BMC Firmware Identity Access Control for Secure Resource Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Custom BMC firmware stacks, developed in uncontrolled environments, often have higher software faults that can cause unintended or malicious control functions, leading to potential damage to IHS components such as overheating or memory degradation, necessitating a need for hierarchical access control of secure BMC resources.

Innovation Solution

A system and method for BMC firmware identity access control that detects the type of firmware being booted during bootstrapping and selectively restricts access to certain resources based on the detected type, ensuring only authorized firmware can access secure BMC resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If custom BMC firmware stacks are used to provide enhanced manageability and control, then ease of operation is improved, but reliability deteriorates due to software faults from uncontrolled development environments

Engineering Contradiction:
ImprovemanageabilityVSAvoidsoftware faults
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A security coprocessor is introduced as an intermediary component between the BMC firmware and critical system resources. This coprocessor verifies firmware authenticity and manages access control, allowing custom firmware to operate while preventing faulty or malicious firmware from causing system damage. The security coprocessor acts as a mediator that enables manageability improvements without compromising reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control is implemented to prevent faulty firmware from accessing resources, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesystem integrityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security coprocessor serves as a dedicated intermediary that handles all access control functions. By isolating the access control logic in a separate coprocessor, the main BMC firmware remains relatively simple while still benefiting from robust security. The coprocessor manages the complexity of verification and authorization mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional components: the BMC firmware for management operations, the security coprocessor for authentication and access control, and the protected resources for critical system functions. This segmentation allows each component to be optimized independently, with the coprocessor handling security complexity separately from the main firmware.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple firmware types are supported for versatility, then adaptability is improved, but reliability deteriorates due to potential compatibility issues and uncontrolled environments

Engineering Contradiction:
Improvefirmware compatibilityVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security coprocessor acts as a universal intermediary that handles all firmware types through a consistent verification and access control framework. This allows the system to support multiple firmware types for different management needs while maintaining reliable security practices. The coprocessor mediates between the diversity of firmware types and the need for consistent, reliable system operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12613969B2Systems and methods for BMC firmware identity based access control
Publication Date: 2026.04.28 DELL PROD LP
  • US12613969B2 patent drawing
  • US12613969B2 patent drawing
  • US12613969B2 patent drawing

AI summary

Embodiments of systems and methods to provide a firmware update to devices configured in a redundant configuration in an Information Handling System (IHS) are disclosed. In an illustrative, non-limiting embodiment, an IHS may include a Baseboard Management Controller (BMC) having computer-executable instructions to, during a boot sequence of the BMC, determine a type of a firmware that is to be booted on the BMC, and selectively restrict access to the resources based upon the determined type of firmware.