SERVER NODE

The server node design addresses the lack of versatility and interoperability in security measures by integrating a switch-controlled motherboard with ASTXXXX and CEC173X safety chips, enhancing security against cyber and physical threats while offering flexible chip selection.

FR3155332A3Active Publication Date: 2025-05-16NEBIUS BV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2024011915
Authority / Receiving Office
FR · FR
Patent Type
Utility models
Current Assignee / Owner
Priority Date
2023-10-31
Filing Date
2024-10-30
Publication Date
2025-05-16
Estimated Expiration
2034-10-30

AI Technical Summary

Technical Problem

Conventional server nodes lack versatility and interoperability in security measures, particularly in integrating safety chips across different devices and systems, which can lead to vulnerabilities in cyber security and physical attacks.

Method used

A server node design that incorporates a motherboard with a BIOS/BMC loading module, a first safety chip of the ASTXXXX type, and a second safety chip, connected through a switch that selectively activates the operation of these chips, enhancing security and flexibility.

Benefits of technology

The solution provides enhanced security against a wide range of cyber threats and physical attacks by utilizing advanced encryption, authentication, and intrusion detection mechanisms, while also offering flexibility in chip selection to optimize security measures according to specific needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Server nodes are provided. The server node has a case containing a server node body designed to house a motherboard. The motherboard has a BIOS / BMC load module, a first security chip of type ASTXXXX, and a second security chip of type CECXXX. The first and second security chips are connected to the BIOS / BMC load module via a switch. The switch is configured to selectively enable the operation of the first and second security chips. [FIG. 2]
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: SERVER NODE Technical field

[0001] The present technology relates to a server node, and more particularly to a server node comprising security microchips. CONTEXT

[0002] A server is a central computer that typically serves computers in a network environment and provides functionality needed by those network computers such as storing, processing, and exchanging information. Conventional servers may be implemented in a similar manner to conventional personal computers and typically include one or more central processing units (CPUs), one or more memories, and one or more input / output devices that are all communicatively coupled together internally via a bus. These internal components of the server or server hardware operate according to inherent specifications and may be influenced by external factors such as temperature, humidity, pressure, and the like. A server rack may encompass a plurality of computing nodes.

[0003] A computing node uses firmware associated with node boot functions. The firmware first boots the hardware components, looking for driver errors, etc. In data center-based solutions, it is essential to validate the hardware components and their immutability when loading the computing node and / or server rack. More specifically, when booting the computing node and / or server rack, it is necessary to verify that no changes in the server firmware can lead to a security breach, for example, with the aim of stealing data or generating fake traffic. SUMMARY

[0004] Embodiments of the present technology have been developed based on developers' appreciation of the demand for firmware security measures. To this end, security chips may be used to provide protection against a wide range of cyber threats. The security chips may incorporate advanced encryption, authentication, and intrusion detection mechanisms. The security chips may also include tamper-resistant features to thwart physical attacks on devices containing the chips.

[0005] However, developers have also become aware of the lack of versatility or interoperability of security chips when integrated in various devices and systems, ranging from personal computers and mobile devices to server racks and / or other critical infrastructure components. Embodiments of the present technology were developed based on the developers' appreciation of at least one technical problem associated with prior art solutions.

[0006] In one aspect of the present technology, there is provided a server node comprising a housing having a server node body for accommodating a motherboard, the motherboard having: (i) a BIOS\BMC loading module, (ii) a first security chip of a type ASTXXXX and (iii) a second security chip of a type CECXXX. The first security chip and the second security chip are connected to the BIOS\BMC loading module via a switch. The switch is configured to selectively enable operation of the first security chip and the second security chip.

[0007] In some embodiments of the server node, the switch includes a first jumper associated with the first security chip and a second jumper associated with the second security chip.

[0008] In some embodiments of the server node, the switch includes a programmable element.

[0009] In some embodiments of the server node, the programmable element is a field programmable gate array (FPGA).

[0010] In some embodiments of the server node, the first jumper is a first hardware jumper and the second jumper is a second hardware jumper.

