BMC-Based Security Processor Hardware Root of Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems face security challenges and increased complexity and cost due to the use of specialized silicon or baseboard management controllers (BMCs) for providing a hardware Root of Trust (RoT), which can expose attack points and complicate the verification of platform firmware.

Innovation Solution

A BMC-based security processor is implemented, which provides a hardware RoT without additional specialized silicon, using a System on Chip (SoC) with a public key stored in immutable memory to cryptographically verify firmware and filter bus requests, thereby minimizing attack points and complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized silicon or separate hardware devices are used to provide hardware RoT, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidplatform complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the hardware RoT functionality with the BMC by integrating a secure processor into the BMC SoC. The BMC firmware includes both a security subsystem that provides HRoT and a management subsystem, merging what were previously separate functions into a single integrated platform controller, thereby reducing overall system complexity while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The BMC is designed to perform multiple functions: traditional out-of-band management tasks and hardware RoT provision. By making the BMC multi-functional, the patent eliminates the need for separate dedicated HRoT hardware devices, reducing platform complexity and component count while maintaining both management and security capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If a BMC is used to provide hardware RoT, then specialized silicon is eliminated, but the number of attack points increases due to BMC complexity

Engineering Contradiction:
Improveplatform complexityVSAvoidattack points
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The BMC firmware is segmented into distinct security and management subsystems. The security subsystem is further isolated with its own protected execution environment and immutable root of trust credentials. This segmentation limits the attack surface by containing potential compromises to specific subsystems rather than exposing the entire BMC to attacks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure processor as an intermediary component within the BMC that mediates security-critical operations. This secure processor acts as a protected intermediary between external threats and the core BMC management functions, providing an additional layer of defense that reduces the effective attack surface

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If immutable memory with public key is used in BMC SOC, then firmware verification security is improved, but manufacturing complexity increases

Engineering Contradiction:
Improvefirmware verification securityVSAvoidBMC SOC manufacturing
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The public key is pre-provisioned into immutable memory during BMC SoC manufacturing, establishing the root of trust before the device is deployed. This preliminary action of embedding unchangeable cryptographic credentials during fabrication enables secure firmware verification from the first boot, with the manufacturing process itself being simplified by using standard immutable memory components rather than requiring specialized cryptographic hardware

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11847226B1Baseboard Management Controller (BMC)-based security processor
Publication Date: 2023.12.19 AMERICAN MEGATRENDS
  • US11847226B1 patent drawing
  • US11847226B1 patent drawing
  • US11847226B1 patent drawing

AI summary

Technologies are described herein for providing a Baseboard Management Controller (“BMC”)-based security processor. The disclosed BMC-based security processor can provide a hardware Root of Trust (“RoT”) for a computing platform without the addition of specialized silicon to the platform and while minimizing the number of attack points. The disclosed BMC-based security processor can also provide functionality for securely filtering requests made on certain buses in a computing platform. Through implementations of the features identified briefly above, and others described herein, various technical benefits can be achieved such as, but not limited to, increased security as compared to previous computing systems that utilize a BMC to provide a hardware RoT and reduced complexity and cost as compared to previous computing systems that utilize a separate hardware device, such as a Field Programmable Gate Array (“FPGA”) or a microcontroller, to provide a hardware RoT.