IP Library › Granted Patent US 11,068,597
Granted Patent B2
US 11,068,597 · App. 15/711,688 · Granted Jul 20, 2021

Out of band management of basic input/output system secure boot variables

Inventor: William E. Jacobs (Beaverton, OR)
Assignee: CISCO TECHNOLOGY, INC.
G06F21/575G06F9/445G06F21/51G06F21/572G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,068,597
App. No.
15/711,688
Granted
Jul 20, 2021
Kind
B2
Abstract

A method is provided in one example embodiment and includes storing secure boot variables in a baseboard management controller; and sending the secure boot variables to a basic input/output system (BIOS) during a power on self-test, where the BIOS utilizes the secure boot variables during runtime to authenticate drivers and an operating system loader execution. In particular embodiments, the secure boot variables may be included in a white list, a black list, or a key list and, further, stored in erasable programmable read only memory.

Claims (35)

1. A method for updating secure boot variables for authenticating drivers, the method comprising:

storing secure boot variables associated with a managed server as a signed binary large object (BLOB), the secure boot variables stored via a management server, the management server being external to a basic input/output system (BIOS) of the managed server, and wherein the signed BLOB is populated into a baseboard management controller at a provisioning time of the managed server that includes the baseboard management controller;

modifying, via the management server, the secure boot variables per deployment requirements;

sending the secure boot variables to the BIOS;

authenticating drivers, by the BIOS, using the secure boot variables; and

updating the secure boot variables, with changes made by the BIOS, during runtime of the BIOS.

2. The method of claim 1 , wherein the secure boot variables are sent in response to a request, from the BIOS, for the secure boot variables.

3. The method of claim 1 , wherein the signed BLOB is created statically in an off-line secure environment, signed using secure signing services, and passed to the baseboard management controller through an update at the provisioning time.

4. The method of claim 1 , wherein the changes are received at a baseboard management controller.

5. The method of claim 1 , wherein communication between a baseboard management controller and the BIOS uses system management mode code and private interfaces.

6. The method of claim 1 , wherein the management server includes a memory with a default key list, a default white list, and a default black list.

7. The method of claim 1 , wherein the deployment requirements include driver revision blacklisting.

8. One or more non-transitory media that includes instructions that, when executed by a processor, cause the processor to perform operations for updating secure boot variables for authenticating an operating system loader, the operations comprising:

storing secure boot variables associated with a managed server as a signed binary large object (BLOB), the secure boot variables stored via a management server, the management server being external to a basic input/output system (BIOS) of the managed server, and wherein the signed BLOB is populated into a baseboard management controller at a provisioning time of the managed server that includes the baseboard management controller;

modifying, via the management server, the secure boot variables per deployment requirements;

sending the secure boot variables to the BIOS;

authenticating the operating system loader, by the BIOS, using the secure boot variables; and

updating the secure boot variables, with changes made by the BIOS, during runtime of the BIOS.

9. The media of claim 8 , wherein the secure boot variables are sent in response to a request from the BIOS for the secure boot variables.

10. The media of claim 8 , wherein the signed BLOB is created statically in an off-line secure environment, signed using secure signing services, and passed to the baseboard management controller through an update at the provisioning time.

11. The media of claim 8 , wherein the changes are received at a baseboard management controller.

12. The media of claim 8 , wherein communication between a baseboard management controller and the BIOS uses system management mode code and private interfaces.

13. The media of claim 8 , wherein the management server includes a memory with a default key list, a default white list, and a default black list.

14. The media of claim 8 , wherein the deployment requirements include driver revision blacklisting.

15. A network element for updating secure boot variables for authenticating drivers, the network element comprising:

a memory element for storing instructions; and

a processor coupled to the memory element and operable to execute the instructions that, when executed by the processor, cause the network element to:

store secure boot variables associated with a managed server as a signed binary large object (BLOB), the secure boot variables stored via a management server, the management server being external to a basic input/output system (BIOS) of the managed server, and wherein the signed BLOB is populated into a baseboard management controller at a provisioning time of the managed server that includes the baseboard management controller;

modify the secure boot variables per deployment requirements;

send the secure boot variables to the BIOS;

authenticate drivers, by the BIOS, using the secure boot variables; and

updating the secure boot variables, with changes made by the BIOS, during runtime of the BIOS.

16. The network element of claim 15 , wherein the secure boot variables are sent in response to a request from the BIOS for the secure boot variables.

17. The network element of claim 15 , wherein the secure boot variables are associated with a specific managed server.

18. The network element of claim 15 , wherein the changes are received by the baseboard management controller.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2017
From: JACOBS, WILIAM E.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 043657/0012 →
Continuity (3)
Continuation 14972502 · Dec 17, 2015
Continuation 13901281 · May 23, 2013
Related Publication 20180012023A1 · Jan 11, 2018