BMC Hardware Authentication for IHS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Information Handling Systems (IHS) lack effective mechanisms to manage and authenticate hardware devices that can be added or removed while the system is running, leading to potential security threats from harmful algorithms or malicious code.

Innovation Solution

Implementing a baseboard management controller (BMC) that performs authentication procedures on hardware devices using the Security Protocol and Data Model (SPDM) specification, ensuring only vetted devices are allowed to function within the IHS, and integrating this process with the BIOS power-on self-test (POST) to establish a secure environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If hardware devices can be freely added or removed while the system is running, then device flexibility and adaptability are improved, but security risks from harmful algorithms or malicious code increase

Engineering Contradiction:
Improvedevice flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The BMC performs authentication of hardware devices before allowing them to function within the IHS. The system inhibits unauthenticated devices from operating and only enables them after successful authentication, ensuring security before the device can potentially cause harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The BMC acts as an intermediary between the hardware device and the IHS. It mediates the interaction by authenticating devices and controlling their access, preventing direct connection of potentially harmful devices to the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication procedures are performed on all hardware devices, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The BMC is an existing component in the IHS that provides system management functions. By making it multi-functional and adding authentication capability to it, the patent avoids adding separate complex authentication hardware, thus improving security without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If hardware devices are inhibited until authenticated, then security is improved, but device functionality and productivity are reduced

Engineering Contradiction:
ImprovesecurityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Authentication is performed preliminarily before device enablement. The BMC authenticates devices during system initialization or at the time of insertion, and only after successful authentication does the device become functional, ensuring security is established before productivity is affected.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12072966B2System and method for device authentication using a baseboard management controller (BMC)
Publication Date: 2024.08.27 DELL PROD LP
  • US12072966B2 patent drawing
  • US12072966B2 patent drawing
  • US12072966B2 patent drawing

AI summary

An Information Handling System (IHS) includes multiple hardware devices, and a baseboard Management Controller (BMC) in communication with the plurality of hardware devices. The BMC includes executable instructions for causing the one hardware device to be inhibited from functioning with the IHS when at least one of the hardware devices is powered on, and performing an authentication procedure with that hardware device. After that hardware device has been successfully authenticated, the instructions then enable the one hardware device to function with the IHS.