[0011] In some embodiments of the server node, the first jumper is a first software jumper and the second jumper is a second software jumper. Brief Description of the Drawings

[0012] These and other features, aspects and advantages of the present technology will be better understood with reference to the following description and the appended drawings and claims wherein:

[0013] [Fig.l] is a front left perspective view of a server rack housing a chassis structure;

[0014] [Fig.2] is a left front perspective view of the chassis structure of [Fig.l] with first and second computer nodes in a receiving position, and housing a plurality of electronic components;

[0015] [Fig.3] is a left front perspective view of a chassis of the chassis structure of [Fig.l], with fans, and with the first and second computing nodes removed;

[0016] [Fig.4] is an exploded left front view of the chassis and second computing node of [Fig.2], with the electronic components of the second computing node removed, with the fans removed, and with the first computing node removed;

[0017] [Fig.5] is a left front perspective view of the chassis structure of [Fig.2] with the first computing node in a first withdrawn position and with the second computing node withdrawn;

[0018] [Fig.6] is a left front perspective view of the chassis structure of [Fig.5] with the first computing node in a second withdrawn position and with fourth electronic components in a storage position;

[0019] [Fig.7] is a top plan view of the frame structure of [Fig.2], with different fluid flow portions during operation;

[0020] [Fig.8] is a right rear perspective view of the chassis structure of [Fig.2];

[0021] [Fig.9] is a wiring diagram of a motherboard of the second computer node of [Fig.2]; and

[0022] [Fig. 10] is a subsystem of the motherboard of [Fig.9] implemented in accordance with certain embodiments of the present technology. DETAILED DESCRIPTION

[0023] The examples and conditional formulations mentioned herein are primarily designed to assist the reader in understanding the principles of the present technology and are not intended to limit its scope to the examples and conditions expressly mentioned. It will be understood that those skilled in the art can devise various arrangements which, although not explicitly described or shown herein, embody the principles of the present technology and do not depart from its spirit or scope.

[0024] Further, in order to facilitate understanding of the present technology, the following description may describe relatively simplified implementations thereof. Those skilled in the art will understand that various implementations of the present technology may be more complex.

[0025] In some instances, examples of modifications to the present technology that are considered useful may be set forth. These are merely for the purpose of facilitating understanding and, again, do not define the scope or establish the limitations of the present technology. These modifications are not an exhaustive list, and those skilled in the art may make other modifications without departing from the scope of the present technology. Furthermore, where no examples of modifications have been presented, it should not be inferred that no modifications are possible and / or that what is described is the only way to implement this element of the present technology. Chassis structure

[0026] Referring to [Fig. 1], there is shown a server rack 1200 housing a chassis structure 100 among a plurality of chassis structures (unnumbered). It can therefore be said that the chassis structure 100 is configured to be housed in the server rack 1200. Generally, one or more chassis structures of the server rack 1200 are configured to process requests and / or processable tasks for an external client. For example, data indicating a given processable request may be acquired by one or more electronic components of the chassis structure 100 (and / or by electronic components of other chassis structures of the server rack 1200). This data may then be processed and / or stored by the one or more electronic components of the chassis structure 100.

[0027] As shown in [Fig. 2], the chassis structure 100 includes a chassis 200 and two computing nodes, namely a first computing node 301 and a second computing node 302. The chassis structure 100 also includes fans 400 at the rear. It is contemplated, in alternative embodiments of the present technology, that the fans 400 may be omitted. It is further contemplated that the fans 400 may, alternatively, be placed on a rear portion of the server rack 1200. It should be noted that, in some embodiments of the present technology, the first computing node 301 may be identical to the second computing node 302. Chassis

[0028] The manner in which the frame 200 of the frame structure 100 may be implemented in at least some embodiments of the present technology will now be described with reference to [Fig. 3].

[0029] As shown in [Fig. 3], the chassis 200 includes a first bottom panel 202, a first side wall 204, a second side wall 206, a partition wall 208, and a rear wall 210. The first side wall 204 and the second side wall extend longitudinally in the chassis 200 and are located on respective sides of the first bottom panel 202. The partition wall 208 also extends longitudinally in the chassis 200 and is located between the first side wall 204 and the second side wall 206. The partition wall 208 is substantially parallel to the first side wall 204 and the second side wall 206. The rear wall 210 extends laterally between the first side wall 204 and the second side wall 206 at the rear of the chassis 200 and is connected thereto.

