IP Library Granted Patent US 11,113,404
Granted Patent B2
US 11,113,404 · App. 16/581,987 · Granted Sep 7, 2021

Securing operating system configuration using hardware

Inventor: Patrick J. Callaghan (Vestal, NY)
Assignee: International Business Machines Corporation
G06F21/575G06F9/4401G06F9/4406G06F21/44G06F21/6218H04L9/0891H04L9/3247G06F9/441G06F2221/034H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,113,404
App. No.
16/581,987
Granted
Sep 7, 2021
Kind
B2
Abstract

A method, system, and computer program product includes receiving, in a booted state of a computing system, a request to load an operating system configuration. The method further includes storing, automatically in response to receiving the request, a digital key to authenticate the operating system configuration. The method further includes restarting the computing system. In response to restarting the computing system and while the computing system is in a pre-boot state, the method includes: validating that the digital key stored is one for a valid operating system configuration; receiving, from a user interface physically coupled to the computing system, a signal confirming the received request; authenticating, in response to receiving the signal, the operating system configuration using the digital key; and booting, in response to the authenticating, the operating system configuration.

Claims (33)

1. A method comprising:

receiving, from a user application executing under a first operating system configuration on a computing device, a request to execute a second operating system configuration of a set of operating system configurations, wherein the second operating system configuration is signed by a private key of a public-private key pair; and

during a pre-boot state of the computing device:

receiving, from a local interface physically coupled to the computing device, a signal confirming the received request;

moving a public key of the public-private key pair to a protected memory in response to receiving the signal confirming the request; and

executing a boot loader having access to the protected memory to authenticate the second operating system configuration using the public key stored in the protected memory, and to boot the second operating system configuration in response to the authenticating.

2. The method of claim 1 , wherein the second operating system configuration comprises an operating system kernel compiled with a set of parameters;

wherein the set of parameters determines software modules loadable under the second operating system configuration.

3. The method of claim 2 , wherein the set of parameters determines enforcement of an access control policy of the second operating system configuration.

4. The method of claim 1 , wherein the protected memory is only writable by a set of applications having an executable code integrity authenticated by a hardware component of the computing system.

5. A system, comprising:

a user interface terminal; and

a computing system physically coupled to the user interface terminal and having a memory and a processor;

wherein the memory includes computer executable code that causes the system:

receive, from a user application executing under a first operating system configuration on a computing device, a request to execute a second operating system configuration of a set of operating system configurations, wherein the second operating system configuration is signed by a private key of a public-private key pair; and

during a pre-boot state of the computing device:

receive, from the user interface terminal, a signal confirming the received request;

move a public key of the public-private key pair to a protected memory of the computing system in response to receiving the signal confirming the request;

and execute a boot loader having access to the protected memory to authenticate the second operating system configuration using public key stored in the protected memory, and to boot the second operating system configuration in response to the authenticating.

6. The system of claim 5 , wherein the second operating system configuration comprises an operating system kernel compiled with a set of parameters;

wherein the set of parameters determines software modules loadable under the second operating system configuration.

7. The system of claim 6 , wherein the set of parameters determines enforcement of an access control policy of the second operating system configuration.

8. The system of claim 5 , wherein the protected memory is only writable by a set of applications having an executable code integrity authenticated by a hardware component of the computing system.

9. A computer program product for securely booting a computing system, the computer program product including a computer readable storage medium having program instructions embodied therewith, wherein the computer readable storage medium is not a transitory signal per se, the program instructions executable by a processor to:

receive, from a user application executing under a first operating system configuration on a computing device, a request to execute a second operating system configuration of a set of operating system configurations, wherein the second operating system configuration is signed by a private key of a public-private key pair; and

during a pre-boot state of the computing device:

receive, from the user interface terminal, a signal confirming the received request;

move a public key of the public-private key pair to a protected memory of the computing system in response to receiving the signal confirming the request; and

execute a boot loader having access to the protected memory to authenticate the second operating system configuration using public key stored in the protected memory, and to boot the second operating system configuration in response to the authenticating.

10. The computer program product of claim 9 , wherein the second operating system configuration comprises an operating system kernel compiled with a set of parameters;

wherein the set of parameters determines software modules loadable under the second operating system configuration.

11. The computer program product of claim 10 , wherein the set of parameters determines enforcement of an access control policy of the second operating system configuration.

12. The computer program product of claim 9 , wherein the protected memory is only writable by a set of applications having an executable code integrity authenticated by a hardware component of the computing system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2019
From: CALLAGHAN, PATRICK J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 050483/0729 →
Continuity (3)
Continuation 15801543 · Nov 2, 2017
Continuation 15624970 · Jun 16, 2017
Related Publication 20200019710A1 · Jan 16, 2020