IP Library Granted Patent US 10,852,352
Granted Patent B2
US 10,852,352 · App. 16/171,215 · Granted Dec 1, 2020

System and method to secure FPGA card debug ports

Inventors: Johan Rahardjo (Austin, TX); Pavan Kumar Gavvala (Anantapur, IN)
Assignee: Dell Products, L.P.
G01R31/31719G01R31/3177G06F21/305G06F21/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,852,352
App. No.
16/171,215
Granted
Dec 1, 2020
Kind
B2
Abstract

Embodiments are described for securing access to a debug port of an FPGA (Field Programmable Gate Array) card installed within an IHS (Information Handling System). A remote access controller determines the status of the FPGA card debug port via a query to a management controller of the FPGA card. The remote access controller generates a passcode for the debug port and disables the debug port via a message to the management controller. The management controller detects a request, that includes a requestor password, for access to the debug port. The remote access controller authorizes the requestor's access to the debug port if the requestor password matches the generated passcode. The remote access controller disables the debug port upon each power cycle of the FPGA card or upon detecting removal of a device from the debug port.

Claims (43)

1. A method for securing access to an FPGA (Field Programmable Gate Array) card debug port by a remote access controller, the method comprising:

determining a status of the FPGA card debug port via a query to a management controller of the FPGA card;

detecting a coupling of a device to the debug port;

generating a passcode for the debug port, wherein the passcode is generated by hashing a serial number of the FPGA card concatenated with a service tag of the IHS (Information Handling System) in which the FPGA card is installed;

disabling the debug port via a message to the management controller;

detecting a request for access to the debug port by a requestor, wherein the request includes a requestor password;

providing the requestor access to the debug port, if the requestor password matches the generated passcode; and

disabling the debug port upon the next power cycle of the FPGA card.

2. The method of claim 1 , wherein the management controller communicates with a service processor of the remote access controller via a sideband management bus.

3. The method of claim 2 , wherein the service processor limits access to the generated passcode to authenticated administrators with access to the remote access controller.

4. The method of claim 1 , wherein the passcode is generated based on inputs provided via a user interface of the remote access controller.

5. The method of claim 1 , wherein, upon enabling of the debug port, the debug port is disabled upon detecting de-coupling of a device from the debug port.

6. The method of claim 5 , wherein the management controller detects the de-coupling of the device from the debug port and reports the disabling of the debug port to the remote access controller.

7. A system for securing access to a debug port of an FPGA (Field Programmable Gate Array) card installed in an Information Handling System (IHS), the system comprising:

a remote access controller configured to monitor operations of the IHS, the remote access controller configured to:

issue a query to a management controller of the FPGA card to determine a status of the FPGA card debug port;

generate a passcode for the debug port, wherein the passcode is generated by hashing a serial number of the FPGA card concatenated with a service tag of the IHS;

disable the debug port via a message to the management controller;

receive a request for access to the debug port, wherein the request includes a requestor password;

authorize access to the debug port by the requestor, if the requestor password matches the generated passcode; and

disable the debug port upon the next power cycle of the FPGA card; and

the management controller configured to:

determine the status of the debug port in response to the query from the remote access controller;

detect the coupling of a device to the debug port;

receive a request from the device for the requestor to access the debug port, wherein the request includes the requestor password; and

enable the debug port upon the authorization of the remote access controller.

8. The system of claim 7 , wherein the management controller communicates with a service processor of the remote access controller via a sideband management bus.

9. The system of claim 8 , wherein the service processor limits access to the generated passcode to authenticated administrators with access to the remote access controller.

10. The system of claim 7 , wherein the passcode is generated based on inputs provided via a user interface of the remote access controller.

11. The system of claim 7 , wherein, upon enabling of the debug port, the debug port is disabled upon detecting de-coupling of a device from the debug port.

12. The system of claim 5 , wherein the management controller detects the de-coupling of the device from the debug port and reports the disabling of the debug port to the remote access controller.

13. A remote access controller configured for securing access to an FPGA (Field Programmable Gate Array) card debug port, the remote access controller configured to:

determine a status of the FPGA card debug port via a query to a management controller of the FPGA card;

detect a coupling of a device to the debug port;

generate a passcode for the debug port, wherein the passcode is generated by hashing a serial number of the FPGA card concatenated with a service tag of the IHS (Information Handling System) in which the FPGA card is installed;

disable the debug port via a message to the management controller;

detect a request for access to the debug port by a requestor, wherein the request includes a requestor password;

provide the requestor access to the debug port if the requestor password matches the generated passcode; and

disable the debug port upon the next power cycle of the FPGA card.

14. The remote access controller of claim 13 , wherein the management controller communicates with a service processor of the remote access controller via a sideband management bus.

15. The remote access controller of claim 14 , wherein the service processor limits access to the generated passcode to authenticated administrators with access to the remote access controller.

16. The remote access controller of claim 13 , wherein the passcode is generated based on inputs provided via a user interface of the remote access controller.

17. The remote access controller of claim 13 , wherein, upon enabling of the debug port, the debug port is disabled upon detecting de-coupling of a device from the debug port.

Assignments (6)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 052771 FRAME 0906 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0298 →
SECURITY AGREEMENT Recorded May 28, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052771/0906 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2018
From: RAHARDJO, JOHAN; GAVVALA, PAVAN KUMAR
To: DELL PRODUCTS, L.P.
Reel/Frame 047316/0517 →
Continuity (1)
Related Publication 20200132761A1 · Apr 30, 2020
Cited By (1)
US 12,656,394