[0030] The first side wall 204, the second side wall 206, the partition wall 208 and the rear wall 210 are attached to the first bottom panel 202 of the chassis 200 using any suitable fastening means, such as bolts and / or screws, for example. Alternatively, the first side wall 204, the second side wall 206, the partition wall 208 and the rear wall 210 may be formed integrally with the first bottom panel 202 to provide the chassis 200.

[0031] The rear wall 210 is also configured to house, among other things, a power connector 214, motherboard connectors 216, and other connectors (unnumbered) that will be discussed in more detail below in this document. The rear wall 210 is provided with ports 212 for, generally, allowing fluid communication between the interior of the chassis 200 and the exterior of the chassis 200 through the rear wall 210.

[0032] It should be noted that, in the non-limiting embodiment shown in [Fig. 3], the fans 400 are removably attached to the rear wall 210 on the exterior of the chassis 200. As illustrated, when the fans 400 are removably attached to the rear wall 214, the fans 400 are longitudinally aligned with respective ports 212. As will be described in more detail below in this document, the position of the fans 400 relative to the ports 212 allows the fans 400 to produce one or more fluid flows in the direction 250, namely from the interior of the chassis 200, through the rear wall 210, to the exterior of the chassis 200.

[0033] It should be noted that the first side wall 204, the second side wall 206, the partition wall 208 and the rear wall 210 and the first bottom panel 202 define two storage spaces in the chassis 200, namely a first storage space 270 and a second storage space 260.

[0034] The first storage space 270 is defined by the first bottom panel 202, by the first side wall 204 on the left, by the partition wall 208 on the right and by the rear wall 210 on the rear. Similarly, the second storage space 260 is defined by the first bottom panel 202, by the second side wall 206 on the right, by the partition wall 208 on the left and by the rear wall 210 on the rear. The two storage spaces 120 are disposed on respective sides of the partition wall 208. In a specific non-limiting embodiment of the present technology, the two storage spaces 270 and 260 may be substantially identical to each other.

[0035] The chassis handles 285 are disposed on the first lower panel 202 and extend forwardly away from the chassis 200.

[0036] The first storage space 270 of the chassis 200 is configured to house the first computing node 301 (see [Fig.l]) and the second storage space 260 of the chassis 200 is configured to house the second computing node 302 (see [Fig.l]) or vice versa. A given storage space among the two storage spaces 270 and 260 can be said to house a respective computing node among the computing nodes 301 and 302. Computer node

[0037] The manner in which the second computing node 302 is implemented will now be described with reference to [Fig. 4]. However, it should be noted that the first computing node 301 may be implemented in a similar manner to the second computing node 302, without departing from the scope of the present technology.

[0038] [Fig. 4] illustrates a representation 300 of the chassis 200 and the second computing node 302 in an exploded view. It should be noted that the first computing node 301 and the internal components of the chassis structure 100 have been omitted from the illustration of [Fig. 4] for the sake of simplicity. In addition, the representation 300 of the chassis 200 and the second computing node 302 is a simplified representation of the chassis 200 and the second computing node 302 for the sake of simplicity.

[0039] As can be seen, the second computer node 302 comprises a body 304, a tray frame 320 and a sliding assembly 325, which will now be described in turn.

[0040] The body 304 includes a first bottom panel 306, a third side wall 308, and a fourth side wall 310. The third side wall 308 and the fourth side wall 310 extend longitudinally within the chassis 304 and are located on respective sides of the second bottom panel 306. The computing node handle 280 is disposed on the second bottom panel 306 and extends forwardly away from the body 304. The third side wall 308 and the fourth side wall 310 are attached to the second bottom panel 306, but may alternatively be formed integrally with the second bottom panel 306.

