Secure Installation of Baseboard Management Controller Firmware via a Physical Interface
By designing circuit devices in computing devices to deactivate and enable the physical interface between the BMC and the processor, the security attack problem and firmware installation problems when the BMC is not running are solved, and a secure and remote firmware installation is achieved.
Patent Information
- Application Number
- CN202080070284.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-10-07
- Filing Date
- 2020-08-19
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2040-08-19
AI Technical Summary
The substrate management controller (BMC) is vulnerable to security attacks when not running, and the prior art is difficult to safely install firmware when the BMC is not running.
A computing device is designed that includes circuitry for deactivating the physical interface when the BMC is not running and enabling the physical interface in response to a sequence of authorization signals received from a trusted external entity, thereby allowing firmware to be installed in the nonvolatile memory of the BMC.
It enables the ability to safely install firmware when the BMC is not running, preventing attackers from writing malicious code to the BMC, and ensuring that authorized users can remotely install firmware.
Smart Images

Figure CN114556343B_ABST
Abstract
Description
Background Art
[0001] A baseboard management controller (BMC) is a dedicated microcontroller that can be embedded on the motherboard of a computing device. In cases where multiple computing devices are connected and work together, BMCs are typically included in the computing devices because they allow a system administrator to remotely perform various tasks. For example, the system administrator can remotely communicate with the BMC to take corrective actions such as resetting the computing device or power cycling the computing device. In addition, different types of sensors built into the computing device report parameters such as temperature, cooling fan speed, power status, operating system (OS) status, etc. to the BMC. The BMC monitors the sensors and, if any of the parameters do not remain within preset limits, can send an alert to another entity (e.g., another computing device operated by the system administrator).
[0002] For various reasons, BMCs are a high-value target for malicious attackers. For example, an attacker can use the out-of-band management feature of the BMC to compromise a computing device even below the operating system and system firmware levels. Thus, BMCs are currently an active area of research for companies and other organizations concerned with security-related issues. A number of security vulnerabilities have been discovered regarding BMCs, including security vulnerabilities related to the installation of firmware within the BMC. If such security vulnerabilities are exploited, an attacker can write malicious code into the BMC firmware. Thus, benefits can be achieved through improved techniques for protecting BMCs from security attacks. Summary of the Invention
[0003] According to one aspect of the present disclosure, a computing device is disclosed that includes a processor, a memory electronically communicating with the processor, a baseband management controller (BMC) including non-volatile memory, and a physical interface between the BMC and the processor. The computing device further includes circuitry configured to deactivate the physical interface when the BMC is not running and to activate the physical interface in response to receiving an authorization signal sequence from a trusted external entity. The computing device further includes instructions stored in the memory that are executable by the processor to install firmware within the non-volatile memory of the BMC via the physical interface when the BMC is not running and the physical interface is activated.
[0004] The circuitry may include a deactivation circuitry and an activation circuitry, the deactivation circuitry being configured to deactivate the physical interface in response to detecting that the BMC has entered a reset mode, the activation circuitry being configured to activate the physical interface in response to receiving an authorization signal sequence.
[0005] The deactivation circuitry may be configured to: deactivate the physical interface in response to detecting that the BMC has entered a reset mode and the authorization signal sequence has not been received in concert with the BMC entering the reset mode.
[0006] The enabling circuit device can be configured to: enable the physical interface only for a single BMC boot sequence in response to receiving an authorization signal sequence.
[0007] The firmware can implement a logical interface between the BMC and the processor. The logical interface can be configured to verify the authenticity of the firmware. The logical interface can be unavailable when the BMC is not running.
[0008] The authorization signal sequence can include a unique sequence of binary signals. The circuit device for enabling the physical interface can include a programmable logic device programmed to identify the unique sequence.
[0009] Disabling the physical interface can include disconnecting the physical interface from the system clock, and enabling the physical interface can include connecting the physical interface to the system clock.
[0010] The computing device can be one of a plurality of computing devices located within a rack. The trusted external entity can include a rack manager.
[0011] The authorization signal sequence can be received from the trusted external entity via a secure out-of-band communication channel.
[0012] According to another aspect of the present disclosure, a system is disclosed that includes a trusted external entity and a plurality of host computing devices in electronic communication with the trusted external entity. Each host computing device of the plurality of host computing devices includes a host processor, a baseband management controller (BMC), a physical interface between the host processor and the BMC, and a circuit device. The circuit device is configured to disable the physical interface between the host processor and the BMC when the BMC is not running, and to enable the physical interface between the host processor and the BMC in response to receiving an authorization signal sequence from the trusted external entity.
[0013] Each host computing device of the plurality of host computing devices can further include a memory in electronic communication with the host processor and instructions stored in the memory. The instructions can be executable by the host processor when the BMC is not running and the physical interface is enabled to install firmware within the non-volatile memory of the BMC via the physical interface.
[0014] The circuit device can include a disabling circuit device and an enabling circuit device. The disabling circuit device is configured to disable the physical interface in response to detecting that the BMC has entered a reset mode, and the enabling circuit device is configured to enable the physical interface in response to receiving an authorization signal sequence.
[0015] The deactivation circuitry can be configured to deactivate the physical interface in response to detecting that the BMC has entered a reset mode and that an authorization signal sequence has not been received in concert with the BMC entering the reset mode.
[0016] The activation circuitry can be configured to activate the physical interface for only a single BMC boot sequence in response to receiving an authorization signal sequence.
[0017] The firmware in the BMC can implement a logical interface between the BMC and the host processor. The logical interface can be configured to verify the authenticity of the firmware. The logical interface can be unavailable when the BMC is not running.
[0018] The authorization signal sequence includes a unique sequence of binary signals. The circuitry for activating the physical interface can include a programmable logic device programmed to recognize the unique sequence.
[0019] Deactivating the physical interface can include disconnecting the physical interface from the system clock. Activating the physical interface can include connecting the physical interface to the system clock.
[0020] Multiple host computing devices can be located within a rack. The trusted external entity can include a rack manager.
[0021] The system can also include a secure out-of-band communication channel between the trusted external entity and the circuitry that receives the authorization signal sequence. The trusted external entity sends the authorization signal sequence to the circuitry via the secure out-of-band communication channel.
