IP Library › Granted Patent US 9,038,130
Granted Patent B2
US 9,038,130 · App. 13/893,685 · Granted May 19, 2015

Sensor aware security policies with embedded controller hardened enforcement

Inventors: James T. Gillon (Round Rock, TX); Ricardo L. Martinez (Leander, TX); Flaviu Cristian Chis (Austin, TX)
Assignee: Dell Products, L.P.
G06F21/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,038,130
App. No.
13/893,685
Filed
May 14, 2013
Granted
May 19, 2015
Kind
B2
Examiner
SONG, HOSUK
Art Unit
2435
USPC
726/1
Abstract

An information handling system (IHS) performs security policy enforcement using security policy data maintained in an embedded controller, which operates within a privileged environment. The security policy data identifies security policies established for the IHS. The EC is directly connected to a number of sensors from which the EC receives sensor data and to at least one integrated functional device. The EC determines whether the received sensor data fulfills any trigger condition of a security policy. If the received sensor data does not fulfill any trigger condition of a security policy described by the security policy data, the EC continues to monitor sensors for updated sensor data. However, if the received sensor data fulfills any trigger condition of the security policy, the EC performs a security measure that involves enabling, disabling, or resetting one or more of the at least one integrated functional devices that can be disabled.

Claims (66)

1. An information handling system comprising:

at least one processor;

at least one memory communicatively coupled to the at least one processor and having stored thereon an operating system (OS);

at least one sensor;

at least one integrated functional device that can be disabled; and

an embedded controller that operates in a privileged environment and is directly coupled to the at least one sensor and to at least one control signal port of the at least one integrated device, and which:

securely stores security policy data that identifies one or more security policies established for the IHS;

in response to receipt of one or more sensor data from the at least one sensor, compares the received one or more sensor data to the established security policies; and

in response to the received one or more sensor data indicating that a trigger condition of one or more of the established security policies is satisfied, performs a security measure that corresponds to the trigger condition of the one or more established security policies being satisfied;

wherein the embedded controller provides secure storage for policy data; and

wherein the embedded controller limits access to policy data within the secure storage to one of: (a) a restricted write operation access that limits a number of changes to specific policy data; (b) an initial manufacturing interface access that allows insertion of policy data during manufacturing of the IHS; and (c) authenticated access requiring entry of a digital signature that is verified via an authorization verification process.

2. The information handling system of claim 1 , wherein: the embedded controller is isolated from the at least one memory and other hardware components of the information handling system; the direct coupling of the embedded controller to the at least one sensor enables the embedded controller to receive an unalterable stream of input data; and the embedded controller comprises: a secure storage in which is stored policy data corresponding to a security policy that is enforceable based on information received from the at least one sensor.

3. The information handling system of claim 1 , wherein the embedded controller:

associates at least one trigger event with pre-defined response actions corresponding to a specific policy provided by said stored security policy data;

detects an occurrence of the at least one trigger event; and

in response to detecting the occurrence of the at least one trigger event, sends a control signal to a control signal port of a corresponding integrated device to provide an associated response action corresponding to the specific policy.

4. The information handling system of claim 1 , wherein: the security measure includes one of enable, disable, and reset of one or more of the at least one integrated device; and the embedded controller performs the security measure by asserting a specific one of an enable signal, a disable signal and a reset signal of one or more of the at least one integrated device.

5. The information handling system of claim 1 , wherein the policy data comprises at least one of: (a) first policy data obtained during a manufacturing process to provide factory specifications; and (b) second policy data that is customizable by a user.

6. The information handling system of claim 1 , wherein the embedded controller:

provides control signals including at least one of a reset signal, an enable signal and a disable signal to trigger a corresponding hardware state of an integrated functional device.

7. The information handling system of claim 1 , wherein the embedded controller:

controls a hardware state of the at least one integrated functional device by using a direct connection to the at least one integrated functional device.

8. The information handling system of claim 1 , wherein the embedded controller:

stores policy data for a location policy that specifies that operation of the IHS can be enabled only within specified location bounds;

periodically receives location data from a location sensor from among a global positioning system (GPS) and a wireless triangulation system;

determines from the received location data whether the IHS is located within the specified location bounds;

in response to determining that the received location data indicates that the IHS is not located within the specified location bounds, disables the IHS; and

allows continued operation of the IHS while the received location data indicates that the IHS is located within the specified location bounds.

