IP Library › Granted Patent US 11,544,414
Granted Patent B2
US 11,544,414 · App. 16/266,538 · Granted Jan 3, 2023

Secure wake-on of a computing device

Inventors: Daniel L. Hamlin (Round Rock, TX); Janardan Pradeep Gopal (Round Rock, TX)
Assignee: Dell Products L.P.
G06F21/81G06F1/3215G06F1/3296G06F21/34G06F9/4401G06F9/4418G06F21/31G06F21/575Y02D10/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,544,414
App. No.
16/266,538
Filed
Feb 4, 2019
Granted
Jan 3, 2023
Kind
B2
Examiner
BAE, JI H
Art Unit
2187
USPC
726/2
Abstract

In some examples, an embedded controller of a computing device may detect, when the computing device is in a low-power state, that a smartcard has been connected to a port of the computing device or that data has been received from an input device (e.g., keyboard or biometric input device) connected to the computing device. For the smartcard, the embedded controller may use a card driver to read data stored on the smartcard. The embedded controller may compute a hash value based on the data read from the smartcard or received from the input device. If the hash value matches a previously stored hash value, then the embedded controller may initiate a boot-up process of the computing device. If the hash value does not match the previously stored hash value, then the embedded controller may cause the computing device to remain in the low-power state.

Claims (99)

1. A method comprising providing a computing device having a first hash value previously stored thereon that is computed based at least in part on data stored on a designated user smartcard, and then:

entering a low-power state of the computing device that has the first hash value previously stored thereon;

then determining, by one or more processors, that the computing device is in the low-power state, and that a current user smartcard has been connected to a port of the computing device while the computing device is in the low-power state;

then loading, by the one or more processors, a card driver;

then reading, using the card driver being executed by the one or more processors, data stored on the connected current user smartcard;

then computing, by the one or more processors, a second hash value based at least in part on the data stored on the connected current user smartcard;

then performing, by the one or more processors, a comparison of the second hash value to the previously stored first hash value;

then only upon determining, by the one or more processors and based on the comparison, that the second hash value matches the previously stored first hash value,

initiating a boot-up of the computing device, and transitioning, by the one or more processors, the computing device from the low-power state to a power-on state.

2. The method of claim 1 , further comprising:

then only upon determining, based on the comparison, that the second hash value does not match the previously stored first hash value, resuming the low-power state.

3. The method of claim 1 , wherein the data stored on the designated user smartcard comprises at least one of:

a public certificate; or

a card identifier that uniquely identifies the designated user smartcard.

4. The method of claim 1 , wherein the card driver comprises a chip card interface device driver.

5. The method of claim 1 , wherein determining that the current user smartcard has been connected to the port of the computing device comprises:

determining that a universal serial bus (USB) dongle comprising the current user smartcard has been inserted into a USB port of the computing device.

6. The method of claim 1 , wherein determining that the current user smartcard has been connected to the port of the computing device comprises:

determining that the current user smartcard has been inserted into a card reader port of a keyboard that is connected to a universal serial bus (USB) port of the computing device.

7. The method of claim 1 , wherein the providing the computing device having the first hash value previously-stored thereon comprises creating and storing the first hash value on the computing device before the entering the low-power state of the computing device by:

enabling a secure wake-on using a smartcard setting of a basic input/output system (BIOS) of the computing device;

then determining that the designated user smartcard has been connected to the port, and loading the card driver;

then reading, using the card driver, the data stored on the designated user smartcard;

then computing the first hash value based at least in part on the data stored on the designated user smartcard; and

then storing the first hash value in a non-volatile memory of the computing device.

8. The method of claim 1 , further comprising using an embedded controller of the computing device to perform the following while the computing device is in the low-power state with a basic input/output system (BIOS) of the computing device not awake:

determining that the computing device is in the low-power state, and that the current user smartcard has been connected to the port of the computing device while the computing device is in the low-power state;

loading of the card driver;

then computing of the second hash value based at least in part on the data stored on the connected current user smartcard;

then comparing the second hash value to the previously stored first hash value and then performing one of:

waking and instructing the basic input/output system (BIOS) of the computing device to initiate the boot-up of the computing device only if the embedded controller determines that the second hash value matches the previously stored first hash value, or

maintaining the low power state only if the embedded controller determines that the second hash value does not match the previously stored first hash value; and

then using the BIOS of the computing device to respond to instructions from the embedded controller by waking and performing the initiating of the boot-up of the computing device to transition the computing device from the low-power state to the power-on state only if the BIOS is awoken and instructed by the embedded controller to initiate the boot-up of the computing device.

9. A computing device comprising:

one or more processors;

a non-volatile memory having a first hash value previously stored thereon that is computed based at least in part on first user input data previously received from at least one input device that is connected to at least one port of the computing device; and

one or more non-transitory computer readable media storing first instructions executable by the one or more processors to perform first operations after the computing device has entered a low-power state with the first hash value previously stored on

the non-volatile memory, the first operations comprising:

determining that the computing device is in the low-power state, and that second user input data has been received while the computing device is in the low-power state from the at least one input device that is connected to the at least one port of the computing device,

then computing a second hash value based at least in part on the second user input data;

then performing a comparison of the second hash value to the previously stored first hash value, and

then only upon determining, based on the comparison, that the second hash value matches the previously stored first hash value, initiating a boot-up of the computing device, and transitioning the computing device from the low-power state to a power-on state;

where the first instructions are further executable by an embedded controller of the computing device to perform the first operations while the computing device is in the low-power state with a basic input/output system (BIOS) of the computing device not awake, the first operations further comprising

then comparing the second hash value to the previously stored first hash value and then performing one of: waking and instructing the basic input/output system (BIOS) of the computing device to initiate the boot-up of the computing device only if the embedded controller determines that the second hash value matches the previously stored first hash value, or maintaining the low power state only if the embedded controller determines that the second hash value does not match the previously stored first hash value, and

then using the BIOS of the computing device to respond to instructions from the embedded controller by waking and performing the initiating of the boot-up of the computing device to transition the computing device from the low-power state to the power-on state only if the BIOS is awoken and instructed by the embedded controller to initiate the boot-up of the computing device.