[0022] According to another aspect of the present disclosure, a computer-readable medium is disclosed. The computer-readable medium includes instructions executable by one or more processors to cause a computing system to detect that a baseboard management controller (BMC) within a host computing device has stopped operating, make replacement firmware available to a host processor within the host computing device, and send a signal to a trusted external entity to cause the trusted external entity to send an authorization signal sequence to the host computing device.
[0023] This Summary is provided to introduce a few concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to help determine the scope of the claimed subject matter.
[0024] Additional features and advantages will be set forth in the description which follows. The features and advantages of the present disclosure may be realized and obtained by means of the systems and methods particularly pointed out in the appended claims. The features of the present disclosure will become more fully apparent from the following description and the appended claims, or may be learned by the practice of the disclosed subject matter as set forth hereinafter. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] To describe the manner in which the above and other features of the present disclosure can be obtained, a more specific description will be presented by referring to its specific embodiments illustrated in the accompanying drawings. For better understanding, the same elements are denoted by the same reference numerals in the various drawings. Understanding that the drawings depict some exemplary embodiments, the embodiments will be described and explained with additional features and details by using the drawings, wherein:
[0026] Figure 1 An example of a system that enables firmware to be securely installed within a BMC even when the BMC is not running is illustrated.
[0027] Figure 2 An example of a method that can be performed by a system manager to securely install replacement firmware within a BMC when the BMC has stopped running is illustrated.
[0028] Figure 3 An example of a method that can be performed by a trusted external entity to securely install replacement firmware within a BMC when the BMC has stopped running is illustrated.
[0029] Figure 4 An example of a method that can be performed by a host computing device to securely install replacement firmware within a BMC when the BMC has stopped running is illustrated.
[0030] Figure 5 Another example of a system that enables firmware to be installed within a BMC even when the BMC is not running is illustrated.
[0031] Figure 6 Another example of a method that can be performed by a host computing device to securely install replacement firmware within a BMC when the BMC has stopped running is illustrated.
[0032] Figure 7 An example of multiple host computing devices that can be located within the same physical structure and can be configured to implement the techniques disclosed herein is illustrated.
[0033] Figure 8 An example of certain components that can be included within a computing device is illustrated. Detailed Description
[0034] The present disclosure generally relates to protecting a BMC from security attacks. One known security vulnerability of the BMC relates to the process of installing firmware within the BMC. Under normal circumstances, a host processor can install firmware within the BMC via a logical interface between the host processor and the BMC. The logical interface can specify certain security mechanisms that make the process of installing firmware within the BMC relatively secure. For example, the logical interface can be configured to verify the authenticity of the firmware being installed within the BMC.
[0035] The logical interface between the BMC and the host processor can be implemented, at least in part, by firmware within the BMC. Thus, the current firmware of the BMC can implement a security mechanism that enables replacement firmware to be installed securely within the BMC. However, in some cases, the BMC may stop functioning properly. When this occurs, the logical interface between the host processor and the BMC is no longer available because the logical interface depends, in part, on instructions contained within the firmware of the BMC. If the logical interface between the BMC and the host processor is unavailable, the security mechanism that enables replacement firmware to be installed securely within the BMC is also unavailable.
[0036] When the BMC is not running and the logical interface between the host processor and the BMC is unavailable, the host processor may still be able to install firmware within the BMC using only the physical interface. The host processor can control the BMC and write information (e.g., replacement firmware) across the physical interface to non-volatile memory within the BMC. Unfortunately, this mechanism for installing firmware using only the physical interface leaves the BMC vulnerable to security attacks. For example, if an attacker can gain access to the host processor, the attacker can write malicious code to the non-volatile memory of the BMC via the physical interface. Because the BMC is not running and the logical interface between the host processor and the BMC is unavailable, the security mechanism incorporated within the logical interface is unavailable to prevent such an attack.
[0037] To address this vulnerability, the physical interface between the BMC and the host processor can be disabled when the BMC is not running. Thus, even if an attacker can gain access to the host processor, the attacker cannot write any malicious code to the non-volatile memory of the BMC. However, disabling the physical interface also prevents authorized users (e.g., system administrators) from installing firmware within the BMC when the BMC is not running, which can be problematic. If the BMC is not functioning, the BMC may require firmware to be installed in order to start functioning again (reinstall the previously installed firmware, or install updated firmware). However, because the BMC is not functioning properly, the normal mechanism for installing firmware within the BMC via the logical interface is unavailable. If the physical interface between the BMC and the host processor is disabled to address the above potential security vulnerability, there is no way to remotely install firmware within the BMC. In other words, the BMC is essentially stuck in a non-operational state.
[0038] The techniques disclosed herein enable a party with appropriate authorization to install firmware within the BMC when the BMC is not running while still addressing the above security vulnerability. In other words, the techniques disclosed herein enable firmware to be installed securely within the BMC even when the BMC is not running. The BMC firmware can be installed from a remote location, which is particularly useful in an environment where the BMC firmware should be installed in multiple computing devices.
[0039] According to the present disclosure, a host computing device may include circuitry configured to disable a physical interface between a BMC and a host processor when the BMC is not operating and a logical interface between the BMC and the host processor is unavailable, thereby preventing an attacker from using the physical interface to write malicious code to the BMC. Advantageously, however, the host computing device further includes circuitry configured to enable the physical interface between the BMC and the host processor in response to receiving a unique signal sequence from a trusted external entity. Thus, when the BMC is not operating and firmware is to be installed on the BMC, a party with appropriate authorization can enable the installation of the firmware by causing the trusted external entity to send the unique signal sequence to the circuitry on the host computing device, thereby enabling the physical interface between the BMC and the host processor. Once the physical interface has been enabled, the host processor can then write the firmware across the physical interface to non-volatile memory within the BMC.
[0040] Figure 1 An example of a system 100 that enables firmware 112a to be installed within a BMC 104 even when the BMC 104 is not operating is illustrated. System 100 includes a host computing device 102 that includes a BMC 104 and a processor 106. Processor 106 may be referred to herein as host processor 106. During normal operation, BMC 104 is connected to host processor 106 via a physical interface 108 and a logical interface 110. Physical interface 108 may be, for example, a low pin count (LPC) bus, a peripheral component interconnect express (PCI-e) bus, or a universal serial bus (USB). Logical interface 110 may be, for example, an intelligent platform management interface (IPMI), a Redfish interface, or a custom interface.
