An agentic ai security adjudication method and system for server baseboard management chips

CN122839448APending Publication Date: 2026-09-29SHANGHAI FANGYI WANQIANG MICROELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611341148.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-09-01
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

第一,现有BMC管理接口直接面向Redfish、IPMI或脚本命令,缺乏对Agent管理动作请求的语义识别能力,无法识别Agent所意图控制的目标硬件对象及其意图控制行为

Benefits of technology

第一,通过步骤S1接收指示目标硬件对象及意图控制行为的管理动作请求,使BMC能够在动作进入硬件控制域之前识别Agent的语义意图,克服了现有BMC无法感知Agent动作语义的技术缺陷。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122839448A_ABST
    Figure CN122839448A_ABST
Patent Text Reader

Abstract

The application provides an Agentic AI security decision method and system for a server baseboard management chip, relates to the technical field of intelligent operation and maintenance, and comprises the following steps: receiving an intention control type management action request of an upper Agentic AI system for a target hardware object; collecting target hardware and server hardware running context data in real time in a chip management domain; fusing a control intention, hardware context and a local security strategy to complete dynamic security decision; isolating an upper AI direct connection bottom layer hardware control channel after decision release, and executing a hardware management action by relying on a chip built-in controlled tool sandbox agent. The beneficial effects are as follows: the Agent action semantics can be identified in advance, and the semantic perception ability defect of the BMC is made up; dynamic security verification is realized by relying on real-time hardware context, and the limitation of static permission control is broken through; the bottom layer register direct control is isolated by the sandbox agent, the operation is executed after parameter verification, and the risk of hardware damage and business interruption caused by AI decision abnormity is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent operation and maintenance technology, and in particular to an Agentic AI security adjudication method and system for server baseboard management chips. Background Technology

[0002] The Baseboard Management Controller (BMC) is a core component for out-of-band server management, enabling independent monitoring and management of server hardware even when the host is unavailable. Existing BMCs typically support management interfaces such as Redfish and IPMI, and can collect telemetry information such as temperature, voltage, and fan speed, as well as perform management actions such as power-on / off, restart, fan policy adjustment, power consumption limiting, and firmware updates.

[0003] In recent years, agentic AI systems have gradually moved from question-and-answer interactions to task execution chains, enabling them to proactively invoke management tools to perform specific operational and maintenance tasks on servers. However, the generation of agent actions is dynamic and uncertain, and may lead to misjudgments based on model inference or historical experience. Existing technologies suffer from at least the following problems: First, the existing BMC management interface directly faces Redfish, IPMI, or script commands, lacking the semantic recognition capability for Agent management action requests, and unable to identify the target hardware object that the Agent intends to control and its intended control behavior.

[0004] Second, existing BMC access control mainly relies on static restrictions based on user roles or command permissions, lacking dynamic correlation with the server's current real-time hardware operating context (such as temperature, power consumption, fan speed, host heartbeat, etc.), and cannot combine the target hardware object and the server's local hardware operating context data for security verification.

[0005] Third, the existing BMC does not effectively isolate the upper-layer agent system from the underlying hardware physical control path after receiving management commands. Once the agent's action passes the interface layer permission verification, it can directly access the PMBus bus, power control register, fan PWM / Tach control register, BIOS flash write pin, and various underlying hardware physical debugging interfaces, exposing the underlying hardware control path to the risk of the agent's autonomous decision-making.

[0006] In summary, existing technologies lack a technical solution that can identify the intent of Agent management action requests within the BMC, make dynamic decisions based on real-time hardware context, effectively isolate the underlying hardware physical control path, and execute the request through a controlled sandbox agent. Summary of the Invention

[0007] To address the problems existing in the prior art, this invention provides an Agentic AI security adjudication method for a server baseboard management chip. The method, executed by the server baseboard management chip, includes the following steps: Step S1, receiving a management action request from an upper-layer Agentic AI system, the management action request indicating an intent control behavior targeting a target hardware object; Step S2, real-time acquisition of local hardware runtime context data of the target hardware object and its associated server within the chip's management domain; Step S3, performing security verification by combining the intent control behavior, the local hardware runtime context data, and locally preset security restriction policies to make a dynamic security adjudication on the management action request; Step S4, when the adjudication result indicates permission, physically or logically isolating the upper-layer Agentic AI system's direct access to the underlying hardware physical control path, and executing the hardware management action corresponding to the intent control behavior through a controlled tool sandbox agent built into the chip.

[0008] Preferably, after performing step S1, step S1A is also performed, which includes: performing structured configuration parsing on the management action request to identify the behavior type, feature parameters and initiator credibility credentials, and converting them into behavior description tokens that can be processed internally by the chip.

[0009] Preferably, the dynamic security decision includes: determining the destructive risk level of the intent to control behavior based on the behavior description token, and directing requests of different risk levels to corresponding hierarchical verification paths; wherein, read-only requests that do not change the hardware state are directly allowed, and high-risk requests that change the hardware state are subject to mandatory pre-hardware context linkage verification.

[0010] Preferably, the local hardware operating context data includes environmental telemetry indicators characterizing the thermal and electrical characteristics of the server environment, status indicators characterizing the activity of the host operating system, and timeliness indicators characterizing whether the current time is within the operation and maintenance compliance cycle; the local hardware operating context data also carries a unique snapshot identifier and data validity information, the data validity information including sampling time, data source, validity period, and status validity bit.

[0011] Preferably, after executing step S4, step S5 is also executed, which includes: recording the action call sequence of the upper-layer Agentic AI system within a historical sliding time window; when the action call sequence is identified as meeting a preset abnormal behavior pattern or triggering continuous operation failure of a specific hardware target, activating the circuit breaker mechanism, forcibly cutting off the passage channel for subsequent high-risk requests and downgrading to read-only telemetry or manual takeover state; wherein, the abnormal behavior pattern includes a thermal power coupling combination of reducing fan cooling capacity and increasing hardware power consumption limit occurring simultaneously within the preset time window; after activating the circuit breaker mechanism, a graded circuit breaker release is also performed according to the cause of the circuit breaker, and after release, the system enters a recovery observation state.

[0012] Preferably, the controlled tool sandbox proxy execution includes: matching the underlying security tool descriptor corresponding to the behavior description token in the tool sandbox, and controlling the transactional secure implementation of hardware management actions based on the parameter validity range whitelist, call frequency limit, and post-state verification conditions restricted by the descriptor.

[0013] Preferably, step S3A is performed before step S4. Step S3A includes: backing up the current physical configuration and image state of the system as snapshot data to a non-volatile storage area to establish a safe rollback point; and when the hardware management action times out, returns an error, or causes subsequent hardware state deterioration, the system is forcibly restored to the initial safe state before the action is performed based on the safe rollback point.

[0014] Preferably, after performing step S4, step S6 is also performed. Step S6 includes: for each management action request, generating an immutable audit evidence chain in the secure storage area embedded inside the server baseboard management chip. The audit evidence chain records the request source identifier, hardware operating context data before and after execution, security adjudication process snapshot, and final execution rollback result in a time sequence using cryptographic digest.

[0015] This invention also provides an Agentic AI security adjudication system for a server baseboard management chip, deployed in the server baseboard management chip, applying the Agentic AI security adjudication method described above, including: a management interface module for receiving management action requests from an upper-layer Agentic AI system; a hardware state snapshot module for real-time acquisition of local hardware runtime context data of the target hardware object and its server within the chip management domain; a security adjudication module for performing security verification by combining the intent control behavior, the local hardware runtime context data, and locally preset security restriction policies to make a dynamic security adjudication on the management action request; and a tool sandbox execution module for physically or logically isolating the upper-layer Agentic AI system from direct access to the underlying hardware physical control path when the adjudication result indicates permission, and executing the hardware management action corresponding to the intent control behavior through a controlled tool sandbox agent built into the chip.

