IP Library › Granted Patent US 12,598,081
Granted Patent B2
US 12,598,081 · App. 18/785,397 · Granted Apr 7, 2026

Data processing system peripheral device management using component certificates

Inventors: Guru Prasad Yadav Naruboina (Bangalore, IN); Kalyani Korubilli (Bangalore, IN)
Assignee: Dell Products L.P.
H04L9/3263G06F11/3051
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,081
App. No.
18/785,397
Granted
Apr 7, 2026
Kind
B2
Abstract

Methods and systems for managing a data processing system are disclosed. Digital certificates may be used by a management controller of a data processing system to enable and/or disable one or more functions of peripheral devices hosted by the data processing system. The functions may include a Reliability, Availability, and Serviceability (RAS) reporting function of the peripheral devices. The management controller may be a microcontroller installed within the data processing system that operates independently of a central processing unit (CPU) of the data processing system. A data processing system manager of the data processing system may authenticate and sign the digital certificates.

Claims (35)

1 . A method for managing a data processing system, the method comprising:

obtaining, by a management controller of the data processing system, a signed delta certificate from a data processing system manager, the signed delta certificate specifying a peripheral device of the data processing system, wherein the signed delta certificate is obtained by the management controller while hardware resources of the data processing system are in a powered off state, and the hardware resources comprise a first processor of the data processing system that is separate from a second processor of the management controller; and

activating, by the management controller and based on the signed delta certificate, a previously disabled function of the peripheral device, the previously disabled function being specified as disabled in a default component certificate stored within the management controller prior to the data processing system being shipped to a user.

2 . The method of claim 1 , wherein the previously disabled function of the peripheral device is a Reliability, Availability, and Serviceability (RAS) reporting function of the peripheral device.

3 . The method of claim 2 , further comprising:

obtaining, by the management controller and after activating the previously disabled function of the peripheral device, peripheral device RAS data from the peripheral device; and

storing, by the management controller, the peripheral device RAS data in a storage of the management controller.

4 . The method of claim 3 , wherein the management controller is a microcontroller that is physically installed within the data processing system.

5 . The method of claim 3 , wherein the default component certificate and the signed delta certificate are stored in the storage of the management controller, the storage of the management controller being separate and independent from a main storage of the data processing system.

6 . The method of claim 1 , wherein the signed delta certificate is obtained in response to the user providing a peripheral device configuration request to the data processing system manager, the user being an authorized user for configuring functions of the peripheral device.

7 . The method of claim 1 , wherein the data processing system further comprises a single network module that is shared by both of the hardware resources and the management controller and that is adapted to separately advertise endpoints used by the data processing system manager to communicate respectively with each of the management controller and the hardware resources.

8 . The method of claim 7 , wherein the single network module separately advertises the endpoints for the management controller and the hardware resources such that:

first communications from the data processing system manager received via a first endpoint of the endpoints and meant for the hardware resources never flow through the management controller, and

second communications from the data processing system manager received via a second endpoint of the endpoints and meant for the management controller never flow through the hardware resources.

9 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing a data processing system, the operations comprising:

obtaining, by a management controller of the data processing system, a signed delta certificate from a data processing system manager, the signed delta certificate specifying a peripheral device of the data processing system, wherein the signed delta certificate is obtained by the management controller while hardware resources of the data processing system are in a powered off state, and the hardware resources comprise a first processor of the data processing system that is separate from a second processor of the management controller; and

activating, by the management controller and based on the signed delta certificate, a previously disabled function of the peripheral device, the previously disabled function being specified as disabled in a default component certificate stored within the management controller prior to the data processing system being shipped to a user.

10 . The non-transitory machine-readable medium of claim 9 , wherein the previously disabled function of the peripheral device is a Reliability, Availability, and Serviceability (RAS) reporting function of the peripheral device.

11 . The non-transitory machine-readable medium of claim 10 , wherein the operations further comprise:

obtaining, by the management controller and after activating the previously disabled function of the peripheral device, peripheral device RAS data from the peripheral device; and

storing, by the management controller, the peripheral device RAS data in a storage of the management controller.

12 . The non-transitory machine-readable medium of claim 11 , wherein the management controller is a microcontroller that is physically installed within the data processing system.

13 . The non-transitory machine-readable medium of claim 11 , wherein the default component certificate and the signed delta certificate are stored in the storage of the management controller, the storage of the management controller being separate and independent from a main storage of the data processing system.

14 . The non-transitory machine-readable medium of claim 9 , wherein the signed delta certificate is obtained in response to the user providing a peripheral device configuration request to the data processing system manager, the user being an authorized user for configuring functions of the peripheral device.