[0041] BMC 104 includes firmware 112 that is stored in non-volatile memory 114 within BMC 104. Firmware 112 includes instructions executed by a processor 128 within BMC 104 to provide various functionality, including implementing logical interface 110.
[0042] During normal operation, when both the host processor 106 and the BMC 104 are operating properly, both the physical interface 108 and the logical interface 110 can be used to install replacement firmware 112a within the BMC 104. In particular, communication between the host processor 106 and the BMC 104 can occur across the physical interface 108 according to various requirements specified by the logical interface 110. The logical interface 110 can specify certain security mechanisms that make the process of installing replacement firmware 112a within the BMC 104 relatively secure. For example, the logical interface 110 can be configured to verify the authenticity of the replacement firmware 112a being installed.
[0043] In some embodiments, the replacement firmware 112a can be a reinstallation of the existing firmware 112 on the BMC 104. In other words, when the existing firmware 112 was initially installed, the replacement firmware 112a can be the same (or substantially the same) as the existing firmware 112, and the reinstallation can be performed because the existing firmware 112 has been corrupted in some way. Alternatively, the replacement firmware 112a can be an updated version of the existing firmware 112.
[0044] However, in certain cases, the BMC 104 may stop operating properly. When this occurs, the logical interface 110 between the host processor 106 and the BMC 104 is no longer available because the logical interface 110 depends in part on the instructions contained within the firmware 112.
[0045] When the BMC 104 is not running and the logical interface 110 between the host processor 106 and the BMC 104 is unavailable, the host processor 106 may install replacement firmware 112a within the BMC 104 using only the physical interface 108. In other words, the BMC 104 provides a mechanism that enables the host processor 106 to access the non-volatile memory 114 of the BMC 104 via the physical interface 108 even when the logical interface 110 is unavailable. In some embodiments, the host processor 106 can control the BMC 104 and place the BMC 104 in a reset mode. In this context, the term "reset mode" can refer to a state in which code can be written to the non-volatile memory 114 of the BMC 104. The BMC 104 can be configured such that when the BMC 104 is in the reset mode, the BMC processor 128 does not execute any code (e.g., firmware 112) stored in the non-volatile memory 114. The BMC 104 can be placed in the reset mode before the BMC 104 is rebooted. Once the BMC 104 has been placed in the reset mode, the host processor 106 can then write information (e.g., replacement firmware 112a) to the non-volatile memory 114 across the physical interface 108.
[0046] However, as described above, this mechanism of installing the firmware 112a only using the physical interface 108 makes the BMC 104 vulnerable to security attacks. For example, if an attacker can gain access to the host processor 106, the attacker can write malicious code to the non-volatile memory 114. A potential solution to this security vulnerability is to deactivate the physical interface 108 between the BMC 104 and the host processor 106 when the BMC 104 is not running. In other words, the host computing device 102 can be configured such that when the BMC 104 is running, the physical interface 108 connects the BMC 104 to the host processor 106. This allows the physical interface 108 and the logical interface 110 to be used to install the replacement firmware 112a in the manner described above. However, when the BMC 104 is not running, the physical interface 108 between the BMC 104 and the host processor 106 can be deactivated to prevent malicious attacks on the BMC 104.
[0047] It is important that deactivating the physical interface 108 between the BMC 104 and the host processor 106 when the BMC 104 is not running prevents an attacker from being able to write malicious code to the firmware 112. However, deactivating the physical interface 108 when the BMC 104 is not running also prevents an authorized user (e.g., a system administrator) from installing the replacement firmware 112a within the BMC 104.
[0048] To enable a person with appropriate authorization to potentially install the replacement firmware 112a within the BMC 104, the host computing device 102 includes circuitry 116 that is configured to enable the physical interface 108 between the BMC 104 and the host processor 106 in response to receiving an authorization signal sequence 118 from another entity 120. Thus, when the BMC 104 is not running, a party with appropriate authorization can make it possible to install the replacement firmware 112a within the BMC 104 by causing the entity 120 to send the authorization signal sequence 118 to the circuitry 116 on the host computing device 102, thereby enabling the physical interface 108 between the BMC 104 and the host processor 106. Once the physical interface 108 has been enabled, the host processor 106 can then write the replacement firmware 112a across the physical interface 108 to the non-volatile memory 114 within the BMC 104.
[0049] The entity 120 that sends the authorization signal sequence 118 can be external to the host computing device 102. In other words, the entity 120 that sends the authorization signal sequence 118 can be separate from and exist independently of the host computing device 102. Additionally, the entity 120 that sends the authorization signal sequence 118 can be trusted by the host computing device 102. In other words, the entity 120 that sends the authorization signal sequence 118 can be known to the host computing device 102, and the host computing device 102 can be configured to rely on communications from the entity 120. For example, the host computing device 102 can be configured to perform an action when the entity 120 indicates to perform the action. Because the entity 120 is external to and trusted by the host computing device 102, the entity 120 can be referred to as the trusted external entity 120.
[0050] The circuitry 116 can be configured to: deactivate the physical interface 108 whenever the BMC 104 enters the reset mode, unless the circuitry 116 has received the authorization signal sequence 118 from the trusted external entity 120. In some embodiments, if the BMC 104 enters the reset mode and the authorization signal sequence 118 is not received in concert with the BMC 104 entering the reset mode, the circuitry 116 deactivates the physical interface 108. On the other hand, the circuitry 116 can be configured to: activate the physical interface 108 if the BMC 104 enters the reset mode and the authorization signal sequence 118 is received from the trusted external entity 120 in concert with the BMC 104 entering the reset mode.
[0051] In some embodiments, the circuitry 116 can be configured to activate the physical interface 108 for a limited duration in response to receiving the authorization signal sequence 118. For example, the circuitry 116 can be configured to: in response to receiving the authorization signal sequence 118, activate the physical interface 108 only for a single boot sequence of the BMC 104. This allows the host processor 106 to install the replacement firmware 112a within the non-volatile memory 114 of the BMC 104 and reboot the BMC 104. If the BMC 104 starts working again after being rebooted with the firmware 112a, the physical interface 108 can be activated because the logical interface 110 is available to protect against the installation of malicious code in the BMC 104. However, if the BMC 104 still does not run after being rebooted with the firmware 112a, after the boot sequence has ended, the physical interface 108 can be deactivated again to protect against the above security vulnerabilities.
