BMC Automated Secure Boot Policy Update

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems require manual updates to secure boot policies when firmware for I/O devices is updated, which is inefficient and prone to human error.

Innovation Solution

An information handling system that includes a memory and a baseboard management controller (BMC) to automate the update of a customized secure boot policy by extracting a new firmware hash value from a firmware update package and performing a firmware update for the I/O device, then replacing the old firmware hash value in the secure boot policy with the new one.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual updates to secure boot policy are performed, then flexibility in updating firmware is maintained, but efficiency is reduced and human error increases

Engineering Contradiction:
Improvefirmware update efficiencyVSAvoidaccuracy of secure boot policy update
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The BMC automatically extracts firmware hash values from update packages and updates the secure boot policy without human intervention. The system performs self-updating by detecting firmware changes and autonomously managing the secure boot policy synchronization, eliminating manual operations and their associated errors

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes a feedback loop where the BMC continuously monitors firmware update status and automatically responds by updating the secure boot policy. The BMC detects when firmware is updated and triggers the corresponding policy update, creating a closed-loop control system that ensures consistency

Inventive Principle:
Principle #23Feedback

2Productivity

If automated firmware update process is implemented, then efficiency and accuracy are improved, but system complexity increases

Engineering Contradiction:
Improvesecure boot policy update speedVSAvoidcomplexity of update management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The BMC serves as an intermediary component that bridges firmware updates and secure boot policy management. By centralizing the automation logic in the BMC, the system achieves automated updates without significantly increasing overall system complexity, as the BMC already exists as a management controller

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The BMC performs multiple functions including firmware update management, secure boot policy maintenance, and hash value extraction. By making the BMC multi-functional, the system avoids adding separate dedicated components for each function, thereby limiting the increase in system complexity while achieving automation

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12321459B2Automated update of a customized secure boot policy
Publication Date: 2025.06.03 DELL PROD LP
  • US12321459B2 patent drawing
  • US12321459B2 patent drawing
  • US12321459B2 patent drawing

AI summary

An information handling system includes a memory and a baseboard management controller (BMC). The memory stores a secure boot policy for multiple input/output (I/O) devices in the information handling system. The BMC extracts a new firmware hash value from a firmware update package. The new firmware hash value is associated with a new firmware image of a first I/O device of the I/O devices. The BMC performs a firmware update for the first I/O device. In response to the firmware update being successfully completed, the BMC replaces an old firmware hash value with the new firmware hash value in the secure boot policy.