IP Library Granted Patent US 11,847,226
Granted Patent B1
US 11,847,226 · App. 17/104,910 · Granted Dec 19, 2023

Baseboard Management Controller (BMC)-based security processor

Inventors: Stefano Righi (Lawrenceville, GA); Umasankar Mondal (Snellville, GA); Sanjoy Maity (Snellville, GA)
Assignee: AMERICAN MEGATRENDS INTERNATIONAL, LLC
G06F21/572G06F13/4063G06F13/4282G06F21/53G06F21/74G06F2213/0016G06F2213/0038
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,847,226
App. No.
17/104,910
Granted
Dec 19, 2023
Kind
B1
Abstract

Technologies are described herein for providing a Baseboard Management Controller (“BMC”)-based security processor. The disclosed BMC-based security processor can provide a hardware Root of Trust (“RoT”) for a computing platform without the addition of specialized silicon to the platform and while minimizing the number of attack points. The disclosed BMC-based security processor can also provide functionality for securely filtering requests made on certain buses in a computing platform. Through implementations of the features identified briefly above, and others described herein, various technical benefits can be achieved such as, but not limited to, increased security as compared to previous computing systems that utilize a BMC to provide a hardware RoT and reduced complexity and cost as compared to previous computing systems that utilize a separate hardware device, such as a Field Programmable Gate Array (“FPGA”) or a microcontroller, to provide a hardware RoT.

Claims (41)

1. A baseboard management controller (BMC) system on chip (SOC), comprising:

a first processor providing a first execution environment, the first processor configured to execute a management subsystem in the first execution environment to provide BMC functionality for a host computer; and

a second processor providing a second execution environment, the second execution environment comprising a secure environment having a bus of the host computer assigned thereto, and wherein the second processor is configured to execute a security subsystem in the second execution environment, the security subsystem configured to enable access to a device connected to the bus by:

receiving a request on the bus to perform an operation on the device;

determining if the request is valid;

responsive to determining the request is not valid, returning an error responsive to the request; and

responsive to determining the request is valid, passing the request to the device of the host computer.

2. The BMC SOC of claim 1 , wherein the device comprises a memory device storing a firmware for the BMC SOC, the firmware comprising the management subsystem and the security subsystem.

3. The BMC SOC of claim 1 , wherein the device comprises a memory device storing a firmware for the host computer.

4. The BMC SOC of claim 1 , wherein the request is received on an enhanced serial peripheral interface (ESDI) bus and wherein the device comprises a serial peripheral interface (SPI) device.

5. The BMC SOC of claim 1 , wherein the request is received on an enhanced serial peripheral interface (ESDI) bus and wherein the device comprises an I 2 C device.

6. The BMC SOC of claim 1 , wherein the request is received on a system management bus (SMB) and wherein the device comprises an SMB device.

7. The BMC SOC of claim 1 , wherein the request is received on a system management bus (SMB) and wherein the device comprises a general purpose input/output (GPIO) device.

8. A computer-implemented method, comprising:

operating a first processor of a baseboard management controller (BMC) system on chip (SOC), the first processor configured to execute a management subsystem in a normal first execution environment to provide BMC functionality for a host computer; and

operating a second processor of the BMC SOC configured to provide a secure second execution environment comprising a secure environment, wherein the secure environment has a bus of the host computer assigned thereto, and wherein the second processor is configured to execute a security subsystem in the secure environment configured to enable access to a device on the bus by:

receiving a request on the bus to perform an operation on the device;

determining if the request is valid;

responsive to determining the request is not valid, returning an error responsive to the request; and

responsive to determining the request is valid, passing the request to the device of the host computer.

9. The computer-implemented method of claim 8 , wherein the device comprises a memory device storing a firmware for the BMC SOC, the firmware comprising the management subsystem and the security subsystem.

10. The computer-implemented method of claim 8 , wherein the device comprises a memory device storing a firmware for the host computer.

11. The computer-implemented method of claim 8 , wherein the request is received on an enhanced serial peripheral interface (ESPI) bus and wherein the device comprises a serial peripheral interface (SPI) device.

12. The computer-implemented method of claim 8 , wherein the request is received on an enhanced serial peripheral interface (ESPI) bus and wherein the device comprises an I 2 C device.

13. The computer-implemented method of claim 8 , wherein the request is received on a system management bus (SMB) and wherein the device comprises an SMB device.

14. The computer-implemented method of claim 8 , wherein the request is received on a system management bus (SMB) and wherein the device comprises a general purpose input/output (GPIO) device.

15. A computing system, comprising:

a bus;

a device; and

a baseboard management controller (BMC) system on chip (SOC), comprising:

a first processor providing a first execution environment, the first processor configured to execute a management subsystem in the first execution environment to provide BMC functionality for the computing system; and

a second processor providing a second execution environment, wherein the second processor has the bus assigned thereto, and wherein the second processor is configured to execute a security subsystem in the second execution environment configured to enable access to a device on the bus by:

receiving a request on the bus to perform an operation on the device;

determining if the request is valid;

responsive to determining the request is not valid, returning an error responsive to the request; and

responsive to determining the request is valid, passing the request to the device.

16. The computing system of claim 15 , wherein the device comprises a memory device storing a firmware for the BMC SOC, the firmware comprising the management subsystem and the security subsystem.

17. The computing system of claim 15 , wherein the device comprises a memory device storing a firmware for the computing system.

18. The computing system of claim 15 , wherein the request is received on an enhanced serial peripheral interface (ESPI) bus and wherein the device comprises a serial peripheral interface (SPI) device.

19. The computing system of claim 15 , wherein the request is received on an enhanced serial peripheral interface (ESPI) bus and wherein the device comprises an I 2 C device.

20. The computing system of claim 15 , wherein the request is received on a system management bus (SMB) and wherein the device comprises an SMB device or a general purpose input/output (GPIO) device.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Oct 23, 2024
From: AMERICAN MEGATRENDS INTERNATIONAL, LLC
To: BAIN CAPITAL CREDIT, LP, AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 069229/0834 →
RELEASE OF SECURITY INTEREST Recorded Oct 17, 2024
From: MIDCAP FINANCIAL TRUST
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 069205/0948 →
SECURITY INTEREST Recorded Apr 30, 2024
From: AMERICAN MEGATRENDS INTERNATIONAL, LLC
To: MIDCAP FINANCIAL TRUST, AS COLLATERAL AGENT
Reel/Frame 067274/0834 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2020
From: RIGHI, STEFANO; MONDAL, UMASANKAR; MAITY, SANJOY
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 054471/0440 →
Cited By (1)
US 12,517,985