US2017132164A1PendingUtilityA1

Unified Extensible Firmware Interface System Management Mode Initialization Protections with System Management Interrupt Transfer Monitor Sandboxing

Assignee: DELL PRODUCTS LPPriority: Feb 12, 2014Filed: Jan 24, 2017Published: May 11, 2017
Est. expiryFeb 12, 2034(~7.5 yrs left)· nominal 20-yr term from priority
G06F 9/45533G06F 9/45558G06F 2009/45579G06F 9/4401G06F 9/4411G06F 13/24G06F 21/53
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An information handling system includes a processor configured to trap system management interrupts (SMIs) via a system management mode transfer monitor (STM), a first system resource, a SMI handler configured to operate within the STM, launch a first system management mode (SMM) virtual machine, load first SMM code for a first driver into the first SMM virtual machine, and associate the first SMM virtual machine with the first system resource and not with the second system resource.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An information handling system comprising:
 a processor configured to trap system management interrupts (SMIs);   a first system resource;   a second system resource; and   an SMI handler configured to:
 launch a first system management mode (SMM) virtual machine; 
 load first SMM code for a first driver into the first SMM virtual machine; and 
 associate the first SMM virtual machine with the first system resource and not with the second system resource. 
   
     
     
         2 . The information handling system of  claim 1 , wherein the SMI handler is further configured to:
 receive a first SMI;   determine that the first SMI is:
 a call to the first SMM code; and 
 targeted to the first system resource; and 
   forward the first SMI to the first SMM virtual machine.   
     
     
         3 . The information handling system of  claim 1 , wherein the SMI handler is further configured to:
 determine a resource policy for the first driver, the resource policy defining that the first SMM virtual machine should be associated with the first system resource and not with the second system resource;   wherein associating the first SMM virtual machine with the first system resource and not with the second system resource is based upon the resource policy.   
     
     
         4 . The information handling system of  claim 3 , wherein the resource policy is determined based upon the first driver. 
     
     
         5 . The information handling system of  claim 4 , wherein the resource policy is determined based upon a globally unique identifier of the first driver. 
     
     
         6 . The information handling system of  claim 1 , wherein the SMI handler is further configured to:
 launch a second SMM virtual machine;   load second SMM code for a second driver into the second SMM virtual machine; and   associate the first SMM virtual machine with the second system resource and not with the first system resource.   
     
     
         7 . The information handling system of  claim 1 , wherein, in handling the second SMI, the SMI handler is further configured to deny the second SMI access to the second system resource. 
     
     
         8 . A method comprising:
 launching, on an information handling system, a system management interrupt (SMI) handler;   launching, by the SMI handler, a first system management mode (SMM) virtual machine in a memory of the information handling system;   loading first SMM code for a first driver into the first SMM virtual machine; and   associating the first SMM virtual machine with a first system resource of the information handling system and not with a second system resource of the information handling system.   
     
     
         9 . The method of  claim 8 , further comprising:
 receiving, by the SMI handler, a first SMI;   determining that the first SMI is:
 a call to the first SMM code; and 
 targeted to the first system resource; and 
   forwarding the first SMI to the first SMM virtual machine.   
     
     
         10 . The method of  claim 8 , further comprising:
 determining, by the SMI handler, a resource policy for the first driver, the resource policy defining that the first SMM virtual machine should be associated with the first system resource and not with the second system resource;   wherein associating the first SMM virtual machine with the first system resource and not with the second system resource is based upon the resource policy.   
     
     
         11 . The method of  claim 10 , wherein the resource policy is determined based upon the first driver. 
     
     
         12 . The method of  claim 11 , wherein the resource policy is determined based upon a globally unique identifier of the first driver. 
     
     
         13 . The method of  claim 8 , further comprising:
 launching, by the SMI handler, a second SMM virtual machine in the memory;   loading second SMM code for a second driver into the second SMM virtual machine; and   associating the second SMM virtual machine with the second system resource and not with the first system resource.   
     
     
         14 . The method of  claim 8 , wherein, in handling the second SMI, the method further comprises:
 denying, by the SMI handler, the second SMI access to the second system resource.   
     
     
         15 . A non-transitory computer-readable medium including code for performing a method, the method comprising:
 launching a system management interrupt (SMI) handler;   launching, by the SMI handler, a first system management mode (SMM) virtual machine in a memory of an information handling system;   loading first SMM code for a first driver into the first SMM virtual machine;   associating the first SMM virtual machine with a first system resource of the information handling system and not with a second system resource of the information handling system;   
     
     
         16 . The computer-readable medium of  claim 15 , the method further comprising:
 receiving, by the SMI handler, a first SMI;   determining that the first SMI is:
 a call to the first SMM code; and 
 targeted to the first system resource; and 
   forwarding the first SMI to the first SMM virtual machine.   
     
     
         17 . The computer-readable medium of  claim 15 , the method further comprising:
 determining, by the SMI handler, a resource policy for the first driver, the resource policy defining that the first SMM virtual machine should be associated with the first system resource and not with the second system resource;   wherein associating the first SMM virtual machine with the first system resource and not with the second system resource is based upon the resource policy.   
     
     
         18 . The computer-readable medium of  claim 17 , wherein the resource policy is determined based upon the first driver. 
     
     
         19 . The computer-readable medium of  claim 18 , wherein the resource policy is determined based upon a globally unique identifier of the first driver. 
     
     
         20 . The computer-readable medium of  claim 16 , the method further comprising:
 launching, by the SMI handler, a second SMM virtual machine in the memory;   loading second SMM code for a second driver into the second SMM virtual machine; and   associating the second SMM virtual machine with the second system resource and not with the first system resource.

Join the waitlist — get patent alerts

Track US2017132164A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.