BIOS Firmware Key Management for Rack Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key management systems for rack server systems are vulnerable to malicious software attacks as they rely on the operating system layer, allowing viruses to exploit security keys and cause network damage.

Innovation Solution

Implementing key management using the BIOS firmware and Baseboard Management Controller (BMC) prior to the operating system loading, utilizing secure protocols like UEFI BIOS and KMIP to securely exchange and manage security keys, avoiding open-source code vulnerabilities and ensuring protection from viruses and malicious software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If key management is implemented using the operating system layer, then key management functionality can be provided, but the system becomes vulnerable to malicious software attacks

Engineering Contradiction:
ImprovesecurityVSAvoidmalicious software vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements key management functionality in the BIOS firmware, which executes before the operating system is loaded. This preliminary action ensures that security keys are established and protected at a lower system level, preventing malicious software that operates at the OS level from compromising key management. The BIOS-based implementation creates a secure foundation before higher-level software can interfere.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a baseboard management controller (BMC) as an intermediary component that mediates between the BIOS firmware and the operating system. The BMC provides a secure communication channel for key management operations, isolating the security-critical BIOS layer from potential OS-level attacks while still allowing necessary interactions. This intermediary structure protects the security keys from malicious software.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If key management is performed after the operating system loads, then the OS can manage security keys, but viruses can enter through the OS and cause damage

Engineering Contradiction:
Improvekey management capabilityVSAvoidvirus propagation
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent reverses the conventional sequence by implementing key management in the BIOS firmware before the operating system is loaded. This preliminary establishment of security keys ensures that the most critical security functionality is in place before any potentially malicious OS-level software can execute. The BIOS layer provides a secure environment for key management that is independent of the OS loading process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent inverts the traditional key management approach by moving the functionality from the OS layer down to the BIOS firmware layer. Instead of having the OS manage security keys (which would expose them to OS-level vulnerabilities), the BIOS manages the keys and provides controlled access to the OS. This inversion places security controls at a more fundamental system level, protecting against virus propagation while maintaining key management capabilities.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS9960912B2Key management for a rack server system
Publication Date: 2018.05.01 QUANTA COMPUTER INC
  • US9960912B2 patent drawing
  • US9960912B2 patent drawing
  • US9960912B2 patent drawing

AI summary

A system and method for providing security key exchange and management prior to the operating system of the server and also provides for executing various security functions to prevent a virus or malicious software from propagating through the server and the network. The system and method utilize the BIOS firmware and baseboard management controller (BMC), which are more secure since they do not rely on open source code for software plug-ins from the user layer. As a result, a secure code can be created for key management with a globally unique identifier (GUID). The system and method provides for a network manager to easily and flexibly manage multiple security keys for a rack server system.