SPDM Session Management via BMC Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SPDM-based attestation systems do not provide a method to manage multiple secure communication sessions, leading to issues when multiple applications within a BMC require concurrent access to secure sessions, especially when the SPDM-enabled device supports fewer sessions than needed.

Innovation Solution

The proposed system and method manage SPDM secure communication sessions by determining whether a private communication session is available when an application requests one, and enabling the application to communicate with the SPDM-enabled device through that session based on the availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple applications request concurrent access to secure SPDM sessions, then the system's ability to handle concurrent secure communication needs is improved, but the SPDM-enabled device supports fewer sessions than required

Engineering Contradiction:
Improveconcurrent secure communication capabilityVSAvoidnumber of supported sessions
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The BMC acts as an intermediary between multiple applications and the SPDM-enabled device. It manages the limited secure sessions by allocating them to different applications through a queue management system, allowing multiple applications to access secure communication capabilities even when the device supports fewer sessions than needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements dynamic session management where the BMC can allocate, release, and reassign secure sessions based on application needs. Applications can be placed in a queue and granted access to sessions as they become available, enabling flexible concurrent access to a limited number of sessions.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If the SPDM-enabled device supports fewer secure sessions than needed, then device complexity is reduced, but multiple applications cannot access secure sessions concurrently

Engineering Contradiction:
Improvesession management complexityVSAvoidconcurrent access capability
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The BMC provides universal session management functionality that serves multiple applications through a single interface. It implements a queue management system that handles session allocation, waiting, and access for multiple applications, allowing the system to support more applications than the number of physical sessions available.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a queue management system is implemented to manage limited secure sessions, then session availability is improved, but system complexity increases

Engineering Contradiction:
Improvesession availabilityVSAvoidsession management overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The queue management system operates autonomously within the BMC, automatically allocating sessions to applications based on availability without requiring external intervention. The system self-manages the queue operations, session allocation, and application access, reducing the need for complex external control mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12287908B2Systems and methods to manage security protocol and data model (SPDM) secure communication sessions
Publication Date: 2025.04.29 DELL PROD LP
  • US12287908B2 patent drawing
  • US12287908B2 patent drawing
  • US12287908B2 patent drawing

AI summary

According to embodiments of the present disclosure, systems and methods to manage Security Protocol and Data Model (SPDM) secure communication sessions are provided. According to one embodiment, an Information Handling System (IHS) includes a Security Protocol and Data Model (SPDM)-enabled device conforming to a SPDM specification in which the SPDM-enabled device has a specified quantity of supported private communication sessions. The IHS also includes computer-executable instructions to, when an application requests use of one of the private communication sessions, determine whether one of the private communication sessions is available, and enable the application to communicate with the SPDM-enabled device through the one private communication session based on the determination.