[0041] It should be noted that a given computing node is configured to be removed from a respective storage space, which may be desirable for various reasons. For example, the given computing node may be removed from the respective storage space by an operator for maintenance and / or replacement purposes. Thus, it can be said that the body 304 is configured to be removably stored in the second storage space 260. It can therefore be said that the second computing node 302 may be removably stored in the second storage space 260.

[0042] In addition, the body 304 has a front portion 312 and a rear portion 314. The front portion 312 of the body 304 and the rear portion 314 of the body 304 are longitudinally arranged sequentially in the body 304 from the front end thereof to a rear end thereof.

[0043] The front portion 312 of the body 304 is configured to accommodate the tray frame 320. The tray frame 320 has two sides (unnumbered) and includes a top opening 322. The tray handle 290 is disposed on one of the two sides of the tray frame 320 and extends forwardly from the tray frame 320. The tray frame 320 is slidably movable from a receiving position to at least one retracting position such that, when the tray frame 320 is in the receiving position, the tray frame 320 is located in the front portion 312 of the body 304.

[0044] It should be noted that the tray frame 320 is configured to slidably move between the receiving position and the at least one retracting position by means of the sliding assembly 325 of the second computing node 302. The sliding assembly 325 is located in the front portion of the body 304. The sliding assembly 325 comprises a given side of the tray frame 320 and the corresponding fourth side wall 310 of the body 304. However, the sliding assembly 325 may comprise the other side of the tray frame 320 and the corresponding third side wall 308. In some embodiments, however, the second computing node 302 may have two sliding assemblies, one on each side of the tray frame 320, and implemented in the same manner as the sliding assembly 325.

[0045] In one embodiment, the given side of the tray frame 320 may be nested within the corresponding side wall of the body 304 to provide the sliding assembly 325. That is, the corresponding side wall of the body may be configured to receive the given side of the tray frame 320 by nesting to provide a sliding assembly. In a further embodiment, the corresponding side wall of the body may be adapted to receive the given side of the tray frame 320 by nesting to provide a sliding assembly. In another embodiment, the given side of the tray frame 320 and the corresponding side wall of the body 304 may have suitable railing structures to provide the sliding assembly 325.

[0046] It should be noted that the sliding assembly 325 may be implemented in a variety of ways for a specific application of the present technology. However, the sliding assembly 325 is configured to longitudinally and slidably move a respective tray frame of a given computing node between (i) a receiving position (see [Fig. 2]), (ii) a first retracting position (see [Fig. 5]), and (iii) a second retracting position (see [Fig. 6]). As will become more apparent from the description below herein, the purpose of slidably moving the given tray frame is to provide access or additional access to at least some components electronics of the respective computing node, without the need to remove the respective computing node from the chassis 200.

[0047] It should also be noted that the second computing node 302 also includes a chain structure 3020 (see [Fig. 7]). The chain structure 3020 is attached to (i) the tray frame 320, to a rear of the tray frame 320, at one end thereof, and (ii) the second bottom panel 306 of the body 304 at the other end thereof. Generally, the chain structure 3020 is provided to prevent the risk of removal of the tray frame 320 from the body 304 at a location where it is separated therefrom. It can be said that the chain structure 3020 can limit the position of the tray frame 320 and cooperates with the sliding assembly 325 to prevent the tray frame 320 from falling or being separated from the body 304 inadvertently.

[0048] It is contemplated, in at least some embodiments of the present technology, that the chain structure 3020 may be pivotally attached to the tray frame 320 at the rear of the tray frame 320 at one end thereof and pivotally attached to the second lower panel 306 of the body 304 at the other end thereof.

[0049] In addition to connecting the tray frame 320 to the body 304, the chain structure 3020 may define a hollow passage (unnumbered) to accommodate wiring for electrically coupling at least some electronic components in the tray frame 320 to at least some electronic components in the body 304. Electronic components

[0050] As mentioned above, the second computing node 302 is configured to house electronic components for data processing and / or storage purposes. It should be noted that at least some of the electronic components are housed in the tray frame 320, while other electronic components are housed in the body 304. The electronic components of the second computing node 302 that are housed in the tray frame 302 (e.g., the one housed in the front portion 312 of the body 304) and the electronic components of the second computing node 302 that are housed in the body 304 (e.g., the rear portion 314 of the body 302) will now be described with reference to FIGS. 7 and 8.

