BMC Firmware Attack Logging via SMI Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems lack effective mechanisms for logging and mitigating firmware attack events, which can compromise system security and integrity.

Innovation Solution

The implementation of a baseboard management controller (BMC) with a memory device for logging malicious firmware modification attempts, utilizing System Management Interrupts (SMIs) to detect and record rule violations, and alerting administrators through remote monitoring and management interfaces like IPMI, ensuring secure firmware updates and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware attack detection and logging mechanisms are implemented, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Baseboard Management Controller (BMC) as an intermediary component that independently handles firmware attack detection, logging, and alerting functions. The BMC acts as a mediator between the firmware system and administrators, providing security monitoring capabilities without requiring complex modifications to the existing firmware architecture. This separates security functions into a dedicated management controller, improving reliability while managing complexity through functional separation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time firmware attack detection is implemented, then system reliability is improved, but loss of time in detecting attacks increases due to additional processing

Engineering Contradiction:
Improvesystem reliabilityVSAvoidtime to detect attack
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring firmware access rules and authentication mechanisms before attacks occur. The BMC is pre-programmed with expected firmware access patterns, authentication credentials, and logging procedures. When an attack occurs, the system can immediately compare actual access attempts against pre-established rules, enabling rapid detection without time-consuming analysis during the attack event itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The firmware authentication and attack detection process operates autonomously through the BMC, which automatically monitors firmware access attempts, validates authentication credentials, detects rule violations, and logs attacks without requiring external intervention. The system services its own security monitoring needs, eliminating delays associated with external detection mechanisms and enabling immediate attack identification.

Inventive Principle:
Principle #25Self-service

3Reliability

If firmware access rules and authentication mechanisms are enforced, then firmware integrity is protected, but ease of operation for legitimate updates is reduced

Engineering Contradiction:
Improvefirmware integrityVSAvoidease of firmware update
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The BMC provides feedback mechanisms that monitor firmware access attempts and communicate authentication results to administrators and update processes. When legitimate firmware updates are initiated, the system provides feedback through the IPMI interface to confirm authentication status and update progress. This feedback loop ensures that authorized updates proceed smoothly while maintaining security controls, as administrators can monitor and verify each step of the update process without manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9817975B2Method for logging firmware attack event and system therefor
Publication Date: 2017.11.14 DELL PROD LP
  • US9817975B2 patent drawing
  • US9817975B2 patent drawing
  • US9817975B2 patent drawing

AI summary

A violation of a firmware access rule is detected, and an entry is generated at a log file stored at a baseboard management controller, the entry identifying the violation. In an embodiment, detecting the violation is in response to receiving a system management interrupt at an information handling system.