BMC Hashing for Computing Device Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers and manufacturers face challenges in ensuring the security and integrity of computing devices during transit, as they can be vulnerable to unauthorized changes, theft, or malicious attacks that compromise hardware or firmware configurations, making it difficult to confirm the device's original state upon delivery.

Innovation Solution

A method involving creating a digital inventory and tracking the number of power-on events for a computing device, which generates a hash that can be compared before and after transit, using firmware components like BIOS or BMC to secure the device and detect any tampering or unauthorized changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If computing devices are shipped from manufacturer to customer, then device delivery is achieved, but device security and integrity are compromised during transit

Engineering Contradiction:
Improvedevice integrityVSAvoidunauthorized changes during transit
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by creating a digital inventory and generating a hash value of the computing device's configuration before shipment. This pre-shipment hash serves as a reference to detect any unauthorized changes that may occur during transit, allowing security verification without requiring physical inspection of the device.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by comparing the pre-shipment hash with a post-arrival hash of the device configuration. This comparison provides feedback on whether the device has been tampered with during transit, enabling automatic detection of unauthorized changes and triggering appropriate security responses.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If device configuration is made verifiable, then security monitoring is improved, but device complexity increases

Engineering Contradiction:
Improveconfiguration verificationVSAvoidsecurity mechanism complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies copying by creating a digital representation (hash) of the device's configuration rather than physically inspecting or modifying the actual device. This digital copy can be stored, transmitted, and compared without affecting the physical device, enabling verification while maintaining device simplicity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces complex physical security mechanisms with a software-based hashing and comparison system. Instead of using physical seals, locks, or tamper-evident materials, the solution uses cryptographic hash functions to verify device integrity, significantly reducing hardware complexity while improving verification precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11030347B2Protect computing device using hash based on power event
Publication Date: 2021.06.08 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11030347B2 patent drawing
  • US11030347B2 patent drawing
  • US11030347B2 patent drawing

AI summary

Examples disclosed herein relate to protecting a computing device by using hashes. A baseboard management controller is to facilitate taking an inventory of components of the computing device. The baseboard management controller is also to determine a number of times the computing device has been powered on. The baseboard management controller generates a hash using a function of the number of times the computing device has been powered on and the inventory.