[0051] The second computing node 302 houses, within the tray frame 320, the first electronic components 1000 and the fourth electronic components 2000. Generally, the first electronic components 1000 and the fourth electronic components 2000 may be distinct types of storage media. For example, the first electronic component 1000 may be a hard disk drive (HDD). The fourth electronic component 2000 may be a solid-state drive (SSD) or a non-volatile memory storage medium (NVME). The first electronic component 1000 may be disposed at the front of the tray frame. 320 and the fourth electronic components 2000 at the rear of the tray frame 320 (longitudinally behind the first electronic components 1000).

[0052] The rear portion 314 of the second computing node 302 houses a motherboard 3000. The motherboard 3000 is electrically coupled to the first electronic components 1000 and the fourth electronic components 2000 by wiring (not shown), as is known in the art. The motherboard 3000 is also electrically coupled to the power connector 214 via the motherboard connector 216. For example, the power connector 214 may be electrically coupled to a power bus of the server rack 1200 (see [Fig. 1]), then to a power source, and may provide electrical power to the motherboard 3000 and other electronic components of the second computing node 302. Motherboard

[0053] With reference to [Fig. 9], the motherboard 3000 will now be described in more detail. The motherboard 3000 includes two central processing units (CPUs), namely a first CPU 3014 and a second CPU 3016. The first CPU 3014 and the second CPU 3016 are connected to the motherboard 3000. It is contemplated that the first CPU 3014 and the second CPU 3016 may be communicatively coupled and / or electrically connected to one or more other electronic components via the motherboard 3000. In some embodiments of the present technology, each of the first and second CPUs 3014, 3016 may be inserted into a respective socket on the motherboard 3000. In some embodiments, the sockets are identical so that the first and second CPUs 3014, 3016 may be interchangeable.In alternative embodiments, a first socket is configured to receive the first CPU 3014 and a second socket is configured to receive the second CPU 3016, such that the first socket is dedicated to the first CPU 3014 and the second socket is dedicated to the second CPU 3016. Although two CPUs 3014, 3016 are shown, it is contemplated that any number of CPUs may be connected to the motherboard 3000 without departing from the scope of the present technology.

[0054] The motherboard 3000 includes a platform controller hub 3018. The platform controller hub 3018 is connected to the motherboard 3000. It is contemplated that the platform controller hub 3018 may be communicatively coupled and / or electrically connected to one or more other electronic components via the motherboard 3000. The platform controller hub 3018 is further connected to the first CPU 3014 and the second CPU 3016.

[0055] It should be noted that a platform controller hub (PCH) is a component in computer architectures that serves as a central hub for managing and controlling various functions of a computer's motherboard, such as the card 3000 motherboard. It acts as a communications and management center, facilitating the flow of data between one or more CPUs, memory, storage devices, and / or peripherals. It is envisioned that the PCH 3018 may also be used for tasks such as connecting USB ports, SATA ports, Ethernet ports, audio components, and other input / output interfaces to the 3000 motherboard. The PCH 3018 may also handle power management, system configuration, and various low-level operations that allow different hardware components to work together. By consolidating one or more of these functions into a single chip, the PCH 3018 helps simplify communication and coordination between different hardware components, thereby optimizing overall system performance and efficiency. It is envisioned that the PCH 3018 may support different interfaces and connectivity options.

[0056] The motherboard 3000 further includes a motherboard management controller (BMC) chip 3021 for remote management, monitoring, and control of hardware. The BMC chip 3021 may include a serial peripheral interface (SPI) flash device 3043. The BMC chip 3021 is integrated with the motherboard 3000 and is connected via an SPI bus 3044. In some embodiments of the present technology, the BMC chip 3021 may be connected via an inter-integrated circuit (I2C) 3040 and / or a system management bus (SMBus). The BMC chip 3021 includes firmware storage that contains code for remote management and monitoring functions and is typically stored in a flash chip disposed on the motherboard 3000. As shown in [Fig.9], the BMC chip 3021 is connected to the platform controller hub 3018 via a first multiplexer 3024.

