IP Library Granted Patent US 12,608,481
Granted Patent B2
US 12,608,481 · App. 18/618,346 · Granted Apr 21, 2026

Offloading secure boot during startups of data processing systems

Inventors: Ankit Singh (Bangalore, IN); Shrikant U. Hallur (Bangalore, IN); Naveen Awasthy (Bangalore, IN)
Assignee: Dell Products L.P.
G06F21/575G06F9/4401G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,608,481
App. No.
18/618,346
Granted
Apr 21, 2026
Kind
B2
Abstract

Methods and systems for managing operation of a data processing system are disclosed. The data processing system may be managed during a startup process for the data processing system. The startup process may use startup data to enable functionality of hardware resources of the data processing system. During the startup process, the startup data may be validated by a management controller of the data processing system operating independently from the hardware resources. The management controller may report a validation state for the startup data to the hardware resources, and the hardware resources may use the validation state to guide completion of the startup process.

Claims (63)

1 . A method for managing operation of a data processing system, the method comprising:

making an identification that a startup process for the data processing system is being performed, the startup process using startup data to enable functionality of hardware resources of the data processing system; and

based on the identification:

obtaining, by a management controller of the data processing system, secure boot data usable to validate the startup data,

performing, by the management controller, a validation of the startup data using at least a portion of the secure boot data to identify a validation state of a portion of the startup data, wherein the validation state indicates whether the startup data comprises a first predetermined amount of trusted startup data for completing one or more types of the startup process, the first predetermined amount being based on a predetermined list of trusted startup data,

reporting, by the management controller, the validation state to the hardware resources, and

using, by the hardware resources, the validation state to guide completion of the startup process that places the data processing system in a predetermined operating state,

wherein when the validation state indicates that the startup data comprises a first instance of the first predetermined amount of the trusted startup data required for completing a remedial startup process but not for completing a nominal startup process, then using, by the hardware resources, the validation state to guide the completion of the startup process comprises:

completing the remedial startup process for the data processing system.

2 . The method of claim 1 , wherein the secure boot data comprises data usable to establish trust in the startup data in order to determine an amount of the trusted startup data contained in the startup data, and the data usable to establish trust comprises reduced-size representations of portions of the startup data.

3 . The method of claim 1 , wherein performing the validation of the startup data comprises:

obtaining, by the management controller, a reduced-size representation of the portion of the startup data;

making a comparison between the reduced-size representation and the portion of the secure boot data to obtain a difference; and

identifying the validation state based on the difference.

4 . The method of claim 1 , wherein the validation of the portion of the startup data is performed in parallel with validations, by the management controller, of other portions of the startup data.

5 . The method of claim 1 , wherein when the validation state indicates the startup data comprises a second predetermined amount of the trusted startup different from the first predetermined amount, then using, by the hardware resources, the validation state to guide the completion of the startup process comprises:

aborting the startup process to place the data processing system in a secure operating state, the second predetermined amount also being based on the predetermined list of trusted startup data.

6 . The method of claim 1 , wherein when the validation state indicates the startup data comprises a second instance of the first predetermined amount of the trusted startup data required for completing the nominal startup process, then using, by the hardware resources, the validation state to guide the completion of the startup process comprises:

completing the nominal startup process for the data processing system, the second instance being an amount different from the first instance.

7 . The method of claim 5 , wherein the nominal startup process places the data processing system in a first operating state that allows for computer-implemented services to be provided, and the remedial startup process places the data processing system in a second operating state that allows for partial provisioning of the computer-implemented services, and the secure operating state deprives the data processing system of providing the computer-implemented services.

8 . The method of claim 1 , wherein obtaining the secure boot data comprises:

reading, by a startup management entity hosted by the hardware resources and from a secure storage of the hardware resources, the secure boot data; and

providing, by the startup management entity and via a sideband channel, the secure boot data to the management controller.

