IP Library › Granted Patent US 12,235,970
Granted Patent B2
US 12,235,970 · App. 18/048,538 · Granted Feb 25, 2025

Systems and methods for aggregated vulnerability proofing of an IHS

Inventors: Raveendra Babu Madala (Bangalore, IN); Santosh Gore (Bangalore, IN)
Assignee: Dell Products, L.P.
G06F21/577G06F21/575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,235,970
App. No.
18/048,538
Granted
Feb 25, 2025
Kind
B2
Abstract

Systems and methods are provided for vulnerability proofing the administration of hardware components of an IHS. A proposed configuration for a hardware component of the IHS is detected. Multiple catalogs specifying known vulnerabilities of hardware components are accessed, such as a catalog of known vulnerabilities provided by a manufacturer of the hardware component and such as a catalog of known vulnerabilities provided by a manufacturer of the IHS. The proposed configuration of the hardware component is evaluated as being vulnerable in the first catalog and also in the second catalog. If the proposed configuration is identified as vulnerable in either the first catalog or in the second catalog, the hardware component is disabled until the proposed configurations for the hardware component are changed to include no configurations with vulnerabilities identified in either the first or second catalogs.

Claims (39)

1. An IHS (Information Handling System) comprising:

one or more CPUs utilizing one or more buses that connect to a plurality of hardware components of the IHS; and

a remote access controller supporting remote management of the Information Handling System (IHS), the remote access controller comprising a logic unit and a memory device having instructions stored thereon that, upon execution by the logic unit, cause the remote access controller to:

detect a proposed configuration of a first of the hardware components of the IHS,

access two or more catalogs specifying known vulnerabilities of hardware components, wherein a first of the catalogs comprises known vulnerabilities provided by a manufacturer of the first hardware component, wherein a second of the catalogs comprises known vulnerabilities provided by a manufacturer of the IHS;

determine whether the proposed configuration of the first hardware component is identified as vulnerable in the first catalog;

determine whether the proposed configuration of the first hardware component is identified as vulnerable in the second catalog; and

disable the first hardware component until the proposed configurations for the first hardware component are changed to include no configurations with vulnerabilities identified in the first catalog or in the second catalog.

2. The IHS of claim 1 , wherein the proposed configuration further comprises a configuration of a second of the hardware components of the IHS and further comprises a configuration of a workload using the first hardware component and the second hardware component.

3. The IHS of claim 2 , wherein execution of the instructions further causes the remote access controller to determine whether the proposed configuration of the second hardware component is identified as vulnerable in a third catalog provided by a manufacture of the second hardware component.

4. The IHS of claim 3 , wherein execution of the instructions further causes the remote access controller to halt the workload using the first hardware component and the second hardware component until the proposed configurations for the second hardware component are changed to include no configurations with vulnerabilities identified in the third catalog and until the proposed configurations for the first hardware component are changed to include no configurations with vulnerabilities identified in the first catalog or in the second catalog.

5. The IHS of claim 1 , wherein execution of the instructions further causes the remote access controller to identify one or more vulnerability proofing requirements for the IHS within a factory provisioned identity certificate of the IHS.

6. The IHS of claim 5 , wherein the factory-provisioned identity certificate is cryptographically bound to the remote access controller of the IHS.

7. The IHS of claim 5 , wherein the factory-provisioned identity certificate comprises digital signatures for authenticating instructions used by the first hardware component.

8. The IHS of claim 5 , wherein the validation proofing requirements in the inventory certificate further specify the first catalog and the second catalog of known vulnerabilities for use in identifying configurations of the first hardware component that are vulnerable.

9. The IHS of claim 1 , wherein the proposed configurations of the first hardware component comprise configurations for using specific versions of firmware in operation of the first hardware component.

10. The IHS of claim 9 , wherein the vulnerability catalogs specify alternate firmware versions that are not associated with known vulnerabilities.

11. A method for vulnerability proofing the administration of hardware components of an IHS (Information Handling System), wherein the vulnerability proofing is implemented by a remote access controller of the IHS that provides remote management of the IHS, the method comprising:

detecting a proposed configuration of a first of the hardware components of the IHS;

accessing two or more catalogs specifying known vulnerabilities of hardware components, wherein a first of the catalogs comprises known vulnerabilities provided by a manufacturer of the first hardware component, wherein a second of the catalogs comprises known vulnerabilities provided by a manufacturer of the IHS;

determining whether the proposed configuration of the first hardware component is identified as vulnerable in the first catalog;

determining whether the proposed configuration of the first hardware component is identified as vulnerable in the second catalog; and

disable the first hardware component until the proposed configurations for the first hardware component are changed to include no configurations with vulnerabilities identified in the first catalog or in the second catalog.

12. The method of claim 11 , wherein the proposed configuration further comprises a configuration of a second of the hardware components of the IHS and further comprises a configuration of a workload using the first hardware component and the second hardware component.

13. The method of claim 12 , further comprising determining whether the proposed configuration of the second hardware component is identified as vulnerable in a third catalog provided by a manufacture of the second hardware component.

14. The method of claim 13 , further comprising halting the workload using the first hardware component and the second hardware component until the proposed configurations for the second hardware component are changed to include no configurations with vulnerabilities identified in the third catalog.