9. An information handling system comprising:

at least one processor;

at least one memory communicatively coupled to the at least one processor and having stored thereon an operating system (OS);

at least one sensor;

at least one integrated functional device that can be disabled;

an embedded controller that operates in a privileged environment and is directly coupled to the at least one sensor and to at least one control signal port of the at least one integrated device, and which:

securely stores security policy data that identifies one or more security policies established for the IHS;

in response to receipt of one or more sensor data from the at least one sensor, compares the received one or more sensor data to the established security policies; and

in response to the received one or more sensor data indicating that a trigger condition of one or more of the established security policies is satisfied, performs a security measure that corresponds to the trigger condition of the one or more established security policies being satisfied;

a Basic Input/Output System (BIOS) within the at least one memory; and

wherein the embedded controller communicates with the BIOS using an application programmable interface (API) to receive the first policy data during the manufacturing process.

10. A method for providing security policy enforcement using an embedded controller within an information handling system (IHS), the method comprising:

securely storing security policy data that identifies one or more security policies established for the IHS;

limiting access to policy data stored within secure storage to one of: (a) a restricted write operation access that limits a number of changes to specific policy data (b) an initial manufacturing interface access that allows insertion of policy data during manufacturing of the IHS; and (c) authenticated access requiring entry of a digital signature that is verified via an authorization verification process;

in response to receipt of one or more sensor data from the at least one sensor, comparing the received one or more sensor data to the established security policies; and

in response to the received one or more sensor data indicating that a trigger condition of one or more of the established security policies is satisfied, performing a security measure that corresponds to the trigger condition of the one or more established security policies being satisfied.

11. The method of claim 10 , wherein: the embedded controller is isolated from the at least one memory and other hardware components of the information handling system; the direct coupling of the embedded controller to the at least one sensor enables the embedded controller to receive an unalterable stream of input data; and the embedded controller comprises: a secure storage in which is stored policy data corresponding to a security policy that is enforceable based on information received from the at least one sensor.

12. The method of claim 10 , further comprising:

associating at least one trigger event with pre-defined response actions corresponding to a specific policy provided by said stored security policy data;

detecting an occurrence of the at least one trigger event; and

in response to detecting the occurrence of the at least one trigger event, sending a control signal to a control signal port of a corresponding integrated device to provide an associated response action corresponding to the specific policy.

13. The method of claim 10 , wherein said performing the security measure further comprises:

asserting a specific one of an enable signal, a disable signal and a reset signal of one or more of the at least one integrated device.

14. The method of claim 10 , wherein said securely storing further comprises:

providing secure storage for the policy data, which comprises at least one of: (a) first policy data obtained during a manufacturing process to provide factory specifications; and (b) second policy data that is customizable by a user.

15. The method of claim 14 , wherein:

the IHS comprises a Basic Input/Output System (BIOS) within the at least one memory; and

the embedded controller communicates with the BIOS using an application programmable interface (API) to receive the first policy data during the manufacturing process.

16. The method of claim 10 , wherein said performing further comprises:

providing control signals including at least one of a reset signal, an enable signal and a disable signal to trigger a corresponding hardware state of an integrated functional device.

17. The method of claim 10 , wherein the embedded controller:

controls a hardware state of the at least one integrated functional device by using a direct connection to the at least one integrated functional device.

18. A method for providing security policy enforcement using an embedded controller within an information handling system (IHS), the method comprising:

securely storing policy data for a location policy that specifies that operation of the IHS can be enabled only within specified location bounds;

periodically receiving location data from a location sensor from among a global positioning system (GPS) and a wireless triangulation system;

in response to receipt of location data from the location sensor, comparing the received location data to the specified location bounds to determine from the received location data whether the IHS is located within the specified location bounds;

in response to determining that the received location data indicates that the IHS is not located within the specified location bounds, disabling the IHS; and

allowing continued operation of the IHS while the received location data indicates that the IHS is located within the specified location bounds.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2013
From: GILLON, JAMES T.; MARTINEZ, RICARDO L.; CHIS, FLAVIU CRISTIAN
To: DELL PRODUCTS L.P.
Reel/Frame 030411/0866 →
Continuity (1)
Related Publication 20140344886A1 · Nov 20, 2014