BMC-Based BIOS Firmware Validation for Unified Root of Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems face challenges in establishing a unified root of trust due to proprietary early-initialization architectures, making it difficult for OEMs to integrate proprietary security and system functionality, especially with divergent initialization methods used by Intel and AMD.

Innovation Solution

A baseboard management controller (BMC) is configured to provide a root of trust by validating and optionally updating BIOS firmware during initialization and runtime, with firmware instructions and data stored in separate flash memory devices to allow out-of-band access and concurrent operation with the operating system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If proprietary early-initialization architectures are used for BIOS firmware validation, then manufacturer-specific security functionality can be implemented, but a unified root of trust cannot be established across different CPU architectures

Engineering Contradiction:
Improveproprietary security functionalityVSAvoidunified root of trust
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a Baseboard Management Controller (BMC) as an intermediary component that establishes a unified root of trust independent of CPU architecture. The BMC validates the initial boot block before BIOS execution, creating a common security foundation that works across Intel, AMD, and other processor platforms while still allowing proprietary security extensions through flash descriptors

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If BIOS firmware and data are stored in the same flash memory device, then simple access is achieved, but the operating system cannot access BIOS data during runtime when BIOS validation is performed

Engineering Contradiction:
Improveaccess simplicityVSAvoidconcurrent access capability
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent divides the flash memory storage into separate regions: one dedicated to BIOS firmware instructions and another for BIOS data. This segmentation allows the BMC to validate firmware while the operating system simultaneously accesses BIOS data without conflicts, enabling concurrent operations that would be impossible with a single unified storage space

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If a unified root of trust is established using a BMC, then proprietary functionality can be integrated, but the initialization architecture becomes more complex

Engineering Contradiction:
Improveproprietary functionality integrationVSAvoidinitialization architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The BMC serves multiple functions: it establishes the root of trust, validates the initial boot block, processes flash descriptors for proprietary security extensions, and manages flash memory operations. By consolidating these diverse functions into a single multi-functional controller, the patent achieves proprietary functionality integration without proportionally increasing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11003780B2Method and apparatus for validating BIOS firmware using a baseboard management controller
Publication Date: 2021.05.11 DELL PROD LP
  • US11003780B2 patent drawing
  • US11003780B2 patent drawing
  • US11003780B2 patent drawing

AI summary

A method includes storing basic input/output system (BIOS) firmware instructions at a first flash memory device included at an information handling system. The BIOS firmware includes an initial boot block. BIOS data is stored at a second flash memory device. A baseboard management controller validates instructions included at the initial boot block.