IP Library Granted Patent US 12,737,473
Granted Patent B2
US 12,737,473 · App. 19/027,198 · Granted Sep 15, 2026

Managing startup of a data processing system using a startup policy

Inventors: Nicholas D. Grobelny (Evergreen, CO); Amy Christine Nelson (Round Rock, TX); David Albert Consolver (Hurst, TX); Raman Sharma (Leander, TX); Richard M. Tonry (Georgetown, TX)
Assignee: Dell Products L.P.
G06F21/575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,473
App. No.
19/027,198
Granted
Sep 15, 2026
Kind
B2
Abstract

Methods and systems for managing operation of a data processing system are disclosed. To do so, during a startup of the data processing system, a startup policy may be obtained. The startup policy may indicate that a first portion of hardware components of the data processing system may be used to evaluate a security posture of the data processing system during startup and a second portion of the hardware components may not be used to evaluate the security posture during startup. A measurement process may be performed based on a security protocol and data model (SPDM) security standard for the first portion to obtain first measurements. The security posture may be evaluated using a trusted platform module based on the first measurements. Operation of the data processing system may be managed based on the security posture to reduce a likelihood of the data processing system being compromised.

Claims (57)

1 . A method for managing operation of a data processing system, the method comprising:

during a startup of the data processing system:

obtaining a startup policy for the data processing system, the startup policy indicating that:

a first portion of hardware components of the data processing system is to be used to evaluate a security posture of the data processing system during the startup, and

a second portion of the hardware components is not to be used to evaluate the security posture of the data processing system during the startup;

performing, based on the startup policy and a security protocol and data model (SPDM) security standard, a first measurement process for the first portion of hardware components to obtain first measurements;

evaluating, using a trusted platform module (TPM), the security posture of the data processing system based on the first measurements and not using measurements of any of the second portion of the hardware components; and

managing operation of the data processing system based on the security posture to reduce a likelihood of the data processing system being compromised.

2 . The method of claim 1 , further comprising:

after the startup of the data processing system:

performing a second measurement process, based on the SPDM security standard, for the second portion of the hardware components to obtain second measurements;

updating the security posture of the data processing system based on the second measurements to obtain an updated security posture for the data processing system; and

managing the operation of the data processing system based on the updated security posture to reduce the likelihood of the data processing system being compromised.

3 . The method of claim 1 , wherein hardware components of the first portion of the hardware components and hardware components of the second portion of the hardware components are compliant with the SPDM security standard.

4 . The method of claim 1 , wherein second measurements are available to be obtained from the second portion of the hardware components at a time that the first measurement process is performed.

5 . The method of claim 1 , wherein members of the first portion of the hardware components and members of the second portion of the hardware components are chosen based on levels of risk to security of the data processing system corresponding to potential compromise of each of the hardware components of the data processing system.

6 . The method of claim 5 , wherein the members of the first portion of the hardware components pose a greater risk to the security of the data processing system if compromised than the members of the second portion of the hardware components.

7 . The method of claim 1 , wherein members of the first portion of the hardware components and members of the second portion of the hardware components are chosen based on likelihoods that changes have been made to each of the hardware components of the data processing system since a previous startup of the data processing system occurred.

8 . The method of claim 1 , wherein the startup policy and a list of hardware components of the data processing system that are compliant with a security protocol and data model (SPDM) security standard are obtained by a startup manager of the data processing system prior to performing the first measurement process.

9 . The method of claim 8 , wherein the startup manager is a basic input-output system (BIOS).

10 . The method of claim 8 , wherein the startup manager is hosted by a hardware processor of the data processing system, and the trusted platform module is a hardware component that is distinguishable from the hardware processor.

11 . The method of claim 1 , wherein the first measurements comprise first security data usable to validate authenticity and/or integrity of software hosted by the first portion of the hardware components.

12 . The method of claim 1 , wherein the SPDM security standard is a data model for hardware components of data processing systems, the SPDM security standard specifying, at least, methods of security communication between the hardware components, minimum standards of data to be made available to other hardware components, and security information to be made available to the other hardware components.

