IP Library Granted Patent US 10,802,916
Granted Patent B2
US 10,802,916 · App. 15/669,419 · Granted Oct 13, 2020

System and method to enable rapid recovery of an operating system image of an information handling system after a malicious attack

Inventors: Mukund P. Khatri (Austin, TX); Akkiah C. Maddukuri (Austin, TX)
Assignee: Dell Products, L.P.
G06F11/1417G06F9/441G06F9/4406G06F9/4408G06F11/1469G06F21/554G06F21/568G06F21/575G06F2201/805G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,802,916
App. No.
15/669,419
Granted
Oct 13, 2020
Kind
B2
Abstract

An information handling system includes a central processing unit, multiple storage devices, and a service processor. The central processing unit executes an operating system of the information handling system. The storage devices include a first storage device that stores a primary boot image for the information handling system, and a second storage device. The service processor executes a first boot process. During the first boot process, the service processor stores a recovery boot image on the second storage device, and restarts the first boot process after the recovery boot image being stored on the second storage device. During a second boot process, the service processor removes the second storage device from a bootable device menu in response to the second storage device storing the recovery boot image, and hides the second storage device from being discoverable by the operating system.

Claims (50)

1. An information handling system comprising:

a plurality of storage devices including a first storage device to store a primary boot image of an operating system of the information handling system, a second storage device, and a third storage device; and

a service processor to communicate with the first and second storage devices, and to execute a first boot process, which causes the service processor to:

execute the first boot process of the primary boot image, so that during the first boot process the service processor:

initiates a basic input/output system (BIOS) setup option;

receives, within the BIOS setup option, a user selection of the second storage device as a recovery storage device;

stores a recovery boot image on the second storage device, wherein the recovery boot image is a partial OS boot image; and

restarts the first boot process after the recovery boot image is stored on the second storage device; and

execute a second boot process of the primary boot image, so that during the second boot process the service processor disables a driver for the second storage device to hide the second storage device from being discoverable by the operating system, and removes the second storage device from a bootable device menu.

2. The information handling system of claim 1 , the service processor to receive a recovery mode selection via an out-of-band communication, to execute a recovery boot process from in response to the recovery mode selection being received, during the recovery boot process, the service processor to: unhide the second storage device, boot to the recovery boot image on the second storage device, and configure the operating system of the information handling system based on the recovery boot image.

3. The information handling system of claim 2 , the service processor to store the recovery boot image as the primary boot image on the first storage device after the operating system of the information handling system is configured during the recovery boot process.

4. The information handling system of claim 2 , the service processor to patch the primary boot image on the first storage device based on the recovery boot image after the operating system of the information handling system is configured during the recovery boot process.

5. The information handling system of claim 1 , the service processor further to provide a basic input/output setup option during the first boot process, and to receive the recovery boot image during the basic input/output setup option prior to the recovery boot image being stored on the second storage device.

6. The information handling system of claim 1 , wherein each of the storage devices is a different type of storage device.

7. A method comprising:

executing, by a service processor, a first boot process of an information handling system, wherein the first boot process is executed from a primary boot image of an operating system stored on a first storage device of the information handling system, wherein the information handling system further includes a second storage device and a third storage device, during the execution of the first boot process:

the service processor initiates a basic input/output system (BIOS) setup option, receives, within the BIOS setup option, a user selection of the second storage device as a recovery storage device, and stores a recovery boot image on the second storage device, wherein the recovery boot image is a partial OS boot image; and

the first boot process restarts after the recovery boot image is stored on the second storage device; and

executing, by the service processor, a second boot process of the primary boot image, so that during the second boot process:

the second storage device is removed from a bootable device menu in response to the second storage device storing the recovery boot image; and

a driver for the second storage device is disabled to hide the second storage device from discovery by the operating system.

8. The method of claim 7 further comprising:

receiving a recovery mode selection via an out-of-band communication,

executing a recovery boot process from in response to the recovery mode selection being received, during the recovery boot process:

unhiding the second storage device;

booting to the recovery boot image on the second storage device; and

configuring the operating system of the information handling system based on the recovery boot image.

9. The method of claim 8 further comprising:

storing the recovery boot image as the primary boot image on the first storage device after the operating system of the information handling system is configured during the recovery boot process.

10. The method of claim 8 further comprising:

patching the primary boot image on the first storage device based on the recovery boot image after the operating system of the information handling system is configured during the recovery boot process.

11. The method of claim 7 further comprising:

providing a basic input/output setup option during the first boot process, and to receive the recovery boot image during the basic input/output setup option prior to the recovery boot image being stored on the second storage device.

12. The method of claim 7 wherein each of the storage devices is a different type of storage device.

13. An information handling system comprising:

a central processing unit to execute an operating system of the information handling system;

a plurality of storage devices including a first storage device to store a primary boot image for the information handling system, a second storage device, and a third storage device; and

a service processor to communicate with the central processing unit and with the plurality of storage devices, to execute a first boot process, which causes the service processor to:

execute the first boot process of the primary boot image, during the first boot process, the service processor to:

initiate a basic input/output system (BIOS) setup option;

receive, within the BIOS setup option, a user selection of the second storage device as a recovery storage device;

store a recovery boot image on the second storage device, wherein the recovery boot image is a partial OS boot image; and

restart the first boot process after the recovery boot image being stored on the second storage device; and

execute a second boot process of the primary boot image, during the second boot process, the service processor to:

remove the second storage device from a bootable device menu in response to the second storage device storing the recovery boot image; and

disable a driver for the second storage device, wherein the second storage device is not accessible by the service processor in response to the driver being disabled.

14. The information handling system of claim 13 , the service processor to receive a recovery mode selection via an out-of-band communication, to execute a recovery boot process from in response to the recovery mode selection being received, during the recovery boot process, the service processor to: unhide the second storage device, boot to the recovery boot image on the second storage device, and configure the operating system of the information handling system based on the recovery boot image.

15. The information handling system of claim 14 , the service processor to store the recovery boot image as the primary boot image on the first storage device after the operating system of the information handling system is configured during the recovery boot process.

16. The information handling system of claim 14 , the service processor to patch the primary boot image on the first storage device based on the recovery boot image after the operating system of the information handling system is configured during the recovery boot process.

17. The information handling system of claim 13 , the service processor further to provide a basic input/output setup option during the first boot process, and to receive the recovery boot image during the basic input/output setup option prior to the recovery boot image being stored on the second storage device.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (043775/0082) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060958/0468 →
RELEASE OF SECURITY INTEREST AT REEL 043772 FRAME 0750 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0606 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2019
From: KHATRI, MUKUND P.; MADDUKURI, AKKIAH C.
To: DELL PRODUCTS, LP
Reel/Frame 050394/0911 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043772/0750 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 043775/0082 →
Continuity (1)
Related Publication 20190042368A1 · Feb 7, 2019