9 . The method of claim 8 , wherein the secure storage comprises a serial peripheral interface storage device.

10 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing operation of a data processing system, the operations comprising:

making an identification that a startup process for the data processing system is being performed, the startup process using startup data to enable functionality of hardware resources of the data processing system; and

based on the identification:

obtaining, by a management controller of the data processing system, secure boot data usable to validate the startup data,

performing, by the management controller, a validation of the startup data using at least a portion of the secure boot data to identify a validation state of a portion of the startup data, wherein the validation state indicates whether the startup data comprises a first predetermined amount of trusted startup data for completing one or more types of the startup process, the first predetermined amount being based on a predetermined list of trusted startup data,

reporting, by the management controller, the validation state to the hardware resources, and

using, by the hardware resources, the validation state to guide completion of the startup process that places the data processing system in a predetermined operating state,

wherein when the validation state indicates that the startup data comprises a first instance of the first predetermined amount of the trusted startup data required for completing a remedial startup process but not for completing a nominal startup process, then using, by the hardware resources, the validation state to guide the completion of the startup process comprises:

completing the remedial startup process for the data processing system.

11 . The non-transitory machine-readable medium of claim 10 , wherein the secure boot data comprises data usable to establish trust in the startup data in order to determine an amount of the trusted startup data contained in the startup data, and the data usable to establish trust comprises reduced-size representations of portions of the startup data.

12 . The non-transitory machine-readable medium of claim 10 , wherein performing the validation of the startup data comprises:

obtaining, by the management controller, a reduced-size representation of the portion of the startup data;

making a comparison between the reduced-size representation and the portion of the secure boot data to obtain a difference; and

identifying the validation state based on the difference.

13 . The non-transitory machine-readable medium of claim 10 , wherein the validation of the portion of the startup data is performed in parallel with validations, by the management controller, of other portions of the startup data.

14 . The non-transitory machine-readable medium of claim 10 , wherein obtaining the secure boot data comprises:

reading, by a startup management entity hosted by the hardware resources and from a secure storage of the hardware resources, the secure boot data; and

providing, by the startup management entity and via a sideband channel, the secure boot data to the management controller.

15 . The non-transitory machine-readable medium of claim 14 , wherein the secure storage comprises a serial peripheral interface storage device.

16 . A data processing system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing operation of the data processing system, the operations comprising:

making an identification that a startup process for the data processing system is being performed, the startup process using startup data to enable functionality of hardware resources of the data processing system, and

based on the identification:

obtaining, by a management controller of the data processing system, secure boot data usable to validate the startup data;

performing, by the management controller, a validation of the startup data using at least a portion of the secure boot data to identify a validation state of a portion of the startup data, wherein the validation state indicates whether the startup data comprises a first predetermined amount of trusted startup data for completing one or more types of the startup process, the first predetermined amount being based on a predetermined list of trusted startup data;

reporting, by the management controller, the validation state to the hardware resources; and

using, by the hardware resources, the validation state to guide completion of the startup process that places the data processing system in a predetermined operating state,

wherein when the validation state indicates that the startup data comprises a first instance of the first predetermined amount of the trusted startup data required for completing a remedial startup process but not for completing a nominal startup process, then using, by the hardware resources, the validation state to guide the completion of the startup process comprises:

completing the remedial startup process for the data processing system.

17 . The data processing system of claim 16 , wherein the secure boot data comprises data usable to establish trust in the startup data in order to determine an amount of the trusted startup data contained in the startup data, and the data usable to establish trust comprises reduced-size representations of portions of the startup data.

18 . The data processing system of claim 16 , wherein performing the validation of the startup data comprises:

obtaining, by the management controller, a reduced-size representation of the portion of the startup data;

making a comparison between the reduced-size representation and the portion of the secure boot data to obtain a difference; and

identifying the validation state based on the difference.

19 . The data processing system of claim 16 , wherein the validation of the portion of the startup data is performed in parallel with validations, by the management controller, of other portions of the startup data.