[0016] The above technical solution has the following advantages or beneficial effects: First, by receiving a management action request that indicates the target hardware object and the intended control behavior through step S1, the BMC can identify the semantic intent of the Agent before the action enters the hardware control domain, thus overcoming the technical defect that the existing BMC cannot perceive the semantics of the Agent's actions.

[0017] Second, by collecting local hardware runtime context data of the target hardware object and its server in real time within the chip management domain through step S2, and combining this context data with the local security policy in step S3 to make dynamic security decisions, the BMC is upgraded from relying on static permissions to a dynamic decision mechanism with real-time hardware status awareness, which can accurately determine the security and compliance of management actions in the current physical environment.

[0018] Third, by physically or logically isolating the Agent's direct access to the underlying hardware physical control path during the decision-making and release process in step S4, and by using the controlled tool sandbox agent built into the chip to perform hardware management actions, all hardware operations must be translated, parameter verified and transactionalized through the sandbox. This physically cuts off the Agent's direct control over the underlying registers, effectively reducing the risk of hardware damage and business interruption caused by Agent decision distortion or uncontrolled behavior. Attached Figure Description

[0019] Figure 1 A flowchart illustrating an Agentic AI security adjudication method for a server board management chip, as a preferred embodiment of the present invention. Figure 2This is a schematic diagram of the structure of an Agentic AI security adjudication system for a server board management chip, which is a preferred embodiment of the present invention. Detailed Implementation

[0020] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments. The present invention is not limited to this embodiment; other embodiments that conform to the spirit of the present invention may also fall within the scope of the present invention.

[0021] In a preferred embodiment of the present invention, based on the above-mentioned problems existing in the prior art, an Agentic AI security adjudication method for a server board management chip is provided, wherein the method is executed by the server board management chip, such as... Figure 1 As shown, the process includes the following steps: Step S1, receiving a management action request from the upper-layer Agentic AI system, the management action request indicating an intent control behavior for a target hardware object; Step S2, collecting local hardware runtime context data of the target hardware object and its server in real time within the chip management domain; Step S3, performing security verification by combining the intent control behavior, the local hardware runtime context data, and locally preset security restriction policies to make a dynamic security decision on the management action request; Step S4, when the decision indicates permission, physically or logically isolating the upper-layer Agentic AI system's direct access to the underlying hardware physical control path, and executing the hardware management action corresponding to the intent control behavior through a controlled tool sandbox agent built into the chip.

[0022] Specifically, in this embodiment, the upper-layer Agentic AI system sends structured management action requests (AgentActionRequests) downwards through the out-of-band management physical network. To achieve proactive behavior control, the management action request (AgentActionRequest) includes fully defined protocol fields, including at least: Action request identifier (Action_ID), agent identifier (Agent_ID), authorized user or policy source identifier (User_ID or Policy_ID), target hardware object (Target_Object), action type (Action_Type), specific action parameters (Action_Parameter), expected execution result (Expected_Result), risk warning reported by the agent itself (Risk_Hint), current execution confidence level (Confidence), external evidence index (Evidence_Ref) used for the agent's decision, whether a rollback is needed and the specific rollback requirement (Rollback_Requirement), whether human approval is available (Human_Approval_Requirement), the time window for allowing the action to be executed (Time_Window), and the overall operation and maintenance long task chain context (Task_Context) associated with the action.

[0023] The hardware runtime context data collected in step S2 will serve as the most authentic hard threshold verification benchmark inside the chip and not tampered with externally during the adjudication phase.

[0024] The dynamic security decision in step S3 compares the expected goal of the action with the local preset static hardware policies (such as extreme temperature and fan speed limits) to determine the decision result, such as Allow, Allow_With_Limit, Delay, Need_Human_Approval, Reject, Quarantine, or directly trigger the behavior circuit breaker Fuse_Triggered.

[0025] Step S4 ensures at the physical level that the intelligent agent cannot bypass the chip logic to directly manipulate electrical components. Physical or logical isolation prevents external intelligent agent programs from directly accessing the PMBus bus, power control registers, fan PWM / Tach control registers, BIOS external flash write pins, the firmware Flash control port of the baseboard management chip itself, and various low-level hardware physical debugging interfaces. All control actions must be invoked, translated, and executed by the pre-built toolkit matched in the controlled tool sandbox.

[0026] This embodiment further illustrates the concept with a specific scenario. Assume the upper-layer Agentic AI operations and maintenance system needs to perform health analysis on a malfunctioning server. It sends a request to the baseboard management chip to query the server's health status, with the Action_Type being "read" and the Target_Object being the entire platform. Upon receiving the request, the baseboard management chip's management interface module parses it and determines that this is a read-only task at level L0. The hardware status snapshot module then retrieves local context data collected from the chip's internal ADCs and I2C buses, including real-time fan speeds, current power module status, voltage, and host heartbeat. The adjudication module determines that the agent possesses valid read credentials and is not under fuse protection. After confirming safety and no risk, tools such as sensor telemetry reading from the tool sandbox are invoked to return accurate data status to the upper-layer agent system. This process ensures that even routine data extraction actions are fully controlled and recorded along their pathways.

[0027] This embodiment effectively cuts off the technical path that causes the actions of upper-layer intelligent agents to directly damage the underlying physical hardware registers by deploying real-time action interception, multi-dimensional snapshot linkage, and sandbox isolation agent at the hardware jurisdiction boundary of the substrate management chip. This overcomes the major technical security risk of traditional passive out-of-band interfaces lacking active hardware interception defenses when facing autonomous intelligent agents.

[0028] In another preferred embodiment of the present invention, the substrate management chip Agentic AI security adjudication method further includes: after performing step S1, performing step S1A, wherein step S1A includes: performing structured configuration parsing on the management action request to identify the behavior type, feature parameters and initiator credibility credentials, and converting them into behavior description tokens that can be processed internally by the chip.

[0029] Specifically, in this embodiment, step S1A is executed in the hardware pipeline by the action parsing module embedded within the substrate management chip, which deserializes and extracts the structured data from the received complex AgentActionRequest message. The behavior description token is a substrate management description token BmcActionDescriptor that can be efficiently transmitted and routed within the chip. This token defines at least: the underlying target hardware object it points to, the physical underlying hardware management path invoked by the action, whether the action is only a read-only attribute, whether the action involves a high-risk control path that changes the physical state of core components, whether the action has a cascading risk that could cause service interruption of the host system, whether the action falls within a locally defined time-sensitive maintenance window, whether the action is preset to require prior manual verification and approval from the system administrator, whether the action has corresponding rollback and recovery logic locally on the chip, whether the action has an irreversible damage risk after physical failure, and whether there is a cascading combination risk between the action and its preceding actions from the same initiator within the historical sliding window.

[0030] This semantic transformation step enables complex intent descriptions generated based on external high-level protocols (such as Redfish or RESTful calls) to be transformed and aligned into unified control bus description items within the substrate management chip. These descriptions can then be quickly retrieved by the chip's highly constrained, low-computing-power microcontroller through hardware table lookup or state machine comparison.

[0031] This embodiment solves the technical bottleneck of semantic asymmetry between external high-dimensional inference logic and chip-level low-level register control instructions by performing localized structure parsing and token mapping of external intelligent agent operation and maintenance intentions. This significantly reduces on-chip computing resource overhead during security policy review and eliminates time lag errors introduced by security adjudication.

