SPDM-Based BMC License Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber attackers exploit vulnerabilities in Baseboard Management Controllers (BMCs) to steal information and manipulate licenses, leading to security risks and revenue loss, as existing technologies lack effective mechanisms to ensure the integrity of BMC licenses throughout the service life of servers.

Innovation Solution

Implementing a Security Protocol and Data Model (SPDM)-based system that generates a Reference Integrity Measurement (RIM) for BMC licenses and compares it with actual measurements, generating an alert if they do not match, ensuring the integrity of BMC licenses and preventing unauthorized use of high-end features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If BMC licenses are stored and managed without integrity verification mechanisms, then ease of operation is improved, but reliability deteriorates due to security vulnerabilities and unauthorized license manipulation

Engineering Contradiction:
Improvelicense managementVSAvoidlicense integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A Reference Integrity Measurement (RIM) is generated and stored in a secure location before the license is deployed. This pre-established reference value serves as the basis for future integrity verification, allowing the system to proactively prevent unauthorized modifications rather than merely detecting them after occurrence.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors license integrity by comparing current license measurements against the stored RIM. When discrepancies are detected, the system generates alerts and takes corrective actions, creating a closed-loop feedback mechanism that maintains license integrity throughout the BMC's operational lifecycle.

Inventive Principle:
Principle #23Feedback

2Reliability

If SPDM-based integrity verification is implemented, then reliability is improved, but device complexity increases due to additional measurement and comparison mechanisms

Engineering Contradiction:
Improvelicense integrityVSAvoidverification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a dedicated integrity verification module that acts as an intermediary between the license storage and the BMC operational components. This specialized component handles all measurement and comparison operations, isolating the complexity from the core BMC functions while maintaining simplicity in the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of implementing complex verification logic throughout the entire BMC system, the patent creates a simplified copy of the license data in the form of a cryptographic hash (RIM). This copy serves as a lightweight representation that can be efficiently stored and compared without requiring the full complexity of the original license validation mechanisms.

Inventive Principle:
Principle #26Copying

3Reliability

If continuous license monitoring is implemented, then reliability is improved, but loss of energy increases due to ongoing measurement and comparison operations

Engineering Contradiction:
Improvelicense integrityVSAvoidverification operations
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The integrity verification is performed periodically at predetermined intervals rather than continuously. This approach maintains adequate security monitoring while significantly reducing energy consumption compared to continuous verification. The periodic checks occur at strategically chosen moments such as during system boot, license updates, or scheduled maintenance windows.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent uses lightweight cryptographic hash functions to create compact RIM values that require minimal computational resources to generate and compare. These simplified verification objects consume far less energy than full license validation processes, enabling frequent or periodic checks without significant energy overhead.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS20240281515A1Context information management system and method for SPDM-enabled devices
Publication Date: 2024.08.22 DELL PROD LP
  • US20240281515A1 patent drawing
  • US20240281515A1 patent drawing
  • US20240281515A1 patent drawing

AI summary

According to embodiments of the present disclosure, an Information Handling System (IHS) includes a Security Protocol and Data Model (SPDM)-enabled device, and executable instructions that may be executed to obtain a SPDM-based measurement of a license associated with the SPDM-enabled device, compare the measurement against a Reference Integrity Measurement (RIM) initially generated for the SPDM-enabled device, and when the measurement and the RIM do not match, generate an alert message indicating that the license is invalid.