SECURE FIRMWARE UPDATES IN HETEROGENEOUS COMPUTING PLATFORMS

    公开(公告)号:US20250045400A1

    公开(公告)日:2025-02-06

    申请号:US18363979

    申请日:2023-08-02

    Abstract: Systems and methods for a secure firmware updates in heterogeneous computing platforms. In some embodiments, an Information Handling System (IHS) may include a heterogeneous computing platform and an Out-of-Band (OOB) Microcontroller Unit (MCU) integrated into the heterogeneous computing platform, where the OOB MCU is configured to: receive a firmware update command while a host processor of the heterogeneous computing platform is in a low-power state, where the firmware update command indicates a target device; validate, using a crypto device, a firmware payload associated with the firmware update command; and cause the validated firmware payload to be installed on a memory of the target device while the host processor is in the low-power state.

    OUT-OF-BAND (OOB) DIAGNOSTICS IN HETEROGENEOUS COMPUTING PLATFORMS

    公开(公告)号:US20250045143A1

    公开(公告)日:2025-02-06

    申请号:US18364068

    申请日:2023-08-02

    Abstract: Systems and methods for Out-of-Band (OOB) diagnostics in heterogeneous computing platforms. In some embodiments, an Information Handling System (IHS) may include a heterogeneous computing platform having a plurality of devices and an Out-of-Band (OOB) Microcontroller Unit (MCU) integrated into the heterogeneous computing platform and coupled to the plurality of devices via an interconnect. The OOB MCU may be configured to: receive a result of a diagnostics operation performed with respect to at least a given one of the plurality of devices, and transmit an indication of the result, as part of an OOB sniffing operation, to a remote IHS.

    ROUTING OF MANAGEABILITY DATA IN HETEROGENEOUS COMPUTING PLATFORMS

    公开(公告)号:US20250007831A1

    公开(公告)日:2025-01-02

    申请号:US18342781

    申请日:2023-06-28

    Abstract: Systems and methods for routing manageability data in heterogeneous computing platforms. In some embodiments, an Information Handling System (IHS) may include a heterogeneous computing platform comprising a plurality of devices and an Out-of-Band (OOB) Microcontroller Unit (MCU), an Embedded Controller (EC), or a network device integrated into or coupled to the heterogeneous computing platform and distinct from any host processor of the heterogeneous computing platform, where the OOB MCU, EC, or network device is configured to receive a packet or command from a cloud service, and send the packet or command to a selected one of the plurality of devices.

    MEMORY ARCHITECTURE FOR OUT-OF-BAND MANAGEABILITY IN HETEROGENEOUS COMPUTING PLATFORMS

    公开(公告)号:US20250004538A1

    公开(公告)日:2025-01-02

    申请号:US18344914

    申请日:2023-06-30

    Abstract: Systems and methods for a memory architecture for Out-of-Band (OOB) manageability in heterogeneous computing platforms. In some embodiments, an Information Handling System (IHS) may include: a heterogeneous computing platform having a plurality of devices, and an OOB Microcontroller Unit (MCU) integrated into the heterogeneous computing platform, where the OOB MCU is configured to: identify a command in an OOB packet received while a host processor is in a low-power state, and determine, based at least in part upon the command, whether to wake up an external memory device coupled to the heterogeneous computing platform.

    Secure delivery and deployment of a virtual environment

    公开(公告)号:US11048551B2

    公开(公告)日:2021-06-29

    申请号:US15962275

    申请日:2018-04-25

    Abstract: A secured container provides access to enterprise data while isolated from the operating system of an Information Handling System (IHS). The secured container remains secured during its delivery and deployment. A secured container is configured to provide a user of the IHS with access to enterprise data. The secured container is encrypted using a symmetrical key that is transmitted to a secured storage that is isolated from the operating system of the IHS via out-of-band communications. The encrypted secured container is digitally signed using an asymmetric key pair. The digital signature and the encrypted secured container are transmitted to the IHS via in-band communications. At the IHS, the public key of the asymmetric key pair is used to validate the digital signature and the private symmetric key is retrieved from secured storage to decrypt the secured container. Additional embodiments provide a technique for securely migrating a secured container between IHSs.

    Validation of data integrity through watermarking

    公开(公告)号:US10990706B2

    公开(公告)日:2021-04-27

    申请号:US15962641

    申请日:2018-04-25

    Abstract: Systems and methods are provided for recording and validating modifications to a secured container. Modifications to the secured container by trusted parties are logged. The log may be maintained in a secured memory of an IHS (Information Handling System) and may be periodically validated. Each logged modification specifies a timestamp of the modification and the digital watermark assigned to the trusted party making the modification. Upon completing modifications, the secured container is sealed by imprinting the first digital watermark and the first timestamp at locations in the secured container specified by a watermarking algorithm assigned to the trusted party making the modification. Additional modifications may be serially watermarked on the secured container according the watermarking algorithm of the trusted party making each modification. The secured container is unsealed by re-applying each of the watermarking algorithms in reverse order. The integrity of the secured container, and each modification, is thus validated.

    REMOTE INTEGRITY ASSURANCE OF A SECURED VIRTUAL ENVIRONMENT

    公开(公告)号:US20190332773A1

    公开(公告)日:2019-10-31

    申请号:US15962520

    申请日:2018-04-25

    Abstract: A secured virtual environment provides access to enterprise data and may be configured remotely while isolated from the operating system of an Information Handling System (IHS). In secured booting of the IHS, references signatures are received via an out-of-band connection to the IHS. The reference signatures specify reference states for components of the IHS. Prior to launching a secured virtual environment, a trusted resource of the IHS, such as embedded controller isolated from the operating system, is queried for updated signatures specifying operating states of the component. The integrity of the IHS is validated based on comparisons of the respective reference signatures and updated signatures. If the integrity of the IHS is validated, a secured virtual environment is configured such that particular user may access the enterprise data according to applicable policies that may be periodically revalidated. The secured virtual environment may then be launched on the IHS.

    Proactive fault avoidance
    10.
    发明授权

    公开(公告)号:US09830226B2

    公开(公告)日:2017-11-28

    申请号:US14750789

    申请日:2015-06-25

    CPC classification number: G06F11/1417 G06F11/00 G06F11/3062

    Abstract: Systems and methods for proactive fault avoidance. In some embodiments, an Information Handling System (IHS) includes: a processor and a Basic I/O System (BIOS) coupled to the processor, the BIOS having program instructions that, upon execution by the processor, cause the IHS to: accumulate telemetry data received from one or more sensors over a period of time; determine, based upon the accumulated telemetry data, that the IHS has been subject to a given type of environmental or stress condition; and identify, based upon the given type of environmental or stress condition, a potential IHS fault before the fault occurs.

Patent Agency Ranking