BMC Emulation of Physical Security Devices for Hardware Flexibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Server platform vendors face challenges in accommodating diverse security solutions requested by customers, leading to increased product development time and costs due to the lack of standardization and the need for multiple hardware configurations.

Innovation Solution

A bridge device, such as a BMC, with a secure enclave that emulates different security solutions through trusted firmware, allowing the same hardware to provide various security functions, including those typically handled by physical security interposer devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple hardware configurations are used to support diverse security solutions, then customer security requirements are met, but product development time and costs increase

Engineering Contradiction:
Improvesecurity solution compatibilityVSAvoidhardware configuration variety
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The BMC is designed with a universal architecture that can perform multiple security functions through software/firmware configuration. The same BMC hardware can emulate different security device types (security interposer, security processor, TPM) by loading appropriate emulation code, eliminating the need for multiple specialized hardware configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The BMC emulates the functionality of physical security devices by creating virtual copies of their behavior and interfaces. Through firmware emulation, the BMC replicates the security functions of dedicated security hardware, allowing it to respond to security requests as if the actual security devices were present, thereby supporting diverse security solutions without additional hardware.

Inventive Principle:
Principle #26Copying

2Reliability

If physical security interposer devices are used, then security functions are provided, but hardware complexity and development costs increase

Engineering Contradiction:
Improvesecurity function provisionVSAvoidhardware architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The BMC acts as an intermediary between the system management interface and the security functions. It receives security-related requests through the management interface and processes them by emulating the appropriate security device response, thereby providing security functions without requiring direct integration of complex security hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical security hardware (mechanical system) with software-based emulation in the BMC. Instead of using actual security interposer devices or security processors as separate hardware components, the BMC uses firmware to simulate their behavior, substituting software for hardware while maintaining the same security functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If standardized security handling is implemented in BMC, then development time is reduced, but security versatility may be limited

Engineering Contradiction:
Improvedevelopment efficiencyVSAvoidsecurity solution variety
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The BMC security handling is designed to be dynamic rather than static. The emulation capabilities can be configured and adapted through firmware updates and software configuration, allowing the same hardware platform to support evolving security requirements and diverse security solutions without requiring hardware changes or lengthy re-development cycles.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12436787B2Emulating physical security devices
Publication Date: 2025.10.07 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12436787B2 patent drawing
  • US12436787B2 patent drawing
  • US12436787B2 patent drawing

AI summary

A technique includes a baseboard management controller receiving, from a requestor, a request for a security function to be performed, where the request is directed to a physical security device other than the baseboard management controller. The technique includes, the baseboard management controller responding to the request to emulate a response to the security device to the request.