IP Library › Granted Patent US 10,282,549
Granted Patent B2
US 10,282,549 · App. 15/451,830 · Granted May 7, 2019

Modifying service operating system of baseboard management controller

Inventors: Jorge Daniel Cisneros (Houston, TX); Lee A. Preimesberger (Houston, TX); Sean Pope (Houston, TX)
Assignee: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
G06F21/575G06F8/65H04L9/0891H04L9/3247G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,282,549
App. No.
15/451,830
Granted
May 7, 2019
Kind
B2
Abstract

In an example, a device comprises a baseboard management controller (BMC). The BMC comprises non-volatile storage storing a service operating system (OS). The BMC also comprises a processor. The processor may: receive, by a baseboard management controller (BMC), a request to modify the non-volatile storage, wherein the request comprises a signature, determine, by the BMC, based on a received signature, and a key for modifying the non-volatile storage, whether the request to modify the non-volatile storage is properly signed, and responsive to determining the request to modify the non-volatile storage is properly signed: allow modification of the non-volatile storage.

Claims (57)

1. A method, comprising:

receiving, by a baseboard management controller (BMC), a request to modify a service operating system (OS) stored on non-volatile storage, wherein the non-volatile storage is coupled to the BMC, and wherein the request comprises a signature;

determining, by the BMC, based on the received signature and a key for modifying the non-volatile storage, whether the request to modify the service OS is properly signed;

responsive to determining the request to modify the service OS is properly signed: allowing modification of the service OS;

generating, by the BMC, a new key for modifying the service OS;

generating, by the BMC, a signature for the service OS based on the new key for modifying the non-volatile storage;

reading, by the BMC, the signature of the service OS; and

determining, by the BMC, whether the service OS is properly signed based on the signature and the new key.

2. The method of claim 1 , wherein receiving the request comprises receiving the request via at least one of: a serial interface or a network interface of the BMC, wherein the at least one serial interface or network interface is coupled to a computing device separate from a computing device comprising the BMC.

3. The method of claim 1 , further comprising:

encrypting, by the BMC, the service OS based on the generated key.

4. The method of claim 1 , further comprising:

booting, by the BMC, the service OS responsive to determining that the service OS is properly signed; and

providing, by the BMC and to the service OS, an encryption key to verify data of the service OS.

5. The method of claim 1 , further comprising:

verifying, by the service OS, data of the non-volatile storage accessed by the service OS.

6. The method of claim 1 , further comprising:

verifying, by the BMC, a signature of a bootloader of the BMC before reading the service OS from the non-volatile storage.

7. A device comprising a baseboard management controller (BMC) comprising:

non-volatile storage comprising a service operating system (OS) stored thereon; and

a processor to:

receive, by a baseboard management controller (BMC), a request to modify the service OS, wherein the request comprises a signature;

determine, by the BMC, based on the received signature and a key for modifying the service OS, whether the request to modify the service OS is properly signed;

responsive to determining the request to modify the service OS is properly signed: allow modification of the service OS;

boot the service OS responsive to determining that the service OS is properly signed;

provide an encryption key to the service OS; and

verify, by the service OS, data of the service OS based on the provided encryption key.

8. The device of claim 7 , comprising:

at least one of: a network interface or a serial interface, wherein the at least one serial interface or network interface is coupled to a computing device separate from a computing device comprising the BMC;

wherein to receive the request, the processor to:

receive the request via the least one of the serial interface or network interface.

9. The device of claim 7 , wherein the processor to:

generate a new key for modifying the service OS; and

store the generated key.

10. The device of claim 9 , wherein the processor to:

encrypt the service OS based on the generated key.

11. The device of claim 7 , the processor to:

generate a signature of the service OS based on the generated key;

read a signature of the service operating system (OS); and

determine whether the service OS is properly signed based on the signature and the generated key.

12. The device of claim 7 , the processor to:

verify, by the BMC, a signature of a bootloader of the computing device before reading the service OS from the non-volatile storage.

13. A non-transitory computer-readable storage medium comprising instructions stored thereon that, when executed, cause a processor to:

receive, by a baseboard management controller (BMC), a request to modify a service operating system (OS), wherein the service OS is stored on non-volatile storage coupled to the BMC, wherein the request comprises a signature;

determine, by the BMC, based on the received signature and a key for modifying the service OS, whether the request to modify the service OS is properly signed;

responsive to determining the request to modify the service OS is properly signed: allow modification of the service OS

generate, by the BMC, a new key for modifying the service OS;

store, by the BMC, the generated key; and

encrypt, by the BMC, the non-volatile storage based on the generated key.

14. The non-transitory computer-readable storage medium of claim 13 , comprising instructions stored thereon that, when executed, cause the processor to:

generate, by the BMC, a signature of the service OS based on the generated key;

read, by the BMC, a signature of the service OS; and

verify, by the BMC, whether the service OS is properly signed based on the signature and a key for the service OS.

15. The non-transitory computer-readable storage medium of claim 14 , comprising instructions stored thereon that, when executed, cause the processor to:

boot, by the BMC, the service OS responsive to determining that the service OS is properly signed;

provide, by the BMC and to the service OS, an encryption key to verify data of the service OS; and

verify, by the service OS, data of the non-volatile storage accessed by the service OS.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2017
From: CISNEROS, JORGE DANIEL; PREIMESBERGER, LEE A.; POPE, SEAN
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 041484/0821 →
Continuity (1)
Related Publication 20180260568A1 · Sep 13, 2018