[0052] Figure 1 Illustrates the host processor 106 on the host computing device 102 receiving the replacement firmware 112a from the system manager 122. Figure 1It is also shown that the host processor 106 receives a command 126 from the system manager 122 to install replacement firmware 112a on the BMC 104. In addition to providing the replacement firmware 112a and the command 126 to the host processor 106, it is shown that the system manager 122 provides a signal 124 to a trusted external entity 120, and this signal 124 causes the trusted external entity 120 to send an authorization signal sequence 118 to the circuitry 116 on the host computing device 102. The communication between the trusted external entity 120 and the circuitry 116 can occur via a secure communication channel, making it extremely unlikely for an attacker to gain access to or compromise such communication.
[0053] The system manager 122 can represent a service that performs management functions for the host computing device 102. In some embodiments, the host computing device 102 can be one of multiple host computing devices for which the system manager 122 performs management functions. In some embodiments, the host computing device 102 can be one of multiple bare-metal servers leased to a customer, and the system manager 122 can represent a service that performs management functions for the bare-metal server. As another example, the host computing device 102 can be one of multiple host computing devices that are part of a distributed computing system (e.g., a cloud computing system). The system manager 122 can represent a service that performs management functions for the distributed computing system.
[0054] Figure 1 The illustrated system 100 achieves the above two objectives. First, the host computing device 102 is configured such that it is extremely unlikely for an attacker to write malicious code to the BMC 104. Second, the host computing device 102 is configured such that an authorized user can still install replacement firmware 112a within the BMC 104 from a remote location even when the BMC 104 is not running.
[0055] Regarding the first objective, assume that an attacker is able to gain access to the host processor 106. As described above, the BMC 104 provides a mechanism that enables the host processor 106 to access the non-volatile memory 114 of the BMC 104 via the physical interface 108 even when the BMC 104 is not running and the logical interface 110 between the BMC 104 and the host processor 106 is unavailable. However, in Figure 1 the illustrated system 100, when the BMC 104 is not running (e.g., when the BMC 104 enters the reset mode), the circuitry 116 on the host computing device 102 deactivates the physical interface 108, thereby preventing an attacker from exploiting this mechanism and writing malicious code to the BMC 104 via the physical interface 108.
[0056] Regarding the second objective, even when the BMC 104 is not running, an authorized user may install replacement firmware 112a in the BMC 104 by causing a trusted external entity 120 to send an authorization signal sequence 118 to circuitry 116 on the host computing device 102. The authorization signal sequence 118 causes the circuitry 116 on the host computing device 102 to enable the physical interface 108 between the BMC 104 and the host processor 106. Once the physical interface 108 has been enabled, the host processor 106 may write the replacement firmware 112a across the physical interface 108 into the non-volatile memory 114 within the BMC 104.
[0057] In Figure 1 the illustrated system 100, the host computing device 102 is generally shown as having circuitry 116 that deactivates the physical interface 108 between the BMC 104 and the host processor 106 when the BMC 104 is not running and also enables the physical interface 108 in response to receiving an authorization signal sequence 118 from the trusted external entity 120. In alternative embodiments, the host computing device 102 may include different circuitry for performing these actions. For example, the host computing device 102 may include a deactivation circuitry and an enabling circuitry, the deactivation circuitry being configured to deactivate the physical interface 108 between the BMC 104 and the host processor 106 when the BMC 104 is not running, and the enabling circuitry being configured to enable the physical interface 108 in response to receiving an authorization signal sequence 118 from the trusted external entity 120.
[0058] Although Figure 1 the replacement firmware 112a and the command 126 are shown separately, this does not mean that the replacement firmware 112a and the command 126 must be sent to the host processor 106 in separate communications. In some embodiments, the replacement firmware 112a and the command 126 may be sent to the host processor 106 in the same communication (e.g., the same message) sent by the system manager 122 to the host processor 106. However, in some other embodiments, the replacement firmware 112a and the command 126 may be sent to the host processor 106 in separate communications (e.g., separate messages) sent by the system manager 122 to the host processor 106.
[0059] Figure 2 An example of a method 200 that may be executable by the system manager 122 to securely install replacement firmware 112a in the BMC 104 when the BMC 104 has stopped running is illustrated. Method 200 will be described with respect to Figure 1 the system manager 122 and other components in the illustrated system 100.
[0060] According to method 200, system manager 122 may detect (202) that BMC 204 has stopped running. This can occur in many different ways. For example, system manager 122 may send a signal to BMC 104 (e.g., via host processor 106) which, if BMC 104 is operating properly, would trigger a response from BMC 104. If BMC 104 does not respond to the signal, system manager 122 may infer that BMC 104 has stopped running. As another example, another entity (e.g., an entity on host computing device 102) may determine that BMC 204 has stopped running and report it to system manager 122.
[0061] In response to detecting (202) that BMC 204 has stopped running, system manager 122 may make (204) replacement firmware 112a available to host processor 106. In some embodiments, system manager 122 may send replacement firmware 112a to host processor 106. In some other embodiments, system manager 122 may send a link to host processor 106 to a location where replacement firmware 112a can be accessed and downloaded.
[0062] System manager 122 may also send (206) command 126 to host processor 106 to install replacement firmware 112a on BMC 104. As described above, replacement firmware 112a and command 126 to install replacement firmware 112a may be sent in the same communication (e.g., the same message) or in different communications (e.g., different messages).
[0063] In addition, system manager 122 may also send (208) signal 124 to trusted external entity 120 which causes trusted external entity 120 to send an authorization signal sequence 118 to host computing device 102. Host computing device 102 includes circuitry 116 configured to recognize authorization signal sequence 118. In response to receiving and recognizing authorization signal sequence 118, circuitry 116 enables physical interface 108 between BMC 104 and host processor 106. Once physical interface 108 has been enabled, then host processor 106 may write replacement firmware 112a across physical interface 108 into non-volatile memory 114 within BMC 104.
[0064] Figure 3 Illustrated is an example of method 300 that may be performed by trusted external entity 120 to securely install replacement firmware 112a within BMC 104 when BMC 104 stops running. Method 300 will be described with respect to Figure 1 trusted external entity 120 and other components in the illustrated system 100.