[0032] In another preferred embodiment of the present invention, the dynamic security decision, in conjunction with the behavior description token obtained by the above step S1A, includes: determining the destructive risk level of the intentional control behavior based on the behavior description token, and directing requests of different risk levels to corresponding hierarchical verification paths; wherein, read-only requests that do not change the hardware state are directly allowed, and high-risk requests that change the hardware state are subject to mandatory pre-hardware context linkage verification.

[0033] Specifically, in this embodiment, the substrate management chip performs a hard match between the parsed BmcActionDescriptor and the locally preset static policy table, classifying the intended action into the following five fine-grained levels of destructive risk: L0 read-only actions: Do not change any hardware state, only obtain physical indicators. This includes reading the current ambient temperature, reading the event log, and obtaining the state of the internal status register.

[0034] L1 low-risk actions: Actions that do not alter the overall server operating environment. These include temporary diagnostic tests that do not affect the system state, or purely software actions that generate diagnostic logs.

[0035] L2 medium-risk actions: These involve moderate changes to hardware-aided non-destructive parameters. Examples include modifying non-critical thresholds for temperature alarms and temporarily lowering diagnostic trigger lines.

[0036] Level 3 high-risk actions: Commands at this level, if out of control, can easily lead to equipment damage or sudden interruption of critical business operations. These include restarting the server host, hard-shutting down the power supply, adjusting the maximum power consumption limit of the CPU or graphics accelerator card, resetting the fan speed curve to override the safety preset line, flashing firmware image files to external flash memory, and changing critical physical parameters of the BIOS.

[0037] L4 Prohibited or Isolated Actions: This level of action refers to actions that severely violate the security guidelines hard-coded by the local administrator (e.g., forcibly erasing firmware outside of maintenance windows) or directly cause fatal electrical conflicts. The corresponding hierarchical verification path is as follows: For lightweight requests at L0 and L1 levels, they are directly approved after the chip verification agent's source permissions are passed to reduce the latency overhead of daily diagnostics; for medium-risk L2 requests, the baseboard management chip forcibly imports real-time hardware context data and performs a comparison of the corresponding values ​​of each parameter within the security whitelist range; for high-risk L3 actions, in addition to implementing dual stringent judgments of hardware status verification and parameter ranges, the chip's adjudication engine forcibly cuts off the automatic release mechanism, suspends the task on the chip, and issues a manual approval request or a specific maintenance work order for authentication; for L4 level actions, the chip's dynamic adjudication engine generates a top-level hardware rejection interrupt signal, cancels the request, and stores it in the security isolation area, awaiting physical-level reset and unlocking.

[0038] This embodiment illustrates the following scenario: After analyzing the server, the intelligent agent determines that the graphics processing unit (GPU) temperature is too high and sends a control intent (Action_Type: adjust fan policy) to the chip to increase the fan speed of that fan zone. Based on the range of the speed adjustment, the adjudication module determines that it belongs to Level 2. The hardware snapshot module immediately retrieves the server's current core processor power, overall ambient temperature, current fan pulse width modulation duty cycle, and speed status. Policy matching indicates that the request is to increase fan speed to eliminate high heat, and the input duty cycle parameter is not lower than the lower limit of the safe fan speed curve. The adjudication module determines that the action complies with the thermodynamic safety policy and allows its execution.

[0039] This embodiment effectively eliminates the limitations of out-of-band management's black-and-white, crude control when facing external autonomous decision-making actions by introducing refined action risk stratification judgment and differentiated linkage verification logic. While ensuring that highly destructive and high-risk operations are physically restricted, it also ensures the continuous and smooth execution of daily status detection behavior, thus balancing safety and operational efficiency.

[0040] In another preferred embodiment of the present invention, based on the local hardware operating context data in the above preferred embodiment, it includes environmental telemetry indicators characterizing the thermal and electrical characteristics of the server environment, status indicators characterizing the activity of the host operating system, and timeliness indicators characterizing whether the current time is within the operation and maintenance compliance cycle.

[0041] Specifically, in this embodiment, the local hardware running context data PreActionSnapshot acquired by the hardware state snapshot module built into the substrate management chip has multi-dimensional decoupling characteristics, and each indicator field is strictly limited to the physical manifestation of the chip's local hardware logic perception layer.

[0042] The environmental telemetry indicators specifically include: physical measurement data such as the surface junction temperature of the core processor and core graphics card, real-time thermodynamic parameters of the chassis air inlet and outlet, current values ​​on multiple power distribution rails, total input and output power consumption, current actual speed of each fan, and water flow rate and pressure in the liquid cooling pipes, all collected using the high-precision analog-to-digital converter inside the chip. The status indicators specifically include: host heartbeat keep-alive signals monitored via an independent bus (e.g., pulses generated by the kernel watchdog or dedicated GPIO heartbeat lines), host power logic status, hardware-level error correction code detection and reporting counters on the physical channels of the dual in-line memory modules and high-speed serial peripheral bus, and the current primary / backup physical mirror operating zone of the baseboard management chip and motherboard BIOS firmware. The timeliness indicators represent compliance markers of the local static calendar or time periods synchronized by a entrusted time service center, including whether the system is currently within a security business maintenance window period hard-coded by the system administrator, and whether another high-risk hardware modification task that is mutually exclusive with its physical resources has been assigned and is currently being executed in the system.

[0043] This embodiment constructs a real-time hardware runtime context snapshot by linking physical characteristics, logical activity, and spatiotemporal compliance status in three dimensions. This solves the technical drawbacks of isolated security detection and judgment data and lack of multi-physical quantity correlation verification, and provides an unforgeable and highly reliable data anchor for subsequent multi-dimensional situational awareness and comprehensive security adjudication in complex environments.

[0044] In another preferred embodiment of the present invention, the Agentic AI security adjudication method for the substrate management chip further includes: performing step S5 after performing step S4, wherein step S5 includes: recording the action call sequence of the upper-layer Agentic AI system within a historical sliding time window; when the action call sequence is identified as meeting a preset abnormal behavior pattern or triggering continuous operation failure of a specific hardware target, activating a circuit breaker mechanism, forcibly cutting off the release channel for subsequent high-risk requests and downgrading to read-only telemetry or manual takeover status.

[0045] Specifically, in this embodiment, the fuse and degradation control module establishes and maintains a dynamic behavior log chain within the substrate management chip to track the evolution of behavior over time. This log chain continuously pushes a sliding window using clock interrupts. Here, an abnormal action call sequence that triggers the chip's protective fuse mechanism includes at least one or more of the following criteria: the same agent (Agentic The frequency of high-risk control-level requests (such as forced system restart or output power adjustment) initiated by the AI ​​within a preset sliding time window (e.g., within 10 consecutive seconds) exceeds the set count limit; the same type of control action initiated by the agent for a specific hardware component shows in the hardware status feedback after execution that the action has repeatedly failed at the physical level and the cumulative number of failures has reached the trigger line; after a specific control behavior initiated by the agent is rejected by the administrator or local rules, the same request is stubbornly and repeatedly submitted downwards within a very short time limit; the agent continuously carries overflow values ​​that cannot be translated by the local sandbox in the action parameters, or inputs feature parameters that exceed the boundary of the security register; the abnormal behavior pattern includes a combination of destructive instruction sequences across physical domains; the combination of instruction sequences includes: within a preset associated timing sequence, simultaneously receiving a cooling request to reduce the server's heat dissipation capacity and a heating request to increase the server's power consumption limit; wherein, the cooling request includes reducing the PWM duty cycle of the system motherboard fan speed, and the heating request includes forcibly increasing the power consumption limit configuration of the graphics acceleration processing board. As a specific, non-restrictive engineering example: within an extremely short correlation timeframe (i.e., a pre-defined correlation timeframe), an agent simultaneously requests a reduction in the PWM duty cycle of the system motherboard fan (i.e., a cooling request) and forcibly requests an increase in the power consumption limit of the graphics accelerator card (i.e., a heating request). This anomalous combination of cooling and heating carries a high deterministic risk of physical thermal runaway; after the actions are allowed, a subsequent snapshot shows that local thermophysical parameters or electrical steady state have deteriorated (e.g., a sharp rise in temperature or a transient drop in voltage).