13 . The method of claim 1 , wherein managing operation of the data processing system comprises:

limiting, by the TPM, use of secrets by the data processing system based on the security posture of the data processing system.

14 . The method of claim 1 , wherein evaluating the security posture of the data processing system comprises:

checking integrity and/or authenticity of software hosted by the first portion of the hardware components using the first measurements and data structures trusted by the TPM.

15 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing operation of a data processing system, the operations comprising:

during a startup of the data processing system:

obtaining a startup policy for the data processing system, the startup policy indicating that:

a first portion of hardware components of the data processing system is to be used to evaluate a security posture of the data processing system during the startup, and

a second portion of the hardware components is not to be used to evaluate the security posture of the data processing system during the startup;

performing, based on the startup policy and a security protocol and data model (SPDM) security standard, a first measurement process for the first portion of hardware components to obtain first measurements;

evaluating, using a trusted platform module (TPM), the security posture of the data processing system based on the first measurements and not using measurements of any of the second portion of the hardware components; and

managing operation of the data processing system based on the security posture to reduce a likelihood of the data processing system being compromised.

16 . The non-transitory machine-readable medium of claim 15 , wherein the operations further comprise:

after the startup of the data processing system:

performing a second measurement process, based on the SPDM security standard, for the second portion of the hardware components to obtain second measurements;

updating the security posture of the data processing system based on the second measurements to obtain an updated security posture for the data processing system; and

managing the operation of the data processing system based on the updated security posture to reduce the likelihood of the data processing system being compromised.

17 . The non-transitory machine-readable medium of claim 15 , wherein hardware components of the first portion of the hardware components and hardware components of the second portion of the hardware components are compliant with the SPDM security standard.

18 . A data processing system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing operation of a data processing system, the operations comprising:

during a startup of the data processing system:

obtaining a startup policy for the data processing system, the startup policy indicating that:

a first portion of hardware components of the data processing system is to be used to evaluate a security posture of the data processing system during the startup, and

a second portion of the hardware components is not to be used to evaluate the security posture of the data processing system during the startup;

performing, based on the startup policy and a security protocol and data model (SPDM) security standard, a first measurement process for the first portion of hardware components to obtain first measurements;

evaluating, using a trusted platform module (TPM), the security posture of the data processing system based on the first measurements and not using measurements of any of the second portion of the hardware components; and

managing operation of the data processing system based on the security posture to reduce a likelihood of the data processing system being compromised.

19 . The data processing system of claim 18 , wherein the operations further comprise:

after the startup of the data processing system:

performing a second measurement process, based on the SPDM security standard, for the second portion of the hardware components to obtain second measurements;

updating the security posture of the data processing system based on the second measurements to obtain an updated security posture for the data processing system; and

managing the operation of the data processing system based on the updated security posture to reduce the likelihood of the data processing system being compromised.

