BMC Site Bitmask for Dynamic Immutable Security Personalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware-based solutions for enterprise product security are susceptible to tampering and inflexible in meeting modern security demands, as they rely on general purpose input-output states and programmable logic arrays that are difficult to trust and adapt.

Innovation Solution

Implementing a method for dynamic immutable security personalization using a baseboard management controller (BMC) that generates site bitmasks to capture and preserve the enterprise product configuration state, allowing for secure and adaptable security settings across the supply chain through one-time programmable memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If hardware-based solutions (general purpose input-output states, programmable logic arrays) are used for enterprise product security, then security functionality can be implemented, but the system becomes susceptible to tampering and inflexible in meeting modern security demands

Engineering Contradiction:
Improvesecurity flexibilityVSAvoidtampering susceptibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by capturing the enterprise product configuration state at predefined lifecycle sites before the product reaches end users. Site bitmasks are generated and stored in one-time programmable memory during manufacturing or initial deployment, establishing a trusted baseline configuration before the product enters the field. This prevents later tampering because the original configuration is immutably recorded at an earlier stage in the lifecycle.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional hardware-based security mechanisms (programmable logic arrays, general purpose input-output states) with a software-based configuration state capture and verification system. Instead of relying on physical hardware security modules that can be tampered with, the system uses immutable digital records (site bitmasks) stored in one-time programmable memory to establish and verify configuration integrity, substituting mechanical/hardware security with information-theoretic security based on immutable data records.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional hardware methods are used to track configuration states, then basic security assumptions can be made, but the system cannot dynamically adapt to changing security requirements throughout the product lifecycle

Engineering Contradiction:
Improvetrusted assumptionsVSAvoidconfiguration adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the enterprise product lifecycle into distinct phases with predefined sites (manufacturing, initial deployment, field operation). At each segment boundary, the configuration state is captured and stored in a structured format (site bitmasks organized by lifecycle site). This segmentation allows the system to maintain trusted assumptions at each stage while enabling adaptability within stages, as configuration changes can be tracked and authorized between sites without compromising overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamics by allowing configuration state capture at multiple lifecycle sites rather than a single static point. The system can dynamically adapt security requirements by capturing configuration states at different sites based on when and where changes occur. The immutable records provide a dynamic audit trail that adapts to changing security needs while maintaining reliability through cryptographic verification of each configuration state.

Inventive Principle:
Principle #15Dynamics

3Reliability

If immutable configuration tracking is implemented using one-time programmable memory, then tampering detection capability is enhanced, but the device complexity increases

Engineering Contradiction:
Improvetampering detectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies copying by creating immutable digital copies (site bitmasks) of the configuration state and storing them in one-time programmable memory. Instead of modifying the physical hardware to add complex tampering detection circuits, the system creates information copies that can be verified computationally. The site bitmask is a simplified digital representation of the configuration state that can be stored and verified without adding physical complexity to the hardware architecture.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11907409B2Dynamic immutable security personalization for enterprise products
Publication Date: 2024.02.20 DELL PROD LP
  • US11907409B2 patent drawing
  • US11907409B2 patent drawing
  • US11907409B2 patent drawing

AI summary

A method for dynamic immutable security personalization for enterprise products. Specifically, the disclosed method describes how a computer processor (e.g., baseboard management controller) of an enterprise product can personalize security requirements in trusted facilities, along the supply chain route of the enterprise product, so that trusted assumptions concerning the enterprise product can be made. Further, through dynamic immutable security personalization, these trusted assumptions are allowed to change over time (e.g., from being less restrictive to more restrictive) as changing enterprise product configuration states are captured while the enterprise product traverses the supply chain route.