SPDM Session Management via BMC Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SPDM-based attestation systems do not provide a method to manage multiple secure communication sessions, leading to issues when multiple applications within a BMC require concurrent access to secure sessions, especially when the SPDM-enabled device supports fewer sessions than needed.
Innovation Solution
The proposed system and method manage SPDM secure communication sessions by determining whether a private communication session is available when an application requests one, and enabling the application to communicate with the SPDM-enabled device through that session based on the availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple applications request concurrent access to secure SPDM sessions, then the system's ability to handle concurrent secure communication needs is improved, but the SPDM-enabled device supports fewer sessions than required
Solution Approach 1:
The BMC acts as an intermediary between multiple applications and the SPDM-enabled device. It manages the limited secure sessions by allocating them to different applications through a queue management system, allowing multiple applications to access secure communication capabilities even when the device supports fewer sessions than needed.
Solution Approach 2:
The system implements dynamic session management where the BMC can allocate, release, and reassign secure sessions based on application needs. Applications can be placed in a queue and granted access to sessions as they become available, enabling flexible concurrent access to a limited number of sessions.
2Device complexity
If the SPDM-enabled device supports fewer secure sessions than needed, then device complexity is reduced, but multiple applications cannot access secure sessions concurrently
Solution Approach 1:
The BMC provides universal session management functionality that serves multiple applications through a single interface. It implements a queue management system that handles session allocation, waiting, and access for multiple applications, allowing the system to support more applications than the number of physical sessions available.
3Reliability
If a queue management system is implemented to manage limited secure sessions, then session availability is improved, but system complexity increases
Solution Approach 1:
The queue management system operates autonomously within the BMC, automatically allocating sessions to applications based on availability without requiring external intervention. The system self-manages the queue operations, session allocation, and application access, reducing the need for complex external control mechanisms.
Data Source
AI summary
According to embodiments of the present disclosure, systems and methods to manage Security Protocol and Data Model (SPDM) secure communication sessions are provided. According to one embodiment, an Information Handling System (IHS) includes a Security Protocol and Data Model (SPDM)-enabled device conforming to a SPDM specification in which the SPDM-enabled device has a specified quantity of supported private communication sessions. The IHS also includes computer-executable instructions to, when an application requests use of one of the private communication sessions, determine whether one of the private communication sessions is available, and enable the application to communicate with the SPDM-enabled device through the one private communication session based on the determination.


