IP Library › Granted Patent US 10,146,942
Granted Patent B2
US 10,146,942 · App. 14/630,413 · Granted Dec 4, 2018

Method to protect BIOS NVRAM from malicious code injection by encrypting NVRAM variables and system therefor

Inventors: Ricardo L. Martinez (Leander, TX); Allen C. Wynn (Round Rock, TX); Richard M. Tonry (Austin, TX)
Assignee: Dell Products, LP
G06F21/572G06F13/4282H04L9/06H04L9/0618G06F12/1408G06F2212/1052G06F2212/7201
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,146,942
App. No.
14/630,413
Filed
Feb 24, 2015
Granted
Dec 4, 2018
Kind
B2
Art Unit
2431
USPC
713/161
Abstract

Data to be stored at a firmware memory is received. A random symmetric encryption key is generated. The data is encrypted using the generated key to provide encrypted data. The encrypted data and the encryption key are both stored at the firmware memory.

Claims (50)

1. A method to protect non-volatile random access memory (NVRAM) from malicious code, the method comprising:

allocating, by a hardware processor of an information handling system, a first region at the NVRAM to store firmware instructions;

allocating, by the hardware processor of the information handling system, a second region to store data that is not the firmware instructions; and

receiving, by the hardware processor of the information handling system, the data to be stored at the second region, the receiving of the data in response to servicing a system management interrupt, the data received at a software function configured to store the data at the second region, the software function including operations for:

generating a random symmetric encryption key;

encrypting the data using the random symmetric encryption key to provide encrypted data, the random symmetric encryption key to only be associated with the data; and

storing the encrypted data and the random symmetric encryption key at the second region at the NVRAM;

wherein the encrypted data protects the second region at the NVRAM from executing the malicious code.

2. The method of claim 1 , wherein the random symmetric encryption key is stored at the second region as plain text.

3. The method of claim 1 , wherein the encrypted data and the random symmetric encryption key are linked by reference by a single globally unique identifier.

4. The method of claim 1 , further comprising decrypting the encrypted data using the random symmetric encryption key in response to receiving a request to retrieve the data from the second region at the NVRAM.

5. The method of claim 1 , further comprising receiving the data from a Windows library function after initialization of an operating system.

6. The method of claim 1 , further comprising receiving the data from a unified extensible firmware interface protocol.

7. The method of claim 1 , further comprising receiving the data during a driver initialization phase of a boot process at the information handling system.

8. The method of claim 1 , wherein the encrypted data and the random symmetric encryption key are referenced at the NVRAM by a single memory address.

9. The method of claim 1 , further comprising:

receiving a request to retrieve the data from the second region at the NVRAM;

retrieving the encrypted data from the second region at the NVRAM;

retrieving the random symmetric encryption key from the second region at the NVRAM;

decrypting the encrypted data using the random symmetric encryption key to unencrypt the data; and

providing the data to fulfill the request.

10. The method of claim 1 , wherein the data is an environment variable.

11. The method of claim 1 , wherein the function for the write operations is configured to prevent execution of malicious code stored at the second region.

12. An information handling system comprising:

a processor;

a system memory device; and

a non-volatile firmware memory device including a first region for storing basic input/output system (BIOSE code and a second region for storing data that is not the BIOS code, the BIOS code executing store operations to the second region, the store operations to further:

receive the data to be stored at the second region of the non-volatile firmware memory device, the data received in response to servicing a system management interrupt;

generate a random symmetric encryption key for each different store operation of the store operations executed by the BIOS code;

encrypt the data using the random symmetric encryption key to provide encrypted data that corresponds to the each different store operation; and

store the encrypted data and the generated random symmetric encryption key at the second region of the non-volatile firmware memory device.

13. The information handling system of claim 12 , further comprising instructions to decrypt the encrypted data using the random symmetric encryption key in response to receiving a request to retrieve the data from the second region.

14. The information handling system of claim 12 , wherein the encrypted data and the random symmetric encryption key are linked by reference by a single identifier.

15. The information handling system of claim 12 , wherein the random symmetric encryption key is stored as plain text.

16. The information handling system of claim 12 , wherein the store operations are configured to prevent execution of malicious code stored at the second region.

17. A non-transitory data storage medium storing instructions executable by a processor to cause the processor to:

allocate a first region of a non-volatile firmware memory to store BIOS code;

allocate a second region of the non-volatile firmware memory to store data that is not the BIOS code; and

implement a function for write operations to the second region of the non-volatile firmware memory, the function for the write operations configured to:

receive the data in response to servicing a system management interrupt at the processor;

generate a different random symmetric encryption key for each corresponding one of the write operations to the second region of the non-volatile firmware memory;

encrypt the data using the different random symmetric encryption key to provide encrypted data for the corresponding one of the write operations to the second region of the non-volatile firmware memory; and

store the encrypted data and the different random symmetric encryption key at the second region of the non-volatile firmware memory for the corresponding one of the write operations.

18. The non-transitory data storage medium of claim 17 , further comprising instructions to:

receive a request to retrieve the data from the second region;

retrieve the encrypted data;

retrieve the different random symmetric encryption key;

decrypt the encrypted data using the different random symmetric encryption key to unencrypt the data; and

provide the unencrypted data to fulfill the request.

19. The non-transitory data storage medium of claim 17 , wherein the different random symmetric encryption key is stored as plain text.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 035860 FRAME 0797 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040028/0551 →
RELEASE OF REEL 035860 FRAME 0878 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040027/0158 →
RELEASE OF REEL 035858 FRAME 0612 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040017/0067 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2015
From: MARTINEZ, RICARDO L.; WYNN, ALLEN C.; TONRY, RICHARD M.
To: DELL PRODUCTS, LP
Reel/Frame 035810/0626 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035858/0612 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035860/0797 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035860/0878 →
Continuity (1)
Related Publication 20160246964A1 · Aug 25, 2016
Cited By (1)
US 12,541,598