IP Library Granted Patent US 10,996,940
Granted Patent B1
US 10,996,940 · App. 16/565,370 · Granted May 4, 2021

Secure firmware integrity monitoring using rest over IPMI interface

Inventors: Oleksandr Podgorsky (Lilburn, GA); Igor Kulchytskyy (Lawrenceville, GA)
Assignee: AMERICAN MEGATRENDS INTERNATIONAL, LLC
G06F8/65G06F13/36G06F21/572G06F21/575G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,996,940
App. No.
16/565,370
Granted
May 4, 2021
Kind
B1
Abstract

Technologies are described herein for a representational state transfer (“REST” or “RESTful”) over Intelligent Platform Management Interface (“IPMI”) interface for firmware to BMC communication and applications thereof. These applications include, but are not limited to, remote firmware configuration, firmware updates, peripheral device firmware updates, provision of management information such as system inventory data, cloning and batch migration of firmware configuration settings, and firmware integrity monitoring. This functionality can be provided in a way that enables communication between BMCs and firmware to utilize modern manageability interfaces while maintaining backward compatibility with previous IPMI implementations.

Claims (34)

1. A computer-implemented method for verifying integrity of a firmware of a computing system, comprising:

receiving, at a management client, a current hash value for a first portion of the firmware from a baseboard management controller (BMC), the current hash value being computed by a second portion of the firmware and provided from the second portion of the firmware to the BMC by way of a representational state transfer (REST) over Intelligent Platform Management Interface (IPMI) interface;

receiving, at the management client, a reference hash value for the firmware from a firmware release server;

determining, at the management client, whether the reference hash value for the firmware and the current hash value for the firmware are different; and

responsive to determining that the reference hash value for the firmware and the current hash value for the firmware are different, initiating, by way of the management client, an update of the firmware.

2. The computer-implemented method of claim 1 , wherein the second portion of the firmware comprises a portion of the firmware that cannot be modified.

3. The computer-implemented method of claim 1 , wherein the first portion of the firmware comprises a remainder of the firmware other than the second portion.

4. The computer-implemented method of claim 1 , wherein the BMC is configured to store the current hash value in a secure location.

5. The computer-implemented method of claim 1 , wherein the reference hash value for the firmware is computed at a build time of the firmware.

6. The computer-implemented method of claim 1 , wherein the current hash value for the firmware is computed at a boot time of the computing system.

7. The computer-implemented method of claim 1 , wherein the BMC performs the update of the firmware.

8. A computing system, comprising:

one or more processors; and

at least one non-transitory computer-readable storage medium having computer-executable instructions stored thereupon which, when executed by the one or more processors, cause the system to:

receive, at a management client, a current hash value for a first portion of firmware from a baseboard management controller (BMC), the current hash value being computed by a second portion of the firmware and provided from the second portion of the firmware to the BMC by way of a representational state transfer (REST) over Intelligent Platform Management Interface (IPMI) interface;

receive, at the management client, a reference hash value for the firmware from a firmware release server;

determine, at the management client, whether the reference hash value for the firmware and the current hash value for the firmware are different; and

responsive to determining that the reference hash value for the firmware and the current hash value for the firmware are different, initiate, by way of the management client, an update of the firmware.

9. The computing system of claim 8 , wherein the second portion of the firmware comprises a portion of the firmware that cannot be modified.

10. The computing system of claim 8 , wherein the first portion of the firmware comprises a remainder of the firmware other than the second portion.

11. The computing system of claim 8 , wherein the BMC is configured to store the current hash value in a secure location.

12. The computing system of claim 8 , wherein the reference hash value for the firmware is computed at a build time of the firmware.

13. The computing system of claim 8 , wherein the current hash value for the firmware is computed at a boot time of the computing system.

14. A non-transitory computer-readable storage medium having computer-executable instructions stored thereupon which, when executed by a computer, cause the computer to:

receive, at a management client, a current hash value for a first portion of firmware from a baseboard management controller (BMC), the current hash value being computed by a second portion of the firmware and provided from the second portion of the firmware to the BMC by way of a representational state transfer (REST) over Intelligent Platform Management Interface (IPMI) interface;

receive, at the management client, a reference hash value for the firmware from a firmware release server;

determine, by way of the management client, whether the reference hash value for the firmware and the current hash value for the firmware are different; and

responsive to determining that the reference hash value for the firmware and the current hash value for the firmware are different, initiate, by way of the management client, an update of the firmware.

15. The non-transitory computer-readable storage medium of claim 14 , wherein the second portion of the firmware comprises a portion of the firmware that cannot be modified.

16. The non-transitory computer-readable storage medium of claim 14 , wherein the first portion of the firmware comprises a remainder of the firmware other than the second portion.

17. The non-transitory computer-readable storage medium of claim 14 , wherein the BMC is configured to store the current hash value in a secure location.

18. The non-transitory computer-readable storage medium of claim 14 , wherein the reference hash value for the firmware is computed at a build time of the firmware.

19. The non-transitory computer-readable storage medium of claim 14 , wherein the current hash value for the firmware is computed at a boot time of the computing system.

20. The non-transitory computer-readable storage medium of claim 14 , wherein the BMC performs the update of the firmware.

Assignments (5)
PATENT SECURITY AGREEMENT Recorded Oct 23, 2024
From: AMERICAN MEGATRENDS INTERNATIONAL, LLC
To: BAIN CAPITAL CREDIT, LP, AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 069229/0834 →
RELEASE OF SECURITY INTEREST Recorded Oct 17, 2024
From: MIDCAP FINANCIAL TRUST
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 069205/0948 →
SECURITY INTEREST Recorded Apr 30, 2024
From: AMERICAN MEGATRENDS INTERNATIONAL, LLC
To: MIDCAP FINANCIAL TRUST, AS COLLATERAL AGENT
Reel/Frame 067274/0834 →
ENTITY CONVERSION Recorded Feb 27, 2020
From: AMERICAN MEGATRENDS, INC.
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 052047/0684 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2019
From: PODGORSKY, OLEKSANDR; KULCHYTSKYY, IGOR
To: AMERICAN MEGATRENDS, INC.
Reel/Frame 050319/0866 →