[0065] According to method 300, a trusted external entity 120 may receive (302) a signal 124 from a system manager 122. The signal 124 may include (or may be interpreted as including) instructions to send an authorization signal sequence 118 to a host computing device 102.
[0066] In response to receiving (302) the signal 124 from the system manager 122, the trusted external entity 120 may send (304) the authorization signal sequence 118 to the host computing device 102. As described above, the authorization signal sequence 118 enables circuitry 116 within the host computing device 102 to enable a physical interface 108 between the BMC 104 and the host processor 106 such that the host processor 106 may write replacement firmware 112a across the physical interface 108 to non-volatile memory 114 within the BMC 104.
[0067] Figure 4 An example of a method 400 that may be executed by a host computing device 102 to securely install replacement firmware 112a within a BMC 104 when the BMC 104 has stopped operating is illustrated. Method 400 will be described with respect to Figure 1 the host computing device 102 and other components within the illustrated system 100. Some of the actions included in method 400 may be executed by a host processor 106 that executes instructions stored in a memory within the host computing device 102, and some of the actions included in method 400 may be executed by circuitry 116 within the host computing device 102.
[0068] According to method 400, a host processor 106 within the host computing device 102 may receive (402) replacement firmware 112a from a system manager 122. In some embodiments, the host processor 106 may directly receive (402) the replacement firmware 112a from the system manager 122. In some other embodiments, the host processor 106 may receive (402) information (e.g., a link) from the system manager 122 that enables the host processor 106 to access and download the replacement firmware 112a from another location.
[0069] The host processor 106 may also receive (404) a command 126 to install the replacement firmware 112a on the BMC 104. In response to receiving (402) the replacement firmware 112a and receiving (404) the command 126 to install the replacement firmware 112a, the host processor 106 may cause the BMC 104 to enter (406) a reset mode. For example, the host processor 106 may send one or more commands to the BMC 104 that cause the BMC 104 to enter the reset mode.
[0070] The circuit device 116 can detect (408) that the BMC 104 has entered the reset mode. In response to detecting (408) that the BMC 104 has entered the reset mode, the circuit device 116 can determine (410) whether the authorization signal sequence 118 has been received from the trusted external entity 120. If the authorization signal sequence 118 has been received from the trusted external entity 120, the circuit device 116 can enable (412) the physical interface 108 between the BMC 104 and the host processor 106. As described above, enabling (412) the physical interface 108 between the BMC 104 and the host processor 106 allows the host processor 106 to write (414) the replacement firmware 112a into the non-volatile memory 114 within the BMC 104.
[0071] As described above, the circuit device 116 can be configured to enable (412) the physical interface 108 for a limited duration in response to receiving the authorization signal sequence 118. For example, the circuit device 116 can be configured to enable the physical interface 108 only for a single boot sequence of the BMC 104 in response to receiving the authorization signal sequence 118. If the BMC 104 starts working again after being rebooted with the firmware 112a, the physical interface 108 can be enabled because the logical interface 110 can be used to protect against the installation of malicious code in the BMC 104. However, if the BMC 104 still does not run even after being rebooted with the replacement firmware 112a, the physical interface 108 can be deactivated again after the boot sequence has ended to protect against the above security vulnerabilities.
[0072] If it is determined (410) that the authorization signal sequence 118 has not been received from the trusted external entity 120, the circuit device 116 can deactivate (416) the physical interface 108 between the BMC 104 and the host processor 106. Deactivating (416) the physical interface 108 between the BMC 104 and the host processor 106 prevents the host processor 106 from writing anything into the non-volatile memory 114 within the BMC 104. As described above, this feature is advantageous if an attacker has gained access to the host processor 106 and attempts to write malicious code into the non-volatile memory 114 within the BMC 104.
[0073] In some embodiments, whenever the BMC 104 enters a reset mode, the circuitry 116 deactivates the physical interface 108, unless an authorization signal sequence 118 is received from a trusted external entity 120 in concert with the BMC 104 entering the reset mode. In other words, in some embodiments, the circuitry 116 may be configured to: by default, deactivate the physical interface 108 whenever the BMC 104 enters a reset mode, and the circuitry 116 may also be configured to change that default condition only if (a) an authorization signal sequence 118 is received from a trusted external entity 120, and (b) there is some relationship (e.g., a temporal relationship) between the receipt of the authorization signal sequence 118 and the BMC 104 entering the reset mode. In some embodiments, if the authorization signal sequence 118 is received at the same time (or substantially the same time) as the BMC 104 enters the reset mode, the authorization signal sequence 118 may be considered to be received in concert with the BMC 104 entering the reset mode. In some other embodiments, the authorization signal sequence 118 may be considered to be received in concert with the BMC 104 entering the reset mode if the authorization signal sequence 118 is received within a certain time period (before or after) starting from when the BMC 104 enters the reset mode. This time period may be predefined as a (possibly configurable) parameter and stored in the memory of the host computing device 102.
[0074] Figure 5 Another example of a system 500 that is capable of installing firmware 512a within the BMC 504 even when the BMC 504 is not running is illustrated. Except as described below, Figure 5 The system 500 shown in Figure 1 is similar to the system 100 shown in
[0075] In Figure 5 the system 500 shown, the host computing device 502 includes enabling circuitry 516a that is configured to enable the physical interface 508 between the BMC 504 and the host processor 506 in response to receiving an authorization signal sequence 518 from a trusted external entity. The host computing device 502 also includes disabling circuitry 516b that is configured to disable the physical interface 508 when the BMC 504 is not running and the logical interface 510 between the BMC 504 and the host processor 506 is unavailable. In summary, the enabling circuitry 516a and the disabling circuitry 516b represent Figure 1 a possible implementation of the circuitry 116 in the system 100 shown in
[0076] In the depicted system 500, the enabling and disabling of the physical interface 508 may be achieved by connecting and disconnecting the physical interface 508 from the system clock 542. Figure 5A switch 546 between a system clock 542 and a physical interface 508 is shown. When a disabling circuit device 516b detects that the BMC 504 is not operating (e.g., the BMC 504 has entered a reset mode), the disabling circuit device 516b can configure the switch 546 such that the physical interface 508 is disconnected from the system clock 542. When an enabling circuit device 516a receives an authorization signal sequence 518, the enabling circuit device 516a can configure the switch 546 such that the physical interface 508 is connected to the system clock 542.