20 . The data processing system of claim 16 , wherein obtaining the secure boot data comprises:

reading, by a startup management entity hosted by the hardware resources and from a secure storage of the hardware resources, the secure boot data; and

providing, by the startup management entity and via a sideband channel, the secure boot data to the management controller.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2024
From: SINGH, ANKIT; HALLUR, SHRIKANT U.; AWASTHY, NAVEEN
To: DELL PRODUCTS L.P.
Reel/Frame 067292/0595 →
Continuity (1)
Related Publication 20250307411A1 · Oct 2, 2025
References Cited (43)
US 6668376B1 · Wang · 2003 [cited by applicant]
US 6854054B1 · Kavanagh · 2005 [cited by applicant]
US 7130997B2 · Hsu · 2006 [cited by applicant]
US 8136900B2 · Iwasaki · 2012 [cited by applicant]
US 8346985B2 · Chassot · 2013 [cited by applicant]
US 9152402B2 · Scheidel et al. · 2015 [cited by applicant]
US 9875115B2 · Russinovich · 2018 [cited by applicant]
US 9990325B2 · Hetzler · 2018 [cited by applicant]
US 10901627B1 · Bshara · 2021 [cited by applicant]
US 11212123B2 · Yoon · 2021 [cited by applicant]
US 11282161B2 · Ray et al. · 2022 [cited by applicant]
US 11489827B2 · Knotwell et al. · 2022 [cited by applicant]
US 11556359B2 · Hart et al. · 2023 [cited by applicant]
US 11768781B2 · Cooray et al. · 2023 [cited by applicant]
US 11770246B2 · Ong · 2023 [cited by applicant]
US 11775651B2 · Jacobs · 2023 [cited by applicant]
US 12299184B2 · Wheeler · 2025 [cited by applicant]
US 12353609B2 · Nelogal · 2025 [cited by applicant]
US 20040210897A1 · Brockway · 2004 [cited by applicant]
US 20070198996A1 · Chiu · 2007 [cited by applicant]
US 20090054045A1 · Zakrzewski · 2009 [cited by applicant]
US 20110055541A1 · Lee · 2011 [cited by applicant]
US 20120023319A1 · Chin · 2012 [cited by applicant]
US 20120060023A1 · Park · 2012 [cited by applicant]
US 20130276144A1 · Hansen · 2013 [cited by applicant]
US 20160364297A1 · Lo · 2016 [cited by applicant]
US 20180032349A1 · Bhimanadhuni · 2018 [cited by applicant]
US 20190068772A1 · Lo · 2019 [cited by applicant]
US 20200074083A1 · Hou · 2020 [cited by examiner]
US 20200242051A1 · Bisa · 2020 [cited by applicant]
US 20200244445A1 · Ponnusamy · 2020 [cited by applicant]
US 20200250293A1 · Paulraj · 2020 [cited by applicant]
US 20200356669A1 · Kim · 2020 [cited by applicant]
US 20210034132A1 · Hamlin · 2021 [cited by applicant]
US 20210099519A1 · Christian · 2021 [cited by examiner]
US 20220222349A1 · Lambert · 2022 [cited by examiner]
US 20230132176A1 · Nelogal · 2023 [cited by applicant]
US 20230136229A1 · Lee · 2023 [cited by applicant]
US 20230229454A1 · Lagnado · 2023 [cited by applicant]
US 20230259291A1 · Porzio · 2023 [cited by examiner]
US 20230259472A1 · Azam · 2023 [cited by applicant]
US 20230297261A1 · Kim · 2023 [cited by applicant]
Seongwook, Jin et al., “Architectual Support for Secure Virtualization under a Vulnerable Hypervisor”, 2011 44th Annual IEEE/ACM International Symposium on Microarchitecture (MICRO), Porto Alegre, Brazil, 2011, pp. 272-… [cited by applicant]