Multi-BMC SPDM Discovery for Secure Hardware Failover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing datacenter and enterprise infrastructure systems face challenges in establishing secure and efficient communication and workload sharing among multiple Baseboard Management Controllers (BMCs) due to varying communication protocols and bandwidths, leading to potential failures and inefficiencies.
Innovation Solution
A system-level approach where BMCs establish SPDM secure sessions based on hardware device topology and bandwidth, enabling seamless workload sharing and connection takeover in case of failures by using SPDM messages for discovery, negotiation, and credential sharing among BMCs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple BMCs manage hardware devices independently without credential sharing, then each BMC maintains secure control over its assigned devices, but system reliability deteriorates when a BMC fails because no takeover mechanism exists
Solution Approach 1:
The patent implements preliminary action by having BMCs exchange credentials and establish trust relationships before failures occur. Each BMC stores credentials for hardware devices in advance, enabling seamless takeover when a BMC fails. The credential exchange and registration processes are performed proactively during normal operation, so that when a failure occurs, the backup BMC already possesses the necessary authentication materials to immediately assume control without requiring complex real-time negotiation or external intervention.
2Reliability
If BMCs share all credentials with each other for failover capability, then system reliability improves through seamless takeover, but security deteriorates due to increased credential exposure
Solution Approach 1:
The patent applies local quality by implementing differentiated credential sharing based on specific device assignments and BMC roles. Instead of universal credential distribution, each BMC receives credentials only for the hardware devices it needs to manage or potentially takeover. The credential registration process is selective and context-aware, registering credentials with specific BMCs based on their management responsibilities. This localized approach ensures that credential exposure is minimized while maintaining adequate failover capability for each specific device-BMC relationship.
3Adaptability or versatility
If BMCs negotiate access to hardware devices dynamically, then adaptability improves for workload sharing, but communication overhead increases due to continuous negotiation requirements
Solution Approach 1:
The patent resolves this contradiction by performing negotiation preliminarily during system initialization and credential exchange phases. BMCs establish their management boundaries and access rights before workload changes occur. When workload sharing or failover is needed, the pre-established credential relationships and registered access rights enable immediate action without requiring real-time negotiation. The system caches the negotiation results and uses them for subsequent workload distribution and failover decisions, thus eliminating repeated negotiation overhead while maintaining adaptability.
4Productivity
If a single BMC manages all hardware devices, then device management is simplified, but productivity deteriorates due to lack of workload distribution across multiple BMCs
Solution Approach 1:
The patent applies segmentation by dividing hardware device management among multiple BMCs based on their capabilities, workload, and credential holdings. Each BMC manages a specific subset of hardware devices, creating natural segmentation that enables parallel processing and workload distribution. The system automatically distributes workloads across available BMCs, utilizing the segmented structure to improve productivity. The segmentation is managed through credential-based access control, where each BMC has authenticated rights to specific devices, simplifying the coordination complexity through clear demarcation of management boundaries.
Data Source
AI summary
Systems and methods provide one or more host processor modules configured to host SPDM-enabled hardware devices, and a secure control module configured to host two or more baseboard management controllers. Each of the baseboard management controllers are configured to discover the SPDM-enabled hardware devices using SPDM messages, negotiate with at least one other baseboard management controller for access to individual ones of the SPDM-enabled hardware devices, and manage selected ones of the SPDM-enabled hardware devices.