[0077] In some embodiments, the enabling circuit device 516a can be a programmable logic device (PLD) that has been programmed to recognize the authorization signal sequence 518. The authorization signal sequence 518 can be a unique sequence of binary signals. For example, the authorization signal sequence can be a sequence of high and low signals, and the durations of the high and low signals can be selected such that the entire sequence is unique. The authorization signal sequence 518 can be predefined. For example, prior to receiving the authorization signal sequence 518, the enabling circuit device 516a can be programmed to recognize the unique pattern formed by the authorization signal sequence 518. Additionally, the enabling circuit device 516a can be programmed to enable the physical interface 508 in response to recognizing the unique pattern formed by the authorization signal sequence 518.
[0078] The host computing device 502 can be one of multiple host computing devices located within the same physical structure (such as a rack). The trusted external entity that sends the authorization signal sequence 518 to the enabling circuit device 516a can be an entity that manages all of the host computing devices within the same rack of host computing devices. Such an entity can be referred to herein as a rack manager 520. Figure 5 A secure communication channel 544 between the rack manager 520 and the host computing device 502 is shown. The rack manager 520 can be configured to send the authorization signal sequence 518 to the enabling circuit device 516a via the secure communication channel 544.
[0079] The rack manager 520 can communicate electronically with a system manager 522 via a connection to a computer network 548. The host computing device 502 can also be connected to the network 548. The network 548 can be a wide area network (WAN) or a local area network (LAN). In some embodiments, the network 548 can include the Internet. Communication across the network 548 can occur via wireless and / or wired connections.
[0080] The system manager 522 can use its connection to the network 548 to provide replacement firmware 512a to be installed in the non-volatile memory 514 within the BMC 504 to the host computing device 502. The system manager 522 can also use its connection to the network 548 to send a signal to the rack manager 520 that causes the rack manager 520 to send an authorization signal sequence 518 to the enabling circuitry 516a within the host computing device 502 via the secure communication channel 544.
[0081] The secure communication channel 544 between the rack manager 520 and the host computing device 502 can be considered an out-of-band communication channel. Generally speaking, an out-of-band communication channel can refer to a communication channel that is separate from the main communication channel. In the depicted system 500, the main communication channel between the rack manager 520 and the host computing device 502 can occur via the network 548. Many of the communications between the rack manager 520 and the host computing device 502 can occur via the main communication channel (i.e., via the network 548). However, sending the authorization signal sequence 518 to the enabling circuitry 516a within the host computing device 502 can occur via the secure out-of-band communication channel 544.
[0082] Figure 6 Another example of a method 600 that can be executed by the host computing device 502 to securely install replacement firmware 512a within the BMC 504 when the BMC 504 has stopped operating is illustrated. Method 600 will be described with respect to Figure 5 the host computing device 502 and other components in the shown system 500. Some of the actions included in method 600 can be executed by the host processor 506 that executes instructions stored in the memory within the host computing device 502, and some of the actions included in method 600 can be executed by the circuitry 516 within the host computing device 502.
[0083] The first few actions of method 600 are similar to the first few actions of method 400 discussed above in connection with Figure 4 The host processor 506 within the host computing device 502 can receive (602) the replacement firmware 512a from the system manager 522. The host processor 506 can also receive (604) a command to install the replacement firmware 512a on the BMC 504. In response to receiving (602) the replacement firmware 512a and receiving (604) the command to install the replacement firmware 512a, the host processor 506 can cause the BMC 504 to enter (606) the reset mode.
[0084] In the depicted method 600, the disable circuitry 516b detects (608) that the BMC 504 has entered the reset mode. The disable circuitry 516b can be configured to disable the physical interface 508 whenever the BMC 504 enters the reset mode, unless an authorization signal sequence 518 has been received from a trusted external entity 520. Accordingly, method 600 also includes determining (610) whether the authorization signal sequence 518 has been received from a trusted external entity such as the rack manager 520.
[0085] If the authorization signal sequence 518 has been received from the rack manager 520, the enable circuitry 516a can temporarily connect (612) the physical interface 508 to the system clock 542. In other words, the enable circuitry 516a can connect (612) the physical interface 508 to the system clock 542 for a limited duration, such as a single boot sequence of the BMC 504. This allows the host processor 506 to write (614) replacement firmware 512a across the physical interface 508 to the non-volatile memory 514 within the BMC 504, as described above. The host processor 506 can then reboot (616) the BMC 504.
[0086] Method 600 also includes determining (618) whether the BMC 504 is running after the BMC 504 has been rebooted. If the BMC 504 is running, the physical interface 508 can remain (620) connected to the system clock 542 because the security mechanisms within the logic interface 510 are available to protect against the installation of malicious code in the BMC 504. However, if the BMC 504 is not running, the disable circuitry 516b can disconnect (622) the physical interface 508 from the system clock 542 in order to protect the BMC 504 from the security vulnerabilities described above.
[0087] As described above, the techniques disclosed herein can be implemented in a system including multiple computing devices having BMCs. In some embodiments, the multiple computing devices can be located within the same physical fabric, such as a rack. The trusted external entity that sends the authorization signal sequence to the circuitry within the computing device can be a rack manager (i.e., the entity that performs management operations on the host computing devices within the rack).
[0088] Figure 7FIG. illustrates an example of a plurality of host computing devices 702 that may be located within the same physical structure such as a rack 754 and may be configured to implement the techniques disclosed herein. Each host computing device 702 includes a BMC 704, a host processor 706, and a physical interface 708 between the BMC 704 and the host processor 706. Each host computing device 702 also includes circuitry 716 configured to deactivate the physical interface 708 when the BMC 704 is not operating and to activate the physical interface 708 in response to receiving an authorization signal sequence from a trusted external entity.
[0089] In the depicted embodiment, the trusted external entity may be a rack manager 720 responsible for performing management operations regarding the host computing devices 702 within the rack 754. The rack manager 720 is shown to communicate electronically with the host computing devices 702 via a power distribution unit (PDU) 758. The rack manager 720 may send an authorization signal sequence to the circuitry 716 within one or more of the host computing devices 702 via the PDU 758.
