boot process, the first operating system image measurement to a Trusted Platform Module (TPM), wherein the TPM is configured to encrypt and store the first operating system measurement in a non-volatile memory subsystem that is included in the TPM;

storing, by the BIOS during the BIOS boot process, the operating system image as a read-only operating system image on a storage subsystem that is separate from the non-volatile memory subsystem;

receiving, by the BIOS from an input device on the computing device subsequent to storing the first operating system image measurement in the non-volatile memory subsystem, a request to install the operating system provided by the operating system image and, in response, performing a second measurement action on the operating system image in order to produce a second operating system measurement; and

determining, by the BIOS, that the second operating system measurement matches the first operating system measurement and, in response, performing an installation of the operating system associated with the operating system image on the computing device.

15. The method of claim 14 , wherein the non-volatile memory subsystem is included in the BIOS.

16. The method of claim 14 , wherein each of the first measurement action and the second measurement action are performed on all of a plurality of data that provides the operating system image.

17. The method of claim 14 , further comprising:

encrypting, by the BIOS, the read-only operating system image that is stored on the storage subsystem, wherein the performing the installation of the operating system associated with the operating system image on the computing device includes decrypting the read-only operating system image.

18. The method of claim 14 , wherein the TPM includes a cryptoprocessor that is configured to encrypt the first operating system measurement with a key.

19. The method of claim 14 , wherein the performing the installation of the operating system associated with the operating system image on the computing device includes:

creating, by the BIOS, a Random Access Memory (RAM) drive;

copying, by the BIOS, the operating system image from the storage subsystem to the RAM drive;

disabling, by the BIOS, at least a portion of the storage subsystem and the at least one external device connector from accessing at least one component in the computing device; and

installing, by the BIOS, the operating system associated with the operating system image on the computing device using the operating system image that was copied to the RAM drive.

20. The method of claim 14 , wherein the BIOS is provided by a Unified Extensible Firmware Interface (UEFI).

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 038664 FRAME 0908 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0390 →
RELEASE OF REEL 038665 FRAME 0041 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0375 →
RELEASE OF REEL 038665 FRAME 0001 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040021/0348 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 11, 2016
From: DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 038664/0908 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 038665/0041 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 038665/0001 →
EMPLOYMENT AGREEMENT Recorded Mar 10, 2016
From: HERZI, DIRIE N.
To: DELL PRODUCTS L.P.
Reel/Frame 038057/0848 →
Continuity (1)
Related Publication 20170249133A1 · Aug 31, 2017
Cited By (1)
US 12,504,976