Power Supply Unit Authentication via Firmware Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Server platforms face security vulnerabilities due to untrusted Power Supply Units (PSUs) that can impair operation by tampering with power management data, leading to potential data exposure and weakened security components.
Innovation Solution
Implementing a secure firmware identifier for each PSU, binding it with hardware identifiers and authenticating before power budget calculations, ensuring only trusted PSUs can transition the platform from a reduced power state to a higher power state, thereby establishing a trust zone for power data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PSU authentication is implemented using firmware identifiers and hardware identifiers, then platform security is improved, but device complexity increases
Solution Approach 1:
The patent implements preliminary authentication of the PSU firmware identifier and hardware identifier before allowing the platform to transition from sleep state to active state. This preliminary verification ensures that only authenticated PSUs can provide power management data, preventing security vulnerabilities before they can cause harm to the platform
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that acts as a mediator between the PSU and the platform. The BMC firmware serves as an intermediary that verifies the PSU's firmware identifier against stored credentials and hardware identifiers, creating a trust layer that enhances security without requiring direct trust between the PSU and platform components
2Reliability
If PSU authentication is performed before power budget calculations, then data integrity is improved, but processing time increases
Solution Approach 1:
The authentication of the PSU firmware identifier and hardware identifier is performed as a preliminary action before power budget calculations are executed. This ensures that only authenticated PSUs can provide power management data for budget calculations, guaranteeing data integrity while establishing a clear sequential process that minimizes redundant verification steps
3Reliability
If trusted PSU verification is implemented, then platform trust zone security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements a self-service authentication mechanism where the PSU automatically provides its firmware identifier and hardware identifier for verification. The BMC firmware automatically performs the authentication check against stored credentials, eliminating the need for manual configuration or intervention by system administrators, thus maintaining ease of operation while ensuring trust zone security
Data Source
AI summary
Examples described herein relate to during a boot of a power supply unit (PSU) connected to a computer platform, circuitry to receive a firmware identifier and manufacturer identifier associated with the PSU and determine whether the PSU is approved to utilize. In some examples, based on, at least, authentication of the firmware identifier and manufacturer identifier of the PSU, the circuitry is to permit access to data and/or power from the PSU. In some examples, based on, at least, failure to authenticate the firmware identifier or manufacturer identifier of the PSU, the circuitry is to deny access to data and/or power from the PSU.


