BMC-Based Security Processor for Hardware Root of Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing systems face security challenges in verifying the authenticity of platform firmware, with specialized silicon or complex BMCs increasing cost and complexity, and exposing numerous attack points.
Innovation Solution
A BMC-based security processor is implemented, which provides a hardware Root of Trust without additional specialized silicon, using a BMC SoC with immutable public keys for cryptographic verification and separate processors for secure and management functionalities, including bus filtering to prevent malicious requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If specialized silicon or separate hardware devices are used to provide hardware Root of Trust, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent merges the hardware Root of Trust functionality with the existing BMC by integrating a secure processor into the BMC SoC. This combination allows the BMC to provide both traditional management functions and security verification functions, eliminating the need for separate specialized silicon while maintaining security requirements.
Solution Approach 2:
The BMC is designed to perform multiple functions: traditional out-of-band management, sensor monitoring, and hardware Root of Trust verification. By making the BMC multi-functional, the patent eliminates the need for dedicated security hardware, reducing overall platform complexity while maintaining security capabilities.
2Device complexity
If a BMC is used to provide hardware Root of Trust, then device complexity is reduced, but security is worsened due to numerous attack points
Solution Approach 1:
The BMC SoC is segmented into distinct processors: a secure processor for cryptographic verification and a management processor for BMC functions. This segmentation isolates security-critical operations in a protected environment, limiting attack surface exposure while maintaining the simplified single-BMC architecture.
Solution Approach 2:
Different parts of the BMC SoC have different security properties. The secure processor operates in a protected execution environment with restricted access, while the management processor handles general BMC functions. This local differentiation of security quality allows the system to maintain low complexity while protecting critical functions.
3Reliability
If immutable public keys are stored in BMC SoC memory, then firmware verification security is improved, but device complexity increases
Solution Approach 1:
The public key is immutably programmed into the BMC SoC memory during manufacturing, establishing the hardware Root of Trust in advance. This preliminary action ensures that the verification key cannot be modified or replaced, providing secure firmware verification without requiring complex runtime key management mechanisms.
Data Source
AI summary
Technologies are described herein for providing a Baseboard Management Controller (“BMC”) -based security processor. The disclosed BMC-based security processor can provide a hardware Root of Trust (“RoT”) for a computing platform without the addition of specialized silicon to the platform and while minimizing the number of attack points. The disclosed BMC-based security processor can also provide functionality for securely filtering requests made on certain buses in a computing platform. Through implementations of the features identified briefly above, and others described herein, various technical benefits can be achieved such as, but not limited to, increased security as compared to previous computing systems that utilize a BMC to provide a hardware RoT and reduced complexity and cost as compared to previous computing systems that utilize a separate hardware device, such as a Field Programmable Gate Array (“FPGA”) or a microcontroller, to provide a hardware RoT.


