Patents by Inventor David Albert Consolver
David Albert Consolver has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260252698Abstract: Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, during a startup of the data processing system, a multi-measurement identification may be made indicating that a multi-measurement process is to be performed by a plurality of entities during the startup. In place of the multi-measurement process, a single-measurement process may be performed to obtain device measurements. The device measurements may be stored in a shared storage location that is accessible to the plurality of entities. The plurality of entities may retrieve at least a portion of the device measurements from the shared storage location. A security posture of the data processing system may be evaluated based on the device measurements. Operation of the data processing system may be managed based on the security posture to reduce a likelihood of the data processing system being compromised.Type: ApplicationFiled: February 25, 2025Publication date: August 27, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260252740Abstract: Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, during a startup of the data processing system, an entity may perform, using identification data obtained from a hardware component of the data processing system using a security protocol and data model (SDPM) security standard, an analysis process to identify a level of trust for the hardware component. Based on the level of trust and an SPDM hardware component policy, at least one action to manage operation of the data processing system may be identified. The at least one action may be performed to reduce a likelihood of the data processing system being compromised.Type: ApplicationFiled: February 25, 2025Publication date: August 27, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260252359Abstract: Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, an occurrence of a security event may be identified by an entity of the data processing system. The entity may obtain a copy of a local certificate trust store log, the local certificate trust store log indicating modifications made to a local certificate trust store managed by the data processing system. The entity and a remote system may cooperatively identify a security state of the data processing system based on the copy of the local certificate trust store log. Operation of the data processing system may be managed based on the security state to reduce a likelihood of the data processing system being compromised.Type: ApplicationFiled: February 25, 2025Publication date: August 27, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260252699Abstract: Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, during a startup of the data processing system, an entity may obtain, using a security protocol and data model (SDPM) security standard, at least a first device certificate of a certificate chain for a device. Using the at least the first device certificate and a store of trusted device certificates, the entity may perform a first analysis process to determine a level of trust in the device. If the level of trust is indeterminate, the entity may use the certificate chain and a store of trusted root certificates to perform a second analysis process to determine the level of trust in the device. Operation of the data processing system may be managed based on the level of trust in the device.Type: ApplicationFiled: February 25, 2025Publication date: August 27, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260252739Abstract: Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, after a startup of the data processing system and while in operable communication with a vendor certificate repository, a management agent may determine that a store of trusted certificates is to be updated. The management agent may perform a synchronization process to obtain an updated store of trusted certificates, the updated store of trusted certificates being accessible by a startup manager of the data processing system while the startup manager is not in operable communication with the vendor certificate repository. Therefore, during a future startup of the data processing system, a security posture of the data processing system may be evaluated using the store of trusted certificates and operation of the data processing system may be managed based on the security posture to facilitate provisioning of desired computer-implemented services.Type: ApplicationFiled: February 25, 2025Publication date: August 27, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260252360Abstract: Methods and systems for managing operation of a data processing system are disclosed. To do so, an identification may be made that a hardware component of the data processing system is to be used to evaluate a security posture of the data processing system after startup. To do so, a set of dynamic measurements may be obtained. The set of dynamic measurements may include: (i) first measurements that indicate a first security state of the data processing system during startup, (ii) second measurements that indicate a second security state of the data processing system after the startup, and (iii) at least one reference measurement obtained from a trusted entity. The security posture may be evaluated using the set of dynamic measurements and operation of the data processing system may be managed based on the security posture to reduce a likelihood of the data processing system being compromised.Type: ApplicationFiled: February 25, 2025Publication date: August 27, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260211685Abstract: Methods and systems for managing operation of a data processing system are disclosed. To manage the operation of the data processing system, during a startup of the data processing system, it may be identified that at least one hardware component is operably connected to a management controller, is not operably connected to the startup management entity, and is compliant with a security protocol and data model (SPDM) security standard. The management controller and startup management entity may, therefore, collaboratively perform a measurement process based on the SPDM security standard to obtain a plurality of measurements. A security posture of the data processing system may be evaluated using a trusted platform module based on the plurality of measurements. Operation of the data processing system may be managed based on the security posture to reduce a likelihood of the data processing system being compromised.Type: ApplicationFiled: January 17, 2025Publication date: July 23, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260211686Abstract: Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, during a startup, a management controller may identify that at least one hardware component operably connected to the management controller is compliant with a security protocol and data model (SPDM) security standard. The management controller may perform a measurement process based on the SPDM security standard for the at least one hardware component to obtain at least one measurement. The management controller may provide the at least one measurement to an entity of the data processing system. The entity and a trusted platform module may collaboratively evaluate