10. The computing device of claim 9 , wherein:

the at least one input device comprises a keyboard; and

the first user input data comprises a series of key presses of the keyboard.

11. The computing device of claim 9 , wherein:

the at least one input device comprises a retinal scanner; and

the first user input data comprises retinal scan data.

12. The computing device of claim 9 , wherein:

the at least one input device comprises a fingerprint reader; and

the first user input data comprises fingerprint scan data.

13. The computing device of claim 9 , wherein:

the at least one input device comprises a facial recognition scanner; and

the first user input data comprises facial data.

14. A computing device comprising:

one or more processors;

a non-volatile memory having a first hash value previously stored thereon that is computed based at least in part on first user input data previously received from at least one input device that is connected to at least one port of the computing device; and

one or more non-transitory computer readable media storing first instructions executable by the one or more processors to perform first operations after the computing device has entered a low-power state with the first hash value previously stored on the non-volatile memory, the first operations comprising:

determining that the computing device is in the low-power state, and that second user input data has been received while the computing device is in the low-power state from the at least one input device that is connected to the at least one port of the computing device,

then computing a second hash value based at least in part on the second user input data;

then performing a comparison of the second hash value to the previously stored first hash value, and

then only upon determining, based on the comparison, that the second hash value matches the previously stored first hash value, initiating a boot-up of the computing device, and transitioning the computing device from the low-power state to a power-on state;

where the one or more non-transitory computer readable media store second instructions executable by the one or more processors to perform second operations before the computing device has entered the low-power state, the second operations comprise:

enabling a secure wake-on using at least one input device setting of a basic input/output system (BIOS) of the computing device,

then receiving the first user input data from the at least one input device,

then computing the first hash value based at least in part on the first user input data, and

then storing the first hash value in the non-volatile memory of the computing device.

15. One or more non-transitory computer readable media storing first instructions executable by one or more processors of a computing device having a first hash value previously stored thereon that is computed based at least in part on first user input data previously received from at least one input device that is connected to at least one port of the computing device, the first instructions being executable to perform first operations after the computing device has entered a low-power state with the first hash value previously stored on the computing device, the first operations comprising:

determining that the computing device is in the low-power state, and that second user input data has been received while the computing device is in the low-power state from the at least one input device that is connected to the at least one port of the computing device;

then computing a second hash value based at least in part on the second user input data;

then performing a comparison of the second hash value to the previously stored first hash value;

then only upon determining, based on the comparison, that the second hash value matches the previously stored first hash value, initiating a boot-up of the computing device; and

transitioning the computing device from the low-power state to a power-on state;

where the first instructions are further executable by an embedded controller of the computing device to perform the first operations while the computing device is in the low-power state with a basic input/output system (BIOS) of the computing device not awake, the first operations further comprising:

then comparing the second hash value to the previously stored first hash value and then performing one of: waking and instructing the basic input/output system (BIOS) of the computing device to initiate the boot-up of the computing device only if the embedded controller determines that the second hash value matches the previously stored first hash value, or maintaining the low power state only if the embedded controller determines that the second hash value does not match the previously stored first hash value, and

then using the BIOS of the computing device to respond to the instructions from the embedded controller by waking and performing the initiating of the boot-up of the computing device to transition the computing device from the low-power state to the power-on state only if the BIOS is awoken and instructed by the embedded controller to initiate the boot-up of the computing device.

16. The one or more non-transitory computer readable media of claim 15 , wherein:

the at least one input device comprises a keyboard; and

the first user input data comprises a series of key presses of the keyboard.

17. The one or more non-transitory computer readable media of claim 15 , wherein:

the at least one input device comprises a retinal scanner; and

the first user input data comprises retinal scan data.

18. The one or more non-transitory computer readable media of claim 15 , wherein:

the at least one input device comprises a biometric scanning device; and

the first user input data comprises biometric data.

19. One or more non-transitory computer readable media storing first instructions executable by one or more processors of a computing device having a first hash value previously stored thereon that is computed based at least in part on first user input data previously received from at least one input device that is connected to at least one port of the computing device, the first instructions being executable to perform first operations after the computing device has entered a low-power state with the first hash value previously stored on the computing device, the first operations comprising:

determining that the computing device is in the low-power state, and that second user input data has been received while the computing device is in the low-power state from the at least one input device that is connected to the at least one port of the computing device;

then computing a second hash value based at least in part on the second user input data;

then performing a comparison of the second hash value to the previously stored first hash value;

then only upon determining, based on the comparison, that the second hash value matches the previously stored first hash value, initiating a boot-up of the computing device; and

transitioning the computing device from the low-power state to a power-on state;

wherein the one or more non-transitory computer readable media store second instructions executable by the one or more processors to perform second operations, before the computing device has entered the low-power state, the second operations comprising:

enabling a secure wake-on using at least one input device setting of a basic input/output system (BIOS) of the computing device,

then receiving the first user input data from the at least one input device,

then computing the first hash value based at least in part on the first user input data, and

then storing the first hash value in a non-volatile memory of the computing device.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0466) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 060753/0486 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 050405 FRAME 0534 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058001/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0466 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050405/0534 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2019
From: HAMLIN, DANIEL L.; GOPAL, JANARDAN PRADEEP
To: DELL PRODUCTS L. P.
Reel/Frame 048259/0103 →
Continuity (1)
Related Publication 20200250348A1 · Aug 6, 2020