Power Supply Unit Authentication via Firmware Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Server platforms face security vulnerabilities due to untrusted Power Supply Units (PSUs) that can impair operation by tampering with power management data, leading to potential data exposure and weakened security components.

Innovation Solution

Implementing a secure firmware identifier for each PSU, binding it with hardware identifiers and authenticating before power budget calculations, ensuring only trusted PSUs can transition the platform from a reduced power state to a higher power state, thereby establishing a trust zone for power data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PSU authentication is implemented using firmware identifiers and hardware identifiers, then platform security is improved, but device complexity increases

Engineering Contradiction:
Improveplatform securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication of the PSU firmware identifier and hardware identifier before allowing the platform to transition from sleep state to active state. This preliminary verification ensures that only authenticated PSUs can provide power management data, preventing security vulnerabilities before they can cause harm to the platform

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that acts as a mediator between the PSU and the platform. The BMC firmware serves as an intermediary that verifies the PSU's firmware identifier against stored credentials and hardware identifiers, creating a trust layer that enhances security without requiring direct trust between the PSU and platform components

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PSU authentication is performed before power budget calculations, then data integrity is improved, but processing time increases

Engineering Contradiction:
Improvedata integrityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication of the PSU firmware identifier and hardware identifier is performed as a preliminary action before power budget calculations are executed. This ensures that only authenticated PSUs can provide power management data for budget calculations, guaranteeing data integrity while establishing a clear sequential process that minimizes redundant verification steps

Inventive Principle:
Principle #10Preliminary action

3Reliability

If trusted PSU verification is implemented, then platform trust zone security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvetrust zone securityVSAvoidPSU installation and configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a self-service authentication mechanism where the PSU automatically provides its firmware identifier and hardware identifier for verification. The BMC firmware automatically performs the authentication check against stored credentials, eliminating the need for manual configuration or intervention by system administrators, thus maintaining ease of operation while ensuring trust zone security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20230325536A1Power supply unit authentication
Publication Date: 2023.10.12 INTEL CORP
  • US20230325536A1 patent drawing
  • US20230325536A1 patent drawing
  • US20230325536A1 patent drawing

AI summary

Examples described herein relate to during a boot of a power supply unit (PSU) connected to a computer platform, circuitry to receive a firmware identifier and manufacturer identifier associated with the PSU and determine whether the PSU is approved to utilize. In some examples, based on, at least, authentication of the firmware identifier and manufacturer identifier of the PSU, the circuitry is to permit access to data and/or power from the PSU. In some examples, based on, at least, failure to authenticate the firmware identifier or manufacturer identifier of the PSU, the circuitry is to deny access to data and/or power from the PSU.