BMC Hardware Authentication for IHS Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Information Handling Systems (IHS) lack effective mechanisms to manage and authenticate hardware devices that can be added or removed while the system is running, leading to potential security threats from harmful algorithms or malicious code.
Innovation Solution
Implementing a baseboard management controller (BMC) that performs authentication procedures on hardware devices using the Security Protocol and Data Model (SPDM) specification, ensuring only vetted devices are allowed to function within the IHS, and integrating this process with the BIOS power-on self-test (POST) to establish a secure environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If hardware devices can be freely added or removed while the system is running, then device flexibility and adaptability are improved, but security risks from harmful algorithms or malicious code increase
Solution Approach 1:
The BMC performs authentication of hardware devices before allowing them to function within the IHS. The system inhibits unauthenticated devices from operating and only enables them after successful authentication, ensuring security before the device can potentially cause harm.
Solution Approach 2:
The BMC acts as an intermediary between the hardware device and the IHS. It mediates the interaction by authenticating devices and controlling their access, preventing direct connection of potentially harmful devices to the system.
2Reliability
If authentication procedures are performed on all hardware devices, then security is improved, but system complexity increases
Solution Approach 1:
The BMC is an existing component in the IHS that provides system management functions. By making it multi-functional and adding authentication capability to it, the patent avoids adding separate complex authentication hardware, thus improving security without proportionally increasing system complexity.
3Reliability
If hardware devices are inhibited until authenticated, then security is improved, but device functionality and productivity are reduced
Solution Approach 1:
Authentication is performed preliminarily before device enablement. The BMC authenticates devices during system initialization or at the time of insertion, and only after successful authentication does the device become functional, ensuring security is established before productivity is affected.
Data Source
AI summary
An Information Handling System (IHS) includes multiple hardware devices, and a baseboard Management Controller (BMC) in communication with the plurality of hardware devices. The BMC includes executable instructions for causing the one hardware device to be inhibited from functioning with the IHS when at least one of the hardware devices is powered on, and performing an authentication procedure with that hardware device. After that hardware device has been successfully authenticated, the instructions then enable the one hardware device to function with the IHS.


