Invention Grant
- Patent Title: Secure encrypted boot with simplified firmware update
- Patent Title (中): 使用简化的固件更新安全加密启动
-
Application No.: US12964091Application Date: 2010-12-09
-
Publication No.: US08566574B2Publication Date: 2013-10-22
- Inventor: John Adam Shriver
- Applicant: John Adam Shriver
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: VanLeeuwen & VanLeeuwen
- Agent Jeffrey S. LaBaw
- Main IPC: G06F12/14
- IPC: G06F12/14

Abstract:
An approach is provided in which a security module, such as a TPM, identifies a change to a boot configuration used in a secure boot operation. This identification results in a non-release of a secret value that is stored in a memory controlled by the security module. The non-release of the secret value is detected by a boot process when the boot process is initiating a session of the information handling system. In response to the detection by the boot process, the boot process retrieves an update encryption key and then decrypts an update copy of a disk encryption key stored on a nonvolatile storage area of the information handling system using the retrieved update encryption key. The nonvolatile storage area also includes a primary copy of the disk encryption key that has been encrypted with the secret value.
Public/Granted literature
- US20120151199A1 Secure Encrypted Boot With Simplified Firmware Update Public/Granted day:2012-06-14
Information query