IP Library Granted Patent US 10,460,111
Granted Patent B2
US 10,460,111 · App. 15/669,400 · Granted Oct 29, 2019

System and method to isolate host and system management in an information handling system

Inventor: Mukund P. Khatri (Austin, TX)
Assignee: Dell Products, LP
G06F21/575G06F8/65G06F9/4401
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,460,111
App. No.
15/669,400
Filed
Aug 4, 2017
Granted
Oct 29, 2019
Kind
B2
Art Unit
2187
USPC
713/2
Abstract

An information handling system includes a central processing unit, a memory, and a service processor. The central processing unit executes an operating system of the information handling system. The memory stores a boot image for a boot process of the information handling system. The service processor executes the boot image to perform the boot process, and to cause the service processor to detect whether an isolation profile is selected within the boot process; and in response to the isolation profile being selected, to disable Intelligent Platform Management Interface system management from the operating system to prevent system management access by the operating system to the service processor.

Claims (39)

1. An information handling system comprising:

a central processing unit to execute an operating system of the information handling system;

a memory to store a boot image for a boot process of the information handling system; and

a service processor to execute the boot image to perform the boot process, and the execution of the boot image to cause the service processor to:

detect whether an isolation profile is enabled within the boot process, wherein the isolation profile is enabled in response to a signal provided by a host device external to the information handling system based on the operating system being compromised; and

in response to the isolation profile being enabled, to disable Intelligent Platform Management Interface system management from the operating system to prevent system management access by the compromised operating system to the service processor.

2. The information handling system of claim 1 , the service processor further disable a management engine interface from the compromised operating system of the information handling system in response to detecting the isolation profile is enabled.

3. The information handling system of claim 2 wherein disabling the Intelligent Platform Management Interface system management and the management engine interface prevents system management drivers from being loaded in the compromised operating system.

4. The information handling system of claim 1 , the service processor further to receive infrastructure management updates for the information handing system via an out-of-band communication.

5. The information handling system of claim 4 wherein the infrastructure management updates include configuration updates, health requests for the information handling system.

6. The information handling system of claim 1 , the central processing unit to perform operating system level updates via in-band access through the operating system.

7. The information handling system of claim 6 wherein the operating system level updates include operating system patches, and operating system driver updates.

8. A method comprising:

starting a boot process of an information handling system;

detecting whether an isolation profile is enabled within the boot process, wherein the isolation profile is enabled in response to a signal provided by a host device external to the information handling system based on an operating system of the information handling system being compromised; and

in response to detecting the isolation profile is enabled, disabling Intelligent Platform Management Interface system management from the compromised operating system of the information handling system to prevent system management access by the compromised operating system to a service processor of the information handling system.

9. The method of claim 8 further comprising:

in response to detecting the isolation profile is enabled, disabling a management engine interface from the compromised operating system of the information handling system.

10. The method of claim 9 wherein disabling the Intelligent Platform Management Interface system management and the management engine interface prevents system management drivers from being loaded in the compromised operating system.

11. The method of claim 8 further comprising:

receiving infrastructure management updates for the information handing system via an out-of-band communication with the service processor.

12. The method of claim 11 wherein the infrastructure management updates include configuration updates, health requests for the information handling system.

13. The method of claim 8 further comprising:

performing operating system level updates via in-band access through the operating system.

14. The method of claim 13 wherein the operating system level updates include operating system patches, and operating system driver updates.

15. A method comprising:

receiving, at a service processor, an isolation profile for an information handling system via an out-of-band communication from a host device external to the information handling system;

storing, by the service processor, the isolation profile as a basic input/output system setting within a memory of the information handling system;

starting a boot process from the basic input/output system of the information handling system;

detecting whether the isolation profile is enabled within the boot process, wherein the isolation profile is enabled in response to a signal provided by the host device based on an operating system of the information handling system being compromised; and

in response to detecting the isolation profile is enabled, disabling Intelligent Platform Management Interface system management from the compromised operating system of the information handling system to prevent system management access by the compromised operating system to a service processor of the information handling system.

16. The method of claim 15 further comprising:

in response to detecting the isolation profile is enabled, disabling a management engine interface from the compromised operating system of the information handling system.

17. The method of claim 16 wherein disabling the Intelligent Platform Management Interface system management and the management engine interface prevents system management drivers from being loaded in the compromised operating system.

18. The method of claim 15 further comprising:

receiving infrastructure management updates for the information handing system via the out-of-band communication.

19. The method of claim 15 further comprising:

performing operating system level updates via in-band access through the operating system.

20. The method of claim 19 wherein the operating system level updates include operating system patches, and operating system driver updates.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (043775/0082) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060958/0468 →
RELEASE OF SECURITY INTEREST AT REEL 043772 FRAME 0750 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0606 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2019
From: KHATRI, MUKUND P.
To: DELL PRODUCTS, LP
Reel/Frame 050394/0523 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043772/0750 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 043775/0082 →
Continuity (1)
Related Publication 20190042755A1 · Feb 7, 2019