[0046] When the circuit breaker mechanism is activated, the circuit breaker and degradation control module forcibly cuts off all subsequent control requests through the underlying hardware state machine, prohibits all L2 and above write configuration actions, and severs the bridge between the external interface and the controlled execution path. At this time, the entire out-of-band controller enters a security degradation mode, and the upper-layer intelligent agent is degraded to only be able to use L0 and L1 level telemetry functions to obtain the server's current system basic information, so as to ensure that the physically isolated core hardware will not be completely destroyed due to subsequent uncontrolled actions. Its release must be achieved by introducing a hard-wired manual physical reset or trusted authentication unlocking from the administrator.

[0047] This embodiment illustrates its working principle using a typical fault. The upper-layer agent determines that the host has lost response and sends a host restart request (L3 action) to the baseboard management chip. However, this request may be triggered four times consecutively within one minute due to an infinite loop in the agent's model. Step S5 within the chip monitors this continuous restart event, determines that it meets the high-frequency restart abnormal mode, immediately triggers the fuse mechanism, and forcibly locks the reset pin. Afterwards, all restart commands from the agent are directly intercepted and rejected. The chip initiates a high-alert to the administrator's backend, the system automatically switches to manual control mode, and presents a read-only diagnostic interface.

[0048] This embodiment overcomes the hidden danger of server thermal or electrical collapse caused by the superposition of a single legal action by adding sequence-level sliding monitoring and abnormal behavior combined circuit breaker protection in the time axis dimension, and greatly enhances the physical defense depth of the server base when facing the self-excited dead loop behavior or cooperative strategy conflict of intelligent agents.

[0049] In another preferred embodiment of the present invention, in conjunction with the behavior description token parsed in step S1A above, the controlled tool sandbox proxy execution includes: matching the underlying security tool descriptor corresponding to the behavior description token in the tool sandbox, and controlling the transactional secure implementation of hardware management actions based on the parameter validity range whitelist, call frequency upper limit and post-state verification conditions restricted by the descriptor.

[0050] Specifically, in this embodiment, to achieve complete control over the action execution process, the tool sandbox embedded in the chip is configured with a read-only descriptor (ToolDescriptor) dedicated to each underlying hardware control channel. Each secure tool descriptor specifically includes: the executable software / hardware entity name of the tool, the range of target hardware physical registers that the tool is allowed to map, the whitelist of parameters input to the tool and the legal physical range of the parameters (e.g., limiting power consumption modification to a maximum of 350 watts), the maximum allowed call frequency of the tool, the physical preconditions that the tool must meet before actually writing to the register, and the post-hardware feedback conditions that must be verified after register configuration. When the decision in step S3 is approved, the sandbox loads the tool descriptor corresponding to the action token (BmcActionDescriptor) and verifies the action parameters. If the parameters do not overflow, the sandbox initiates transaction-level execution: first, it checks if the fan is currently in a non-faulty state (precondition), then writes the fan configuration register through the chip bus control module (execution), and immediately rereads the actual physical speed of the fan through the on-chip analog-to-digital channel after a hardware delay period (post-feedback verification). If the rotation speed does not increase, the tool execution is declared to have failed, and the process will proceed to the exception handling branch.

[0051] This embodiment confines all underlying execution processes within a tool sandbox descriptor that features strong type safety, defined numerical boundaries, and pre / post-execution judgment conditions. This prevents external malicious or faulty programs from using the underlying control path for direct access behaviors such as buffer overflow attacks or illegal register writes. Thus, it ensures the final landing of physical actions on the base in an extremely well-organized and restricted transactional mode.

[0052] In another preferred embodiment of the present invention, the Agentic AI security adjudication method for the substrate management chip further includes: performing step S3A before performing step S4, wherein step S3A includes: backing up the physical configuration and mirror state of the current system as snapshot data to a non-volatile storage area to establish a secure rollback point; and when the hardware management action times out, returns an error, or causes subsequent hardware state deterioration, forcibly restoring the system to the initial secure state before the action is performed based on the secure rollback point.

[0053] Specifically, in this embodiment, step S3A is the pre-rollback redemption channel when a high-risk operation fails. The snapshot data here includes at least: the physical initial configuration values ​​of each control register of the system before the modification operation, the version and sector identifier of the physical image of the main firmware running at the time of the pre-action, the pre-action fan PWM and speed management characteristic curves, and a summary of the operating environment configuration of the host BIOS or power management module before the modification. The physical area storing the backup of the safe rollback point is located in the local on-chip non-volatile RAM with write protection isolation features in the baseboard management chip. The working details of the rollback mechanism are as follows: once the L3 firmware upgrade instruction requested by the upper-layer intelligent agent is interrupted during execution, a write timeout is found during tool sandbox agent verification, or a blockage of the motherboard's critical physical bus is detected after the upgrade (post-state deterioration), the rollback and recovery control module is immediately activated by the on-chip high-priority interrupt signal. This module forcibly overwrites the current failed running area, uses the backup image of the SPI Flash to completely flash the firmware back to the trusted version before the modification, initializes all registers to the pre-action safe snapshot, and issues an emergency alarm to the system, thereby achieving forced self-healing of the system.

[0054] This embodiment is illustrated with a specific scenario. The agent executes a BIOS upgrade command on the server. Before this, step S3A of the chip completely backs up the physical image of the previously bootable main BIOS. During step S4, if a physical verification error occurs due to an integrity defect in the image package pushed by the agent, the rollback control hard core forcibly enables the dual BIOS automatic switching logic, physically reverting the system to the original backup point, thus preventing the server device from experiencing irreversible locking risks due to firmware failure.

[0055] This embodiment solves the problem of permanent physical damage to equipment caused by dynamic environmental changes in high-risk scenarios by automatically and atomically establishing a snapshot rollback mechanism within the chip before substantial control takes effect. It provides a zero-crash, highly self-healing underlying fault-tolerant mechanism for heterogeneous server environments.

[0056] In another preferred embodiment of the present invention, the Agentic AI security adjudication method for the baseboard management chip further includes: performing step S6 after performing step S4, wherein step S6 includes: generating an immutable audit evidence chain in a secure storage area embedded within the server baseboard management chip for each management action request, wherein the audit evidence chain records the request source identifier, hardware operating context data before and after execution, a snapshot of the security adjudication process, and the final execution rollback result in a time sequence using a cryptographic digest method.