[0057] It is contemplated that a BMC may be implemented as a specialized microcontroller embedded on a computer motherboard, such as the 3000 motherboard. As such, a BMC chip may be responsible for monitoring, managing, and controlling many aspects of a system, even when a CPU is powered down or unresponsive. The 3021 BMC chip may be used for remote management, system health monitoring, and maintenance of servers, network equipment, and other business hardware. For example, the 3021 BMC chip may be used for system security by enabling features such as BIOS updates, monitoring intrusion detection sensors, and providing a secure interface for managing encryption keys.

[0058] A 3022 SPI flash device for a basic input-output system (BIOS) is connected to the motherboard 3000. The 3022 SPI flash device is connected to the motherboard 3000 via a 3042 SPI bus. In some embodiments of the present technology, the 3022 SPI flash device may be connected via an I3C or an SMBus. The SPI flash device 3022 stores in memory instructions for a hardware initialization and boot process, as well as to facilitate communication between the operating system and hardware components during boot. As shown in [Fig.9], the SPI flash device 3022 is connected to the PCH 3018 via a second multiplexer 3024.

[0059] Generally speaking, an SPI flash device is a type of non-volatile memory used in electronic devices, such as systems, microcontrollers, and other embedded hardware components. An SPI flash device can store data when power is off and is accessible using the SPI protocol. SPI flash memory comes in various capacities and is used for storing firmware, boot sequences, configuration data, and other information that must be retained across power cycles. The SPI protocol is a synchronous communication protocol commonly used to connect microcontrollers, sensors, and other peripherals to a CPU or other microcontrollers. It involves a master-slave architecture where one device (master) controls communication with one or more peripherals (slaves).SPI uses a clock signal and multiple data lines to transmit data between devices. The clock signal synchronizes data transmission, and data can be exchanged in full-duplex mode, allowing simultaneous sending and receiving of data. SPI is often used for tasks involving reading and writing to memory devices (such as SPI flash memories), controlling peripherals such as sensors and display screens, and establishing communication between microcontrollers in various embedded systems. This may require more pins compared to other communication protocols such as I2C, for example.

[0060] Upon server startup, validation of software and / or hardware components must be completed to determine if they have been tampered with by hackers or fraudulent users who may modify the firmware or server(s) to steal data and / or generate false traffic. It is possible to implement microchips with security checks that can verify the server's operating system and hardware components. More specifically, the present technology implements a microchip of the ASTxxxx 3021 chip series by AspeedTech™ for the BMC 3021 chip. It will be understood that, in this context, the identifier of xxxx indicates a serial number associated with the ASTxxxx type chip series. In embodiments of the present technology, an AST2xxx 3021 chip, such as FAST2600, may be used. This technology implements a microchip from the CECxxx 3023 chip series by Microchip™ for the 3023 BIOS chip.It will be understood that, . in this context, the identifier of xxx indicates a serial number associated with the series of chips of type CECxxx. In embodiments of the present technology, a CEC173x 3023 chip is implemented.

[0061] The AST2xxx 3021 chip provides security features such as secure boot, encryption, and remote authentication to protect the server and its management functions. The AST2xxx 3021 chip uses a special memory section that writes instructions only once, eliminating the possibility of overwriting instructions.

[0062] The CEC173x 3023 chip serves as a root of trust, providing robust security features, such as hardware cryptographic acceleration, secure boot, secure key storage and encryption capabilities that make the CEC173x chip suitable for a high level of data protection.

[0063] The AST2xxx 3021 chip and the CEC173x 3023 chip are integrated into the 3000 motherboard. Having the AST2xxx 3021 chip and the CEC173x 3023 chip on the same 3000 motherboard provides end users with the flexibility and adaptability to optimize chip selection to server / data center requirements. That is, end users can select whether the AST2xxx 3021 chip or the CEC173x chip is connected to best meet the end users' needs.

