Network Chip Port Reconfiguration via NC-SI for Secure BMC Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current server platforms face challenges in allowing flexible reconfiguration of network chips by external entities while maintaining a secure boot environment, as existing solutions often compromise security to enable external management.

Innovation Solution

The network chip is configured to provide designated networking ports to a baseboard management controller (BMC) via a Network Controller Sideband Interface (NC-SI) block, allowing the BMC to access registers and configure ports without violating security features, using NC-SI compliant commands and a permissions table to control access and maintain secure operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If external entities are allowed to reconfigure network chips, then management flexibility is improved, but security is compromised

Engineering Contradiction:
Improvemanagement flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network chip's configuration space is segmented into multiple register regions with different access permissions. The BMC is granted access only to specific non-critical registers for port configuration, while critical security-related registers remain protected. This segmentation allows management flexibility for non-security functions while preserving security integrity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A permissions table acts as an intermediary layer between the BMC and the network chip's register space. This intermediary structure mediates access requests by the BMC, allowing it to reconfigure networking ports through permitted registers while blocking access to security-critical registers, thus resolving the contradiction between management flexibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If BMC accesses registers directly to configure ports, then configuration capability is improved, but secure boot environment is violated

Engineering Contradiction:
Improveconfiguration capabilityVSAvoidsecure boot environment
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Different regions of the register space are assigned different security qualities. Non-critical registers used for port configuration are made accessible to the BMC, while critical registers that would compromise the secure boot environment are kept protected. This local differentiation of access permissions enables configuration capability without violating the secure boot environment.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The permissions table serves as an intermediary that filters BMC access requests. It allows the BMC to directly access and configure permitted registers for port management while blocking access to registers that would violate the secure boot environment, thus enabling configuration capability without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If network chip ports are designated for BMC communication, then management efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The network chip's networking ports are designed with multi-functionality, serving both normal network traffic and BMC management communication. By making the ports universal, the system achieves management efficiency without adding dedicated separate infrastructure, and the complexity is managed through software configuration rather than hardware multiplication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The BMC management communication function is merged with the existing networking ports rather than requiring separate dedicated ports. This merging approach improves management efficiency by utilizing existing infrastructure while keeping system complexity low through shared hardware resources and software-based function differentiation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12047419B2Systems and methods for allowing flexible chip configuration by external entity
Publication Date: 2024.07.23 MARVELL ASIA PTE LTD
  • US12047419B2 patent drawing
  • US12047419B2 patent drawing

AI summary

The systems and methods to support flexible reconfiguration of a network chip by an external entity, such as a baseboard management controller (BMC), while maintaining a secured environment for the chip so that it can be booted securely. Specifically, the network chip is configured to designate one or more of its networking ports to the BMC and allow the BMC to configure the designated networking ports without violating the secure areas of the network chip. To this end, the network chip is configured to allow the BMC to access a plurality of registers of the network chip via an Network Controller Sideband Interface (NC-SI) block of the network chip by issuing a plurality NC-SI compliant commands. By configuring the designated networking ports, the BMC is configured to establish a data path to a management software of a platform that includes the network chip though the designated networking ports.