[0057] Specifically, in this embodiment, the evidence generation process in step S6 is assisted by a dedicated hash / encryption calculation hardware block with high security features in the baseboard management chip to achieve non-repudiation and strong traceability of audit records. Each generated audit evidence chain is a chain-like block structure formed by an encrypted hash algorithm (e.g., SHA-256 algorithm). The physical information bound to the audit evidence chain specifically includes: the unique identifier (Agent_ID) of the intelligent agent device that initiated this action call, the upper-layer user or management policy authorization credential (User_ID / Policy_ID), the atomic task index number corresponding to the action itself, the unmodified original action intent request data of the upper-layer intelligent agent, the BmcActionDescriptor behavior token after semantic parsing within the chip, the hardware state snapshot extracted before execution, the final decision-making process snapshot and approval mark, the whitelist verification report of the specific tools and parameters actually called by the physical sandbox, the hardware state snapshot after execution and recaptured after the execution ends and the state stabilizes, the specific physical error message indicating whether the action was successful or failed, and the flag indicating whether the rollback recovery module and behavior circuit breaker mechanism were triggered. The entire data is recorded in a hash chain within a non-volatile physical isolation zone inside the chip, ensuring that even the highest-level super administrator or an out-of-control agent cannot stealthily tamper with or delete these underlying traces outside the substrate management chip.

[0058] This embodiment analyzes the principle using a real-world operation and maintenance review scenario: A motherboard in an AI server cluster suddenly experienced a power outage due to protection mechanisms late at night. After the fault occurred, the operation and maintenance security officer directly retrieved the audit evidence chain from the security audit area permanently stored in the baseboard management chip. The data showed that a specific Agent_ID operation and maintenance intelligent agent initiated a power consumption limit adjustment request at a specific timestamp while executing a task; the complete PreActionSnapshot in the evidence showed that the motherboard power supply module was already at the temperature warning line before the adjustment; the adjudication snapshot proved that the action passed S3 verification due to the exemption work order mark left in advance by the administrator; after the agent tool sandbox execution, the power module directly generated a protective power-off error. This complete process, without any semantic modification or data loss, clearly demonstrates the evidence backtracking from the generation of the intelligent agent's intent, local adjudication, hardware execution, and the final result, effectively eliminating the technical drawback of difficulty in determining responsibility when faults are caused by autonomous operation of the intelligent agent.

[0059] This embodiment addresses the legal and technical deficiencies of incomplete behavior reconstruction and chaotic causal boundaries of post-failure events in multi-layered intelligent agent operation and maintenance by adding an immutable audit evidence chain based on chip-fixed areas, timing binding, and hash connections in the post-physical execution stage. It provides the strongest physical evidence barrier for building a transparent and trustworthy operation and maintenance mechanism for cloud data centers.

[0060] In another preferred embodiment of the present invention, a baseboard management chip Agentic AI security adjudication system is provided, deployed in a server baseboard management chip, such as... Figure 2 As shown, it includes: a management interface module 1, used to receive management action requests from the upper-layer Agentic AI system; a hardware status snapshot module 2, used to collect local hardware runtime context data of the target hardware object and its server in real time within the chip management domain; a security adjudication module 3, used to perform security verification by combining the intent control behavior, the local hardware runtime context data, and locally preset security restriction policies, so as to make a dynamic security adjudication on the management action request; and a tool sandbox execution module 4, used to physically or logically isolate the direct access of the upper-layer Agentic AI system to the underlying hardware physical control path when the adjudication result indicates permission, and to execute the hardware management action corresponding to the intent control behavior through the chip's built-in controlled tool sandbox agent.

[0061] Furthermore, to facilitate the execution of the method, the system / device further includes: an action parsing module, used to perform structured configuration parsing on the management action request and convert it into the behavior description token (in this embodiment, it can physically correspond to the structured parsing and conversion unit inside the chip, which is physically connected to the management interface module); a circuit breaker and degradation control module, used to activate the circuit breaker mechanism and forcibly cut off subsequent control requests when the action call sequence meets the abnormal behavior pattern or continuous operation failure (in this embodiment, it can physically correspond to the circuit breaker and degradation controller connected to the tool sandbox and the adjudication logic bidirectional signal, which is equipped with a sliding window counting register with clock interrupt counting characteristics); and a rollback and recovery control module, used to execute the hard... The system generates a security rollback point before hardware management actions and performs a recovery action to restore the system to its initial secure state before the action was executed when an action fails (such as the hardware management action timing out, returning an error, or causing subsequent hardware state deterioration). In this embodiment, the system can physically correspond to a local rollback snapshot backup storage associated with the physical control path of the sandbox tool, which can be a write-proof EEPROM hardware chip or protected non-volatile RAM. The audit evidence chain recording module is used to generate and record the audit evidence chain in the solidified secure storage area. In this embodiment, the system can physically correspond to an audit evidence chain record generator physically connected to the on-chip hardware encryption engine and the high-reliability clock, which is used to generate tamper-proof encrypted hash storage blocks.

[0062] Specifically, in this embodiment, the security adjudication device is deployed in a substrate management system-on-chip (SoC) based on an ARM or RISC-V architecture. The various modules are highly coupled in the chip's internal logic structure, and the specific physical mapping and internal network topology design are as follows: Management interface module: physically connected to the external out-of-band network layer and the Redfish and REST API encapsulation layer, receiving data packets from the remote AI operations and maintenance manager.

[0063] Hardware Status Snapshot Module: It is directly connected to the on-chip integrated temperature acquisition analog-to-digital converter, PWM generator and various sensors connected to the SMBus bus, and can collect the current thermal, electrical and heartbeat status of the server concurrently within a very short clock cycle without delay.

[0064] Security adjudication module: It adopts a hardwired secure multi-clock domain logic engine, which forcibly loads the core security restriction criteria hardcoded by the administrator through the on-chip protected read-only ROM, and performs parameter matching by dedicated comparators and logic gate circuits.

[0065] The tool sandbox execution module: This module locks out high-risk hardware access endpoints (PMBus ports, GPIO power control pins, motherboard fan control channels, etc.) at the physical bus level. It uses on-chip logic multiplexers to redirect control flow, preventing any unregistered program from directly writing to these hardware contacts. It only provides externally accessible, read-only secure proxy call endpoints within the sandbox whitelist.

[0066] Furthermore, to facilitate the execution of the method, the device also integrates: an internal chip-based parsing and conversion unit physically connected to the management interface module, used to convert AgentActionRequest messages into BmcActionDescriptor tokens; a circuit breaker degradation controller physically connected to the tool sandbox and adjudication logic, equipped with a sliding window counter register with clock interrupt counting characteristics; a local rollback snapshot backup storage associated with the physical control path of the sandbox tool, employing a write-proof EEPROM hardware chip; and an evidence chain generator physically connected to the on-chip hardware encryption engine and high-reliability clock (RTC), used to generate tamper-proof encrypted hash storage blocks. This embodiment overcomes the weakness of relying solely on software-level firewalls for protection against highly destructive operational actions by deeply hard-core integrating dynamic parsing, context capture, physical isolation sandbox, and security policy comparison logic into an independent substrate management SoC chip. It perfectly establishes a high-physical-strength, adaptive, chip-level proactive defense between the out-of-band management layer and the intelligent AI high-level operation and maintenance layer.

[0067] In another preferred embodiment of the present invention, the management action request also carries a request timestamp, serial number or random number, session identifier, request authentication information, and channel binding information; before the server baseboard management chip executes the dynamic security decision in step S3, the request integrity verification module first performs integrity, freshness, and anti-replay verification on the management action request for identity source, signature or message authentication code, timestamp, serial number, random number, session identifier, and channel binding. For requests that fail authentication, exceed the time window limit, have a backdated serial number, have duplicate random numbers, have inconsistent channel binding, or are determined to be replays, the action decision process is not entered, and a rejection or isolation result is directly returned and an audit record is generated.

