BMC Firmware Authentication via Multiplexer Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information handling systems lack effective security measures to prevent firmware attacks, particularly in components without integrated security features, making it difficult to determine if the firmware has been tampered with or compromised.
Innovation Solution
Incorporating a baseboard management controller (BMC) with additional integrated circuits and cryptographic capabilities to manage firmware, including providing signals to reset states, clearing/write protecting non-volatile memory, and executing firmware while authenticating it by determining hash values, thereby preventing firmware attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firmware is stored in non-volatile memory of a component, then the component can execute firmware functions, but the firmware may be tampered with or compromised without detection
Solution Approach 1:
The patent introduces a Baseboard Management Controller (BMC) as an intermediary security authority that mediates between the external environment and the component's firmware. The BMC verifies firmware integrity through cryptographic authentication (hash comparison) before allowing execution, and controls memory access through write protection signals. This intermediary prevents direct tampering with firmware in non-volatile memory, resolving the contradiction between firmware accessibility and security.
2Device complexity
If a component without integrated security features is used, then device complexity is reduced, but security measures to prevent firmware attacks are insufficient
Solution Approach 1:
The patent merges security functions into a separate centralized controller (BMC) rather than embedding them in each component. The BMC combines multiple security capabilities: firmware authentication through cryptographic hash verification, write protection control for non-volatile memory, and reset state management. This consolidation provides robust security while keeping individual components simple, resolving the contradiction between device complexity and security capability.
Data Source
AI summary
In one or more embodiments, one or more systems, one or more methods, and/or one or more processes may determine, via a baseboard management controller (BMC) of an information handling system, to provide firmware to a component of the information handling system; may provide, via the BMC, first data to the component via a first bus; based at least on the first data, may provide, via a communications bridge of the component, a first signal to a non-volatile memory medium (NVMM) of the component, a multiplexer of the component, and an integrated circuit of the component, in which the first signal causes the integrated circuit to be held in a reset state, causes a write protection of the NVMM to be cleared, and causes the multiplexer to couple the BMC to the NVMM; and may provide, via the BMC, the firmware to the NVMM via the multiplexer.


