IP Library Granted Patent US 10,949,539
Granted Patent B2
US 10,949,539 · App. 16/403,090 · Granted Mar 16, 2021

Systems and methods for secure boot and runtime tamper detection

Inventors: Prakash Nara (Round Rock, TX); Wei Liu (Austin, TX); Charles E. Rose (Nashua, NH); Santosh Kumar (Round Rock, TX); Sudhir Vittal Shetty (Cedar Park, TX); Marshal F. Savage (Austin, TX); Rhushabh Bhandari (Cedar Park, TX); Madhav Karri (Austin, TX)
Assignee: Dell Products L.P.
G06F21/575G06F9/4401G06F21/554G06F21/6218H04L9/3247G06F8/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,949,539
App. No.
16/403,090
Filed
May 3, 2019
Granted
Mar 16, 2021
Kind
B2
Examiner
CHEN, XUXING
Art Unit
2187
USPC
713/2
Abstract

A method may include determining if both of two redundant operating system images for executing functionality of a chassis management controller were found during one or more previous boot sessions of the chassis management controller to be unsecure, wherein each operating system image comprises an integrated kernel and initial file root system stored in a respective first partition of a memory of the chassis management controller, verity hashes of a root file system of such operating system image, the verity hashes stored in a respective second partition of the memory, and the root file system of such operating system image stored in a respective third partition of the memory. The method may also include, in response to determining that one of the two redundant operating system images is secure, initiate verification of such operating system image to determine if such operating system image has indicia of tampering.

Claims (54)

1. An information handling system comprising:

a processor;

a memory communicatively coupled to the processor and having stored thereon two redundant operating system images, each operating system image comprising:

an integrated kernel and initial root file system stored in a respective first partition of the memory;

verity hashes of a root file system of such operating system image, the verity hashes stored in a respective second partition of the memory; and

the root file system of such operating system image stored in a respective third partition of the memory; and

a basic input/output system configured to, when executed by the processor:

determine if both of the redundant operating system images were found during one or more previous boot sessions of the information handling system to be unsecure; and

in response to determining that one of the two redundant operating system images is secure, initiating verification of such operating system image to determine if such operating system image has indicia of tampering.

2. The information handling system of claim 1 , wherein verification of such operating system image comprises:

verifying a signature of the integrated kernel and initial root file system of such operating system image; and

verifying the root file system of such operating system based on the verity hashes of such operating system.

3. The information handling system of claim 2 , wherein the verification of such operating system image further comprises completing execution of such operating system image in response to verification of the root file system.

4. The information handling system of claim 2 , wherein verification of such operating system image further comprises verifying the root file system of such operating system based on the verity hashes of such operating system during runtime of such operating system.

5. The information handling system of claim 2 , wherein the verification of such operating system image further comprises, in response to a failure in verification of such operating system image:

writing a variable to the basic input/output system such that the basic input/output system determines such operating system image to be unsecure during a subsequent boot of the information handling system; and

rebooting the information handling system.

6. The information handling system of claim 1 , wherein the verification of such operating system image further comprises, in response to determining that the two redundant operating system images are unsecure, communicating a message to a user indicating that the two redundant operating system images are unsecure.

7. The information handling system of claim 1 , wherein the integrated kernel and initial root file system, the verity hashes, and the root file system of each operating system image is signed with a digital signature verifiable by a certificate stored in the basic input/output system.

8. A chassis comprising:

a plurality of slots each configured to receive a corresponding modular information handling system; and

a chassis management controller communicatively coupled to the plurality of slots and comprising a memory communicatively having stored thereon two redundant operating system images for executing the functionality of the chassis management controller, each operating system image comprising:

an integrated kernel and initial root file system stored in a respective first partition of a memory of the chassis management controller;

verity hashes of a root file system of such operating system image, the verity hashes stored in a respective second partition of the memory; and

the root file system of such operating system image stored in a respective third partition of the memory; and

wherein the chassis management controller is configured to:

determine if both of the redundant operating system images were found during one or more previous boot sessions of the chassis management controller to be unsecure; and

in response to determining that one of the two redundant operating system images is secure, initiating verification of such operating system image to determine if such operating system image has indicia of tampering.

9. The chassis of claim 8 , wherein verification of such operating system image comprises:

verifying a signature of the integrated kernel and initial root file system of such operating system image; and

verifying the root file system of such operating system based on the verity hashes of such operating system.

10. The chassis of claim 9 , wherein the verification of such operating system image further comprises completing execution of such operating system image in response to verification of the root file system.

11. The chassis of claim 9 , wherein verification of such operating system image further comprises verifying the root file system of such operating system based on the verity hashes of such operating system during runtime of such operating system.

12. The chassis of claim 9 , wherein the verification of such operating system image further comprises, in response to a failure in verification of such operating system image:

writing a variable to the chassis management controller such that the chassis management controller is configured to determine such operating system image to be unsecure during a subsequent boot of the chassis management controller; and

rebooting the chassis management controller.

13. The chassis of claim 8 , wherein the verification of such operating system image further comprises, in response to determining that the two redundant operating system images are unsecure, communicating a message to a user indicating that the two redundant operating system images are unsecure.

14. The chassis of claim 8 , wherein the integrated kernel and initial root file system, the verity hashes, and the root file system of each operating system image is signed with a digital signature verifiable by a certificate.

15. A method comprising:

determining if both of two redundant operating system images for executing functionality of a chassis management controller were found during one or more previous boot sessions of the chassis management controller to be unsecure, wherein each operating system image comprises:

an integrated kernel and initial root file system stored in a respective first partition of a memory of the chassis management controller;

verity hashes of a root file system of such operating system image, the verity hashes stored in a respective second partition of the memory; and

the root file system of such operating system image stored in a respective third partition of the memory; and

in response to determining that one of the two redundant operating system images is secure, initiate verification of such operating system image to determine if such operating system image has indicia of tampering.

16. The method of claim 15 , wherein verification of such operating system image comprises:

verifying a signature of the integrated kernel and initial root file system of such operating system image; and

verifying the root file system of such operating system based on the verity hashes of such operating system.

17. The method of claim 16 , wherein the verification of such operating system image further comprises completing execution of such operating system image in response to verification of the root file system.

18. The method of claim 16 , wherein verification of such operating system image further comprises verifying the root file system of such operating system based on the verity hashes of such operating system during runtime of such operating system.

19. The method of claim 16 , wherein the verification of such operating system image further comprises, in response to a failure in verification of such operating system image:

writing a variable to the chassis management controller such that the chassis management controller determines such operating system image to be unsecure during a subsequent boot of the chassis management controller; and

rebooting the chassis management controller.

20. The method of claim 15 , wherein the verification of such operating system image further comprises in response to determining that the two redundant operating system images are unsecure, communicating a message to a user indicating that the two redundant operating system images are unsecure.

21. The method of claim 15 , wherein the integrated kernel and initial root file system, the verity hashes, and the root file system of each operating system image is signed with a digital signature verifiable by a certificate.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0466) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 060753/0486 →
RELEASE OF SECURITY INTEREST AT REEL 050405 FRAME 0534 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058001/0001 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0466 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050405/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2019
From: NARA, PRAKASH; LIU, WEI; ROSE, CHARLES E.; KUMAR, SANTOSH; SHETTY, SUDHIR VITTAL; SAVAGE, MARSHAL F.; BHANDARI, RHUSHABH; KARRI, MADHAV
To: DELL PRODUCTS L.P.
Reel/Frame 049076/0857 →
Continuity (2)
Continuation 15441601 · Feb 24, 2017
Related Publication 20190258802A1 · Aug 22, 2019