[0064] Each of the AST2xxx chip 3021 and the CEC173x chip 3023 may be connected to the motherboard 3000 via a respective jumper 3028, 3029. A host RST line 3045 is used in association with the jumper 3028 and a BMC RST line 3046 is used in association with the jumper 3029. Generally, the host RST line 3045 and the BMC RST line 3046 correspond to wired (circuit) communication lines for reboot command transfer to reboot the host and the BMC, respectively.

[0065] Generally speaking, a jumper connection, often simply referred to as a "jumper," is an electrical component used in electronic components and computer hardware to configure and / or modify the behavior of a device and / or circuit. In some embodiments, a jumper has a pair of conductive metal pins or "terminals" that can be connected and / or disconnected using a plastic cap or metal bridge. Jumper connections are used to set specific parameters and modes on printed circuit boards, such as motherboards. They allow operators to select options without necessarily requiring specialized programming or software. By placing or removing the jumper cap on the appropriate pins, specific functions or configurations can be selectively enabled or disabled.

[0066] In some cases, jumpers may be used to configure hardware settings such as disk master / slave settings, clock frequencies, voltage levels, and data transfer modes. For example, on hard drives, these may determine whether a drive is set as the master or slave in a dual-drive configuration. In other cases, a given motherboard may be implemented with a jumper to clear BIOS or CMOS settings, effectively resetting the hardware to default values. In still other cases, jumpers may enable or disable specific features or components on a printed circuit board, as will be discussed herein.

[0067] In some embodiments, one or more jumpers may be implemented as software jumpers, as opposed to physical / hardware jumpers. Arguably, a software jumper may enable the same functionality as a hardware jumper using software commands without necessarily requiring physical manipulation. It is contemplated that a software jumper may allow alteration of configuration parameters, through software interfaces or commands, that may be changed easily and remotely relative to hardware jumpers. This virtual approach to jumper functionality allows for dynamic reconfiguration and customization. These provide the flexibility to adjust system behavior, parameters, and / or operating modes without requiring operators to access physical hardware.This simplifies system maintenance, troubleshooting, and upgrades. In some embodiments, a software jumper may be implemented via one or more embedded BIOS commands.

[0068] It should be noted that the AST2xxx chip 3021 is associated with a first jumper 3024 and the CEC173x chip 3023 is associated with a second jumper 3026. In this embodiment, the first and second jumpers 3028, 3029 are physical connectors having a jumper cap that are used to complete the electrical circuit on the motherboard 3000. The end user can select whether the AST2xxx chip 3021 or the CEC173x chip is connected by connecting the respective jumper 3028, 3029. More specifically, when the first jumper 3028 is connected, the AST2xxx chip 3021 is connected. Similarly, when the second jumper 3029 is connected, the CEC173x chip is connected. It is contemplated, in other embodiments of the present technology, that the first and second jumpers 3028, 3029 may be other forms of connectors without departing from the scope of the present technology.

[0069] In some embodiments, a server node is provided. The server node may include a body housing a motherboard. More specifically, the motherboard comprises (i) a loading module such as a BIOS \ BMC module, for example, (ii) a first security chip such as the AST2xxx chip, for example, and (ii) a second security chip such as the CEC173x chip, for example. The first security chip is associated with a first connection and a first jumper on the motherboard, and the second security chip is associated with a second connection and a second jumper on the motherboard.

[0070] During operation, one or more components of the motherboard may be configured to use at least one of the first security chip and the second security chip by closing and / or opening at least one of the first jumper or the second jumper. In some embodiments, the one or more components of the motherboard may utilize the first jumper and the second jumper to selectively and interchangeably use the first security chip and the second security chip during operation of the server node.

[0071] In some embodiments, the functionality of the one or more jumpers may be implemented using a switch comprising a programmable element. For example, the switch may comprise field-programmable gate arrays (FPGAs) which are integrated circuits providing reconfigurable hardware functionality. Unlike traditional application-specific integrated circuits (ASICs), FPGAs can be programmed and reprogrammed after manufacturing, allowing rapid customization for various computing tasks. FPGAs consist of an array of programmable logic blocks interconnected by configurable routing paths, allowing users to create custom digital circuits or even entire processors.

