BMC Firmware Security Verification via CPLD and Branding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Server devices with Baseboard Management Controller (BMC) devices face challenges in providing secure configurations while allowing users to customize BMC firmware, which can compromise the security and functionality of the server platform.

Innovation Solution

A BMC firmware security system that verifies licenses and branding identity information to ensure authorized use of BMC firmware, establishing a 'circle of trust' between the BMC device, a Complex Programmable Logic Device (CPLD), and the processing system, allowing secure utilization of different BMC firmware configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users are allowed to configure custom BMC firmware, then firmware adaptability and user customization capability are improved, but system security and functionality integrity deteriorate

Engineering Contradiction:
Improvefirmware customization capabilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary verification of firmware authenticity before execution by checking digital signatures and licensing information during the initialization process, preventing unauthorized firmware from being executed while allowing legitimate custom firmware to be used

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism that acts as a mediator between the firmware and the execution environment, using licensing information and branding verification to determine whether to allow firmware execution, thus resolving the conflict between customization and security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If default BMC firmware configuration is enforced, then system security and functionality are maintained, but user customization flexibility is reduced

Engineering Contradiction:
Improvesystem securityVSAvoiduser customization flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts its firmware acceptance criteria based on verification results, allowing strict enforcement for unverified firmware while permitting customized firmware that passes authentication checks, thus adapting security measures to the specific firmware being loaded

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the verification parameters from a simple default/non-default distinction to a multi-parameter verification system that includes digital signature validation, licensing information verification, and branding identity checks, enabling nuanced control over firmware execution

Inventive Principle:
Principle #35Parameter changes

3Reliability

If firmware verification processes are implemented, then unauthorized firmware usage is prevented, but initialization time and system complexity increase

Engineering Contradiction:
Improvefirmware authorization controlVSAvoidinitialization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The verification processes are performed during the initialization phase before the BMC becomes operational, preparing authentication data and performing checks in advance so that the running system can operate with verified firmware without continuous verification overhead

Inventive Principle:
Principle #10Preliminary action

4Reliability

If multiple verification steps are performed, then firmware authenticity is ensured, but device complexity and initialization overhead increase

Engineering Contradiction:
Improvefirmware authenticityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple verification functions (digital signature verification, licensing information validation, and branding identity checking) into an integrated verification process that operates within the existing BMC initialization routine, reducing the need for separate complex verification subsystems

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11593462B2Baseboard management controller firmware security system
Publication Date: 2023.02.28 DELL PROD LP
  • US11593462B2 patent drawing
  • US11593462B2 patent drawing
  • US11593462B2 patent drawing

AI summary

A BMC firmware security system includes a BMC coupled to a programmable circuit device and a first storage subsystem. In response to BMC initialization, the BMC uses a system identifier to verify that a license in the first storage subsystem authorizes the BMC to use BMC firmware in the BMC, uses branding identity information in the BMC to verify that the BMC is branded for the BMC firmware, determines that the programmable circuit device identifies the BMC firmware and, in response, the performs BMC initialization operations using the BMC firmware. A BIOS is coupled to the programmable circuit device and a second storage system. In response to BIOS initialization, the BIOS uses the branding identity information in the second storage subsystem to identify the BMC firmware, determines that the programmable circuit device identifies the BMC firmware and, in response, performs BIOS initialization operations.