[0090] Figure 7 Also shown is that the rack manager 720 and the host computing devices 702 communicate electronically with a network switch 756 that supports a connection to a network such as Figure 5 the network 548 shown. Thus, the rack manager 720 is able to communicate with the host computing devices 702 via the network connection. This network connection may be considered the primary communication channel (or communication path) between the rack manager 720 and the host computing devices 702. The communication channel (or communication path) from the rack manager 720 to the circuitry 716 within the host computing devices 702 via the PDU 758 may be considered an out-of-band communication channel (or communication path).
[0091] The techniques disclosed herein can be applicable to service providers that lease bare-metal servers to customers. For example, the host computing device 702 in the rack 754 can be a bare-metal server leased to a customer. In this context, the term "bare-metal server" can refer to a host machine with a single tenant. In other words, a bare-metal server is dedicated entirely to a single customer that leases the bare-metal server (as opposed to being shared among customers). A service provider that leases bare-metal servers to customers generally does not control the type of software that a customer runs on the server. A customer may install malware on the server (either inadvertently or perhaps even deliberately). If such software can write malicious code to the BMC firmware, the entire server may become compromised. A policy of disconnecting the physical interface between the BMC and the host processor protects against such security vulnerabilities. Thus, a bare-metal server provider can utilize this policy to protect its bare-metal servers from being compromised. However, as described above, disconnecting the physical interface between the BMC and the host processor makes it impossible to install firmware within the BMC. Thus, a bare-metal server provider can use the techniques disclosed herein to enable the BMC firmware to be updated within its bare-metal servers while still protecting its bare-metal servers from the security vulnerabilities described above.
[0092] As described above, the techniques disclosed herein relate to installing firmware within a BMC. In this context, the term "install" (and its grammatical variants) can refer to the process of transferring firmware into non-volatile memory within the BMC and preparing the firmware for execution by the BMC's processor. In some embodiments, the firmware installed within the BMC can be an updated version of the firmware that is currently present within the BMC. In some other embodiments, the firmware installed within the BMC can be the same (or substantially the same) as the firmware that is currently present within the BMC. In such a case, the installation of the firmware can substantially be a reinstallation of the same firmware that was previously installed. Depending on the circumstances, either type of installation can be performed in response to detecting that the BMC has stopped operating. If updated firmware is available, the updated firmware can be installed within the BMC as part of an attempt to get the BMC to start operating again. However, if only the same version of the firmware is available, the same firmware can be reinstalled within the BMC in an attempt to get the BMC to start operating again.
[0093] One or more computing devices 800 can be used to implement at least some aspects of the techniques disclosed herein. Figure 8 Certain components that can be included within the computing device 800 are illustrated.
[0094] The computing device 800 includes a processor 801 and a memory 803 that is in electronic communication with the processor 801. Instructions 805 and data 807 can be stored in the memory 803. The instructions 805 can be executable by the processor 801 to implement some or all of the methods, steps, operations, actions, or other functionality disclosed herein. Executing the instructions 805 can involve using the data 807 stored in the memory 803. Unless otherwise specified, in any of the various examples of the modules and components described herein, they can be implemented partially or fully as instructions 805 stored in the memory 803 and executed by the processor 801. Any of the various examples of data described herein can be the data 807 stored in the memory 803 and used during the execution of the instructions 805 by the processor 801.
[0095] Although only a single processor 801 is shown in the Figure 8 computing device 800, in alternative configurations, a combination of processors (e.g., ARM and DSP) can be used.
[0096] The computing device 800 can also include one or more communication interfaces 809 for communicating with other electronic devices. The (multiple) communication interfaces 809 can be based on wired communication technologies, wireless communication technologies, or both. Some examples of the communication interface 809 include Universal Serial Bus (USB), Ethernet adapter, wireless adapter operating according to the Institute of Electrical and Electronics Engineers (IEEE) 802.11 wireless communication protocol, wireless communication adapter, and infrared (IR) communication port.
[0097] The computing device 800 can also include one or more input devices 811 and one or more output devices 813. Some examples of the input device 811 include keyboard, mouse, microphone, remote control device, button, joystick, trackball, touchpad, and light pen. A particular type of output device 813 that is typically included in the computing device 800 is a display device 815. The display device 815 used in conjunction with the embodiments disclosed herein can utilize any suitable image projection technology, such as liquid crystal display (LCD), light emitting diode (LED), gas plasma, electroluminescence, etc. A display controller 817 can also be provided for converting the data 807 stored in the memory 803 into text, graphics, and / or moving images (as appropriate) shown on the display device 815. The computing device 800 can also include other types of output devices 813, such as speakers, printers, etc.
[0098] The various components of the computing device 800 can be coupled together by one or more buses, which can include a power bus, a control signal bus, a status signal bus, a data bus, etc. For the sake of clarity, in Figure 8Each bus is illustrated as a bus system 819.
[0099] Unless explicitly described as implemented in a specific manner, the techniques disclosed herein may be implemented in hardware, software, firmware, or any combination thereof. Any features described as modules, components, etc. may also be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be at least partially implemented by a non-transitory computer-readable medium storing computer-executable instructions that, when executed by at least one processor, perform some or all of the steps, operations, actions, or other functionality disclosed herein. The instructions may be organized into routines, programs, objects, components, data structures, etc., which may perform specific tasks and / or implement specific data types, and which may be combined or distributed as desired in various embodiments.
[0100] The term "processor" may refer to a general-purpose single-chip or multi-chip microprocessor (e.g., an Advanced RISC (Reduced Instruction Set Computer) Machine (ARM)), a dedicated microprocessor (e.g., a Digital Signal Processor (DSP)), a microcontroller, a programmable gate array, etc. The processor may be a central processing unit (CPU). In some embodiments, a combination of processors (e.g., an ARM and a DSP) may be used to implement some or all of the techniques disclosed herein.
[0101] The term "memory" may refer to any electronic component capable of storing electronic information. By way of example, the memory may be implemented as random access memory (RAM), read-only memory (ROM), disk storage media, optical storage media, flash devices in RAM, on-board memory included with a processor, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM) memory, registers, etc., including combinations thereof.