15. The method of claim 11 , further comprising identifying one or more vulnerability proofing requirements for the IHS within a factory provisioned identity certificate of the IHS.

16. A remote access controller supporting remote management of an Information Handling System (IHS), the remote access controller comprising a memory device having instructions stored thereon that, upon execution by a logic unit, cause the remote access controller to:

detect a proposed configuration of a first of the hardware components of the IHS;

access two or more catalogs specifying known vulnerabilities of hardware components, wherein a first of the catalogs comprises known vulnerabilities provided by a manufacturer of the first hardware component, wherein a second of the catalogs comprises known vulnerabilities provided by a manufacturer of the IHS;

determine whether the proposed configuration of the first hardware component is identified as vulnerable in the first catalog;

determine whether the proposed configuration of the first hardware component is identified as vulnerable in the second catalog; and

disable the first hardware component until the proposed configurations for the first hardware component are changed to include no configurations with vulnerabilities identified in the first catalog or in the second catalog.

17. The remote access controller of claim 16 , wherein the proposed configuration further comprises a configuration of a second of the hardware components of the IHS and further comprises a configuration of a workload using the first hardware component and the second hardware component.

18. The remote access controller of claim 17 , determine whether the proposed configuration of the second hardware component is identified as vulnerable in a third catalog provided by a manufacture of the second hardware component.

19. The remote access controller of claim 18 , wherein execution of the instructions further causes the remote access controller to:

halt the workload using the first hardware component and the second hardware component until the proposed configurations for the second hardware component are changed to include no configurations with vulnerabilities identified in the third catalog.

20. The remote access controller of claim 16 , wherein execution of the instructions further causes the remote access controller to:

identify one or more vulnerability proofing requirements for the IHS within a factory provisioned identity certificate of the IHS.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2022
From: MADALA, RAVEENDRA BABU; GORE, SANTOSH
To: DELL PRODUCTS, L.P.
Reel/Frame 061495/0178 →
Continuity (2)
Related Publication 20240135002A1 · Apr 25, 2024
Related Publication 20240232379A9 · Jul 11, 2024
References Cited (45)
US 9064134B1 · Agarwal · 2015 [cited by examiner]
US 10084809B1 · Rambo · 2018 [cited by examiner]
US 10140453B1 · Fridakis · 2018 [cited by examiner]
US 10469517B1 · Higbee · 2019 [cited by examiner]
US 10534918B1 · Davidi · 2020 [cited by examiner]
US 10754959B1 · Rajasooriya · 2020 [cited by examiner]
US 11070582B1 · Berger · 2021 [cited by examiner]
US 11153074B1 · Nikitas · 2021 [cited by examiner]
US 11271961B1 · Berger · 2022 [cited by examiner]
US 11374958B2 · Ngo · 2022 [cited by examiner]
US 11681811B1 · Dixit · 2023 [cited by examiner]
US 20070067848A1 · Gustave · 2007 [cited by examiner]
US 20080163374A1 · Rogers · 2008 [cited by examiner]
US 20080189788A1 · Bahl · 2008 [cited by examiner]
US 20130167238A1 · Russell · 2013 [cited by examiner]
US 20130239168A1 · Sreenivas · 2013 [cited by examiner]
US 20140331326A1 · Thakur · 2014 [cited by examiner]
US 20170078322A1 · Seiver · 2017 [cited by examiner]
US 20170286689A1 · Kelley · 2017 [cited by examiner]
US 20180004953A1 · Smith, II · 2018 [cited by examiner]
US 20180219908A1 · Tamir · 2018 [cited by examiner]
US 20180351987A1 · Patel · 2018 [cited by examiner]
US 20190034256A1 · Fox · 2019 [cited by examiner]
US 20190166149A1 · Gerrick · 2019 [cited by examiner]
US 20190238584A1 · Somasundaram · 2019 [cited by examiner]
US 20190245879A1 · Ward · 2019 [cited by examiner]
US 20200050769A1 · Bhosale · 2020 [cited by examiner]
US 20200162497A1 · Iyer · 2020 [cited by examiner]
US 20200183677A1 · Hong · 2020 [cited by examiner]
US 20200202005A1 · Wurster · 2020 [cited by examiner]
US 20200228560A1 · Murthy · 2020 [cited by examiner]
US 20200272743A1 · Song · 2020 [cited by examiner]
US 20200311630A1 · Risoldi · 2020 [cited by examiner]
US 20200372156A1 · Sayyed · 2020 [cited by examiner]
US 20210120028A1 · Pluderman · 2021 [cited by examiner]
US 20210141906A1 · Pickren · 2021 [cited by examiner]
US 20210336992A1 · Shivanna · 2021 [cited by examiner]
US 20210409438A1 · Sundaram · 2021 [cited by examiner]
US 20220237301A1 · Godowski · 2022 [cited by examiner]
US 20220245260A1 · Priller · 2022 [cited by examiner]
US 20230019180A1 · de Nijs · 2023 [cited by examiner]
US 20230061121A1 · Tosevska · 2023 [cited by examiner]
US 20230259633A1 · Oddo · 2023 [cited by examiner]
US 20240028730A1 · Munger · 2024 [cited by examiner]
US 20240070290A1 · Koike · 2024 [cited by examiner]