Logic Device Authentication via Dual Interface Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems lack secure authentication, update, and recovery mechanisms for logic devices, particularly low- to medium-complexity devices, which can lead to compromised systems and potential denial of service or permanent damage.

Innovation Solution

An information handling system with a management controller that performs initial authentication via an immutable interface during boot, enables a hardware lock to prevent write access, and conducts a second authentication via a mutable interface upon power-on, ensuring secure authentication and update processes for logic devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic authentication and secure update mechanisms are added to logic devices, then system security and reliability are improved, but device complexity and cost increase

Engineering Contradiction:
Improvesystem securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the authentication system into two distinct interfaces: an immutable interface for initial authentication during manufacturing or first boot, and a mutable interface for subsequent updates. This segmentation allows security-critical operations to be isolated from general update operations, reducing the complexity burden on the overall device while maintaining strong security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary authentication through the immutable interface before the logic device is fully operational or before allowing mutable updates. This preliminary security check ensures that only authenticated devices can proceed to later update cycles, establishing a trust foundation without requiring continuous complex authentication mechanisms.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple authentication interfaces are implemented, then authentication security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent makes the interface characteristics dynamic rather than static. The immutable interface is locked after initial authentication, while the mutable interface becomes active for subsequent operations. This dynamic allocation of interface functions simplifies operation at different stages: initial setup uses the immutable interface, while all future updates use the mutable interface, eliminating the need for operators to choose between interfaces.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

By performing the complex immutable authentication once during initialization, the system establishes security without requiring repeated complex operations. Subsequent operations can use the simpler mutable interface, improving ease of operation while maintaining security through the established authentication chain.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If hardware locking is implemented to prevent write access, then protection against unauthorized modification is improved, but adaptability for future updates deteriorates

Engineering Contradiction:
Improveprotection against unauthorized modificationVSAvoidadaptability for future updates
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the write protection mechanism into two parts: the immutable interface which is hardware-locked after initial authentication, and the mutable interface which remains writable for authorized updates. This segmentation allows the system to have strong protection against unauthorized modification through the locked immutable interface, while maintaining adaptability for legitimate future updates through the mutable interface.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The mutable interface acts as an intermediary that mediates between the hardware-locked immutable interface and update operations. It allows authorized updates to proceed while the immutable interface remains protected, effectively decoupling the need for protection from the need for update capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11630898B2Systems and methods for providing secure logic device authentication, update, and recovery
Publication Date: 2023.04.18 DELL PROD LP
  • US11630898B2 patent drawing
  • US11630898B2 patent drawing
  • US11630898B2 patent drawing

AI summary

An information handling system may include a host system comprising a host system processor, a logic device configured to perform a functionality of the information handling system in accordance with code stored on non-transitory computer-readable media of the logic device, and a management controller communicatively coupled to the host system processor and the logic device and configured to perform out-of-band management of the information handling system. The management controller may be further configured to: during a boot of the management controller, perform an initial authentication of the code via an immutable interface of the logic device, after the initial authentication and prior to completion of boot of the management controller, enable a hardware lock to prevent write access to the logic device via the immutable interface, and in response to a power on request of the host system, perform a second authentication of the code via a mutable interface of the logic device.