20 . The data processing system of claim 18 , wherein hardware components of the first portion of the hardware components and hardware components of the second portion of the hardware components are compliant with the SPDM security standard.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2025
From: GROBELNY, NICHOLAS D.; NELSON, AMY CHRISTINE; CONSOLVER, DAVID ALBERT; SHARMA, RAMAN; TONRY, RICHARD M.
To: DELL PRODUCTS L.P.
Reel/Frame 070229/0558 →
Continuity (1)
Related Publication 20260212019A1 · Jul 23, 2026
References Cited (57)
US 10708256B1 · Kane-Parry · 2020 [cited by applicant]
US 11120136B1 · BeSerra · 2021 [cited by examiner]
US 11316891B2 · Sbandi · 2022 [cited by applicant]
US 11928639B2 · Young et al. · 2024 [cited by applicant]
US 12261966B1 · Levy · 2025 [cited by applicant]
US 12393691B2 · Edwards · 2025 [cited by examiner]
US 12556922B1 · Richards · 2026 [cited by applicant]
US 20060242405A1 · Gupta · 2006 [cited by applicant]
US 20090080661A1 · Brown · 2009 [cited by applicant]
US 20100031028A1 · Adams · 2010 [cited by applicant]
US 20130166899A1 · Courtney · 2013 [cited by applicant]
US 20170180355A1 · Enns · 2017 [cited by applicant]
US 20190238584A1 · Somasundaram · 2019 [cited by examiner]
US 20200162262A1 · Shekh-Yusef · 2020 [cited by applicant]
US 20200344265A1 · Kelly · 2020 [cited by applicant]
US 20200358623A1 · Munzert · 2020 [cited by applicant]
US 20210034733A1 · Grobelny · 2021 [cited by examiner]
US 20210312044A1 · Berger et al. · 2021 [cited by applicant]
US 20210320944A1 · Ogle · 2021 [cited by examiner]
US 20210367974A1 · Ponnuru · 2021 [cited by applicant]
US 20220067123A1 · Rafey · 2022 [cited by examiner]
US 20220092203A1 · Khatri et al. · 2022 [cited by applicant]
US 20220292203A1 · Severns-Williams · 2022 [cited by applicant]
US 20220329604A1 · Guy · 2022 [cited by examiner]
US 20220358220A1 · Smith · 2022 [cited by examiner]
US 20230007874A1 · Mugunda · 2023 [cited by applicant]
US 20230009968A1 · Ramaiah · 2023 [cited by applicant]
US 20230087829A1 · Ponnuru · 2023 [cited by examiner]
US 20230239165A1 · Young et al. · 2023 [cited by applicant]
US 20230367860A1 · Stewart · 2023 [cited by applicant]
US 20240104215A1 · Paulraj et al. · 2024 [cited by applicant]
US 20240134996A1 · Madala et al. · 2024 [cited by applicant]
US 20240134999A1 · Madala et al. · 2024 [cited by applicant]
US 20240152620A1 · Marando · 2024 [cited by applicant]
US 20240179014A1 · Ruan · 2024 [cited by applicant]
US 20240184929A1 · Orlando · 2024 [cited by applicant]
US 20240249002A1 · Yoon · 2024 [cited by applicant]
US 20240284317A1 · Barton · 2024 [cited by examiner]
US 20240296214A1 · Bisa · 2024 [cited by applicant]
US 20240296256A1 · Ramaiah · 2024 [cited by examiner]
US 20240303317A1 · Ahmed · 2024 [cited by applicant]
US 20240303380A1 · Ponnuru · 2024 [cited by applicant]
US 20240303381A1 · Ponnuru · 2024 [cited by applicant]
US 20240311482A1 · Paulraj · 2024 [cited by examiner]
US 20240320322A1 · Yao · 2024 [cited by applicant]
US 20240411652A1 · Prabhakar · 2024 [cited by applicant]
US 20240413982A1 · Prabhakar · 2024 [cited by applicant]
US 20250013760A1 · Smith · 2025 [cited by examiner]
US 20250139305A1 · Sahita · 2025 [cited by applicant]
US 20250159016A1 · Hen · 2025 [cited by examiner]
US 20250165577A1 · Radhakrishnan · 2025 [cited by examiner]
US 20250260565A1 · Abdelsamie · 2025 [cited by applicant]
US 20250265337A1 · Kumar · 2025 [cited by applicant]
US 20250267015A1 · Yao · 2025 [cited by applicant]
US 20260030358A1 · Paulraj · 2026 [cited by applicant]
Sanders, Ryan. (Mar. 8, 2021). “The Key to Firmware Security in Connected IoT Devices”. Keyfactor. Retrieved from <https://www.keyfactor.com/blog/firmware-security-iot-devices/> on Jan. 28, 2025 (3 pages). [cited by applicant]
Epp, Sergej. “Firmware Security: Watch Out for These 5 Excuses”. paloalto Networks. Retrieved from <https://www.paloaltonetworks.sg/cybersecurity-perspectives/firmware-security-watch-out-for-these-5-excuses> on Jan. 28,… [cited by applicant]