IP Library › Granted Patent US 12,265,632
Granted Patent B2
US 12,265,632 · App. 18/177,156 · Granted Apr 1, 2025

Systems and methods for key distribution of low end SPDM devices

Inventors: Mini Thottunkal Thankappan (Bangalore, IN); Shinose Abdul Rahiman (Bangalore, IN); Rama Rao Bisa (Bangalore, IN); Dharma Bhushan Ramaiah (Bangalore, IN); Vineeth Radhakrishnan (Palakkad, IN)
Assignee: Dell Products, L.P.
G06F21/602G06F21/33G06F21/85
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,265,632
App. No.
18/177,156
Granted
Apr 1, 2025
Kind
B2
Abstract

According to embodiments of the present disclosure, a dynamic key distribution system is provided. The dynamic key distribution includes computer-executable instructions to encrypt, using a first Security Protocol and Data Model (SPDM)-enabled device conforming to a SPDM specification, an original Pre-Shared Key (PSK) with a SPDM identity certificate of the first SPDM-enabled device, wherein the original PSK is associated with a second SPDM-enabled device. The instructions are also configured to provision the encrypted PSK in the second SPDM-enabled device, and authenticate the second SPDM-enabled device by decrypting the encrypted PSK to obtain the original PSK using an SPDM protocol.

Claims (31)

1. An Information Handling System (IHS) comprising:

a first Security Protocol and Data Model (SPDM)-enabled device conforming to a SPDM specification; and

at least one memory coupled to at least one processor, the at least one memory having program instructions stored thereon that, upon execution by the at least one processor, cause the IHS to:

encrypt an original Pre-Shared Key (PSK) with a SPDM identity certificate of the first SPDM-enabled device, wherein the original PSK is associated with a second SPDM-enabled device;

provision the encrypted PSK in the second SPDM-enabled device; and

authenticate, using an SPDM protocol, the second SPDM-enabled device by decrypting the encrypted PSK to obtain the original PSK.

2. The IHS of claim 1 , wherein the PSK is distributed out-of-band relative to how the second SPDM-enabled device is distributed to the IHS.

3. The IHS of claim 2 , wherein the PSK is distributed via an e-mail message.

4. The IHS of claim 2 , wherein the act of encrypting the PSK, provisioning the encrypted PSK, and authenticating the second SPDM-enabled device is performed by a provider of the IHS.

5. The IHS of claim 1 , wherein the SPDM identity certificate comprises a public identity key of the first SPDM-enabled device.

6. The IHS of claim 1 , wherein the act of encrypting the PSK and provisioning the encrypted PSK is performed by a vendor of the second SPDM-enabled device, and the act of authenticating the second SPDM-enabled device is performed by a provider of the IHS.

7. The IHS of claim 6 , wherein the act of encrypting the PSK is performed using the SPDM identity certificate received from a user of the IHS.

8. The IHS of claim 1 , wherein the first SPDM-enabled device comprises a Baseboard Management Controller (BMC) configured in the IHS, and the second SPDM-enabled device comprises a component of the IHS.

9. A dynamic key distribution method comprising:

encrypting, using a first Security Protocol and Data Model (SPDM)-enabled device conforming to a SPDM specification, an original Pre-Shared Key (PSK) with a SPDM identity certificate of the first SPDM-enabled device, wherein the original PSK is associated with a second SPDM-enabled device;

provisioning, using the first SPDM-enabled device, the encrypted PSK in the second SPDM-enabled device; and

authenticating, using the first SPDM-enabled device, the second SPDM-enabled device by decrypting the encrypted PSK to obtain the original PSK using a SPDM protocol.

10. The dynamic key distribution method of claim 9 , further comprising distributing the PSK out-of-band relative to how the second SPDM-enabled device is distributed to an Information Handling System (HIS).

11. The dynamic key distribution method of claim 10 , further comprising distributing the PSK via an e-mail message.

12. The dynamic key distribution method of claim 10 , further comprising encrypting the PSK, provisioning the encrypted PSK, and authenticating the second SPDM-enabled device by a provider of the IHS.

13. The dynamic key distribution method of claim 9 , further comprising encrypting the PSK and provisioning the encrypted PSK by a vendor of the second SPDM-enabled device, and authenticating the second SPDM-enabled device by a provider of the IHS.

14. The dynamic key distribution method of claim 13 , further comprising encrypting the PSK using the SPDM identity certificate received from a user of the IHS.

15. A computer program product comprising a computer readable storage medium having program instructions stored thereon that, upon execution by an Information Handling System (IHS), cause the IHS to:

encrypt, using a first Security Protocol and Data Model (SPDM)-enabled device conforming to a SPDM specification, an original Pre-Shared Key (PSK) with a SPDM identity certificate of the first SPDM-enabled device, wherein the original PSK is associated with a second SPDM-enabled device;

provision, using the first SPDM-enabled device, the encrypted PSK in the second SPDM-enabled device; and

authenticate, using the first SPDM-enabled device, the second SPDM-enabled device by decrypting the encrypted PSK to obtain the original PSK using an SPDM protocol.

16. The computer program product of claim 15 , wherein the act of encrypting the PSK, provisioning the encrypted PSK, and authenticating the second SPDM-enabled device is performed by a provider of the IHS.

17. The computer program product of claim 15 , wherein the SPDM identity certificate comprises a public identity key of the first SPDM-enabled device.

18. The computer program product of claim 15 , wherein the act of encrypting the PSK and provisioning the encrypted PSK is performed by a vendor of the second SPDM-enabled device, and the act of authenticating the second SPDM-enabled device is performed by a provider of the IHS.

19. The computer program product of claim 18 , wherein the act of encrypting the PSK is performed using the SPDM identity certificate received from a user of the IHS.

20. The computer program product of claim 15 , wherein the first SPDM-enabled device comprises a Baseboard Management Controller (BMC) configured in the IHS, and the second SPDM-enabled device comprises a component of the IHS.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2023
From: THANKAPPAN, MINI THOTTUNKAL; RAHIMAN, SHINOSE ABDUL; BISA, RAMA RAO; RAMAIAH, DHARMA BHUSHAN; RADHAKRISHNAN, VINEETH
To: DELL PRODUCTS, L.P.
Reel/Frame 062849/0988 →
Continuity (1)
Related Publication 20240296234A1 · Sep 5, 2024
References Cited (14)
US 10949540B2 · Andrews · 2021 [cited by examiner]
US 20170243021A1 · Gupta · 2017 [cited by examiner]
US 20180075242A1 · Khatri · 2018 [cited by examiner]
US 20190332421A1 · Kozlowski · 2019 [cited by examiner]
US 20200259805A1 · Grobelny · 2020 [cited by examiner]
US 20210367974A1 · Ponnuru · 2021 [cited by examiner]
US 20220207186A1 · Young · 2022 [cited by examiner]
US 20220292203A1 · Severns-Williams · 2022 [cited by examiner]
US 20240281538A1 · Radhakrishnan · 2024 [cited by examiner]
US 20240291636A1 · Rahiman · 2024 [cited by examiner]
US 20240296234A1 · Thankappan · 2024 [cited by examiner]
US 20240296255A1 · Paulraj · 2024 [cited by examiner]
“All Published Versions of dsp0274”, 2 pages, copyright: 2024. (Year: 2024). [cited by examiner]
“Security Protocol and Data Model (SPDM) Specification”, Version: 1.0.1, 61 pages, Dated: Mar. 19, 2021. (Year: 2021). [cited by examiner]
Cited By (1)
US 12,489,641