IP Library › Granted Patent US 12,506,788
Granted Patent B2
US 12,506,788 · App. 18/543,102 · Granted Dec 23, 2025

Telemetry-initiated mitigations in a zero-trust computing environment

Inventors: Balasingh P. Samuel (Round Rock, TX); Srikanth Kondapi (Austin, TX)
Assignee: Dell Products, L.P.
H04L63/20G06F21/575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,788
App. No.
18/543,102
Granted
Dec 23, 2025
Kind
B2
Abstract

Information Handling Systems (IHSs) support pre-boot telemetry for use in a zero-trust environment. A pre-boot telemetry orchestrator of the IHS retrieves a factory-provisioned resource locator of a service that provides a location of a policy decision point of the zero-trust environment. The pre-boot telemetry orchestrator establishes an encrypted session with the policy decision point that is located using the factory-provisioned resource locator. Via the encrypted session, the pre-boot telemetry orchestrator receives a telemetry definition specifying pre-boot telemetry to be collected by the IHS. The telemetry is collected and transmitted during the pre-boot intervals according to the telemetry definition.

Claims (35)

1 . An Information Handling System (IHS) supporting pre-boot telemetry for use in a zero-trust environment, the IHS comprising:

one or more processors;

a memory coupled to the processors, the memory storing program instructions that, upon execution by the processors, cause a pre-boot telemetry orchestrator to:

retrieve a factory-provisioned resource locator of a service that provides a location of a policy decision point of the zero-trust environment;

establish an encrypted session with the policy decision point that is located using the factory-provisioned resource locator;

via the encrypted session, receive a telemetry definition specifying pre-boot telemetry to be collected by the IHS; and

collect and transmit telemetry during the pre-boot intervals according to the telemetry definition.

2 . The IHS of claim 1 , wherein the resource locator comprises a network address of a rendezvous server that provides the location of the policy decision point.

3 . The IHS of claim 1 , wherein the telemetry definition specifies a boot mode for the IHS.

4 . The IHS of claim 3 , wherein the boot mode comprises a protected boot mode that only initializes hardware components validated as operating using factory-installed firmware.

5 . The IHS of claim 3 , wherein the boot mode comprises a network boot mode that boots the IHS from a network address specified in the telemetry definition.

6 . The IHS of claim 3 , wherein the boot mode comprises a protected boot mode that initializes hardware components based on their position in a trust chain of the IHS.

7 . The IHS of claim 1 , wherein the processor and memory of the IHS that operate the telemetry orchestrator are components of a remote access controller of the IHS that supports a plurality of sideband management connections with hardware components of the IHS.

8 . The IHS of claim 7 , wherein the sideband management connections of the remote access controller are used to collect telemetry during pre-boot intervals.

9 . The IHS of claim 1 , wherein the telemetry definition specifies hardware components of the IHS from which to collect pre-boot telemetry.

10 . The IHS of claim 1 , wherein the pre-boot telemetry is collected and transmitted without booting an operating system of the IHS.

11 . A method for pre-boot telemetry collection by an Information Handling System (IHS), the method comprising:

retrieving a resource locator from a factory-provisioned storage of the IHS, wherein the resource locator identifies a service that provides the location of a policy decision point of the zero-trust environment;

retrieving a factory-provisioned resource locator of a service that provides a location of a policy decision point of the zero-trust environment;

establishing an encrypted session with the policy decision point that is located using the factory-provisioned resource locator;

via the encrypted session, receiving a telemetry definition specifying pre-boot telemetry to be collected by the IHS; and

collecting and transmitting telemetry during the pre-boot intervals according to the telemetry definition.

12 . The method of claim 11 , wherein the telemetry definition specifies hardware components of the IHS from which to collect pre-boot telemetry.

13 . The method of claim 11 , wherein the pre-boot telemetry is collected and transmitted without booting an operating system of the IHS.

14 . The method of claim 11 , wherein the resource locator comprises a network address of a rendezvous server that provides the location of the policy decision point.

15 . The method of claim 11 , wherein the telemetry definition specifies a boot mode for the IHS.

16 . A computer-readable storage device having instructions stored thereon for pre-boot telemetry collection by an IHS (Information Handling System), wherein execution of the instructions by one or more processors causes the one or more processors to:

retrieve a factory-provisioned resource locator of a service that provides a location of a policy decision point of the zero-trust environment;

establish an encrypted session with the policy decision point that is located using the factory-provisioned resource locator;

via the encrypted session, receive a telemetry definition specifying pre-boot telemetry to be collected by the IHS; and

collect and transmit telemetry during the pre-boot intervals according to the telemetry definition.

17 . The computer-readable storage device of claim 16 , wherein the telemetry definition specifies hardware components of the IHS from which to collect pre-boot telemetry.

18 . The computer-readable storage device of claim 16 , wherein the pre-boot telemetry is collected and transmitted without booting an operating system of the IHS.

19 . The computer-readable storage device of claim 16 , wherein the resource locator comprises a network address of a rendezvous server that provides the location of the policy decision point.

20 . The computer-readable storage device of claim 16 , wherein the telemetry definition specifies a boot mode for the IHS.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2023
From: SAMUEL, BALASINGH P.; KONDAPI, SRIKANTH
To: DELL PRODUCTS, L.P.
Reel/Frame 065895/0567 →
Continuity (1)
Related Publication 20250202947A1 · Jun 19, 2025
References Cited (22)
US 11334419B1 · Suryanarayana · 2022 [cited by examiner]
US 20170344429A1 · Boyapalle · 2017 [cited by examiner]
US 20220012339A1 · Martinez · 2022 [cited by examiner]
US 20220107997A1 · Sethi · 2022 [cited by examiner]
US 20220191247A1 · Dhoble · 2022 [cited by examiner]
US 20250045414A1 · Gaikwad · 2025 [cited by examiner]
US 20250045415A1 · Gaikwad · 2025 [cited by examiner]
US 20250047676A1 · Gaikwad · 2025 [cited by examiner]
US 20250047679A1 · Gaikwad · 2025 [cited by examiner]
US 20250047710A1 · Gaikwad · 2025 [cited by examiner]
US 20250200184A1 · Kondapi · 2025 [cited by examiner]
US 20250202895A1 · Robison · 2025 [cited by examiner]
US 20250202904A1 · Kondapi · 2025 [cited by examiner]
US 20250202909A1 · Kondapi · 2025 [cited by examiner]
US 20250202910A1 · Kondapi · 2025 [cited by examiner]
US 20250202941A1 · Robison · 2025 [cited by examiner]
US 20250202942A1 · Kondapi · 2025 [cited by examiner]
US 20250202945A1 · Samuel · 2025 [cited by examiner]
US 20250202946A1 · Kondapi · 2025 [cited by examiner]
US 20250202947A1 · Samuel · 2025 [cited by examiner]
US 20250202948A1 · Tan · 2025 [cited by examiner]
US 20250202953A1 · Kondapi · 2025 [cited by examiner]