IP Library Granted Patent US 9,823,934
Granted Patent B2
US 9,823,934 · App. 14/537,786 · Granted Nov 21, 2017

Firmware updates during limited time period

Inventors: Michael David Marr (Monroe, WA); Matthew R. Corddry (Seattle, WA); James R. Hamilton (Seattle, WA)
Assignee: Amazon Technologies, Inc.
G06F9/4416G06F8/65G06F21/572H04L41/082H04L63/126H04L67/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,823,934
App. No.
14/537,786
Granted
Nov 21, 2017
Kind
B2
Abstract

When providing a user with native access to at least a portion of device hardware, the user can be prevented from modifying firmware and other configuration information by controlling the mechanisms used to update that information. In some embodiments, an asymmetric keying approach can be used to encrypt or sign the firmware. In other cases access can be controlled by enabling firmware updates only through a channel or port that is not exposed to the customer, or by mapping only those portions of the hardware that are to be accessible to the user. In other embodiments, the user can be prevented from modifying firmware by only provisioning the user on a machine after an initial mutability period wherein firmware can be modified, such that the user never has access to a device when firmware can be updated. Combinations and variations of the above also can be used.

Claims (43)

1. A computer-implemented method, comprising: under control of one or more computer systems configured with executable instructions,

providing a period of mutability for a host machine, wherein the length of the period of mutability is variable;

modifying the configuration information for the at least one device during the period of mutability;

providing non-virtualized direct memory access via a guest operating system on the host machine after the period of mutability; and

blocking the guest operating system from modifying configuration information for at least one device of the host machine after the period of mutability.

2. The computer-implemented method of claim 1 , further comprising:

triggering a secure clock configured to determine the period of mutability.

3. The computer-implemented method of claim 1 , further comprising:

utilizing a discovery protocol for the at least one device to determine a length of the period of mutability.

4. The computer-implemented method of claim 1 , further comprising:

applying at least one policy defining a length of the period of mutability.

5. The computer-implemented method of claim 1 , further comprising:

extending a network booting protocol to include tags specifying a length of the period of mutability.

6. The computer-implemented method of claim 1 , further comprising:

triggering the period of mutability through a secure channel.

7. The computer-implemented method of claim 1 , wherein blocking the guest operating system includes triggering a hardware-based access control to prevent access to a configuration subsystem.

8. A system, comprising:

a processor; and

non-transitory memory including instructions that, upon being executed by the processor, cause the system to:

provide a period of mutability for a host machine, wherein the length of the period of mutability is variable;

modify configuration information for at least one device during the period of mutability;

provide non-virtualized direct memory access via a guest operating system on the host machine after the period of mutability; and

block the guest operating system from modifying the configuration information for the at least one device after the period of mutability.

9. The system of claim 8 , wherein a length of the period of mutability is specified in hardware on the host machine.

10. The system of claim 8 , wherein a length of the period of mutability is configurable by an external source.

11. The system of claim 8 , wherein the period of mutability can vary between multiple hardware devices on the host machine.

12. The system of claim 8 , wherein the configuration information comprises firmware for the at least one device.

13. The system of claim 8 , wherein the instructions, upon being executed, further cause the system to:

suspend a clock for determining the period of mutability via a physical switch on the at least one device.

14. A non-transitory computer readable storage medium storing instructions that, upon being executed by a processor, cause the processor to: provide a period of mutability for a host machine, wherein the length of the period of mutability is variable;

modify configuration information for at least one device during the period of mutability;

provide non-virtualized direct memory access via a guest operating system on the host machine after the period of mutability; and

block the guest operating system from modifying the configuration information for the at least one device after the period of mutability.

15. The non-transitory computer readable storage medium of claim 14 , wherein the instructions, upon being executed, further cause the processor to:

trigger a secure clock configured to determine the period of mutability.

16. The non-transitory computer readable storage medium of claim 14 , wherein the instructions, upon being executed, further cause the processor to perform at least one of:

utilizing a discovery protocol for the at least one device to determine a length of the period of mutability;

applying at least one policy defining the length of the period of mutability; or

extending a network booting protocol to include tags specifying the length of the period of mutability.

17. The non-transitory computer readable storage medium of claim 14 , wherein a length of the period of mutability is specified in hardware on the host machine or configurable by an external source.

18. The non-transitory computer readable storage medium of claim 14 , wherein the instructions, upon being executed, further cause the processor to:

trigger the period of mutability through a secure channel.

19. The non-transitory computer readable storage medium of claim 18 , wherein the secure channel comprises a physical switch on the at least one device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2017
From: MARR, MICHAEL DAVID; CORDDRY, MATTHEW T.; HAMILTON, JAMES R.
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 042614/0113 →
Continuity (2)
Continuation 12554770 · Sep 4, 2009
Related Publication 20150160948A1 · Jun 11, 2015