15 . A data processing system, comprising:

hardware resources comprising a first processor;

a management controller comprising a second processor that is separate from the first processor, wherein data processing system stores instructions that causes the management controller to perform operations for managing the data processing system, the operations comprising:

obtaining a signed delta certificate from a data processing system manager, the signed delta certificate specifying a peripheral device of the data processing system, wherein the signed delta certificate is obtained by the management controller while the hardware resources of the data processing system are in a powered off state; and p 2 activating, based on the signed delta certificate, a previously disabled function of the peripheral device, the previously disabled function being specified as disabled in a default component certificate stored within the management controller prior to the data processing system being shipped to a user.

16 . The data processing system of claim 15 , wherein the previously disabled function of the peripheral device is a Reliability, Availability, and Serviceability (RAS) reporting function of the peripheral device.

17 . The data processing system of claim 16 , wherein the operations further comprise:

obtaining, after activating the previously disabled function of the peripheral device, peripheral device RAS data from the peripheral device; and

storing the peripheral device RAS data in a storage of the management controller.

18 . The data processing system of claim 17 , wherein the management controller is a microcontroller that is physically installed within the data processing system.

19 . The data processing system of claim 17 , wherein the default component certificate and the signed delta certificate are stored in the storage of the management controller, the storage of the management controller being separate and independent from a main storage of the data processing system.

20 . The data processing system of claim 15 , wherein the signed delta certificate is obtained in response to the user providing a peripheral device configuration request to the data processing system manager, the user being an authorized user for configuring functions of the peripheral device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2024
From: NARUBOINA, GURU PRASAD YADAV; KORUBILLI, KALYANI
To: DELL PRODUCTS L.P.
Reel/Frame 068151/0087 →
Continuity (1)
Related Publication 20260032004A1 · Jan 29, 2026
References Cited (30)
US 5339404A · Vandling, III · 1994 [cited by applicant]
US 5740429A · Wang · 1998 [cited by examiner]
US 7418545B2 · Marushak · 2008 [cited by examiner]
US 7865775B2 · Yao · 2011 [cited by applicant]
US 7974286B2 · Keohane et al. · 2011 [cited by applicant]
US 10416988B1 · Kulchytskyy · 2019 [cited by applicant]
US 20020095611A1 · Jochiong · 2002 [cited by applicant]
US 20030182577A1 · Mocek · 2003 [cited by examiner]
US 20080059720A1 · Rothman · 2008 [cited by applicant]
US 20090132838A1 · Cherian · 2009 [cited by applicant]
US 20110119686A1 · Chen · 2011 [cited by examiner]
US 20140195684A1 · Taaghol · 2014 [cited by applicant]
US 20140258526A1 · Le Sant · 2014 [cited by examiner]
US 20150287273A1 · Panzarella · 2015 [cited by applicant]
US 20150304343A1 · Cabrera · 2015 [cited by examiner]
US 20150309559A1 · Jacobson · 2015 [cited by applicant]
US 20180011524A1 · Stumpf · 2018 [cited by applicant]
US 20200044868A1 · Vakulenko · 2020 [cited by examiner]
US 20200097379A1 · Truong · 2020 [cited by applicant]
US 20200218527A1 · Ganesan · 2020 [cited by applicant]
US 20200257517A1 · Seater · 2020 [cited by applicant]
US 20210042062A1 · Betusno · 2021 [cited by applicant]
US 20230008238A1 · Mugunda · 2023 [cited by applicant]
US 20230315485A1 · Paulraj · 2023 [cited by applicant]
US 20230376575A1 · Anzai · 2023 [cited by applicant]
US 20240054039A1 · Srinivasan · 2024 [cited by examiner]
Cycuity, “Detect and Prevent Security Vulnerabilities in your Hardware Root of Trust,” 2022. Web Page <https://cycuity.com/wp-content/uploads/2022/06/Cycuity_White-Paper_Detect-Security-Vulnerabilities-HRoT.pdf> accesse… [cited by applicant]
Elmaghbub, Abdurrahman, et al., “Domain-Agnostic Hardware Fingerprinting-Based Device Identifier for Zero-Trust IoT Security,” IEEE Wireless Communications 31.2 (2024) (7 Pages). [cited by applicant]
Rostami, Mohamadreza, et al. “Beyond random inputs: A novel ml-based hardware fuzzing.” 2024 Design, Automation & Test in Europe Conference & Exhibition. IEEE. (2024) (6 Pages). [cited by applicant]
Gaikwad, Pravin, et al. “Third-party hardware IP assurance against Trojans through supervised learning and post-processing.” arXiv preprint arXiv:2111.14956. IEEE. (2021) (13 Pages). [cited by applicant]