[0068] Specifically, in this embodiment, when the upper-layer Agentic AI system generates the management action request (AgentActionRequest), in addition to fields such as action request identifier, intelligent agent identifier initiating the request, authorized user or policy source identifier, target hardware object, action type, action parameters, expected execution result, risk warning, execution confidence, external evidence index, rollback requirement, manual approval mark, execution sequence window, and task chain context, it also carries additional fields such as request timestamp (Request_Timestamp), sequence number or random number (Sequence_Number or Nonce), session identifier (Session_ID), request authentication information (Request_Authenticator), and channel binding information (Channel_Binding). The request integrity verification module verifies the request source, integrity, freshness, and session consistency based on the above fields, thereby ensuring source credibility, integrity, and freshness before the action enters the underlying action adjudication process, preventing legitimate high-risk actions from being copied and replayed or reused across sessions.

[0069] Correspondingly, the local hardware runtime context data collected by the hardware status snapshot module in step S2 also carries a unique snapshot identifier Snapshot_ID and data validity information. The data validity information includes the sampling time, data source, validity period, reading status, status validity bit, and sensor health information for each status item. When critical temperature, power supply, fan, host heartbeat, firmware status, or target object status is missing, outdated, contradictory, or sensor health status is abnormal, the security adjudication module resamples, lowers the allowed action level, enters restricted execution, or adopts a default rejection policy for high-risk actions. This ensures that dynamic security adjudication is based on valid hardware status within the same time boundary, avoiding erroneous execution caused by using expired telemetry.

[0070] This embodiment eliminates the security risks of Agent management actions being forged, tampered with, or replayed, and the adjudication basis becoming outdated and invalid by adding request integrity verification and snapshot validity verification before adjudication, from both the request source and adjudication data source levels.

[0071] In another preferred embodiment of the present invention, the system further includes a conflict domain and concurrent arbitration module, which is used to establish conflict domains based on the target object level, shared resource domains and the scope of action impact, perform mutual exclusion, sequentialization or re-arbitration on high-risk write actions located in the same conflict domain, and perform priority arbitration on conflicts caused by multiple Agent parallel requests or human administrator intervention.

[0072] Specifically, in this embodiment, the conflict domain and concurrent arbitration module establish a conflict domain (Conflict_Domain) based on the target object hierarchy, shared power domain, shared heat dissipation domain, shared firmware storage, shared reset link, shared management bus, and the scope of action impact. Each conflict domain is associated with a conflict domain identifier (Conflict_Domain_ID), a set of target objects, a set of shared resources, allowed concurrent action types, mutually exclusive action types, and lock escalation rules. High-risk actions located in the same conflict domain, even if they have different target hardware objects, must be subject to mutual exclusion, sequential processing, or re-arbitration. For example, host power-on / off and graphics accelerator card firmware updates, baseboard management chip flash memory writing and baseboard management chip reset, power module switching and overall power consumption limit adjustment, fan area adjustment and liquid cooling pump control can be located in the same host service domain, firmware storage domain, power domain, or thermal management domain, respectively.

[0073] When multiple agents make parallel requests, or when an agent request conflicts with an action initiated by a human administrator through an out-of-band management interface, the conflict domain and the concurrent arbitration module arbitrate according to the following priorities: hardware protection and security recovery take priority; high-risk transactions that have entered the execution phase maintain atomicity; manual emergency takeover takes priority over agent-automated high-risk actions; high-risk write actions in the same conflict domain are mutually exclusive; low-risk actions in different conflict domains can be executed in parallel; the arbitration result, in addition to allowing, restricting, delaying execution, requiring manual verification, refusing execution, entering the isolation zone, and triggering circuit breaker, further includes Conflict_Hold and Manual_Takeover.

[0074] Furthermore, for high-risk actions determined to be allowed, the execution sequence and transaction lock control module generates an execution sequence for the permitted actions and sets transaction locks for the target object and corresponding conflict domain before the action enters the underlying tool call path, recording the transaction identifier (Transaction_ID), conflict domain identifier, lock holder, lock lease period, maximum execution time, and execution heartbeat. When the transaction execution heartbeat is lost, the transaction exceeds the maximum execution time, the underlying tool is unresponsive, or the post-execution state remains abnormal, the transaction is switched to an aborted pending or recovery state, stopping subsequent stages at a safe abort point, restoring the original configuration, or transitioning to a protected manual takeover process. High-risk actions typically require both policy confirmation and manual confirmation. Actions triggered by the server baseboard management chip's local hardware protection, trusted recovery policy, or pre-authorized emergency policy can be automatically executed if preset security conditions are met and complete audit records are retained, thus avoiding manual confirmation becoming a bottleneck in the hardware protection path.

[0075] This embodiment combines conflict domains and transaction locks to extend concurrent mutual exclusion from a single target object to a resource dependency domain. This solves the problem of multiple management actions entering the same high-risk hardware path simultaneously under conditions of multiple agent collaboration or human-machine collaboration, while also taking into account the atomicity and fault recoverability of high-risk transactions.

[0076] In another preferred embodiment of the present invention, based on the circuit breaker mechanism described in the above embodiments, a configurable time window and threshold determination are further introduced to address the risks of thermal power coupling in the abnormal behavior mode and the risks of continuous restarts or continuous resets for specific hardware targets.

[0077] Specifically, in this embodiment, for the combined risk of cooling and heating requests as described in the above embodiments, the circuit breaker and degradation control module further sets a configurable associated time window T_comb and expands the hardware status input for association determination; the security adjudication module reads the current CPU and graphics accelerator card surface junction temperature, air inlet temperature, air outlet temperature, fan feedback speed, power module output power, voltage regulator current, and thermal alarm status. If any of the above states is close to or exceeds the local policy threshold, or the fan feedback speed is lower than its target speed, then the combination of requests to reduce fan cooling capacity and increase hardware power consumption limit within the associated time window by the same Agent, the same task chain, or the same authorization policy is determined as a thermal power coupling risk. The adjudication result can be to reject power consumption increase, reject fan decrease, delay execution, maintain the minimum safe fan curve, enter a restricted execution state, or trigger Agent circuit breaker.

[0078] To address the risk of continuous restarts or resets described in the above embodiments, the circuit breaker and degradation control module further sets a configurable time window T_reset and a retry threshold N_reset, and maintains reset and power-on / off counts for the host, graphics accelerator card, network card, solid-state drive, and high-speed serial bus expansion device respectively. If the same agent or multiple agents continuously request reset, power-on / off, link reset, or device reset for the same target object within the configurable time window, and the host heartbeat has not recovered, the target device error count has not decreased, the event log continues to add, or the previous recovery action has not been completed, it is determined to be a risk of repeated recovery failure. When the cumulative number of times exceeds the retry threshold, the server baseboard management chip prohibits the automatic execution of restart or reset actions and switches the relevant agent or target object to read-only telemetry, isolation pending, or manual takeover status. The above time window and threshold can be determined by the local policy table of the server baseboard management chip, server platform policy, maintenance window policy, or administrator configuration.

[0079] This embodiment, based on existing abnormal behavior patterns and high-frequency restart judgments, introduces configurable associated time windows, extended hardware status inputs, and sequence-level retry thresholds. It implements the judgment of combined risks and sequence-level risks into specific judgment conditions and decision outputs that can be executed by the server baseboard management chip, thus overcoming the hidden danger of server thermal runaway or electrical collapse caused by repeated or combined calls of a single legal action.

[0080] In another preferred embodiment of the present invention, the circuit breaker and degradation control module is further configured to determine the circuit breaker scope (FuseScope) based on the source of the anomaly, the affected object, and the scope of risk diffusion, and to perform graded circuit breaker release and recovery observation after the circuit breaker is triggered.

