IP Library › Granted Patent US 12,585,776
Granted Patent B2
US 12,585,776 · App. 18/492,127 · Granted Mar 24, 2026

Information processing system and BIOS update method

Inventors: Yusaku Morishige (Kanagawa, JP); Ken Sasaki (Kanagawa, JP); Kazuya Shibayama (Kanagawa, JP); Naoyuki Araki (Kanagawa, JP)
Assignee: Lenovo (Singapore) Pte. Ltd.
G06F21/572G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,776
App. No.
18/492,127
Granted
Mar 24, 2026
Kind
B2
Abstract

An information processing system includes a server that assigns a signature of a server manager to a capsule file encapsulating a program of an extended function of a BIOS and provides the capsule file to an information processing apparatus. The information processing apparatus includes a BIOS storage and a BIOS processor that extracts the program from the capsule file to store the program in the BIOS storage in a case in which validity of the capsule file acquired from the server is confirmed based on the signature, permits execution of the program in a case in which validity of the program is confirmed based on a signature certificate of a user and a signature of the user, and prohibits execution of the program in a case in which the validity of the program is not confirmed.

Claims (29)

1 . An information processing system comprising:

a server that encapsulates a program of an extended function of a basic input output system (BIOS) to which a signature of a user is assigned, assigns a signature of a server manager to an encapsulated capsule file, and provides the encapsulated capsule file to an information processing apparatus;

wherein the information processing apparatus includes:

a BIOS storage that stores a program of the BIOS, and

a BIOS processor that extracts the program of the extended function from the encapsulated capsule file to store the program of the extended function in the BIOS storage in a case in which validity of the encapsulated capsule file acquired from the server is confirmed based on the signature of the server manager, permits execution of the program of the extended function in a case in which validity of the program of the extended function is confirmed based on a signature certificate of the user and the signature of the user, and prohibits execution of the program of the extended function in a case in which the validity of the program of the extended function is not confirmed,

wherein the BIOS storage includes

a BIOS memory that is a rewritable non-volatile memory, which is not connectable from an operating system (OS) without going through the BIOS, and stores at least a boot program required to start up the OS and management information of the extended function, and

a BIOS area that is a partial area of a solid state drive (SSD) and is not connectable from the OS without going through the BIOS, and

in a case in which the validity of the encapsulated capsule file is confirmed, the BIOS processor extracts the program of the extended function from the encapsulated capsule file to store the program of the extended function in the BIOS area.

2 . The information processing system according to claim 1 ,

wherein, in a case in which the management information of the extended function is stored in the BIOS memory and the program of the extended function is not stored in the BIOS area when the BIOS is started up, the BIOS processor reacquires the encapsulated capsule file corresponding to the program of the extended function from the server.

3 . The information processing system according to claim 1 ,

wherein, in a case in which the signature certificate of the user is not stored in the BIOS memory, the BIOS processor prohibits execution of the program of the extended function.

4 . The information processing system according to claim 1 ,

wherein the server includes:

an update file storage that stores the encapsulated capsule file to which the signature of the server manager is assigned, and

a distribution processor that transmits, in response to a distribution request for the encapsulated capsule file, the encapsulated capsule file corresponding to the distribution request to the information processing apparatus.

5 . The information processing system according to claim 1 ,

wherein, in a case in which the validity of the encapsulated capsule file is confirmed when the information processing apparatus is restarted up after storing the encapsulated capsule file acquired from the server in an area different from the BIOS area of the SSD, the BIOS processor extracts the program of the extended function from the encapsulated capsule file, and stores the program of the extended function in the BIOS area.

6 . A basic input output system (BIOS) update method of updating a BIOS of an information processing apparatus including a BIOS storage that stores a program of the BIOS, the BIOS update method comprising:

a distribution step of, via a server, encapsulating a program of an extended function of the BIOS to which a signature of a user is assigned, assigning a signature of a server manager to an encapsulated capsule file, and providing the encapsulated capsule file to the information processing apparatus; and

a BIOS processing step of, via the information processing apparatus,

extracting the program of the extended function from the encapsulated capsule file to store the program of the extended function in the BIOS storage in a first case in which validity of the encapsulated capsule file acquired from the server is confirmed based on the signature of the server manager,

permitting execution of the program of the extended function in a case in which validity of the program of the extended function is confirmed based on a signature certificate of the user and the signature of the user, and

prohibiting execution of the program of the extended function in a second case in which the validity of the program of the extended function is not confirmed,

wherein the BIOS storage includes

a BIOS memory that is a rewritable non-volatile memory, which is not connectable from an operating system (OS) without going through the BIOS, and stores at least a boot program required to start up the OS and management information of the extended function, and

a BIOS area that is a partial area of a solid state drive (SSD) and is not connectable from the OS without going through the BIOS, and

in a case in which the validity of the encapsulated capsule file is confirmed, the program of the extended function is extracted from the encapsulated capsule file to store the program of the extended function in the BIOS area.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2023
From: MORISHIGE, YUSAKU; SASAKI, KEN; SHIBAYAMA, KAZUYA; ARAKI, NAOYUKI
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 065521/0048 →
Priority Claims (1)
JP 2022-183191 · Nov 16, 2022 · national
Continuity (1)
Related Publication 20240160740A1 · May 16, 2024
References Cited (14)
US 9930051B1 · Potlapally et al. · 2018 [cited by applicant]
US 11681809B2 · Ishikawa · 2023 [cited by examiner]
US 20040186998A1 · Kim · 2004 [cited by examiner]
US 20180129809A1 · Zhang et al. · 2018 [cited by applicant]
US 20190325138A1 · Ishikawa · 2019 [cited by examiner]
US 20230168901A1 · Hung · 2023 [cited by examiner]
US 20230385419A1 · Gowda · 2023 [cited by examiner]
US 20230394154A1 · Gowda · 2023 [cited by examiner]
JP 2001222421A · 2001 [cited by applicant]
JP 2017072897A · 2017 [cited by applicant]
JP 2022084319A · 2022 [cited by applicant]
Extended European Search Report issued in European Application No. 23200959.7, dated Apr. 2, 2024 (6 pages). [cited by applicant]
Wikipedia. “Unified Extensible Firmware Interface”, Oct. 20, 2017, XP055585891, (21 pages). [cited by applicant]
Retrieved from the Internet. “Signing UEFI Applications and Drivers for UEFI Secure Boot”, Nov. 1, 2012, XP055125999, (47 pages). [cited by applicant]