NAND Flash Security Scanning via Baseboard Management Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face significant challenges in ensuring the secure operation of computing devices, as security vulnerabilities can lead to information security breaches and damage to their credibility and business operations.
Innovation Solution
A system utilizing NAND flash memory and a management controller, with scanning, metric, analytics, and transfer engines, scans and analyzes software programs based on predefined rules to identify security vulnerabilities, providing alerts and reports for remediation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security scanning methods are used, then security vulnerabilities can be detected, but the scanning process may disrupt normal system operations and consume significant resources
Solution Approach 1:
The patent implements preliminary action by performing security vulnerability scans during system boot-up or maintenance windows before normal operations begin. The BMC conducts scans of the software program in NAND flash memory before the operating system fully loads, ensuring vulnerability detection occurs proactively without disrupting production workloads.
Solution Approach 2:
The patent introduces the BMC as an intermediary component that independently manages security scanning operations separate from the main operating system. The BMC acts as a mediator between the hardware (NAND flash memory) and the software program, enabling security scans to be performed through a dedicated management interface that does not interfere with normal system operations.
2Reliability
If comprehensive security scanning is performed on all software programs, then all security vulnerabilities can be identified, but the scanning time and computational resources increase significantly
Solution Approach 1:
The patent applies segmentation by dividing the security scanning process into distinct modules within the BMC: a scanning engine that identifies software programs, a metric collection engine that gathers specific vulnerability indicators, and an analytics engine that evaluates risks. This modular approach allows selective scanning of different software components based on their vulnerability profiles rather than uniform comprehensive scanning.
Solution Approach 2:
The patent implements partial action by focusing scanning efforts on critical security metrics and high-risk areas rather than performing exhaustive analysis of all software parameters. The analytics engine prioritizes vulnerability assessment based on predefined risk criteria, conducting detailed analysis only on software programs or components that exhibit suspicious metrics or known vulnerability patterns.
3Reliability
If real-time security monitoring is implemented, then security vulnerabilities can be detected immediately, but the system consumes more processing power and memory resources
Solution Approach 1:
The patent implements periodic action by scheduling security vulnerability scans at predetermined intervals (e.g., daily, weekly, or during maintenance windows) rather than continuously monitoring all system operations in real-time. The BMC periodically executes scanning cycles that collect metrics, analyze vulnerabilities, and generate reports, balancing timely detection with resource conservation during normal operational periods.
Data Source
AI summary
Some examples relate to identifying a security vulnerability in a computer system. In an example, via a NAND flash memory, a computer system may be scanned to obtain information related to a software program, based on a rule set defined in a management controller (e.g., baseboard management controller (BMC)) on the computer system. The NAND flash memory may obtain metrics related to the software program via the BMC. The NAND flash memory may analyze the information related to the software program along with the metrics related to the software program to identify a security vulnerability in the computer system. The NAND flash memory may provide the information related to the security vulnerability in the computer system to the BMC.


