Invention Grant
- Patent Title: Systems and methods for evaluating security risks using a manufacturer-signed software identification manifest
-
Application No.: US17111253Application Date: 2020-12-03
-
Publication No.: US11586738B2Publication Date: 2023-02-21
- Inventor: Charles D. Robison , Nicholas D. Grobelny
- Applicant: Dell Products, L.P.
- Applicant Address: US TX Round Rock
- Assignee: Dell Products, L.P.
- Current Assignee: Dell Products, L.P.
- Current Assignee Address: US TX Round Rock
- Agency: Fogarty LLP
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F21/60 ; G06F21/74 ; G06F21/73 ; G06F21/64

Abstract:
Systems and methods for evaluating security risks using a manufacturer-signed software identification manifest are described. In some embodiments, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to: receive a request to perform attestation of a client device; retrieve, from an agent executed by the client device, a manifest comprising: (i) a signature portion encrypted with a first key, and (ii) a software identification (SWID) portion encrypted with a second key; retrieve the first key from a manufacturer database; retrieve the second key from a customer database; decrypt the signature and the manifest with the first and second keys; and perform the attestation using the decrypted manifest.
Public/Granted literature
Information query