IP Library Granted Patent US 12,267,441
Granted Patent B2
US 12,267,441 · App. 18/046,595 · Granted Apr 1, 2025

System and method for securing operation of data processing systems during and after onboarding

Inventors: Bradley K. Goodman (Nashua, NH); Kirk Alan Hutchinson (Londonderry, NH); Joseph Caisse (Burlington, MA)
Assignee: Dell Products L.P.
H04L9/3265H04L9/0819H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,441
App. No.
18/046,595
Granted
Apr 1, 2025
Kind
B2
Abstract

Systems, devices, and methods for managing operation of data processing systems are disclosed. To manage operation of the data processing systems, onboarding processes may be performed to conform the operation of the data processing systems to meet the expectations of owners of the data processing systems. During onboarding, keys usable to verify subsequently issued commands may be obtained by the data processing systems. The data processing systems may perform verifications processes for issued commands that rely on a root of trust established with the keys rather than identifies of entities that may issue the commands for command verification.

Claims (55)

1. A method for managing operation of a data processing system, the method comprising:

obtaining, by the data processing system, a key with authority over the data processing system, the key being obtained from an ownership voucher received by the data processing system during a secure onboarding of the data processing system;

obtaining, by the data processing system and after completion of the secure onboarding, a command, the command specifying a change in operation of the data processing system, the command being allegedly signed by an entity with the authority over the data processing system;

making, by the data processing system, a determination regarding whether the command is verifiable using the key and a chain of certificates from the ownership voucher, the chain of certificates defining a chain of trust to a root of trust for the data processing system; and

in a first instance of the determination where the command is verifiable, executing, by the data processing system, the command to conform the operation of the data processing system to the change specified by the command.

2. The method of claim 1 , further comprising:

in a second instance of the determination where the command is not verifiable, delaying, by the data processing system, processing of the command.

3. The method of claim 2 , wherein executing command comprises an operation from a group of operations consisting of:

modifying a configuration of the data processing system;

modifying a security policy of the data processing system;

modifying a personalization settings of the data processing system; and

modifying ownership of the data processing system.

4. The method of claim 1 , wherein the key is a public key from a public key pair of a second entity to which authority over the data processing system is delegated.

5. The method of claim 4 , wherein the chain of certificates specifies changes in authority over the data processing system as the data processing system traversed through a channel of commerce.

6. The method of claim 4 , wherein the second entity is an owner of the data processing system, the secure onboarding conforms the operation of the data processing system to at least one policy specified by the owner, and information regarding the policy being conveyed via a certificate of the ownership voucher.

7. The method of claim 1 , further comprising:

obtaining, by the data processing system and after completion of the secure onboarding, a second command, the second command specifying inclusion of a new certificate with the chain of certificates.

8. The method of claim 7 , further comprising:

verifying, using the key, that the second command is valid;

adding the new certificate to a certificate repository.

9. The method of claim 8 , wherein the new certificate specifies a new key as having authority over the data processing system.

10. The method of claim 9 , further comprising:

obtaining, by the data processing system and after adding the new certificate to the certificate repository, a third command;

making a second determination, using the new key, that the third command is not verifiable; and

based on the second determination, delaying processing of the third command until it is verifiable.

11. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing operation of a data processing system, the operations comprising:

obtaining, by the data processing system, a key with authority over the data processing system, the key being obtained from an ownership voucher received by the data processing system during a secure onboarding of the data processing system;

obtaining, by the data processing system and after completion of the secure onboarding, a command, the command specifying a change in operation of the data processing system, the command being allegedly signed by an entity with the authority over the data processing system;

making, by the data processing system, a determination regarding whether the command is verifiable using the key and a chain of certificates from the ownership voucher, the chain of certificates defining a chain of trust to a root of trust for the data processing system; and

in a first instance of the determination where the command is verifiable, executing, by the data processing system, the command to conform the operation of the data processing system to the change specified by the command.

12. The non-transitory machine-readable medium of claim 11 , wherein the operations further comprise:

in a second instance of the determination where the command is not verifiable, delaying, by the data processing system, processing of the command.

