BMC Security Co-processor Key Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems lack secure mechanisms to control Baseboard Management Controller (BMC) ports, making them vulnerable to unauthorized access and potential attacks during the boot process.

Innovation Solution

Incorporating a security co-processor within the BMC that stores an access key, which is matched with an externally received security key to unlock BMC functions, ensuring secure boot operations and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If BMC ports are made accessible for boot operations, then system functionality is improved, but security vulnerability increases

Engineering Contradiction:
ImproveBMC port accessibilityVSAvoidUnauthorized access vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security verification by storing access keys in a security co-processor before BMC operations. The system performs key validation in advance of any BMC port access, ensuring that authorization checks are completed before allowing any boot or management operations. This preliminary authentication mechanism prevents unauthorized access while maintaining legitimate system functionality.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security verification is implemented for BMC access, then security is improved, but system complexity increases

Engineering Contradiction:
ImproveAccess securityVSAvoidBMC system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security co-processor as an intermediary component between the BMC and external access requests. This dedicated security module handles all authentication and key verification operations, isolating the complex security logic from the main BMC functionality. The co-processor acts as a specialized mediator that manages security operations without complicating the overall BMC system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple security keys are stored for different functions, then access control precision is improved, but key management complexity increases

Engineering Contradiction:
ImproveAccess control precisionVSAvoidKey management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments security access control by implementing function-specific access keys stored in the security co-processor. Each BMC function (such as serial console, KVM, or out-of-band management) has its own dedicated access key, allowing precise control over which functions can be accessed by which users. This segmentation enables fine-grained access control where different keys can be distributed to different administrators based on their required functions, without requiring complex permission management systems.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10462664B2System and method for control of baseboard management controller ports
Publication Date: 2019.10.29 DELL PROD LP
  • US10462664B2 patent drawing
  • US10462664B2 patent drawing
  • US10462664B2 patent drawing

AI summary

An information handling system includes a Baseboard Management Controller (BMC) and a communication interface coupled to the BMC. The BMC includes a security co-processor that stores an access key. The access is associated with a first function of the BMC. The communication interface receives a security key from a device external to the information handling system. The BMC directs the security co-processor to determine if the first security key matches the first access key, and unlocks the first function when the first security key matches the first access key.