IP Library › Granted Patent US 10,942,750
Granted Patent B2
US 10,942,750 · App. 16/370,129 · Granted Mar 9, 2021

System and method to securely load non-UEFI based file format as OEM based UEFI custom capsule format in UEFI loader

Inventors: Venkata Atta (Bangalore, IN); Shekar Babu Suryanarayana (Bangalore, IN); Sumanth Vidyadhara (Bangalore, IN)
Assignee: DELL PRODUCTS L.P.
G06F9/4406G06F9/44505G06F15/177G06F21/57G06F21/64H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,942,750
App. No.
16/370,129
Filed
Mar 29, 2019
Granted
Mar 9, 2021
Kind
B2
Art Unit
2186
USPC
713/2
Abstract

A system for secure load of binary code, comprising a processor, a data memory device configured to be accessible by the processor, a data capsule configured to be accessible by the processor, the data capsule including a data signature and a network interface device configured to authenticate the data signature over a network using a remote data signature verification server.

Claims (21)

1. A system for secure load of binary code, comprising: a processor; a data memory device configured to be accessible by the processor; a data capsule configured to be accessible by the processor, the data capsule including a data signature; wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and a signature data field for each payload capsule, and the processor is configured to implement the custom UEFI data capsule and each of the plurality of payload data capsules after authenticating the signature data field for the payload data capsule; and a network interface device configured to authenticate the data signature over a network using a remote data signature verification server.

2. The system of claim 1 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule.

3. The system of claim 1 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule and the processor is configured to implement the custom UEFI data capsule.

4. The system of claim 1 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules.

5. The system of claim 1 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and the processor is configured to implement the custom UEFI data capsule and the plurality of payload data capsules.

6. The system of claim 1 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and at least one signature data field.

7. The system of claim 1 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and at least one signature data field, and the processor is configured to implement the custom UEFI data capsule and the plurality of payload data capsules after authenticating the at least one signature data field.

8. The system of claim 1 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and a signature data field for each payload capsule.

9. A method for secure load of binary code, comprising: executing boot code with a processor; accessing a data capsule with the processor during the boot process, the data capsule including a data signature; wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and a signature data field for each payload capsule, and further comprising implementing the custom UEFI data capsule and each of the plurality of payload data capsules after authenticating the signature data field for the payload data capsule and authenticating the data signature over a network using a remote data signature verification server.

10. The method of claim 9 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule.

11. The method of claim 9 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule and further comprising implementing the custom UEFI data capsule with the processor.

12. The method of claim 9 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules.

13. The method of claim 9 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and further comprising implementing the custom UEFI data capsule and the plurality of payload data capsules with the processor.

14. The method of claim 9 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and at least one signature data field.

15. The method of claim 9 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and at least one signature data field, and further comprising implementing the custom UEFI data capsule and the plurality of payload data capsules after authenticating the at least one signature data field.

16. The method of claim 9 wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and a signature data field for each payload capsule.

17. In a system for secure load of binary code having a processor, a data memory device configured to be accessible by the processor, a data capsule configured to be accessible by the processor, the data capsule including a data signature and a network interface device configured to authenticate the data signature over a network using a remote data signature verification server, wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and a signature data field for each payload capsule, and the processor is configured to implement the custom UEFI data capsule and each of the plurality of payload data capsules after authenticating the signature data field for the payload data capsule, a method comprising:

executing boot code with the processor;

accessing a data capsule with the processor during the boot process, the data capsule including a data signature;

authenticating the data signature over a network using a remote data signature verification server; and

wherein the data capsule comprises a custom Unified Extensible Firmware Interface (UEFI) data capsule with a plurality of payload capsules and a signature data field for each payload capsule, and further comprising implementing the custom UEFI data capsule and each of the plurality of payload data capsules after authenticating the signature data field for the payload data capsule.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0466) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 060753/0486 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST AT REEL 050405 FRAME 0534 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058001/0001 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0466 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050405/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2019
From: ATTA, VENKATA; SURYANARAYANA, SHEKAR BABU; VIDYADHARA, SUMANTH
To: DELL PRODUCTS L.P.
Reel/Frame 048743/0583 →
Continuity (1)
Related Publication 20200310824A1 · Oct 1, 2020
Cited By (1)
US 12,578,970