BMC Firmware Authentication via Multiplexer Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems lack effective security measures to prevent firmware attacks, particularly in components without integrated security features, making it difficult to determine if the firmware has been tampered with or compromised.

Innovation Solution

Incorporating a baseboard management controller (BMC) with additional integrated circuits and cryptographic capabilities to manage firmware, including providing signals to reset states, clearing/write protecting non-volatile memory, and executing firmware while authenticating it by determining hash values, thereby preventing firmware attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware is stored in non-volatile memory of a component, then the component can execute firmware functions, but the firmware may be tampered with or compromised without detection

Engineering Contradiction:
Improvefirmware integrityVSAvoidfirmware attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Baseboard Management Controller (BMC) as an intermediary security authority that mediates between the external environment and the component's firmware. The BMC verifies firmware integrity through cryptographic authentication (hash comparison) before allowing execution, and controls memory access through write protection signals. This intermediary prevents direct tampering with firmware in non-volatile memory, resolving the contradiction between firmware accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a component without integrated security features is used, then device complexity is reduced, but security measures to prevent firmware attacks are insufficient

Engineering Contradiction:
Improvecomponent structureVSAvoidsecurity capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent merges security functions into a separate centralized controller (BMC) rather than embedding them in each component. The BMC combines multiple security capabilities: firmware authentication through cryptographic hash verification, write protection control for non-volatile memory, and reset state management. This consolidation provides robust security while keeping individual components simple, resolving the contradiction between device complexity and security capability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11431506B2System and method of utilizing a component of an information handling system
Publication Date: 2022.08.30 DELL PROD LP
  • US11431506B2 patent drawing
  • US11431506B2 patent drawing
  • US11431506B2 patent drawing

AI summary

In one or more embodiments, one or more systems, one or more methods, and/or one or more processes may determine, via a baseboard management controller (BMC) of an information handling system, to provide firmware to a component of the information handling system; may provide, via the BMC, first data to the component via a first bus; based at least on the first data, may provide, via a communications bridge of the component, a first signal to a non-volatile memory medium (NVMM) of the component, a multiplexer of the component, and an integrated circuit of the component, in which the first signal causes the integrated circuit to be held in a reset state, causes a write protection of the NVMM to be cleared, and causes the multiplexer to couple the BMC to the NVMM; and may provide, via the BMC, the firmware to the NVMM via the multiplexer.