[0081] Specifically, in this embodiment, the circuit breaker and degradation control module determines the circuit breaker scope to cover at least the tool level, action type level, target object level, conflict domain level, agent level, task chain level, and platform level. The circuit breaker and degradation control module preferentially adopts the smallest circuit breaker scope that can meet the security objectives. If similar anomalies occur repeatedly, the impact spreads to shared resources, the circuit breaker fails to be released, or multiple agents continuously generate related anomalies, the circuit breaker scope is expanded in the applicable order of tool level, action type level, target object level, conflict domain level, agent level, task chain level, and platform level. After the state stabilizes and passes the release check, it is restored step by step in the opposite direction.

[0082] When a circuit breaker is triggered, the circuit breaker and degradation control module records the circuit breaker reason code FuseReason, the circuit breaker scope FuseScope, the target object, the conflict domain identifier, the triggering action, the triggering time, a snapshot of the hardware state before the trigger, the action history window, and the current Agent tool capability status. Circuit breaker release is determined based on the circuit breaker reason, the circuit breaker scope, the target object status, the stable observation window, the action failure count, the hardware state recovery result, the manual confirmation status, and the policy version, and is categorized into automatic release, semi-automatic release, and manual release. For circuit breaker reasons such as parameter out-of-bounds errors, excessively high call frequency, or continuous failures of low-risk tools, if no similar anomalies reappear within the configurable stable observation window T_stable, and the target object status, temperature, power supply, fan, host heartbeat, and event logs are all within the policy's allowed range, the Agent can be restored from read-only telemetry state to restricted execution state. For circuit breaker triggers due to reasons such as continuous restarts, continuous power consumption modifications, continuous fan policy modifications, repeated submissions after manual rejection, and risks associated with combined actions, recovery is only possible if the following conditions are met simultaneously: hardware status stabilizes, action failure count is cleared or falls below the threshold, the target object is not in an abnormal recovery process, administrator confirmation or work order confirmation is valid, and the policy version has not been rolled back or revoked. For circuit breaker triggers due to reasons such as firmware write failure, flash memory verification failure, power control anomalies, increased thermal risk, abnormal debugging interface activation, secure boot, or firmware integrity verification anomalies, automatic circuit breaker release is prohibited. Only read-only telemetry, recovery mode, and manual takeover capabilities are retained, and restricted tool capabilities can only be restored after administrator confirmation. An audit record is generated for each circuit breaker release or failure to release. After a circuit breaker is released, the tool enters a recovery observation state first, and then restores its capabilities level by level. If the same anomaly reappears during the recovery observation period, the tool re-enters the circuit breaker state, extends the stability observation window, or escalates the circuit breaker level.

[0083] This embodiment forms a complete state machine closed loop of triggering, limiting, releasing, observing, and re-triggering, realizing hierarchical control of local limiting and global protection, reducing excessive circuit breaking caused by single-point anomalies, and improving the protection level when serious risks spread.

[0084] In another preferred embodiment of the present invention, the example of conflict arbitration between multiple agent concurrent requests and manual takeover is used for illustration.

[0085] Specifically, in this embodiment, the data center management platform contains multiple agents: the first agent requests power-on / off of a server based on a host heartbeat anomaly, and the second agent requests device reset of the graphics accelerator card on the same server based on a graphics accelerator card error log; simultaneously, the administrator accesses the server through an out-of-band management interface to prepare for manual takeover. The server baseboard management chip assigns an action request identifier to each request and records the agent identifier, authorization source, target object, action type, timing window, and task chain context; the security adjudication module determines that both host power-on / off and graphics accelerator card reset are high-risk actions and both affect the same host's service status, and the conflict domain and concurrency arbitration module classifies them into the same host service conflict domain. If the administrator has set a manual takeover flag, the high-risk actions of the two agents will be placed in a conflict-holding or manually verified state, allowing only continued reading of sensor data, event logs, and hardware health summaries. If the host power-on / off has entered the execution sequence, the execution sequence and the transaction lock control module will set a transaction lock on the host's business conflict domain. During the transaction lock period, the graphics accelerator card reset request needs to be re-checked for conflict, and execution will be delayed, rejected, or executed under restricted conditions depending on the conflict situation. If the two agents repeatedly request to perform reset, power-on / off, or firmware update on the same conflict domain within a short period of time and the target state is not restored, a target-level or conflict domain-level circuit breaker will be triggered. If the anomaly continues to spread, it will be escalated to an agent-level or platform-level circuit breaker. The audit evidence chain records the original requests of the two agents, the action parsing results, the target object lock state, the manual takeover state, the concurrent arbitration result, the final execution result, and the circuit breaker state.

[0086] This embodiment avoids multiple management actions from simultaneously entering the same high-risk hardware control path by utilizing target object locks, transaction status, manual takeover flags, and tiered adjudication results when multiple agents are operating in parallel or when a human administrator intervenes.

[0087] In another preferred embodiment of the present invention, the audit evidence chain, based on the original binding information, further incorporates the request integrity and anti-replay verification results, snapshot unique identifier and data validity, combined risk judgment results, conflict domain identifier, concurrent request set, concurrent arbitration results, manual takeover flag, transaction identifier and transaction lock status, lock heartbeat, circuit breaker reason code, circuit breaker scope, circuit breaker release condition check results, and recovery observation results into the time-series binding record. This unified identifier links the request, adjudication, execution, rollback, circuit breaker, and recovery records, forming a complete evidence chain for responsibility tracing and fault review, providing a complete evidence barrier for behavior restoration and fault causal determination under the multi-layer link of intelligent agent operation and maintenance.

[0088] Furthermore, the newly added mechanisms in this embodiment can all be implemented in multiple equivalent ways: transaction locks can be implemented using hardware locks, firmware locks, service process locks, or hardware and firmware collaborative locks, and lock lease periods, execution heartbeats, maximum execution times, and protected emergency takeover paths can be set; conflict domains can be established according to target object levels, shared power domains, shared thermal management domains, shared firmware storage, shared reset links, or shared management buses, and their granularity and locking rules can be configured by the platform; the circuit breaker's scope can be upgraded or downgraded according to the number of abnormal repetitions, the scope of impact diffusion, and the recovery result; the unique identifier, timestamp, data freshness, status validity bits, sensor health status, and policy version of the snapshot of the local hardware running context data can all be recorded along with the snapshot.

[0089] Furthermore, it should be noted that the present invention is not limited to the specific implementations described in the above embodiments. Those skilled in the art, based on their understanding of the core concept of the present invention, can make various equivalent modifications to the implementation methods. Specific examples are as follows: Although the above embodiments use a cloud-based Agentic AI system as an example, the source of the Agent management action requests described in the present invention is not limited to this. It can also come from an Agent system deployed privately by an enterprise, a local data center management node, a lightweight Agent running locally on a server, or other management entities with autonomous decision-making capabilities, such as an AI PC management terminal.

[0090] The functional modules within the server baseboard management chip (BMC SoC) of this invention (including the action parsing module, risk classification module, policy adjudication module, tool sandbox module, circuit breaker and degradation control module, and audit evidence chain recording module, etc.) can be implemented using a pure hardware state machine, or by having the management microcontroller within the chip run firmware. Alternatively, they can be implemented using the chip's built-in hardware security module (HSM), trusted execution environment (TEE), or through a combination of hardware logic and on-chip firmware. Any technical means that can achieve the corresponding functions described in this invention are considered equivalent alternatives.