[0072] In some embodiments, the motherboard 3000 may be configured to implement one or more secure boot mechanisms. It should be noted that the first security chip and the second security chip may include respective roots of trust (RoTs) that may be used to verify firmware and / or generate reset signals for application processors. It is contemplated that a first RoT of the first security chip or a second RoT of the second security chip may be selectively used depending on, among other things, the needs or configuration of a client system.

[0073] Referring to [Fig. 10], there is shown a subsystem 1000, comprising a RoT device 1002, an application processor 1004 and a flash device 1006. Generally, the RoT device 1002 is a hardware component configured to store encryption keys used in a “chain of trust” (CoT) where the The code to be executed is initially verified. In computer security, a CoT is established by validating each hardware and software component from the end entity to the root certificate. It is intended to ensure that only trusted software and hardware can be used while maintaining flexibility.

[0074] During the verification operation, if the code execution is valid / legitimate at a given time and / or server state, the cryptographic signature can be calculated and verified by the RoT device 1002. The public and private key pair is used in this process - the private key is used to generate a signature and the public key is used to verify that the signature is correct (i.e., that the signed file has not been modified). On the one hand, access to the private key is controlled or kept "secret" for an environment that generates signatures. On the other hand, the public key is written to the RoT device 1002 and is used by the hardware for firmware verification.

[0075] Additionally or alternatively, the RoT device 1002 may be configured to perform data encryption and / or decryption mechanisms (without exposing the keys), key generation mechanisms, key revocation mechanisms, storage of at least some boot parameters, and the like. Although the RoT device 1002 is considered "secure"—that is, recovery of cryptographic data from the device is complex—developers of the present technology have realized that it may be beneficial for security reasons to avoid storing private keys in RoT devices.

[0076] It is contemplated that a one-time programmable (OTP) memory device may be further used to store cryptographic data and hardware parameters. Depending on a specific implementation of an RoT device, hardware boot parameters and other parameters may also be stored in a corresponding OTP memory device. In some implementations, a write operation may be performed in configurable regions of the OTP memory device after initial OTP provisioning to support key revocation mechanisms.

[0077] In some embodiments, it is contemplated that the RoT device 1002 may be used to prevent execution of untrusted / unverified code on one or more components of the motherboard 3000 and / or the subsystem 1000. To this end, during the power-up phase, the RoT device 1002 may generate a reset signal for the application processor 1004 such as a BMC or a host device, for example, thereby preventing execution of a CPU of the application processor 1004. Furthermore, the RoT device 1002 may read firmware data from the application processor 1004, generate signatures, and perform a verification against the keys in the OTP memory device. In cases where the verification fails, the RoT device 1002 may, among other things, program a master image (an immutable firmware known to be secure) into the SPI image of the application processor 1004. Additionally or alternatively, the RoT device 1002 may further transmit signals to report a current verification status to external subsystems such as a BMC, for example, via an I2C interface.

[0078] Modifications and improvements to the implementations of the present technology described above may be apparent to those skilled in the art. The foregoing description is given by way of example and is not limiting. The scope of the present technology is therefore intended to be limited only by the scope of the appended claims.

Claims

Claims

1. A server node comprising: a housing having a server node body for accommodating a motherboard; the motherboard having (i) a BIOS\BMC loading module, (ii) a first security chip of an ASTXXXX type, and (iii) a second security chip of a CECXXX type; the first security chip and the second security chip being connected to the BIOS\BMC loading module via a switch; the switch being configured to selectively enable operation of the first security chip and the second security chip.

2. The server node of claim 1, wherein the switch comprises a first jumper associated with the first security chip and a second jumper associated with the second security chip.

3. The server node of claim 1, wherein the switch comprises a programmable element.

4. The server node of claim 3, wherein the programmable element is a field programmable gate array (FPGA).

5. The server node of claim 2, wherein the first jumper is a first hardware jumper and the second jumper is a second hardware jumper.

6. The server node of claim 2, wherein the first jumper is a first software jumper and the second jumper is a second software jumper.