[0102] As an example, the term "circuitry" may refer to one or more integrated circuits, where an integrated circuit may include a set of electronic circuits on a piece of semiconductor material (e.g., silicon). In some embodiments, the circuitry may include programmable logic devices, such as a field programmable gate array (FPGA) and / or a complex programmable logic device (CPLD). In some embodiments, the circuitry may include an application specific integrated circuit (ASIC). As another example, the term "circuitry" may refer to one or more discrete electronic circuits including individual electronic components. As another example, the term "circuitry" may refer to a digital circuit, an analog circuit, or a mixed-signal circuit. "Circuitry" may also include combinations of the foregoing.
[0103] The steps, operations, and / or acts of the methods described herein may be interchanged with one another without departing from the scope of the claims. In other words, unless the proper operation of the methods described requires a particular order of steps, operations, and / or acts, the order and / or use of particular steps, operations, and / or acts may be modified without departing from the scope of the claims.
[0104] The term "determine" (and its grammatical variants) can encompass a variety of actions. For example, "determine" can include calculating, computing, processing, deriving, investigating, looking up (e.g., looking up in a table, database, or another data structure), ascertaining, etc. Additionally, "determine" can include receiving (e.g., receiving information), accessing (e.g., accessing data in a memory), etc. Moreover, "determine" can include parsing, selecting, picking, establishing, etc.
[0105] The terms "comprising", "including", and "having" are intended to be inclusive and mean that there may be additional elements other than the listed elements. Additionally, it should be understood that references to "an embodiment" or "embodiments" of the present disclosure are not to be construed as excluding the existence of additional embodiments that also incorporate the recited features. For example, where compatible, any element or feature described with respect to an embodiment herein may be combined with any element or feature of any other embodiment described herein.
[0106] The present disclosure may be embodied in other specific forms without departing from its spirit or characteristics. The described embodiments are to be considered illustrative rather than restrictive. Accordingly, the scope of the present disclosure is indicated by the appended claims rather than by the foregoing description. Changes within the meaning and range of equivalents of the claims will be included within its scope.
Claims
1. A computing device, comprising: a processor; a memory electronically communicating with the processor; a baseband management controller (BMC) including non-volatile memory; a physical interface between the BMC and the processor; a deactivation circuitry configured to deactivate the physical interface in response to detecting that the BMC has entered a reset mode; an enabling circuitry configured to enable the physical interface in response to receiving an authorization signal sequence from a trusted external entity; and instructions stored in the memory, the instructions executable by the processor to install firmware in the non-volatile memory of the BMC via the physical interface when the BMC is not operating and the physical interface is enabled.
2. The computing device according to claim 1, wherein the deactivation circuitry is configured to: deactivate the physical interface in response to detecting that the BMC has entered the reset mode and the authorization signal sequence has not been received in concert with the BMC entering the reset mode.
3. The computing device according to claim 1, wherein the enabling circuitry is configured to enable the physical interface in response to receiving the authorization signal sequence only for a single BMC boot sequence.
4. The computing device according to claim 1, wherein: the firmware implements a logical interface between the BMC and the processor; the logical interface is configured to verify the authenticity of the firmware; and the logical interface is unavailable when the BMC is not operating.
5. The computing device according to claim 1, wherein: the authorization signal sequence includes a unique sequence of binary signals; and the circuitry for enabling the physical interface includes a programmable logic device programmed to identify the unique sequence.
6. The computing device according to claim 1, wherein: deactivating the physical interface includes disconnecting the physical interface from a system clock; and enabling the physical interface includes connecting the physical interface to the system clock.
7. The computing device according to claim 1, wherein: the computing device is one of a plurality of computing devices located within a rack; and the trusted external entity includes a rack manager.
8. The computing device according to claim 1, wherein the authorization signal sequence is received from the trusted external entity via a secure out-of-band communication channel.
9. A system, comprising: a trusted external entity; and a plurality of host computing devices electronically communicating with the trusted external entity, wherein each host computing device of the plurality of host computing devices includes a host processor, a baseband management controller (BMC), a physical interface between the host processor and the BMC, and circuitry configured to: deactivate the physical interface between the host processor and the BMC in response to detecting that the BMC has entered a reset mode; and In response to receiving an authorization signal sequence from the trusted external entity, the physical interface between the host processor and the BMC is enabled.
10. The system according to claim 9, wherein each host computing device among the plurality of host computing devices further comprises: a memory in electronic communication with the host processor; and instructions stored in the memory, the instructions being executable by the host processor to install firmware in the non-volatile memory of the BMC via the physical interface when the BMC is not running and the physical interface is enabled.
11. The system according to claim 9, wherein the circuitry includes a deactivation circuitry configured to: in response to detecting that the BMC has entered the reset mode and the authorization signal sequence has not been received in coordination with the BMC entering the reset mode, deactivate the physical interface.
12. The system according to claim 9, wherein the circuitry includes an enabling circuitry configured to enable the physical interface only for a single BMC boot sequence in response to receiving the authorization signal sequence.
13. The system according to claim 9, wherein: the firmware in the BMC implements a logical interface between the BMC and the host processor; the logical interface is configured to verify the authenticity of the firmware; and the logical interface is unavailable when the BMC is not running.
14. The system according to claim 9, wherein: the authorization signal sequence includes a unique sequence of binary signals; and the circuitry for enabling the physical interface includes a programmable logic device programmed to identify the unique sequence.
15. The system according to claim 9, wherein: deactivating the physical interface includes disconnecting the physical interface from the system clock; and enabling the physical interface includes connecting the physical interface to the system clock.
16. The system according to claim 9, wherein: the plurality of host computing devices are located within a rack; and the trusted external entity includes a rack manager.
17. The system according to claim 9, further comprises: a secure out-of-band communication channel between the trusted external entity and the circuitry for receiving the authorization signal sequence, wherein the trusted external entity sends the authorization signal sequence to the circuitry via the secure out-of-band communication channel.
18. A computer-readable medium comprising instructions executable by one or more processors to cause a computing system to perform the following operations: detect that a baseband management controller (BMC) within a host computing device has stopped running; make replacement firmware available to a host processor within the host computing device; and send a signal to a trusted external entity to cause the trusted external entity to send an authorization signal sequence to the host computing device, wherein the trusted external entity is external to the host computing device and wherein the authorization signal sequence causes a physical interface between the BMC and the host computing device to be enabled.
Citation Information
Patent Citations
Systems and methods for secure recovery of host system code
CN109791515A
Secure execution environment on a server
CN110073355A