[0091] Although the above embodiments use a locally preset static risk level classification (L0 to L4) as an example, the specific implementation of the action risk classification in this invention is not limited to this. It can employ a fixed rule table for hard-coded matching, a dynamically loadable configurable strategy table, a whitelist or blacklist-based filtering mechanism, a multi-dimensional feature-based hierarchical scoring mechanism, or a multi-condition combined state machine for dynamic judgment. All of the above judgment methods are equivalent replacements for the risk classification mechanism of this invention.

[0092] While the above embodiments illustrate the storage of the audit evidence chain in a secure storage area embedded within the chip, the storage location of the audit evidence chain described in this invention is not limited to this. It can be stored in the BMC's local non-volatile memory (such as a protected partition of on-chip eFlash or SPI Flash), or reported to a remote log server or a unified security audit system in a data center via an out-of-band network, or stored in an external trusted storage area (such as a blockchain evidence storage platform or a tamper-proof log database) for centralized management and long-term traceability.

[0093] Any equivalent substitution, partial technology integration, module function reorganization, or structural improvement made based on the core idea of ​​this invention—that is, establishing a complete secure execution link within the server baseboard management chip (BMC SoC) for AgenticAI management actions, including action parsing and semantic modeling, risk classification, real-time hardware status verification, permission and policy adjudication, tool call sandbox isolation, execution circuit breaking and degradation, transactional rollback recovery, and an immutable audit evidence chain record—should fall within the protection scope of this invention.

[0094] Those skilled in the art will understand that the execution order of the above method steps can be reasonably and adaptively adjusted according to the timing characteristics of specific hardware platforms, without departing from the core security mechanism of this invention. Furthermore, the above embodiments only illustrate several preferred implementations of this invention, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of protection of this invention. Any equivalent substitutions, partial technical integrations, and structural improvements made under the guidance of the core concepts of physical interception, state verification, sandbox proxy execution, and timing circuit breaking of this invention should fall within the protection scope of the claims of this invention.

Claims

1. An Agentic AI security adjudication method for server board management chips, characterized in that, The method is executed by the server baseboard management chip and includes the following steps: Step S1, receiving a management action request from the upper-layer Agentic AI system, the management action request indicating an intent control behavior for a target hardware object; Step S2, collecting local hardware runtime context data of the target hardware object and its server in real time within the chip's management domain; Step S3, performing security verification by combining the intent control behavior, the local hardware runtime context data, and locally preset security restriction policies to make a dynamic security decision on the management action request; Step S4, when the decision indicates permission, physically or logically isolating the upper-layer Agentic AI system's direct access to the underlying hardware physical control path, and executing the hardware management action corresponding to the intent control behavior through a controlled tool sandbox agent built into the chip.

2. The Agentic AI security adjudication method according to claim 1, characterized in that, After performing step S1, step S1A is also performed, which includes: performing structured configuration parsing on the management action request to identify the behavior type, feature parameters and initiator credibility credentials, and converting them into behavior description tokens that can be processed inside the chip.

3. The Agentic AI security adjudication method according to claim 2, characterized in that, The dynamic security decision includes: determining the destructive risk level of the intent to control behavior based on the behavior description token, and directing requests of different risk levels to corresponding hierarchical verification paths; wherein, read-only requests that do not change the hardware state are directly allowed, and high-risk requests that change the hardware state are subject to mandatory pre-hardware context linkage verification.

4. The Agentic AI security adjudication method according to claim 1, characterized in that, The local hardware operating context data includes environmental telemetry indicators characterizing the thermal and electrical characteristics of the server environment, status indicators characterizing the activity of the host operating system, and timeliness indicators characterizing whether the current time is within the operation and maintenance compliance cycle; the local hardware operating context data also carries a unique snapshot identifier and data validity information, the data validity information including sampling time, data source, validity period, and status validity bit.

5. The Agentic AI security adjudication method according to claim 1, characterized in that, After executing step S4, step S5 is also executed, which includes: recording the action call sequence of the upper-layer Agentic AI system within a historical sliding time window; when the action call sequence is identified as meeting a preset abnormal behavior pattern or triggering continuous operation failure of a specific hardware target, activating the circuit breaker mechanism, forcibly cutting off the passage channel for subsequent high-risk requests and downgrading to read-only telemetry or manual takeover state; wherein, the abnormal behavior pattern includes a thermal power coupling combination of reducing fan cooling capacity and increasing hardware power consumption limit occurring simultaneously within the preset time window; after activating the circuit breaker mechanism, a graded circuit breaker release is also performed according to the cause of the circuit breaker, and after release, the system enters a recovery observation state.

6. The Agentic AI security adjudication method according to claim 2, characterized in that, The controlled tool sandbox proxy execution includes: matching the underlying security tool descriptor corresponding to the behavior description token in the tool sandbox, and controlling the transactional secure implementation of hardware management actions based on the parameter validity range whitelist, call frequency limit, and post-state verification conditions restricted by the descriptor.

7. The Agentic AI security adjudication method according to claim 1, characterized in that, Before performing step S4, step S3A is also performed. Step S3A includes: backing up the current physical configuration and image state of the system as snapshot data to a non-volatile storage area to establish a safe rollback point; and when the hardware management action times out, returns an error, or causes subsequent hardware state deterioration, the system is forcibly restored to the initial safe state before the action is performed based on the safe rollback point.

8. The Agentic AI security adjudication method according to claim 1, characterized in that, After performing step S4, step S6 is also performed. Step S6 includes: for each management action request, generating an immutable audit evidence chain in the secure storage area embedded inside the server baseboard management chip. The audit evidence chain records the request source identifier, hardware operating context data before and after execution, security adjudication process snapshot, and final execution rollback result in a time sequence using cryptographic digest.

9. An Agentic AI security adjudication system for server board management chips, characterized in that, Deployed in a server baseboard management chip, and applying the Agentic AI security adjudication method as described in any one of claims 1-8, the method includes: a management interface module for receiving management action requests from an upper-layer Agentic AI system; a hardware state snapshot module for real-time acquisition of local hardware runtime context data of the target hardware object and its server within the chip management domain; a security adjudication module for performing security verification by combining the intent control behavior, the local hardware runtime context data, and locally preset security restriction policies to make a dynamic security adjudication on the management action request; and a tool sandbox execution module for physically or logically isolating the upper-layer Agentic AI system from direct access to the underlying hardware physical control path when the adjudication result indicates permission, and executing the hardware management action corresponding to the intent control behavior through a controlled tool sandbox agent built into the chip.

10. The Agentic AI security adjudication system according to claim 9, characterized in that, Also includes: The request integrity verification module is used to verify the integrity, freshness, and anti-replay of the management action request in terms of identity source, signature or message authentication code, timestamp, sequence number, random number, session identifier, and channel binding. The conflict domain and concurrency arbitration module is used to establish conflict domains based on the target object level, shared resource domain, and action impact scope. It performs mutual exclusion, sequentialization, or re-arbitration on high-risk write actions located within the same conflict domain, and prioritizes arbitration for conflicts arising from multiple agent parallel requests or human administrator intervention. The execution sequence and transaction lock control module is used to generate execution sequences for permitted actions and set transaction identifiers, lock holders, lock lease periods, maximum execution times, and execution heartbeats for high-risk actions. The circuit breaker and degradation control module is used to determine the circuit breaker scope based on the anomaly source, affected objects, and risk propagation range. The circuit breaker scope at least covers the tool level, action type level, target object level, conflict domain level, agent level, task chain level, and platform level, and performs tiered circuit breaker release and recovery observation.