Secure and dynamic independent diagnostics module injections to support an independent diagnostics module during preboot diagnostics
A firmware management operation. The firmware management operation includes providing an information handling system with a distributed BIOS; identifying information handling system diagnostics data, the information handling system diagnostics data being associated with an independent diagnostics module; authenticating the independent diagnostics module; and, executing the independent diagnostics module on the information handling system via a diagnostics event manager.
1 . A computer-implementable method for performing a firmware management operation, comprising:
providing an information handling system with a distributed BIOS, the distributed BIOS including a BIOS component and a BIOS variable, the BIOS component and the BIOS variable being stored within different storage locations of the information handling system;
identifying information handling system diagnostics data, the information handling system diagnostics data being associated with an independent diagnostics module;
authenticating the independent diagnostics module; and,
executing the independent diagnostics module on the information handling system via a diagnostics event manager; and wherein
the independent diagnostics module communicates with a diagnostic content validation module via a secure active port.
2 . The method of claim 1 , wherein:
the diagnostics event manager executes within a Driver execution Environment (DXE) pre-boot phase.
3 . The method of claim 1 , wherein:
the information handling system includes an embedded controller, the embedded controller being implemented to provide a root of trust.
4 . The method of claim 3 , wherein:
the root of trust is used when authenticating the independent diagnostics module.
5 . The method of claim 1 , wherein:
the secure active port includes at least one of a dependency resolver module, a version resolver module, an OEM and third party IDM detector module, and a telemetry detector module.
6 . A system comprising:
a processor;
a data bus coupled to the processor; and
a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:
providing an information handling system with a distributed BIOS, the distributed BIOS including a BIOS component and a BIOS variable, the BIOS component and the BIOS variable being stored within different storage locations of the information handling system;
identifying information handling system diagnostics data, the information handling system diagnostics data being associated with an independent diagnostics module;
authenticating the independent diagnostics module; and,
executing the independent diagnostics module on the information handling system via a diagnostics event manager; and wherein
the independent diagnostics module communicates with a diagnostic content validation module via a secure active port.
7 . The system of claim 6 , wherein:
the diagnostics event manager executes within a Driver execution Environment (DXE) pre-boot phase.
8 . The system of claim 6 , wherein:
the information handling system includes an embedded controller, the embedded controller being implemented to provide a root of trust.
9 . The system of claim 8 , wherein:
the root of trust is used when authenticating the independent diagnostics module.
10 . The system of claim 6 , wherein:
the secure active port includes at least one of a dependency resolver module, a version resolver module, an OEM and third party IDM detector module, and a telemetry detector module.
11 . A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:
providing an information handling system with a distributed BIOS, the distributed BIOS including a BIOS component and a BIOS variable, the BIOS component and the BIOS variable being stored within different storage locations of the information handling system;
identifying information handling system diagnostics data, the information handling system diagnostics data being associated with an independent diagnostics module;
authenticating the independent diagnostics module; and,
executing the independent diagnostics module on the information handling system via a diagnostics event manager; and wherein
the independent diagnostics module communicates with a diagnostic content validation module via a secure active port.
12 . The non-transitory, computer-readable storage medium of claim 11 , wherein:
the diagnostics event manager executes within a Driver execution Environment (DXE) pre-boot phase.
13 . The non-transitory, computer-readable storage medium of claim 11 , wherein:
the information handling system includes an embedded controller, the embedded controller being implemented to provide a root of trust.
14 . The non-transitory, computer-readable storage medium of claim 13 , wherein:
the root of trust is used when authenticating the independent diagnostics module.
15 . The non-transitory, computer-readable storage medium of claim 11 , wherein:
the secure active port includes at least one of a dependency resolver module, a version resolver module, an OEM and third party IDM detector module, and a telemetry detector module.
16 . The non-transitory, computer-readable storage medium of claim 11 , wherein:
the computer executable instructions are deployable to a client system from a server system at a remote location.
17 . The non-transitory, computer-readable storage medium of claim 11 , wherein:
the computer executable instructions are provided by a service provider to a user on an on-demand basis.