13. The non-transitory machine-readable medium of claim 12 , wherein executing command comprises an operation from a group of operations consisting of:

modifying a configuration of the data processing system;

modifying a security policy of the data processing system;

modifying a personalization settings of the data processing system; and

modifying ownership of the data processing system.

14. The non-transitory machine-readable medium of claim 11 , wherein the key is a public key from a public key pair of a second entity to which authority over the data processing system is delegated.

15. The non-transitory machine-readable medium of claim 14 , wherein the chain of certificates specifies changes in authority over the data processing system as the data processing system traversed through a channel of commerce.

16. A data processing system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing operation of the data processing system, the operations comprising:

obtaining a key with authority over the data processing system, the key being obtained from an ownership voucher received by the data processing system during a secure onboarding of the data processing system;

obtaining, after completion of the secure onboarding, a command, the command specifying a change in operation of the data processing system, the command being allegedly signed by an entity with the authority over the data processing system;

making a determination regarding whether the command is verifiable using the key and a chain of certificates from the ownership voucher, the chain of certificates defining a chain of trust to a root of trust for the data processing system; and

in a first instance of the determination where the command is verifiable, executing the command to conform the operation of the data processing system to the change specified by the command.

17. The data processing system of claim 16 , wherein the operations further comprise:

in a second instance of the determination where the command is not verifiable, delaying, processing of the command.

18. The data processing system of claim 17 , wherein executing command comprises an operation from a group of operations consisting of:

modifying a configuration of the data processing system;

modifying a security policy of the data processing system;

modifying a personalization settings of the data processing system; and

modifying ownership of the data processing system.

19. The data processing system of claim 16 , wherein the key is a public key from a public key pair of a second entity to which authority over the data processing system is delegated.

20. The data processing system of claim 19 , wherein the chain of certificates specifies changes in authority over the data processing system as the data processing system traversed through a channel of commerce.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2022
From: GOODMAN, BRADLEY K.; HUTCHINSON, KIRK ALAN; CAISSE, JOSEPH
To: DELL PRODUCTS L.P.
Reel/Frame 061444/0729 →
Continuity (1)
Related Publication 20240129134A1 · Apr 18, 2024
References Cited (18)
US 11552803B1 · Simkhada · 2023 [cited by examiner]
US 20040193917A1 · Drews · 2004 [cited by examiner]
US 20060236111A1 · Bodensjo · 2006 [cited by applicant]
US 20140298040A1 · Ignatchenko · 2014 [cited by examiner]
US 20190384916A1 · Shah · 2019 [cited by applicant]
US 20200327231A1 · Smith · 2020 [cited by applicant]
US 20210409231A1 · Fedorkow · 2021 [cited by examiner]
US 20220303123A1 · Cabre · 2022 [cited by examiner]
US 20230034615A1 · Detienne · 2023 [cited by examiner]
US 20230367489A1 · Dover · 2023 [cited by examiner]
US 20230370454A1 · Mohammed · 2023 [cited by examiner]
US 20230394493A1 · Rao · 2023 [cited by examiner]
US 20240039723A1 · Ito · 2024 [cited by examiner]
US 20240064028A1 · Fedorkow · 2024 [cited by examiner]
K. Watsen et al. “A Voucher Artifact for Bootstrapping Protocols”, May 2018, Internet Engineering Task Force (IETF) Request for Comments: 8366 (Year: 2018). [cited by examiner]
“Detailed Protocol Description—Secure Device Onboard”, Apr. 28, 2021, obtained online from <https://secure-device-onboard.github.io/docs/1.8.0/protocol-specification/detailed-protocol-description/>, retrieved on Jul. 13… [cited by examiner]
“Secure Device Onboard”, 2020, obtained online from <https://secure-device-onboard.github.io/docs/1.9.0/>, retrieved on Oct. 11, 2024 (Year: 2020). [cited by examiner]
G. Cooper et al., “FIDO Device Onboard Specification 1.1”, Apr. 19, 2022, obtained online from <https://fidoalliance.org/specs/FDO/FIDO-Device-Onboard-PS-v1.1-20220419/FIDO-Device-Onboard-PS-v1.1-20220419.pdf>, retrieve… [cited by examiner]