BMC-Based Non-Volatile Storage Configuration During Power-On Self-Test
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information handling systems face challenges in securely configuring and managing non-volatile storage devices, particularly during power-on self-test phases, where ensuring the device is not in use by the host operating system is crucial to avoid crashes or wayward behavior.
Innovation Solution
A hybrid job is created that includes a first portion for the baseboard management controller and a second portion for the information handling system firmware, allowing secure cryptographic erasure or firmware updates of non-volatile storage devices, such as NVMe self-encrypting drives, by obtaining an authentication key and executing commands in a pre-boot environment, ensuring the device is not in use by the host system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic erasure or firmware update is performed on a non-volatile storage device during power-on self-test, then security and device configuration reliability are improved, but system complexity and operational risk increase
Solution Approach 1:
The patent performs cryptographic erasure or firmware update operations during the power-on self-test phase, before the host operating system is loaded. This preliminary action ensures the storage device is properly configured and secured before normal operation begins, preventing potential security issues and system crashes that could occur if such operations were attempted while the OS is running.
Solution Approach 2:
The patent introduces a baseboard management controller as an intermediary component that facilitates the configuration of the non-volatile storage device. The BMC handles the cryptographic erasure and firmware update operations independently from the host system, reducing the complexity and risk for the main information handling system while ensuring reliable device configuration.
2Reliability
If cryptographic erasure is performed on a storage device in use by the host operating system, then security is improved, but system stability deteriorates due to potential crashes
Solution Approach 1:
The patent performs cryptographic erasure operations during the power-on self-test phase, before the host operating system is loaded and before the storage device is made available for normal use. This timing ensures that no data access operations are in progress when the cryptographic erasure occurs, preventing system crashes while maintaining security.
Solution Approach 2:
The baseboard management controller acts as an intermediary that performs the cryptographic erasure operation independently of the host operating system. This separation allows the security operation to proceed without interfering with OS processes, maintaining system stability while achieving the desired security outcome.
Data Source
AI summary
In one or more embodiments, one or more systems, one or more methods, and/or one or more processes may determine that the staged job needs to be executed by a baseboard management controller (BMC) while an information handling system (IHS) is held in a power-on self-test; create a hybrid job associated with the staged job; reboot the IHS; launch an IHS firmware application in a pre-boot IHS firmware environment; provide, to the BMC, a command to execute a first portion of the hybrid job; obtain, by the BMC, an authentication key; provide, by the BMC, the authentication key to the non-volatile storage device; execute, by the BMC, the first portion of the hybrid job to configure the non-volatile storage device; and execute, by the IHS firmware application, the second portion of the hybrid job to poll the baseboard management controller for a result status of configuring the non-volatile storage device.