a security posture of the data processing system based on at least the at least one measurement. Operation of the data processing system may be managed based on the security posture to reduce a likelihood of the data processing system being compromised.Type: ApplicationFiled: January 17, 2025Publication date: July 23, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260211684Abstract: Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, during a startup of the data processing system, a list of hardware components that are compliant with a security protocol and data model (SPDM) security standard may be obtained using an existing list of hardware components that are compliant with the SPDM security standard and any new hardware components that are not identified in the existing list. A measurement process may be performed based on the SPDM security standard for hardware components listed to obtain a plurality of measurements. A security posture of the data processing system may be evaluated using a trusted platform module based on the plurality of measurements. Operation of the data processing system may be managed based on the security posture to reduce a likelihood of the data processing system being compromised.Type: ApplicationFiled: January 17, 2025Publication date: July 23, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260211654Abstract: Methods and systems for managing operation of a data processing system are disclosed. To do so, an identification may be made that a firmware update is to be performed for a hardware component of the data processing system. An update package usable to perform the firmware update may be obtained, the update package including: (i) firmware update data and (ii) a reference integrity manifest (RIM) for the firmware update data. The firmware update data and the RIM may be cryptographically verified. If the cryptographic verifications are successful, a reference value may be obtained from the RIM. A security check process may be performed based on the reference value and the firmware update data to obtain a result and operation of the data processing system may be managed based on the result to reduce a likelihood of compromise of the data processing system.Type: ApplicationFiled: January 17, 2025Publication date: July 23, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260212004Abstract: Methods and systems for managing operation of a data processing system are disclosed. To do so, after a startup of the data processing system, an identification may be made that a security check is to be performed for a hardware component of the data processing system using a measurement obtained from the hardware component and that a reference value corresponding to the measurement is not available in a references repository. Identifying information for the hardware component may be obtained and provided to a trusted entity to obtain the reference value. The identifying information may include a device identifier and a firmware version for the hardware component. The reference value and the measurement may be used to perform the security check process. Operation of the data processing system may be managed based on a result of the security check process to reduce a likelihood of the data processing system being compromised.Type: ApplicationFiled: January 17, 2025Publication date: July 23, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260212019Abstract: Methods and systems for managing operation of a data processing system are disclosed. To do so, during a startup of the data processing system, a startup policy may be obtained. The startup policy may indicate that a first portion of hardware components of the data processing system may be used to evaluate a security posture of the data processing system during startup and a second portion of the hardware components may not be used to evaluate the security posture during startup. A measurement process may be performed based on a security protocol and data model (SPDM) security standard for the first portion to obtain first measurements. The security posture may be evaluated using a trusted platform module based on the first measurements. Operation of the data processing system may be managed based on the security posture to reduce a likelihood of the data processing system being compromised.Type: ApplicationFiled: January 17, 2025Publication date: July 23, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Publication number: 20260212020Abstract: Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, during a startup of the data processing system, an entity may obtain, using a security protocol and data model (SDPM) security standard, a digest for a hardware component, the digest being based on a certificate for the hardware component. The entity may perform, using at least the digest and a store of trusted digests, an analysis process to determine a level of trust in the hardware component. If the level of trust is trusted, the entity may perform a measurement process using the SPDM security standard for the hardware component to obtain at least one measurement. The operation of the data processing system may be managed based on the at least one measurement.Type: ApplicationFiled: January 17, 2025Publication date: July 23, 2026Inventors: NICHOLAS D. GROBELNY, AMY CHRISTINE NELSON, DAVID ALBERT CONSOLVER, RAMAN SHARMA, RICHARD M. TONRY
-
Patent number: 9110963Abstract: Embodiments of methods, systems, and services for transparent adaptive file transform are described. In one embodiment a method for transparent adaptive file transform is performed by a data processing device. The method may include automatically detecting a data transfer addressed to an external data storage. The method may also include redirecting data associated with the data transfer to a data transformer. Additionally, the method may include applying one or more data transforms to the data associated with the data transfer to generate a transformed data set. In an embodiment, the method may also include transferring the transformed data set to the external data storage. In one embodiment, the external data storage is a cloud storage facility.Type: GrantFiled: April 10, 2013Date of Patent: August 18, 2015Assignee: Dell IncInventors: Christopher Burchett, Warren Robbins, James Michael Burke, James Darrell Testerman, David Albert Consolver
-
Publication number: 20130268545Abstract: Embodiments of methods, systems, and services for transparent adaptive file transform are described. In one embodiment a method for transparent adaptive file transform is performed by a data processing device. The method may include automatically detecting a data transfer addressed to an external data storage. The method may also include redirecting data associated with the data transfer to a data transformer. Additionally, the method may include applying one or more data transforms to the data associated with the data transfer to generate a transformed data set. In an embodiment, the method may also include transferring the transformed data set to the external data storage. In one embodiment, the external data storage is a cloud storage facility.Type: ApplicationFiled: April 10, 2013Publication date: October 10, 2013Applicant: Dell Inc.Inventors: Christopher Burchett, Warren Robbins, James Michael Burke, James Darrell Testerman, David Albert Consolver