Management controller resource usage by a security processor
In some examples, an electronic device includes a host processor, a security processor separate from the host processor, and a management controller separate from the host processor. The security processor loads agent instructions associated with the security processor to the management controller, and sends, from the security processor to the agent instructions executing on the management controller, an indication to execute identified machine-readable instructions. The agent instructions when executed on the management controller cause the management controller to, based on the indication, execute the identified machine-readable instructions that employ a resource of the management controller, and provide, from the management controller to the security processor, a result of a process that employs the resource of the management controller.
1 . An electronic device comprising:
a host processor;
a security processor separate from the host processor;
a management controller separate from the host processor, the management controller to perform management tasks of the electronic device; and
a bus connecting the management controller and the security processor,
the security processor to:
send agent instructions associated with the security processor over the bus to the management controller, wherein the security processor is to leverage use of a resource of the management controller based on execution of the agent instructions on the management controller,
send, from the security processor to the agent instructions executing on the management controller, an indication to execute identified machine-readable instructions,
the agent instructions when executed on the management controller causing the management controller to:
based on the indication, execute the identified machine-readable instructions that employ the resource of the management controller, and
provide, from the management controller to the security processor, a result of a process that employs the resource of the management controller.
2 . The electronic device of claim 1 , wherein the security processor is to:
check program code stored at the management controller to determine a validity of the program code, and
send the agent instructions over the bus to the management controller based on the check indicating that the program code of the management controller is invalid.
3 . The electronic device of claim 2 , wherein the program code comprises firmware of the management controller, and wherein the security processor declines to load a boot block in the firmware to the management controller based on the check indicating that the program code of the management controller is invalid.
4 . The electronic device of claim 2 , wherein the resource of the management controller comprises a network interface of the management controller, and the security processor is to leverage use of the network interface based on execution of the agent instructions on the management controller, and wherein the agent instructions when executed on the management controller cause the management controller to:
execute the identified machine-readable instructions to enable the network interface of the management controller, and
retrieve, using the enabled network interface, program code from a storage location over a network,
wherein the result provided from the management controller to the security processor comprises the retrieved program code.
5 . The electronic device of claim 4 , wherein the security processor is to instruct the agent instructions to retrieve the program code from the storage location, by providing the agent instructions with location information of the program code.
6 . The electronic device of claim 4 , wherein the security processor is to:
load, over the bus, the retrieved program code to the management controller to execute at the management controller.
7 . The electronic device of claim 6 , wherein the security processor is to:
check the retrieved program code to determine a validity of the retrieved program code,
wherein the loading of the retrieved program code over the bus to the management controller is performed responsive to the security processor determining that the retrieved program code is valid.
8 . The electronic device of claim 6 , wherein the loading of the retrieved program code over the bus to the management controller causes replacement of the program code previously loaded in the management controller with the retrieved program code.
9 . The electronic device of claim 4 , wherein a remaining portion of the management controller remains disabled while the network interface is enabled.
10 . The electronic device of claim 1 , wherein the resource of the management controller comprises a network interface of the management controller, and wherein the agent instructions when executed on the management controller cause the management controller to:
execute the identified machine-readable instructions to enable the network interface of the management controller, and
wherein the security processor is to:
send, to the management controller, a ping indication that is to be sent to a remote resource over a network through the network interface of the management controller,
receive a response to the ping indication from the management controller, and
confirm that the network interface is enabled based on receipt of the response to the ping indication.
11 . The electronic device of claim 1 , wherein the resource of the management controller comprises a processing resource of the management controller, and the security processor is to leverage use of the processing resource based on execution of the agent instructions on the management controller, and wherein the identified machine-readable instructions are executed on the processing resource of the management controller.
12 . The electronic device of claim 11 , wherein the execution of the identified machine-readable instructions on the processing resource of the management controller causes a measurement of the management controller.
13 . The electronic device of claim 12 , wherein the measurement of the management controller comprises a measurement of information in one or more components of the management controller.
14 . The electronic device of claim 12 , wherein the measurement of the management controller comprises a measurement of configuration information in the management controller.
15 . A non-transitory machine-readable storage medium comprising instructions that upon execution cause a security processor in an electronic device to:
load agent instructions associated with the security processor to a management controller, wherein the security processor and the management controller are separate from a host processor of the electronic device;
check a program code of the management controller in a memory;
based on determining that the program code of the management controller is invalid, instruct the agent instructions executed on the management controller to enable a network interface of the management controller, and retrieve a replacement program code through the enabled network interface;
replace the program code in the memory with the replacement program code; and
send the replacement program code to the management controller for execution at the management controller.
16 . The non-transitory machine-readable storage medium of claim 15 , wherein the replacement program code comprises firmware of the management controller, and the sending of the replacement program code to the management controller comprises sending a boot block of the firmware from the security processor over a bus to the management controller to initiate a boot process of the management controller.
17 . The non-transitory machine-readable storage medium of claim 15 , wherein the instructions upon execution cause the security processor to:
instruct the agent instructions executed on the management controller to measure information at the management controller; and
receive, at the security processor, a result of the measurement over a bus from the management controller.
18 . A method comprising:
sending, agent instructions from a security processor over a bus to a management controller, wherein the security processor performs security tasks of an electronic device, and the management controller performs management tasks of the electronic device, wherein the security processor and the management controller are separate from a host processor of the electronic device, and wherein the security processor is to leverage use of a resource of the management controller on behalf of the security processor based on execution of the agent instructions on the management controller;
sending, from the security processor to the agent instructions executing on the management controller, an indication to execute identified machine-readable instructions that allow the security processor to leverage the use of the resource of the management controller on behalf of the security processor;
executing, at the management controller, a process that employs the resource of the management controller; and
sending, from the management controller to the security processor, a result of the process that employs the resource of the management controller.
19 . The method of claim 18 , wherein the identified machine-readable instructions when executed at the management controller enable a network interface of the management controller, and the process employs the enabled network interface.
20 . The method of claim 19 , comprising:
instructing, by the security processor, the agent instructions to retrieve a replacement program code using the enabled network interface;
receiving, by the security processor over the bus from the management controller, the replacement program code;
checking, by the security processor, a validity of the replacement program code; and
causing execution of the replacement program code at the management controller based on determining that the replacement program code is valid.